Pub Internet (Cid), virus attrappé par msn [Resolu] - Sécurité - Virus
TomsGuide.com : 700 000 inscrits répondent à toutes vos questions high-tech et informatique.
Pour obtenir de l'aide, inscrivez-vous gratuitement !
 




Mot :   Pseudo :  
 
 Page : 1 2
Page Précédente
Auteur
 Sujet : Pub Internet (Cid), virus attrappé par msn [Resolu]
 
Profil : IDNaute
Plus d'informations

Bonjour,

J'ai un souci avec des pubs internet qui s'ouvrent toutes seules, je pense à des Cid.

Si quelqu'un peut m'aider merci à vous.

Ps: si ça peut aider, j'ai OTMoveIt, HijackThis et CCleaner.


Message édité par Gnondpom@IDN le 13-02-2008 à 23:37:38
Liens sponsorisés


Inscrivez-vous ou connectez-vous pour masquer ceci.

Profil : Helper
Plus d'informations

Bonjour,

Télécharge Lop S&D.exe sur ton Bureau.

  • Double-clique dessus pour lancer l'installation
  • Puis double-clique sur le raccourci Lop S&D présent sur ton Bureau
  • Séléctionne la langue souhaitée , puis choisis l'option 1 (Recherche)
  • Patiente jusqu'à la fin du scan
  • Poste le rapport généré (C:\lopR.txt)


(Si le Bureau ne réapparait pas presse Ctrl + Alt + Suppr , Onglet Fichier , Nouvelle tâche , tape explorer.exe et valide)


---------------
Prévention & Protection|Les logiciels gratuits|L'homme du FLCCF
Profil : IDNaute
Plus d'informations

Voilà le rapport:


-----------------------------[ Lop S&D 2.0.8 ]---------------------------

[ Windows XP (NT 5.1) Build 2600, Service Pack 2 ]

[ USER: POULLY ] [ "C:\Program Files\Lop SD" ]

[ 21/01/2008 | 13:39:13.00 ] [ YANNICK ]

[ MAJ : 21-01-2008 | 13.15 ]


-------------[ Listing des dossiers dans Application Data ]------------

[30/07/2007|15:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Grisoft
[30/07/2007|15:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\..
[30/07/2007|15:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\.
[10/04/2007|13:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!
[22/03/2007|19:43] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WinZip
[11/02/2007|18:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Zylom
[06/10/2006|15:40] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[06/10/2006|15:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Real
[22/09/2006|14:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Macrovision
[21/09/2006|19:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\PC Suite
[21/09/2006|19:46] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Downloaded Installations
[30/06/2006|09:05] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[14/02/2006|17:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[25/01/2006|19:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[25/01/2006|14:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\desktop.ini


[25/01/2006|14:48] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
[25/01/2006|14:36] C:\DOCUME~1\DEFAUL~1\APPLIC~1\desktop.ini
[25/01/2006|14:36] C:\DOCUME~1\DEFAUL~1\APPLIC~1\..
[25/01/2006|14:36] C:\DOCUME~1\DEFAUL~1\APPLIC~1\.



[30/09/2006|16:50] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft
[25/01/2006|14:53] C:\DOCUME~1\LOCALS~1\APPLIC~1\..
[25/01/2006|14:53] C:\DOCUME~1\LOCALS~1\APPLIC~1\.

[25/01/2006|14:53] C:\DOCUME~1\NETWOR~1\APPLIC~1\..
[25/01/2006|14:53] C:\DOCUME~1\NETWOR~1\APPLIC~1\.
[25/01/2006|14:48] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft

[21/01/2008|13:37] C:\DOCUME~1\POULLY\APPLIC~1\OpenOffice.org2
[14/01/2008|14:08] C:\DOCUME~1\POULLY\APPLIC~1\mIRC
[01/01/2008|14:59] C:\DOCUME~1\POULLY\APPLIC~1\LimeWire
[26/12/2007|15:45] C:\DOCUME~1\POULLY\APPLIC~1\..
[26/12/2007|15:45] C:\DOCUME~1\POULLY\APPLIC~1\.
[01/04/2007|20:49] C:\DOCUME~1\POULLY\APPLIC~1\Microsoft
[12/02/2007|19:36] C:\DOCUME~1\POULLY\APPLIC~1\Ahead
[22/01/2007|23:53] C:\DOCUME~1\POULLY\APPLIC~1\vlc
[29/10/2006|23:19] C:\DOCUME~1\POULLY\APPLIC~1\Real
[06/10/2006|15:57] C:\DOCUME~1\POULLY\APPLIC~1\Media Player Classic
[21/09/2006|14:03] C:\DOCUME~1\POULLY\APPLIC~1\PC Suite
[15/05/2006|19:15] C:\DOCUME~1\POULLY\APPLIC~1\Sun
[27/02/2006|18:57] C:\DOCUME~1\POULLY\APPLIC~1\Help
[07/02/2006|13:23] C:\DOCUME~1\POULLY\APPLIC~1\AdobeUM
[07/02/2006|13:22] C:\DOCUME~1\POULLY\APPLIC~1\Adobe
[25/01/2006|20:53] C:\DOCUME~1\POULLY\APPLIC~1\Macromedia
[25/01/2006|19:38] C:\DOCUME~1\POULLY\APPLIC~1\Lavasoft
[25/01/2006|14:54] C:\DOCUME~1\POULLY\APPLIC~1\Identities

----------------[ Tâches planifiées dans C:\WINDOWS\tasks ]---------------

[21/01/2008 12:00][--ah-----] C:\WINDOWS\tasks\A8684309916FFBA9.job
[21/01/2008 13:37][--ah-----] C:\WINDOWS\tasks\SA.DAT
[30/08/2002 13:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini

---------------[ Listing des dossiers dans C:\Program Files ]--------------

[21/01/2008|13:39] C:\Program Files\Lop SD
[21/01/2008|13:33] C:\Program Files\..
[21/01/2008|13:33] C:\Program Files\.
[21/01/2008|12:00] C:\Program Files\Helper
[17/01/2008|21:47] C:\Program Files\Temporary
[17/01/2008|19:15] C:\Program Files\Dot1XCfg
[16/01/2008|22:00] C:\Program Files\eChanblard
[09/01/2008|16:31] C:\Program Files\eMule
[21/12/2007|16:27] C:\Program Files\Messenger Plus! Live
[21/12/2007|16:27] C:\Program Files\MSN Messenger
[11/12/2007|23:47] C:\Program Files\Internet Explorer
[19/11/2007|18:42] C:\Program Files\flashget196en.exe
[12/11/2007|18:51] C:\Program Files\LimeWire
[12/11/2007|18:22] C:\Program Files\LimeWireWin.exe
[15/10/2007|14:34] C:\Program Files\Java
[09/10/2007|15:39] C:\Program Files\MSN plus
[09/10/2007|15:39] C:\Program Files\Multimedia V3.54
[03/10/2007|16:17] C:\Program Files\eMule0.48a-Installer.exe
[26/09/2007|14:27] C:\Program Files\MSN Reaper
[02/09/2007|21:06] C:\Program Files\eChanblard.exe
[14/06/2007|21:13] C:\Program Files\Windows Live
[12/06/2007|22:34] C:\Program Files\Outlook Express
[08/05/2007|12:23] C:\Program Files\WinRAR
[08/04/2007|16:57] C:\Program Files\CCleaner
[02/04/2007|23:26] C:\Program Files\Grisoft
[01/04/2007|10:43] C:\Program Files\PC Camera
[22/03/2007|23:54] C:\Program Files\BitComet
[07/03/2007|18:19] C:\Program Files\Free
[07/03/2007|16:42] C:\Program Files\Fichiers communs
[07/03/2007|16:18] C:\Program Files\NETGEAR
[07/03/2007|16:18] C:\Program Files\NETGEAR(2)
[22/01/2007|21:42] C:\Program Files\VideoLAN
[09/11/2006|18:14] C:\Program Files\Windows Media Player
[09/11/2006|18:05] C:\Program Files\Windows Media Connect 2
[09/11/2006|17:41] C:\Program Files\windows media player 11
[09/11/2006|17:28] C:\Program Files\Windows NT
[06/10/2006|15:40] C:\Program Files\K-Lite Codec Pack
[23/09/2006|15:55] C:\Program Files\Jeux t‚l‚charg‚
[22/09/2006|15:02] C:\Program Files\Boonty
[22/09/2006|15:02] C:\Program Files\BoontyGames
[22/09/2006|14:51] C:\Program Files\Mes Jeux T‚l‚charg‚s
[21/09/2006|19:47] C:\Program Files\DIFX
[11/04/2006|20:36] C:\Program Files\Bearshare
[22/03/2006|18:55] C:\Program Files\JEUX MONOPOLY
[09/02/2006|15:37] C:\Program Files\essai convertisseur
[04/02/2006|14:28] C:\Program Files\Oxilog
[04/02/2006|12:04] C:\Program Files\C-Media 3D Audio
[02/02/2006|16:29] C:\Program Files\InstallShield Installation Information
[28/01/2006|14:33] C:\Program Files\SigmaTel
[25/01/2006|21:09] C:\Program Files\Messenger
[25/01/2006|19:37] C:\Program Files\Lavasoft
[25/01/2006|19:37] C:\Program Files\PowerArchiver
[25/01/2006|19:36] C:\Program Files\Adobe
[25/01/2006|19:33] C:\Program Files\OpenOffice.org 2.0
[25/01/2006|19:30] C:\Program Files\Alwil Software
[25/01/2006|16:32] C:\Program Files\Ahead
[25/01/2006|16:16] C:\Program Files\Movie Maker
[25/01/2006|16:13] C:\Program Files\NetMeeting
[25/01/2006|15:56] C:\Program Files\SiSLan
[25/01/2006|14:54] C:\Program Files\Uninstall Information
[25/01/2006|14:49] C:\Program Files\xerox
[25/01/2006|14:49] C:\Program Files\microsoft frontpage
[25/01/2006|14:47] C:\Program Files\Services en ligne
[25/01/2006|14:44] C:\Program Files\ComPlus Applications
[25/01/2006|14:44] C:\Program Files\WindowsUpdate
[25/01/2006|14:44] C:\Program Files\MSN Gaming Zone

------[ Listing des dossiers dans C:\Program Files\Fichiers communs ]------

[12/06/2007|22:34] C:\Program Files\Fichiers communs\System
[01/04/2007|19:22] C:\Program Files\Fichiers communs\Microsoft Shared
[07/03/2007|16:42] C:\Program Files\Fichiers communs\..
[07/03/2007|16:42] C:\Program Files\Fichiers communs\.
[12/02/2007|19:31] C:\Program Files\Fichiers communs\Nero
[12/02/2007|19:30] C:\Program Files\Fichiers communs\LightScribe
[22/09/2006|14:52] C:\Program Files\Fichiers communs\Macrovision Shared
[10/05/2006|19:48] C:\Program Files\Fichiers communs\Java
[09/02/2006|15:37] C:\Program Files\Fichiers communs\MimarSinan
[07/02/2006|13:22] C:\Program Files\Fichiers communs\Adobe
[02/02/2006|16:29] C:\Program Files\Fichiers communs\InstallShield
[25/01/2006|16:29] C:\Program Files\Fichiers communs\Ahead
[25/01/2006|14:46] C:\Program Files\Fichiers communs\Services
[25/01/2006|14:46] C:\Program Files\Fichiers communs\MSSoap
[25/01/2006|14:37] C:\Program Files\Fichiers communs\ODBC
[25/01/2006|14:37] C:\Program Files\Fichiers communs\SpeechEngines

----------------------[ Recherche avec S_Lop ]---------------------

Aucun fichier / dossier Lop trouvé !

-----------------[ Recherche de Fichiers / Dossiers Lop ]-----------------

C:\WINDOWS\Tasks\A8684309916FFBA9.job

----------------------[ Verification du Registre ]----------------------

..... OK !

--------------------[ Verification du fichier Hosts ]---------------------

Fichier Hosts MODIFIE

127.0.0.1 localhost
127.0.0.1 bin.errorprotector.com ## added by CiD
127.0.0.1 br.errorsafe.com ## added by CiD
127.0.0.1 br.winantivirus.com ## added by CiD
127.0.0.1 br.winfixer.com ## added by CiD
127.0.0.1 cdn.drivecleaner.com ## added by CiD
127.0.0.1 cdn.errorsafe.com ## added by CiD
127.0.0.1 cdn.winsoftware.com ## added by CiD
127.0.0.1 de.errorsafe.com ## added by CiD
127.0.0.1 de.winantivirus.com ## added by CiD
127.0.0.1 download.cdn.drivecleaner.com ## added by CiD
127.0.0.1 download.cdn.errorsafe.com ## added by CiD
127.0.0.1 download.cdn.winsoftware.com ## added by CiD
127.0.0.1 download.errorsafe.com ## added by CiD
127.0.0.1 download.systemdoctor.com ## added by CiD
127.0.0.1 download.winantispyware.com ## added by CiD
127.0.0.1 download.windrivecleaner.com ## added by CiD
127.0.0.1 download.winfixer.com ## added by CiD
127.0.0.1 drivecleaner.com ## added by CiD
127.0.0.1 dynamique.drivecleaner.com ## added by CiD
127.0.0.1 errorprotector.com ## added by CiD
127.0.0.1 errorsafe.com ## added by CiD
127.0.0.1 es.winantivirus.com ## added by CiD
127.0.0.1 fr.winantivirus.com ## added by CiD
127.0.0.1 fr.winfixer.com ## added by CiD
127.0.0.1 go.drivecleaner.com ## added by CiD
127.0.0.1 go.errorsafe.com ## added by CiD
127.0.0.1 go.winantispyware.com ## added by CiD
127.0.0.1 go.winantivirus.com ## added by CiD
127.0.0.1 hk.winantivirus.com ## added by CiD
127.0.0.1 instlog.errorsafe.com ## added by CiD
127.0.0.1 instlog.winantivirus.com ## added by CiD
127.0.0.1 instlog.winfixer.com ## added by CiD
127.0.0.1 jsp.drivecleaner.com ## added by CiD
127.0.0.1 kb.errorsafe.com ## added by CiD
127.0.0.1 kb.winantivirus.com ## added by CiD
127.0.0.1 nl.errorsafe.com ## added by CiD
127.0.0.1 se.errorsafe.com ## added by CiD
127.0.0.1 secure.drivecleaner.com ## added by CiD
127.0.0.1 secure.errorsafe.com ## added by CiD
127.0.0.1 secure.winantispam.com ## added by CiD
127.0.0.1 secure.winantispy.com ## added by CiD
127.0.0.1 secure.winantivirus.com ## added by CiD
127.0.0.1 support.winantivirus.com ## added by CiD
127.0.0.1 trial.updates.winsoftware.com ## added by CiD
127.0.0.1 ulog.winantivirus.com ## added by CiD
127.0.0.1 utils.errorsafe.com ## added by CiD
127.0.0.1 utils.winantivirus.com ## added by CiD
127.0.0.1 utils.winfixer.com ## added by CiD
127.0.0.1 winantispyware.com ## added by CiD
127.0.0.1 winantivirus.com ## added by CiD
127.0.0.1 winfixer.com ## added by CiD
127.0.0.1 winfixer2006.com ## added by CiD
127.0.0.1 winsoftware.com ## added by CiD
127.0.0.1 www.drivecleaner.com ## added by CiD
127.0.0.1 www.errorprotector.com ## added by CiD
127.0.0.1 www.errorsafe.com ## added by CiD
127.0.0.1 www.systemdoctor.com ## added by CiD
127.0.0.1 www.utils.winfixer.com ## added by CiD
127.0.0.1 www.win-anti-virus-pro.com ## added by CiD
127.0.0.1 www.win-virus-pro.com ## added by CiD
127.0.0.1 www.winantispam.com ## added by CiD
127.0.0.1 www.winantispy.com ## added by CiD
127.0.0.1 www.winantispyware.com ## added by CiD
127.0.0.1 www.winantivirus.com ## added by CiD
127.0.0.1 www.winantiviruspro.com ## added by CiD
127.0.0.1 www.windrivecleaner.com ## added by CiD
127.0.0.1 www.windrivesafe.com ## added by CiD
127.0.0.1 www.winfixer.com ## added by CiD
127.0.0.1 www.winfixer2006.com ## added by CiD
127.0.0.1 www.winsoftware.com ## added by CiD

----------------[ Recherche de fichiers avec Catchme ]-----------------

catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-21 13:41:22
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden files ...
scan completed successfully
hidden files: 0

--------------------[ Recherche d'autres infections ]---------------------

Aucune autre infection trouvée !

/!\ [Fich:1826][Doss:896] C:\DOCUME~1\POULLY\LOCALS~1\Temp
/!\ [Fich:17112][Doss:28] C:\DOCUME~1\POULLY\LOCALS~1\TEMPOR~1\content.IE5

--------------------[ Fin du rapport a 13:43:15.17 ]----------------------

Profil : Helper
Plus d'informations

Re,

Relance Lop S&D

  • Choisis cette fois ci l'Option 2 (Suppression)
  • Ne ferme pas la fenêtre lors de la suppression !
  • Poste le rapport généré (C:\lopR.txt)


(Si le Bureau ne réapparît pas presse Ctrl + Alt + Suppr , Onglet Fichier , Nouvelle tâche , tape explorer.exe et valide)

&

Télécharge puis installe Hijackthis (Trend Micro).
Poste ensuite un rapport dans ta prochaine réponse.
AIDE : Comment utiliser Hijackthis v2.0.2


---------------
Prévention & Protection|Les logiciels gratuits|L'homme du FLCCF
Profil : IDNaute
Plus d'informations

J'ai Avast qui me trouve plein de virus/cheval de troie.
Avast m'indique aussi que je reçois plein de courriers electroniques dans un faible intervalle de temps.

Profil : Helper
Plus d'informations

Désactive-le pensant les opérations ci-dessous.


---------------
Prévention & Protection|Les logiciels gratuits|L'homme du FLCCF
Profil : IDNaute
Plus d'informations

Re,
Voilà le rapport Lop:



-----------------------------[ Lop S&D 2.0.8 ]---------------------------

[ Windows XP (NT 5.1) Build 2600, Service Pack 2 ]

[ USER: POULLY ] [ "C:\Program Files\Lop SD" ]

[ 21/01/2008 | 14:17:31.76 ] [ YANNICK ]

[ MAJ : 21-01-2008 | 13.15 ]

\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ SUPPRESSION /////////////////////////////

Supprimé! - C:\WINDOWS\Tasks\A8684309916FFBA9.job
Restauré! - Fichier Hosts

//////////////////////////////////////-\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\


-------------[ Listing des dossiers dans Application Data ]------------

[30/07/2007|15:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Grisoft
[30/07/2007|15:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\..
[30/07/2007|15:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\.
[10/04/2007|13:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!
[22/03/2007|19:43] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WinZip
[11/02/2007|18:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Zylom
[06/10/2006|15:40] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[06/10/2006|15:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Real
[22/09/2006|14:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Macrovision
[21/09/2006|19:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\PC Suite
[21/09/2006|19:46] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Downloaded Installations
[30/06/2006|09:05] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[14/02/2006|17:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[25/01/2006|19:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[25/01/2006|14:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\desktop.ini


[25/01/2006|14:48] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
[25/01/2006|14:36] C:\DOCUME~1\DEFAUL~1\APPLIC~1\desktop.ini
[25/01/2006|14:36] C:\DOCUME~1\DEFAUL~1\APPLIC~1\..
[25/01/2006|14:36] C:\DOCUME~1\DEFAUL~1\APPLIC~1\.



[30/09/2006|16:50] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft
[25/01/2006|14:53] C:\DOCUME~1\LOCALS~1\APPLIC~1\..
[25/01/2006|14:53] C:\DOCUME~1\LOCALS~1\APPLIC~1\.

[25/01/2006|14:53] C:\DOCUME~1\NETWOR~1\APPLIC~1\..
[25/01/2006|14:53] C:\DOCUME~1\NETWOR~1\APPLIC~1\.
[25/01/2006|14:48] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft

[21/01/2008|13:48] C:\DOCUME~1\POULLY\APPLIC~1\OpenOffice.org2
[14/01/2008|14:08] C:\DOCUME~1\POULLY\APPLIC~1\mIRC
[01/01/2008|14:59] C:\DOCUME~1\POULLY\APPLIC~1\LimeWire
[26/12/2007|15:45] C:\DOCUME~1\POULLY\APPLIC~1\..
[26/12/2007|15:45] C:\DOCUME~1\POULLY\APPLIC~1\.
[01/04/2007|20:49] C:\DOCUME~1\POULLY\APPLIC~1\Microsoft
[12/02/2007|19:36] C:\DOCUME~1\POULLY\APPLIC~1\Ahead
[22/01/2007|23:53] C:\DOCUME~1\POULLY\APPLIC~1\vlc
[29/10/2006|23:19] C:\DOCUME~1\POULLY\APPLIC~1\Real
[06/10/2006|15:57] C:\DOCUME~1\POULLY\APPLIC~1\Media Player Classic
[21/09/2006|14:03] C:\DOCUME~1\POULLY\APPLIC~1\PC Suite
[15/05/2006|19:15] C:\DOCUME~1\POULLY\APPLIC~1\Sun
[27/02/2006|18:57] C:\DOCUME~1\POULLY\APPLIC~1\Help
[07/02/2006|13:23] C:\DOCUME~1\POULLY\APPLIC~1\AdobeUM
[07/02/2006|13:22] C:\DOCUME~1\POULLY\APPLIC~1\Adobe
[25/01/2006|20:53] C:\DOCUME~1\POULLY\APPLIC~1\Macromedia
[25/01/2006|19:38] C:\DOCUME~1\POULLY\APPLIC~1\Lavasoft
[25/01/2006|14:54] C:\DOCUME~1\POULLY\APPLIC~1\Identities

----------------[ Tâches planifiées dans C:\WINDOWS\tasks ]---------------

[21/01/2008 13:47][--ah-----] C:\WINDOWS\tasks\SA.DAT
[30/08/2002 13:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini

---------------[ Listing des dossiers dans C:\Program Files ]--------------

[21/01/2008|14:17] C:\Program Files\Lop SD
[21/01/2008|13:33] C:\Program Files\..
[21/01/2008|13:33] C:\Program Files\.
[21/01/2008|12:00] C:\Program Files\Helper
[17/01/2008|21:47] C:\Program Files\Temporary
[17/01/2008|19:15] C:\Program Files\Dot1XCfg
[16/01/2008|22:00] C:\Program Files\eChanblard
[09/01/2008|16:31] C:\Program Files\eMule
[21/12/2007|16:27] C:\Program Files\Messenger Plus! Live
[21/12/2007|16:27] C:\Program Files\MSN Messenger
[11/12/2007|23:47] C:\Program Files\Internet Explorer
[19/11/2007|18:42] C:\Program Files\flashget196en.exe
[12/11/2007|18:51] C:\Program Files\LimeWire
[12/11/2007|18:22] C:\Program Files\LimeWireWin.exe
[15/10/2007|14:34] C:\Program Files\Java
[09/10/2007|15:39] C:\Program Files\MSN plus
[09/10/2007|15:39] C:\Program Files\Multimedia V3.54
[03/10/2007|16:17] C:\Program Files\eMule0.48a-Installer.exe
[26/09/2007|14:27] C:\Program Files\MSN Reaper
[02/09/2007|21:06] C:\Program Files\eChanblard.exe
[14/06/2007|21:13] C:\Program Files\Windows Live
[12/06/2007|22:34] C:\Program Files\Outlook Express
[08/05/2007|12:23] C:\Program Files\WinRAR
[08/04/2007|16:57] C:\Program Files\CCleaner
[02/04/2007|23:26] C:\Program Files\Grisoft
[01/04/2007|10:43] C:\Program Files\PC Camera
[22/03/2007|23:54] C:\Program Files\BitComet
[07/03/2007|18:19] C:\Program Files\Free
[07/03/2007|16:42] C:\Program Files\Fichiers communs
[07/03/2007|16:18] C:\Program Files\NETGEAR
[07/03/2007|16:18] C:\Program Files\NETGEAR(2)
[22/01/2007|21:42] C:\Program Files\VideoLAN
[09/11/2006|18:14] C:\Program Files\Windows Media Player
[09/11/2006|18:05] C:\Program Files\Windows Media Connect 2
[09/11/2006|17:41] C:\Program Files\windows media player 11
[09/11/2006|17:28] C:\Program Files\Windows NT
[06/10/2006|15:40] C:\Program Files\K-Lite Codec Pack
[23/09/2006|15:55] C:\Program Files\Jeux t‚l‚charg‚
[22/09/2006|15:02] C:\Program Files\Boonty
[22/09/2006|15:02] C:\Program Files\BoontyGames
[22/09/2006|14:51] C:\Program Files\Mes Jeux T‚l‚charg‚s
[21/09/2006|19:47] C:\Program Files\DIFX
[11/04/2006|20:36] C:\Program Files\Bearshare
[22/03/2006|18:55] C:\Program Files\JEUX MONOPOLY
[09/02/2006|15:37] C:\Program Files\essai convertisseur
[04/02/2006|14:28] C:\Program Files\Oxilog
[04/02/2006|12:04] C:\Program Files\C-Media 3D Audio
[02/02/2006|16:29] C:\Program Files\InstallShield Installation Information
[28/01/2006|14:33] C:\Program Files\SigmaTel
[25/01/2006|21:09] C:\Program Files\Messenger
[25/01/2006|19:37] C:\Program Files\Lavasoft
[25/01/2006|19:37] C:\Program Files\PowerArchiver
[25/01/2006|19:36] C:\Program Files\Adobe
[25/01/2006|19:33] C:\Program Files\OpenOffice.org 2.0
[25/01/2006|19:30] C:\Program Files\Alwil Software
[25/01/2006|16:32] C:\Program Files\Ahead
[25/01/2006|16:16] C:\Program Files\Movie Maker
[25/01/2006|16:13] C:\Program Files\NetMeeting
[25/01/2006|15:56] C:\Program Files\SiSLan
[25/01/2006|14:54] C:\Program Files\Uninstall Information
[25/01/2006|14:49] C:\Program Files\xerox
[25/01/2006|14:49] C:\Program Files\microsoft frontpage
[25/01/2006|14:47] C:\Program Files\Services en ligne
[25/01/2006|14:44] C:\Program Files\ComPlus Applications
[25/01/2006|14:44] C:\Program Files\WindowsUpdate
[25/01/2006|14:44] C:\Program Files\MSN Gaming Zone

------[ Listing des dossiers dans C:\Program Files\Fichiers communs ]------

[12/06/2007|22:34] C:\Program Files\Fichiers communs\System
[01/04/2007|19:22] C:\Program Files\Fichiers communs\Microsoft Shared
[07/03/2007|16:42] C:\Program Files\Fichiers communs\..
[07/03/2007|16:42] C:\Program Files\Fichiers communs\.
[12/02/2007|19:31] C:\Program Files\Fichiers communs\Nero
[12/02/2007|19:30] C:\Program Files\Fichiers communs\LightScribe
[22/09/2006|14:52] C:\Program Files\Fichiers communs\Macrovision Shared
[10/05/2006|19:48] C:\Program Files\Fichiers communs\Java
[09/02/2006|15:37] C:\Program Files\Fichiers communs\MimarSinan
[07/02/2006|13:22] C:\Program Files\Fichiers communs\Adobe
[02/02/2006|16:29] C:\Program Files\Fichiers communs\InstallShield
[25/01/2006|16:29] C:\Program Files\Fichiers communs\Ahead
[25/01/2006|14:46] C:\Program Files\Fichiers communs\Services
[25/01/2006|14:46] C:\Program Files\Fichiers communs\MSSoap
[25/01/2006|14:37] C:\Program Files\Fichiers communs\ODBC
[25/01/2006|14:37] C:\Program Files\Fichiers communs\SpeechEngines

----------------------[ Recherche avec S_Lop ]---------------------

Aucun fichier / dossier Lop trouvé !

-----------------[ Recherche de Fichiers / Dossiers Lop ]-----------------

Aucun fichier / dossier Lop trouvé !

----------------------[ Verification du Registre ]----------------------

..... OK !

--------------------[ Verification du fichier Hosts ]---------------------

Fichier Hosts PROPRE


----------------[ Recherche de fichiers avec Catchme ]-----------------

catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-21 14:20:10
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden files ...
scan completed successfully
hidden files: 0

--------------------[ Recherche d'autres infections ]---------------------

Aucune autre infection trouvée !

/!\ [Fich:1830][Doss:898] C:\DOCUME~1\POULLY\LOCALS~1\Temp
/!\ [Fich:17361][Doss:28] C:\DOCUME~1\POULLY\LOCALS~1\TEMPOR~1\content.IE5

--------------------[ Fin du rapport a 14:23:03.18 ]----------------------

Profil : IDNaute
Plus d'informations

Voilà le rapport HijackThis (v1.99.1)


Logfile of HijackThis v1.99.1
Scan saved at 14:30:58, on 21/01/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\System32\sistray.EXE
C:\WINDOWS\System32\keyhook.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\DOCUME~1\POULLY\LOCALS~1\Temp\services.exe
C:\WINDOWS\mrofinu1148.exe
C:\WINDOWS\system32\snrb2.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Dot1XCfg\Dot1XCfg.exe
C:\bhij.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\NETGEAR\WG311v3\wlancfg5.exe
C:\Program Files\OpenOffice.org 2.0\program\soffice.exe
C:\Program Files\OpenOffice.org 2.0\program\soffice.BIN
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\17PHolmes1148.exe
C:\WINDOWS\17PHolmes1148.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\POULLY\Mes documents\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.free.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ustart.org
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: e404 helper - {F10587E9-0E47-4CBE-84AE-7DD20B8684CC} - C:\Program Files\Helper\superfindout.dll
O2 - BHO: Microsoft copyright - {FFFFFFFF-F538-4f86-ABAF-E9D94D5C007C} - socketa.dll (file missing)
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [SiS Tray] C:\WINDOWS\System32\sistray.EXE
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\System32\keyhook.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [Flash Player2] C:\DOCUME~1\POULLY\LOCALS~1\Temp\services.exe
O4 - HKLM\..\Run: [runner1] C:\WINDOWS\mrofinu1148.exe 61A847B5BBF72813339F30466188719AB689201522886B092CBD44BD8689220221DD3257
O4 - HKLM\..\Run: [Winupdates] snrb2.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Dot1XCfg] C:\Program Files\Dot1XCfg\Dot1XCfg.exe
O4 - HKCU\..\Run: [WintelUpdate] C:\bhij.exe
O4 - Startup: OpenOffice.org 2.0.lnk = C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe
O4 - Global Startup: NETGEAR WG311v3 Wireless Assistant.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: Interface Chat Wanadoo - http://chat14.x-echo.com/version6/Applet/wchatsign.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://webscanner.kaspersky.fr/kavwebscan_unicode.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/ [...] loader.cab
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game02.zylom.com/activex/zylomgamesplayer.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O21 - SSODL: rdihost - {C575CAAC-7286-4989-84B9-192F69D7A809} - rdihost.dll (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
O23 - Service: Microsoft security update service (msupdate) - Unknown owner - c:\windows\system32\msvcrtd.exe


Message édité par Gnondpom@IDN le 21-01-2008 à 14:40:03
Profil : Helper
Plus d'informations