fenetres intempestives[résolu]
Forum Sécurité - Virus : fenetres intempestives[résolu]
bonjour je suis envahis de fenetre de pub casino banque et autres
merci de votre aide
magali
Message édité par mag14100 le 20-04-2008 à 21:53:25
voici un log hijackthis
merci
Logfile of HijackThis v1.99.1
Scan saved at 11:16:29, on 15/04/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\WgaTray.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\sistray.EXE
C:\WINDOWS\system32\keyhook.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
C:\PROGRA~1\INCRED~1\bin\IMApp.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe
C:\PROGRA~1\Mozilla Firefox\firefox.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\Administrateur\Bureau\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Favoris
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [CamMonitor] C:\Program Files\Hewlett-Packard\Digital Imaging\\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SiS Tray] C:\WINDOWS\system32\sistray.EXE
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\system32\keyhook.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [bend logo clock film] C:\Documents and Settings\All Users\Application Data\Frag great bend logo\bone book.exe
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Netlog 24] "C:\Program Files\Netlog 24\Notifier\Netlog24Notifier.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [City meet] C:\DOCUME~1\ADMINI~1\APPLIC~1\FUNKDR~1\Internetdrivemail.exe
O4 - Global Startup: BlueSoleil.lnk = C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O11 - Options group: [INTERNATIONAL] International*
O15 - Trusted Zone: http://www.msi.com.tw
O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/too [...] ontrol.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-F [...] E_UNO1.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/r [...] se4009.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://copainsdavant.linternaute.c [...] oader4.cab
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - http://www.touslesdrivers.com/fich [...] _0_4_9.cab
O16 - DPF: {BD8667B7-38D8-4C77-B580-18C3E146372C} (Creative Toolbox Plug-in) - http://kiw.imgag.com/imgag/cp/inst [...] -kiwen.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/bina [...] b56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/bina [...] b56986.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
Bonjour,
Télécharge Lop S&D.exe sur ton Bureau.
- Double-clique dessus pour lancer l'installation
- Puis double-clique sur le raccourci Lop S&D présent sur ton Bureau
- Séléctionne la langue souhaitée , puis choisis l'option 1 (Recherche)
- Patiente jusqu'à la fin du scan
- Poste le rapport généré (C:\lopR.txt)
(Si le Bureau ne réapparait pas presse Ctrl + Alt + Suppr , Onglet Fichier , Nouvelle tâche , tape explorer.exe et valide)
Répondre à Angeldark
-----------------------[ Lop S&D 4.1.1-0 XP/Vista ]---------------------
[ Windows XP (NT 5.1) Build 2600, Service Pack 2 ]
[ USER : Administrateur ] [ "C:\Lop SD" ]
[ 15/04/2008 | 14:47:38,09 ] [ PC : XPSP2-F87D6FB42 ]
[ MAJ : 14-04-2008 | 20:30 ]
-------------[ Listing des dossiers dans Application Data ]------------
[11/04/2008|17:32] C:\DOCUME~1\ADMINI~1\APPLIC~1\.
[11/04/2008|17:32] C:\DOCUME~1\ADMINI~1\APPLIC~1\..
[16/02/2008|23:12] C:\DOCUME~1\ADMINI~1\APPLIC~1\Adobe
[18/09/2007|13:40] C:\DOCUME~1\ADMINI~1\APPLIC~1\AdobeUM
[10/09/2007|21:36] C:\DOCUME~1\ADMINI~1\APPLIC~1\Ahead
[23/09/2007|11:32] C:\DOCUME~1\ADMINI~1\APPLIC~1\Apple Computer
[20/12/2007|18:50] C:\DOCUME~1\ADMINI~1\APPLIC~1\Chessmaster Challenge
[16/09/2007|17:10] C:\DOCUME~1\ADMINI~1\APPLIC~1\CyberLink
[09/09/2007|21:37] C:\DOCUME~1\ADMINI~1\APPLIC~1\desktop.ini
[14/10/2007|22:14] C:\DOCUME~1\ADMINI~1\APPLIC~1\DivX
[09/09/2007|20:48] C:\DOCUME~1\ADMINI~1\APPLIC~1\Dossier de t‚l‚chargement Share-to-Web
[12/09/2007|21:30] C:\DOCUME~1\ADMINI~1\APPLIC~1\Dossier de t‚l‚chargement Share-to-Web
[10/04/2008|09:09] C:\DOCUME~1\ADMINI~1\APPLIC~1\funk draw rect
[06/01/2008|23:58] C:\DOCUME~1\ADMINI~1\APPLIC~1\GDIPFONTCACHEV1.DAT
[09/09/2007|23:02] C:\DOCUME~1\ADMINI~1\APPLIC~1\Google
[13/10/2007|22:18] C:\DOCUME~1\ADMINI~1\APPLIC~1\Grisoft
[19/12/2007|16:03] C:\DOCUME~1\ADMINI~1\APPLIC~1\Help
[11/09/2007|14:46] C:\DOCUME~1\ADMINI~1\APPLIC~1\Hewlett-Packard
[17/11/2007|17:11] C:\DOCUME~1\ADMINI~1\APPLIC~1\HP
[22/03/2008|20:12] C:\DOCUME~1\ADMINI~1\APPLIC~1\Identities
[13/03/2008|16:56] C:\DOCUME~1\ADMINI~1\APPLIC~1\Image Zone Express
[25/01/2008|19:21] C:\DOCUME~1\ADMINI~1\APPLIC~1\IMBooster
[20/10/2007|16:54] C:\DOCUME~1\ADMINI~1\APPLIC~1\Lavasoft
[22/09/2007|01:07] C:\DOCUME~1\ADMINI~1\APPLIC~1\Leadertech
[31/10/2007|18:17] C:\DOCUME~1\ADMINI~1\APPLIC~1\LimeWire
[26/03/2008|14:38] C:\DOCUME~1\ADMINI~1\APPLIC~1\Macromedia
[01/11/2007|17:59] C:\DOCUME~1\ADMINI~1\APPLIC~1\Media Player Classic
[27/03/2008|12:55] C:\DOCUME~1\ADMINI~1\APPLIC~1\Microsoft
[09/09/2007|22:35] C:\DOCUME~1\ADMINI~1\APPLIC~1\Mindscape
[12/09/2007|09:06] C:\DOCUME~1\ADMINI~1\APPLIC~1\Mozilla
[08/04/2008|19:16] C:\DOCUME~1\ADMINI~1\APPLIC~1\Plopp1.2
[17/11/2007|17:35] C:\DOCUME~1\ADMINI~1\APPLIC~1\Printer Info Cache
[06/03/2008|21:05] C:\DOCUME~1\ADMINI~1\APPLIC~1\Skype
[14/10/2007|23:06] C:\DOCUME~1\ADMINI~1\APPLIC~1\Sun
[12/09/2007|09:06] C:\DOCUME~1\ADMINI~1\APPLIC~1\Talkback
[16/09/2007|11:47] C:\DOCUME~1\ADMINI~1\APPLIC~1\TuxPaint
[21/12/2007|11:51] C:\DOCUME~1\ADMINI~1\APPLIC~1\Uniblue
[29/09/2007|17:46] C:\DOCUME~1\ADMINI~1\APPLIC~1\Windows Live Writer
[11/04/2008|14:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\.
[11/04/2008|14:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\..
[14/02/2008|10:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[09/09/2007|22:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[16/01/2008|14:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Bluetooth
[16/09/2007|17:10] C:\DOCUME~1\ALLUSE~1\APPLIC~1\CyberLink
[09/09/2007|21:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\desktop.ini
[01/03/2008|09:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Downloaded Installations
[10/04/2008|09:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Frag great bend logo
[09/09/2007|20:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
[13/10/2007|22:18] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Grisoft
[17/11/2007|13:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\HP
[28/03/2008|22:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\HPSSUPPLY
[28/03/2008|22:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\hpzinstall.log
[07/03/2008|12:10] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!
[11/03/2008|17:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[12/09/2007|09:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Mozilla
[12/11/2007|09:23] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MumboJumbo
[05/04/2008|12:33] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Plopp1.2
[16/02/2008|17:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\QTSBandwidthCache
[09/09/2007|20:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Skype
[15/04/2008|10:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
[16/11/2007|23:01] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
[12/09/2007|11:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[10/10/2007|20:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Live Toolbar
[24/03/2008|22:38] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
[01/04/2008|13:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Yahoo! Companion
[09/09/2007|21:37] C:\DOCUME~1\DEFAUL~1\APPLIC~1\.
[09/09/2007|21:37] C:\DOCUME~1\DEFAUL~1\APPLIC~1\..
[09/09/2007|21:37] C:\DOCUME~1\DEFAUL~1\APPLIC~1\desktop.ini
[09/09/2007|19:46] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
[09/09/2007|19:49] C:\DOCUME~1\LOCALS~1\APPLIC~1\.
[09/09/2007|19:49] C:\DOCUME~1\LOCALS~1\APPLIC~1\..
[29/09/2007|17:40] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft
[29/09/2007|17:36] C:\DOCUME~1\NETWOR~1\APPLIC~1\.
[29/09/2007|17:36] C:\DOCUME~1\NETWOR~1\APPLIC~1\..
[29/09/2007|17:36] C:\DOCUME~1\NETWOR~1\APPLIC~1\Identities
[29/09/2007|17:36] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft
----------------[ Tâches planifiées dans C:\WINDOWS\tasks ]---------------
[15/04/2008 14:00][--ah-----] C:\WINDOWS\tasks\A9031E3E91849592.job
[15/04/2008 14:42][--ah-----] C:\WINDOWS\tasks\SA.DAT
[02/10/2001 18:16][-r-h-----] C:\WINDOWS\tasks\desktop.ini
---------------[ Listing des dossiers dans C:\Program Files ]--------------
[10/04/2008|09:08] C:\Program Files\.
[10/04/2008|09:08] C:\Program Files\..
[14/02/2008|10:44] C:\Program Files\Adobe
[10/09/2007|21:00] C:\Program Files\Ahead
[09/09/2007|20:23] C:\Program Files\Alwil Software
[19/11/2007|18:39] C:\Program Files\Apple Software Update
[11/10/2007|23:12] C:\Program Files\aRPNCalc
[22/12/2007|17:55] C:\Program Files\Atari
[20/12/2007|19:08] C:\Program Files\B4Playing
[26/09/2007|21:01] C:\Program Files\BarreConfCMCIC
[05/04/2008|11:38] C:\Program Files\CA Yahoo! Anti-Spy
[13/10/2007|23:18] C:\Program Files\CCleaner
[10/04/2008|09:08] C:\Program Files\Circle Developement
[08/03/2008|19:48] C:\Program Files\C-Media 3D Audio
[09/04/2008|10:12] C:\Program Files\Common Files
[09/09/2007|19:42] C:\Program Files\ComPlus Applications
[08/03/2008|19:34] C:\Program Files\Conduit
[16/09/2007|17:09] C:\Program Files\CyberLink
[12/12/2007|13:56] C:\Program Files\Disney Interactive
[27/12/2007|18:31] C:\Program Files\DivX
[28/10/2007|13:43] C:\Program Files\DK
[18/01/2008|01:36] C:\Program Files\Dot1XCfg
[05/04/2008|11:36] C:\Program Files\Fichiers communs
[08/03/2008|19:34] C:\Program Files\free-downloads.net
[10/04/2008|09:08] C:\Program Files\funk draw rect
[21/12/2007|21:30] C:\Program Files\Google
[13/10/2007|22:18] C:\Program Files\Grisoft
[17/11/2007|13:41] C:\Program Files\Hewlett-Packard
[17/11/2007|17:35] C:\Program Files\HP
[16/11/2007|23:36] C:\Program Files\Incredijeux
[13/11/2007|15:58] C:\Program Files\IncrediMail
[08/03/2008|13:52] C:\Program Files\InstallShield Installation Information
[02/03/2008|23:07] C:\Program Files\Intel Desktop Board
[09/04/2008|18:00] C:\Program Files\Internet Explorer
[09/09/2007|19:54] C:\Program Files\Inventel
[16/01/2008|14:31] C:\Program Files\IVT Corporation
[04/04/2008|18:00] C:\Program Files\Java
[09/04/2008|13:25] C:\Program Files\Kiwee Toolbar2
[20/10/2007|16:54] C:\Program Files\Lavasoft
[01/03/2008|00:25] C:\Program Files\lecteur windows media 11
[10/04/2008|09:08] C:\Program Files\Messenger Plus! Live
[09/09/2007|19:47] C:\Program Files\microsoft frontpage
[19/11/2007|17:21] C:\Program Files\Microsoft Hardware
[04/12/2007|16:33] C:\Program Files\Microsoft Office
[29/09/2007|17:36] C:\Program Files\Microsoft SQL Server Compact Edition
[26/09/2007|11:46] C:\Program Files\Mindscape
[17/09/2007|20:27] C:\Program Files\Movie Maker
[15/04/2008|14:45] C:\Program Files\Mozilla Firefox
[09/09/2007|23:09] C:\Program Files\MSECache
[12/09/2007|21:54] C:\Program Files\MSI
[09/09/2007|19:42] C:\Program Files\MSN Gaming Zone
[24/10/2007|15:42] C:\Program Files\MSN Messenger
[17/11/2007|23:05] C:\Program Files\MSXML 4.0
[08/03/2008|19:55] C:\Program Files\Multimedia V3.54
[29/03/2008|22:14] C:\Program Files\Netlog
[23/11/2007|13:16] C:\Program Files\Netlog 24
[09/09/2007|19:43] C:\Program Files\NetMeeting
[17/09/2007|20:27] C:\Program Files\Outlook Express
[28/01/2008|10:58] C:\Program Files\PhotoFiltre
[09/09/2007|22:36] C:\Program Files\QuickTime
[20/12/2007|18:47] C:\Program Files\ReflexiveArcade
[24/12/2007|16:43] C:\Program Files\SAMSUNG
[09/09/2007|19:44] C:\Program Files\Services en ligne
[25/10/2007|19:57] C:\Program Files\SiS7012
[08/03/2008|13:52] C:\Program Files\sisagp
[08/03/2008|19:46] C:\Program Files\SiSLan
[09/09/2007|20:20] C:\Program Files\Skype
[16/10/2007|10:11] C:\Program Files\Sunbelt Software
[09/09/2007|19:50] C:\Program Files\Uninstall Information
[09/09/2007|19:57] C:\Program Files\Wanadoo
[26/10/2007|15:18] C:\Program Files\Windows Desktop Search
[11/04/2008|11:12] C:\Program Files\Windows Live
[08/04/2008|18:56] C:\Program Files\Windows Live Safety Center
[20/10/2007|16:44] C:\Program Files\Windows Live Toolbar
[11/03/2008|13:16] C:\Program Files\Windows Media Connect 2
[11/03/2008|13:40] C:\Program Files\Windows Media Player
[09/09/2007|19:41] C:\Program Files\Windows NT
[09/09/2007|19:44] C:\Program Files\WindowsUpdate
[09/09/2007|20:05] C:\Program Files\WinRAR
[09/09/2007|19:47] C:\Program Files\xerox
[09/04/2008|10:12] C:\Program Files\Yahoo!
------[ Listing des dossiers dans C:\Program Files\Fichiers communs ]------
[05/04/2008|11:36] C:\Program Files\Fichiers communs\.
[05/04/2008|11:36] C:\Program Files\Fichiers communs\..
[14/02/2008|10:45] C:\Program Files\Fichiers communs\Adobe
[10/09/2007|21:00] C:\Program Files\Fichiers communs\Ahead
[12/09/2007|15:23] C:\Program Files\Fichiers communs\Designer
[04/03/2008|20:00] C:\Program Files\Fichiers communs\DirectX
[09/09/2007|19:55] C:\Program Files\Fichiers communs\FDEUnInstaller.exe
[11/10/2007|23:18] C:\Program Files\Fichiers communs\GTK
[17/11/2007|13:36] C:\Program Files\Fichiers communs\Hewlett-Packard
[17/11/2007|17:35] C:\Program Files\Fichiers communs\HP
[30/09/2007|13:38] C:\Program Files\Fichiers communs\InstallShield
[20/09/2007|16:31] C:\Program Files\Fichiers communs\Java
[09/09/2007|20:49] C:\Program Files\Fichiers communs\Logitech
[17/01/2008|22:58] C:\Program Files\Fichiers communs\Microsoft Shared
[09/09/2007|19:43] C:\Program Files\Fichiers communs\MSSoap
[09/09/2007|21:37] C:\Program Files\Fichiers communs\ODBC
[05/04/2008|11:36] C:\Program Files\Fichiers communs\Scanner
[09/09/2007|19:43] C:\Program Files\Fichiers communs\Services
[09/09/2007|20:20] C:\Program Files\Fichiers communs\Skype
[09/09/2007|21:37] C:\Program Files\Fichiers communs\SpeechEngines
[16/09/2007|22:16] C:\Program Files\Fichiers communs\System
[03/01/2008|21:45] C:\Program Files\Fichiers communs\Vivendi Universal Games
[17/01/2008|22:56] C:\Program Files\Fichiers communs\WindowsLiveInstaller
----------------------[ Recherche avec S_Lop ]---------------------
Aucun fichier / dossier Lop trouvé !
-----------------[ Recherche de Fichiers / Dossiers Lop ]-----------------
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Frag great bend logo
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Frag great bend logo\bone book.exe
C:\Program Files\Circle Developement
C:\Program Files\Circle Developement\Uninstall.exe
C:\WINDOWS\Tasks\A9031E3E91849592.job
----------------------[ Verification du Registre ]----------------------
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"bend logo clock film"="C:\\Documents and Settings\\All Users\\Application Data\\Frag great bend logo\\bone book.exe"
--------------------[ Verification du fichier Hosts ]---------------------
Fichier Hosts MODIFIE
127.0.0.1 bin.errorprotector.com ## added by CiD
127.0.0.1 br.errorsafe.com ## added by CiD
127.0.0.1 br.winantivirus.com ## added by CiD
127.0.0.1 br.winfixer.com ## added by CiD
127.0.0.1 cdn.drivecleaner.com ## added by CiD
127.0.0.1 cdn.errorsafe.com ## added by CiD
127.0.0.1 cdn.winsoftware.com ## added by CiD
127.0.0.1 de.errorsafe.com ## added by CiD
127.0.0.1 de.winantivirus.com ## added by CiD
127.0.0.1 download.cdn.drivecleaner.com ## added by CiD
127.0.0.1 download.cdn.errorsafe.com ## added by CiD
127.0.0.1 download.cdn.winsoftware.com ## added by CiD
127.0.0.1 download.errorsafe.com ## added by CiD
127.0.0.1 download.systemdoctor.com ## added by CiD
127.0.0.1 download.winantispyware.com ## added by CiD
127.0.0.1 download.windrivecleaner.com ## added by CiD
127.0.0.1 download.winfixer.com ## added by CiD
127.0.0.1 drivecleaner.com ## added by CiD
127.0.0.1 dynamique.drivecleaner.com ## added by CiD
127.0.0.1 errorprotector.com ## added by CiD
127.0.0.1 errorsafe.com ## added by CiD
127.0.0.1 es.winantivirus.com ## added by CiD
127.0.0.1 fr.winantivirus.com ## added by CiD
127.0.0.1 fr.winfixer.com ## added by CiD
127.0.0.1 go.drivecleaner.com ## added by CiD
127.0.0.1 go.errorsafe.com ## added by CiD
127.0.0.1 go.winantispyware.com ## added by CiD
127.0.0.1 go.winantivirus.com ## added by CiD
127.0.0.1 hk.winantivirus.com ## added by CiD
127.0.0.1 instlog.errorsafe.com ## added by CiD
127.0.0.1 instlog.winantivirus.com ## added by CiD
127.0.0.1 instlog.winfixer.com ## added by CiD
127.0.0.1 jsp.drivecleaner.com ## added by CiD
127.0.0.1 kb.errorsafe.com ## added by CiD
127.0.0.1 kb.winantivirus.com ## added by CiD
127.0.0.1 nl.errorsafe.com ## added by CiD
127.0.0.1 se.errorsafe.com ## added by CiD
127.0.0.1 secure.drivecleaner.com ## added by CiD
127.0.0.1 secure.errorsafe.com ## added by CiD
127.0.0.1 secure.winantispam.com ## added by CiD
127.0.0.1 secure.winantispy.com ## added by CiD
127.0.0.1 secure.winantivirus.com ## added by CiD
127.0.0.1 support.winantivirus.com ## added by CiD
127.0.0.1 trial.updates.winsoftware.com ## added by CiD
127.0.0.1 ulog.winantivirus.com ## added by CiD
127.0.0.1 utils.errorsafe.com ## added by CiD
127.0.0.1 utils.winantivirus.com ## added by CiD
127.0.0.1 utils.winfixer.com ## added by CiD
127.0.0.1 winantispyware.com ## added by CiD
127.0.0.1 winantivirus.com ## added by CiD
127.0.0.1 winfixer.com ## added by CiD
127.0.0.1 winfixer2006.com ## added by CiD
127.0.0.1 winsoftware.com ## added by CiD
127.0.0.1 www.drivecleaner.com ## added by CiD
127.0.0.1 www.errorprotector.com ## added by CiD
127.0.0.1 www.errorsafe.com ## added by CiD
127.0.0.1 www.systemdoctor.com ## added by CiD
127.0.0.1 www.utils.winfixer.com ## added by CiD
127.0.0.1 www.win-anti-virus-pro.com ## added by CiD
127.0.0.1 www.win-virus-pro.com ## added by CiD
127.0.0.1 www.winantispam.com ## added by CiD
127.0.0.1 www.winantispy.com ## added by CiD
127.0.0.1 www.winantispyware.com ## added by CiD
127.0.0.1 www.winantivirus.com ## added by CiD
127.0.0.1 www.winantiviruspro.com ## added by CiD
127.0.0.1 www.windrivecleaner.com ## added by CiD
127.0.0.1 www.windrivesafe.com ## added by CiD
127.0.0.1 www.winfixer.com ## added by CiD
127.0.0.1 www.winfixer2006.com ## added by CiD
127.0.0.1 www.winsoftware.com ## added by CiD
-> 8070 ( 70 ## added by CiD )
/!\ 1 Not 127.0.0.1 !!
----------------[ Recherche de fichiers avec Catchme ]-----------------
catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-15 14:48:45
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 0
--------------------[ Recherche d'autres infections ]---------------------
C:\Program Files\Dot1XCfg
! Virus MSN !
/!\ [Fich:70][Doss:16] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp
/!\ [Fich:58][Doss:0] C:\DOCUME~1\ADMINI~1\Cookies
/!\ [Fich:768][Doss:5] C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMPOR~1\content.IE5
--------------------[ Fin du rapport a 14:50:18,50 ]----------------------
Re,
Relance Lop S&D
- Choisis cette fois ci l'Option 2 (Suppression)
- Ne ferme pas la fenêtre lors de la suppression !
- Poste le rapport généré (C:\lopR.txt)
(Si le Bureau ne réapparaît pas, presse Ctrl + Alt + Suppr , Onglet Fichier , Nouvelle tâche , tape explorer.exe et valide)
Répondre à Angeldark
-----------------------[ Lop S&D 4.1.1-0 XP/Vista ]---------------------
[ Windows XP (NT 5.1) Build 2600, Service Pack 2 ]
[ USER : Administrateur ] [ "C:\Lop SD" ]
[ 15/04/2008 | 15:27:37,29 ] [ PC : XPSP2-F87D6FB42 ]
[ MAJ : 14-04-2008 | 20:30 ]
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ SUPPRESSION /////////////////////////////
Supprimé! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\Frag great bend logo\bone book.exe
Supprimé! - C:\Program Files\Circle Developement\Uninstall.exe
Supprimé! - C:\WINDOWS\Tasks\A9031E3E91849592.job
Supprimé! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\Frag great bend logo
Supprimé! - C:\Program Files\Circle Developement
Restauré! - Fichier Hosts
//////////////////////////////////////-\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
-------------[ Listing des dossiers dans Application Data ]------------
[11/04/2008|17:32] C:\DOCUME~1\ADMINI~1\APPLIC~1\.
[11/04/2008|17:32] C:\DOCUME~1\ADMINI~1\APPLIC~1\..
[16/02/2008|23:12] C:\DOCUME~1\ADMINI~1\APPLIC~1\Adobe
[18/09/2007|13:40] C:\DOCUME~1\ADMINI~1\APPLIC~1\AdobeUM
[10/09/2007|21:36] C:\DOCUME~1\ADMINI~1\APPLIC~1\Ahead
[23/09/2007|11:32] C:\DOCUME~1\ADMINI~1\APPLIC~1\Apple Computer
[20/12/2007|18:50] C:\DOCUME~1\ADMINI~1\APPLIC~1\Chessmaster Challenge
[16/09/2007|17:10] C:\DOCUME~1\ADMINI~1\APPLIC~1\CyberLink
[09/09/2007|21:37] C:\DOCUME~1\ADMINI~1\APPLIC~1\desktop.ini
[14/10/2007|22:14] C:\DOCUME~1\ADMINI~1\APPLIC~1\DivX
[09/09/2007|20:48] C:\DOCUME~1\ADMINI~1\APPLIC~1\Dossier de t‚l‚chargement Share-to-Web
[12/09/2007|21:30] C:\DOCUME~1\ADMINI~1\APPLIC~1\Dossier de t‚l‚chargement Share-to-Web
[10/04/2008|09:09] C:\DOCUME~1\ADMINI~1\APPLIC~1\funk draw rect
[06/01/2008|23:58] C:\DOCUME~1\ADMINI~1\APPLIC~1\GDIPFONTCACHEV1.DAT
[09/09/2007|23:02] C:\DOCUME~1\ADMINI~1\APPLIC~1\Google
[13/10/2007|22:18] C:\DOCUME~1\ADMINI~1\APPLIC~1\Grisoft
[19/12/2007|16:03] C:\DOCUME~1\ADMINI~1\APPLIC~1\Help
[11/09/2007|14:46] C:\DOCUME~1\ADMINI~1\APPLIC~1\Hewlett-Packard
[17/11/2007|17:11] C:\DOCUME~1\ADMINI~1\APPLIC~1\HP
[22/03/2008|20:12] C:\DOCUME~1\ADMINI~1\APPLIC~1\Identities
[13/03/2008|16:56] C:\DOCUME~1\ADMINI~1\APPLIC~1\Image Zone Express
[25/01/2008|19:21] C:\DOCUME~1\ADMINI~1\APPLIC~1\IMBooster
[20/10/2007|16:54] C:\DOCUME~1\ADMINI~1\APPLIC~1\Lavasoft
[22/09/2007|01:07] C:\DOCUME~1\ADMINI~1\APPLIC~1\Leadertech
[31/10/2007|18:17] C:\DOCUME~1\ADMINI~1\APPLIC~1\LimeWire
[26/03/2008|14:38] C:\DOCUME~1\ADMINI~1\APPLIC~1\Macromedia
[01/11/2007|17:59] C:\DOCUME~1\ADMINI~1\APPLIC~1\Media Player Classic
[27/03/2008|12:55] C:\DOCUME~1\ADMINI~1\APPLIC~1\Microsoft
[09/09/2007|22:35] C:\DOCUME~1\ADMINI~1\APPLIC~1\Mindscape
[12/09/2007|09:06] C:\DOCUME~1\ADMINI~1\APPLIC~1\Mozilla
[08/04/2008|19:16] C:\DOCUME~1\ADMINI~1\APPLIC~1\Plopp1.2
[17/11/2007|17:35] C:\DOCUME~1\ADMINI~1\APPLIC~1\Printer Info Cache
[06/03/2008|21:05] C:\DOCUME~1\ADMINI~1\APPLIC~1\Skype
[14/10/2007|23:06] C:\DOCUME~1\ADMINI~1\APPLIC~1\Sun
[12/09/2007|09:06] C:\DOCUME~1\ADMINI~1\APPLIC~1\Talkback
[16/09/2007|11:47] C:\DOCUME~1\ADMINI~1\APPLIC~1\TuxPaint
[21/12/2007|11:51] C:\DOCUME~1\ADMINI~1\APPLIC~1\Uniblue
[29/09/2007|17:46] C:\DOCUME~1\ADMINI~1\APPLIC~1\Windows Live Writer
[15/04/2008|15:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\.
[15/04/2008|15:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\..
[14/02/2008|10:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[09/09/2007|22:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[16/01/2008|14:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Bluetooth
[16/09/2007|17:10] C:\DOCUME~1\ALLUSE~1\APPLIC~1\CyberLink
[09/09/2007|21:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\desktop.ini
[01/03/2008|09:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Downloaded Installations
[09/09/2007|20:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
[13/10/2007|22:18] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Grisoft
[17/11/2007|13:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\HP
[28/03/2008|22:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\HPSSUPPLY
[28/03/2008|22:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\hpzinstall.log
[07/03/2008|12:10] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!
[11/03/2008|17:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[12/09/2007|09:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Mozilla
[12/11/2007|09:23] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MumboJumbo
[05/04/2008|12:33] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Plopp1.2
[16/02/2008|17:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\QTSBandwidthCache
[09/09/2007|20:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Skype
[15/04/2008|10:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
[16/11/2007|23:01] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
[12/09/2007|11:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[10/10/2007|20:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Live Toolbar
[24/03/2008|22:38] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
[01/04/2008|13:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Yahoo! Companion
[09/09/2007|21:37] C:\DOCUME~1\DEFAUL~1\APPLIC~1\.
[09/09/2007|21:37] C:\DOCUME~1\DEFAUL~1\APPLIC~1\..
[09/09/2007|21:37] C:\DOCUME~1\DEFAUL~1\APPLIC~1\desktop.ini
[09/09/2007|19:46] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
[09/09/2007|19:49] C:\DOCUME~1\LOCALS~1\APPLIC~1\.
[09/09/2007|19:49] C:\DOCUME~1\LOCALS~1\APPLIC~1\..
[29/09/2007|17:40] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft
[29/09/2007|17:36] C:\DOCUME~1\NETWOR~1\APPLIC~1\.
[29/09/2007|17:36] C:\DOCUME~1\NETWOR~1\APPLIC~1\..
[29/09/2007|17:36] C:\DOCUME~1\NETWOR~1\APPLIC~1\Identities
[29/09/2007|17:36] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft
----------------[ Tâches planifiées dans C:\WINDOWS\tasks ]---------------
[15/04/2008 14:42][--ah-----] C:\WINDOWS\tasks\SA.DAT
[02/10/2001 18:16][-r-h-----] C:\WINDOWS\tasks\desktop.ini
---------------[ Listing des dossiers dans C:\Program Files ]--------------
[15/04/2008|15:27] C:\Program Files\.
[15/04/2008|15:27] C:\Program Files\..
[14/02/2008|10:44] C:\Program Files\Adobe
[10/09/2007|21:00] C:\Program Files\Ahead
[09/09/2007|20:23] C:\Program Files\Alwil Software
[19/11/2007|18:39] C:\Program Files\Apple Software Update
[11/10/2007|23:12] C:\Program Files\aRPNCalc
[22/12/2007|17:55] C:\Program Files\Atari
[20/12/2007|19:08] C:\Program Files\B4Playing
[26/09/2007|21:01] C:\Program Files\BarreConfCMCIC
[05/04/2008|11:38] C:\Program Files\CA Yahoo! Anti-Spy
[13/10/2007|23:18] C:\Program Files\CCleaner
[08/03/2008|19:48] C:\Program Files\C-Media 3D Audio
[09/04/2008|10:12] C:\Program Files\Common Files
[09/09/2007|19:42] C:\Program Files\ComPlus Applications
[08/03/2008|19:34] C:\Program Files\Conduit
[16/09/2007|17:09] C:\Program Files\CyberLink
[12/12/2007|13:56] C:\Program Files\Disney Interactive
[27/12/2007|18:31] C:\Program Files\DivX
[28/10/2007|13:43] C:\Program Files\DK
[18/01/2008|01:36] C:\Program Files\Dot1XCfg
[05/04/2008|11:36] C:\Program Files\Fichiers communs
[08/03/2008|19:34] C:\Program Files\free-downloads.net
[10/04/2008|09:08] C:\Program Files\funk draw rect
[21/12/2007|21:30] C:\Program Files\Google
[13/10/2007|22:18] C:\Program Files\Grisoft
[17/11/2007|13:41] C:\Program Files\Hewlett-Packard
[17/11/2007|17:35] C:\Program Files\HP
[16/11/2007|23:36] C:\Program Files\Incredijeux
[13/11/2007|15:58] C:\Program Files\IncrediMail
[08/03/2008|13:52] C:\Program Files\InstallShield Installation Information
[02/03/2008|23:07] C:\Program Files\Intel Desktop Board
[09/04/2008|18:00] C:\Program Files\Internet Explorer
[09/09/2007|19:54] C:\Program Files\Inventel
[16/01/2008|14:31] C:\Program Files\IVT Corporation
[04/04/2008|18:00] C:\Program Files\Java
[09/04/2008|13:25] C:\Program Files\Kiwee Toolbar2
[20/10/2007|16:54] C:\Program Files\Lavasoft
[01/03/2008|00:25] C:\Program Files\lecteur windows media 11
[10/04/2008|09:08] C:\Program Files\Messenger Plus! Live
[09/09/2007|19:47] C:\Program Files\microsoft frontpage
[19/11/2007|17:21] C:\Program Files\Microsoft Hardware
[04/12/2007|16:33] C:\Program Files\Microsoft Office
[29/09/2007|17:36] C:\Program Files\Microsoft SQL Server Compact Edition
[26/09/2007|11:46] C:\Program Files\Mindscape
[17/09/2007|20:27] C:\Program Files\Movie Maker
[15/04/2008|15:14] C:\Program Files\Mozilla Firefox
[09/09/2007|23:09] C:\Program Files\MSECache
[12/09/2007|21:54] C:\Program Files\MSI
[09/09/2007|19:42] C:\Program Files\MSN Gaming Zone
[24/10/2007|15:42] C:\Program Files\MSN Messenger
[17/11/2007|23:05] C:\Program Files\MSXML 4.0
[08/03/2008|19:55] C:\Program Files\Multimedia V3.54
[23/11/2007|13:16] C:\Program Files\Netlog 24
[09/09/2007|19:43] C:\Program Files\NetMeeting
[17/09/2007|20:27] C:\Program Files\Outlook Express
[28/01/2008|10:58] C:\Program Files\PhotoFiltre
[09/09/2007|22:36] C:\Program Files\QuickTime
[20/12/2007|18:47] C:\Program Files\ReflexiveArcade
[24/12/2007|16:43] C:\Program Files\SAMSUNG
[09/09/2007|19:44] C:\Program Files\Services en ligne
[25/10/2007|19:57] C:\Program Files\SiS7012
[08/03/2008|13:52] C:\Program Files\sisagp
[08/03/2008|19:46] C:\Program Files\SiSLan
[09/09/2007|20:20] C:\Program Files\Skype
[16/10/2007|10:11] C:\Program Files\Sunbelt Software
[09/09/2007|19:50] C:\Program Files\Uninstall Information
[09/09/2007|19:57] C:\Program Files\Wanadoo
[26/10/2007|15:18] C:\Program Files\Windows Desktop Search
[11/04/2008|11:12] C:\Program Files\Windows Live
[08/04/2008|18:56] C:\Program Files\Windows Live Safety Center
[20/10/2007|16:44] C:\Program Files\Windows Live Toolbar
[11/03/2008|13:16] C:\Program Files\Windows Media Connect 2
[11/03/2008|13:40] C:\Program Files\Windows Media Player
[09/09/2007|19:41] C:\Program Files\Windows NT
[09/09/2007|19:44] C:\Program Files\WindowsUpdate
[09/09/2007|20:05] C:\Program Files\WinRAR
[09/09/2007|19:47] C:\Program Files\xerox
[09/04/2008|10:12] C:\Program Files\Yahoo!
------[ Listing des dossiers dans C:\Program Files\Fichiers communs ]------
[05/04/2008|11:36] C:\Program Files\Fichiers communs\.
[05/04/2008|11:36] C:\Program Files\Fichiers communs\..
[14/02/2008|10:45] C:\Program Files\Fichiers communs\Adobe
[10/09/2007|21:00] C:\Program Files\Fichiers communs\Ahead
[12/09/2007|15:23] C:\Program Files\Fichiers communs\Designer
[04/03/2008|20:00] C:\Program Files\Fichiers communs\DirectX
[09/09/2007|19:55] C:\Program Files\Fichiers communs\FDEUnInstaller.exe
[11/10/2007|23:18] C:\Program Files\Fichiers communs\GTK
[17/11/2007|13:36] C:\Program Files\Fichiers communs\Hewlett-Packard
[17/11/2007|17:35] C:\Program Files\Fichiers communs\HP
[30/09/2007|13:38] C:\Program Files\Fichiers communs\InstallShield
[20/09/2007|16:31] C:\Program Files\Fichiers communs\Java
[09/09/2007|20:49] C:\Program Files\Fichiers communs\Logitech
[17/01/2008|22:58] C:\Program Files\Fichiers communs\Microsoft Shared
[09/09/2007|19:43] C:\Program Files\Fichiers communs\MSSoap
[09/09/2007|21:37] C:\Program Files\Fichiers communs\ODBC
[05/04/2008|11:36] C:\Program Files\Fichiers communs\Scanner
[09/09/2007|19:43] C:\Program Files\Fichiers communs\Services
[09/09/2007|20:20] C:\Program Files\Fichiers communs\Skype
[09/09/2007|21:37] C:\Program Files\Fichiers communs\SpeechEngines
[16/09/2007|22:16] C:\Program Files\Fichiers communs\System
[03/01/2008|21:45] C:\Program Files\Fichiers communs\Vivendi Universal Games
[17/01/2008|22:56] C:\Program Files\Fichiers communs\WindowsLiveInstaller
----------------------[ Recherche avec S_Lop ]---------------------
Aucun fichier / dossier Lop trouvé !
-----------------[ Recherche de Fichiers / Dossiers Lop ]-----------------
Aucun fichier / dossier Lop trouvé !
----------------------[ Verification du Registre ]----------------------
..... OK !
--------------------[ Verification du fichier Hosts ]---------------------
Fichier Hosts PROPRE
----------------[ Recherche de fichiers avec Catchme ]-----------------
catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-15 15:28:40
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 0
--------------------[ Recherche d'autres infections ]---------------------
C:\Program Files\Dot1XCfg
! Virus MSN !
/!\ [Fich:70][Doss:16] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp
/!\ [Fich:65][Doss:0] C:\DOCUME~1\ADMINI~1\Cookies
/!\ [Fich:1076][Doss:5] C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMPOR~1\content.IE5
--------------------[ Fin du rapport a 15:29:53,18 ]----------------------
voila le log merci
Re,
Télécharge MSNFix.zip (!aur3n7) sur ton Bureau.
Décompresse-le sur ton bureau (Clique-Droit/Extraire tout).
Ouvre le dossier MSNFix puis double-clique sur MSNFix.bat.
- Exécute l'option R.
-- Si l'infection est détectée, presse une touche pour lancer le nettoyage.
Si une erreur de suppression est détectée un message s'affichera demandant de redémarrer l'ordinateur afin de terminer les opérations.
Dans ce cas il suffit de redémarrer l'ordinateur manuellement.
Poste le rapport situé dans le dossier MSNFix.
Le nom du rapport correspond au moment de sa création : date_heure.log
Répondre à Angeldark
MSNFix 1.705
C:\Documents and Settings\Administrateur\Bureau\MSNFix
Fix exécuté le 15/04/2008 - 15:35:15,82 By Administrateur
mode normal
************************ Recherche les fichiers présents
Aucun Fichier trouvé
************************ Recherche les dossiers présents
Aucun dossier trouvé
************************ Fichiers suspects
Aucun Fichier trouvé
************************ HKLM\...\Winlogon\Userinit
Userinit = C:\WINDOWS\system32\userinit.exe,
------------------------------------------------------------------------
Auteur : !aur3n7 Contact: http://changelog.fr
------------------------------------------------------------------------
--------------------------------------------- END ---------------------------------------------
Reposte un rapport Hijackthis.
Répondre à Angeldark
voila
Logfile of HijackThis v1.99.1
Scan saved at 16:25:54, on 15/04/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\sistray.EXE
C:\WINDOWS\system32\keyhook.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Program Files\Netlog 24\Notifier\Netlog24Notifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\PROGRA~1\INCRED~1\bin\IMApp.exe
C:\Documents and Settings\Administrateur\Bureau\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Favoris
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [CamMonitor] C:\Program Files\Hewlett-Packard\Digital Imaging\\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SiS Tray] C:\WINDOWS\system32\sistray.EXE
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\system32\keyhook.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Netlog 24] "C:\Program Files\Netlog 24\Notifier\Netlog24Notifier.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [City meet] C:\DOCUME~1\ADMINI~1\APPLIC~1\FUNKDR~1\Internetdrivemail.exe
O4 - Global Startup: BlueSoleil.lnk = C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O11 - Options group: [INTERNATIONAL] International*
O15 - Trusted Zone: http://www.msi.com.tw
O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/too [...] ontrol.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-F [...] E_UNO1.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/r [...] se4009.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://copainsdavant.linternaute.c [...] oader4.cab
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - http://www.touslesdrivers.com/fich [...] _0_4_9.cab
O16 - DPF: {BD8667B7-38D8-4C77-B580-18C3E146372C} (Creative Toolbox Plug-in) - http://kiw.imgag.com/imgag/cp/inst [...] -kiwen.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/bina [...] b56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/bina [...] b56986.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
Re,
Télécharge MalwareByte's Anti-Malware sur ton Bureau.
Installe-le en double-cliquant sur le fichier Download_mbam-setup.exe.
Une fois l'installation et la mise à jour effectuées, redémarre en mode sans échec.
AIDE : Redémarrer en mode sans échec
- Exécute maintenant MalwareByte's Anti-Malware. Si cela n'est pas déjà fait, sélectionne "Exécuter un examen complet".
- Afin de lancer la recherche, clic sur"Rechercher".
- Une fois le scan terminé, une fenêtre s'ouvre, clic sur OK. Deux possibilités s'offrent à toi :
-- si le programme n'a rien trouvé, appuie sur OK. Un rapport va apparaître, ferme-le.
-- si des infections sont présentes, clic sur "Afficher les résultats" puis sur "Supprimer la sélection". Enregistre le rapport sur ton Bureau afin de le poster dans ta prochaine réponse.
REMARQUE : Si MalwareByte's Anti-Malware a besoin de redémarrer pour terminer la suppression, accepte en cliquant sur Ok.
AIDE : Tuto en images sur MBAM
Répondre à Angeldark
Malwarebytes' Anti-Malware 1.11
Version de la base de données: 633
Type de recherche: Examen complet (C:\|D:\|)
Eléments examinés: 73967
Temps écoulé: 21 minute(s), 45 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 1
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 1
Fichier(s) infecté(s): 0
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
HKEY_CURRENT_USER\Software\MediaHoldings (Adware.PlayMP3Z) -> Quarantined and deleted successfully.
Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
C:\Program Files\Dot1XCfg (Trojan.Downloader) -> Quarantined and deleted successfully.
Fichier(s) infecté(s):
(Aucun élément nuisible détecté)
Reposte un rapport Hijackthis.
Répondre à Angeldark
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:49:12, on 16/04/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\sistray.EXE
C:\WINDOWS\system32\keyhook.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Netlog 24\Notifier\Netlog24Notifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
C:\PROGRA~1\INCRED~1\bin\IMApp.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe
D:\eMule\emule.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Favoris
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [CamMonitor] C:\Program Files\Hewlett-Packard\Digital Imaging\\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SiS Tray] C:\WINDOWS\system32\sistray.EXE
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\system32\keyhook.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Netlog 24] "C:\Program Files\Netlog 24\Notifier\Netlog24Notifier.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [City meet] C:\DOCUME~1\ADMINI~1\APPLIC~1\FUNKDR~1\Internetdrivemail.exe
O4 - HKUS\S-1-5-19\..\RunOnce: [XPPro4.0] %systemroot%\REG\run.cmd (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\RunOnce: [XPPro4.0] %systemroot%\REG\run.cmd (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [Picasa Media Detector] D:\montage\Picasa2\PicasaMediaDetector.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [XPPro4.0] %systemroot%\REG\run.cmd (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Picasa Media Detector] D:\montage\Picasa2\PicasaMediaDetector.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [XPPro4.0] %systemroot%\REG\run.cmd (User 'Default user')
O4 - Global Startup: BlueSoleil.lnk = C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O15 - Trusted Zone: http://www.msi.com.tw
O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/too [...] ontrol.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-F [...] E_UNO1.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/r [...] se4009.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://copainsdavant.linternaute.c [...] oader4.cab
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - http://www.touslesdrivers.com/fich [...] _0_4_9.cab
O16 - DPF: {BD8667B7-38D8-4C77-B580-18C3E146372C} (Creative Toolbox Plug-in) - http://kiw.imgag.com/imgag/cp/inst [...] -kiwen.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/bina [...] b56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/bina [...] b56986.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
--
End of file - 11081 bytes
merci beaucoup car je n'est plus ces pubs qui m'envahissaient
mag
Refais un scan LopSD. Ne met pas résolu quand cela ne l'est pas
Répondre à Angeldark
désolé mais je croyez que ct bon
je te remet çà tout de suite
-----------------------[ Lop S&D 4.1.1-2 XP/Vista ]---------------------
[ Windows XP (NT 5.1) Build 2600, Service Pack 2 ]
[ USER : Administrateur ] [ "C:\Lop SD" ]
[ 16/04/2008 | 22:27:46,57 ] [ PC : XPSP2-F87D6FB42 ]
[ MAJ : 16-04-2008 | 20:05 ]
-------------[ Listing des dossiers dans Application Data ]------------
[15/04/2008|19:54] C:\DOCUME~1\ADMINI~1\APPLIC~1\.
[15/04/2008|19:54] C:\DOCUME~1\ADMINI~1\APPLIC~1\..
[16/02/2008|23:12] C:\DOCUME~1\ADMINI~1\APPLIC~1\Adobe
[18/09/2007|13:40] C:\DOCUME~1\ADMINI~1\APPLIC~1\AdobeUM
[10/09/2007|21:36] C:\DOCUME~1\ADMINI~1\APPLIC~1\Ahead
[23/09/2007|11:32] C:\DOCUME~1\ADMINI~1\APPLIC~1\Apple Computer
[20/12/2007|18:50] C:\DOCUME~1\ADMINI~1\APPLIC~1\Chessmaster Challenge
[16/09/2007|17:10] C:\DOCUME~1\ADMINI~1\APPLIC~1\CyberLink
[09/09/2007|21:37] C:\DOCUME~1\ADMINI~1\APPLIC~1\desktop.ini
[16/04/2008|21:33] C:\DOCUME~1\ADMINI~1\APPLIC~1\DivX
[09/09/2007|20:48] C:\DOCUME~1\ADMINI~1\APPLIC~1\Dossier de t‚l‚chargement Share-to-Web
[12/09/2007|21:30] C:\DOCUME~1\ADMINI~1\APPLIC~1\Dossier de t‚l‚chargement Share-to-Web
[10/04/2008|09:09] C:\DOCUME~1\ADMINI~1\APPLIC~1\funk draw rect
[06/01/2008|23:58] C:\DOCUME~1\ADMINI~1\APPLIC~1\GDIPFONTCACHEV1.DAT
[09/09/2007|23:02] C:\DOCUME~1\ADMINI~1\APPLIC~1\Google
[13/10/2007|22:18] C:\DOCUME~1\ADMINI~1\APPLIC~1\Grisoft
[19/12/2007|16:03] C:\DOCUME~1\ADMINI~1\APPLIC~1\Help
[11/09/2007|14:46] C:\DOCUME~1\ADMINI~1\APPLIC~1\Hewlett-Packard
[17/11/2007|17:11] C:\DOCUME~1\ADMINI~1\APPLIC~1\HP
[22/03/2008|20:12] C:\DOCUME~1\ADMINI~1\APPLIC~1\Identities
[13/03/2008|16:56] C:\DOCUME~1\ADMINI~1\APPLIC~1\Image Zone Express
[25/01/2008|19:21] C:\DOCUME~1\ADMINI~1\APPLIC~1\IMBooster
[20/10/2007|16:54] C:\DOCUME~1\ADMINI~1\APPLIC~1\Lavasoft
[22/09/2007|01:07] C:\DOCUME~1\ADMINI~1\APPLIC~1\Leadertech
[31/10/2007|18:17] C:\DOCUME~1\ADMINI~1\APPLIC~1\LimeWire
[26/03/2008|14:38] C:\DOCUME~1\ADMINI~1\APPLIC~1\Macromedia
[15/04/2008|19:54] C:\DOCUME~1\ADMINI~1\APPLIC~1\Malwarebytes
[01/11/2007|17:59] C:\DOCUME~1\ADMINI~1\APPLIC~1\Media Player Classic
[27/03/2008|12:55] C:\DOCUME~1\ADMINI~1\APPLIC~1\Microsoft
[09/09/2007|22:35] C:\DOCUME~1\ADMINI~1\APPLIC~1\Mindscape
[12/09/2007|09:06] C:\DOCUME~1\ADMINI~1\APPLIC~1\Mozilla
[08/04/2008|19:16] C:\DOCUME~1\ADMINI~1\APPLIC~1\Plopp1.2
[17/11/2007|17:35] C:\DOCUME~1\ADMINI~1\APPLIC~1\Printer Info Cache
[06/03/2008|21:05] C:\DOCUME~1\ADMINI~1\APPLIC~1\Skype
[14/10/2007|23:06] C:\DOCUME~1\ADMINI~1\APPLIC~1\Sun
[12/09/2007|09:06] C:\DOCUME~1\ADMINI~1\APPLIC~1\Talkback
[16/09/2007|11:47] C:\DOCUME~1\ADMINI~1\APPLIC~1\TuxPaint
[21/12/2007|11:51] C:\DOCUME~1\ADMINI~1\APPLIC~1\Uniblue
[29/09/2007|17:46] C:\DOCUME~1\ADMINI~1\APPLIC~1\Windows Live Writer
[15/04/2008|15:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\.
[15/04/2008|15:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\..
[14/02/2008|10:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[09/09/2007|22:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[16/01/2008|14:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Bluetooth
[16/09/2007|17:10] C:\DOCUME~1\ALLUSE~1\APPLIC~1\CyberLink
[09/09/2007|21:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\desktop.ini
[01/03/2008|09:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Downloaded Installations
[09/09/2007|20:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
[13/10/2007|22:18] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Grisoft
[17/11/2007|13:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\HP
[28/03/2008|22:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\HPSSUPPLY
[28/03/2008|22:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\hpzinstall.log
[15/04/2008|19:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Malwarebytes
[07/03/2008|12:10] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!
[11/03/2008|17:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[12/09/2007|09:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Mozilla
[12/11/2007|09:23] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MumboJumbo
[05/04/2008|12:33] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Plopp1.2
[16/02/2008|17:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\QTSBandwidthCache
[09/09/2007|20:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Skype
[15/04/2008|10:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
[16/11/2007|23:01] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
[12/09/2007|11:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[10/10/2007|20:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Live Toolbar
[24/03/2008|22:38] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
[01/04/2008|13:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Yahoo! Companion
[09/09/2007|21:37] C:\DOCUME~1\DEFAUL~1\APPLIC~1\.
[09/09/2007|21:37] C:\DOCUME~1\DEFAUL~1\APPLIC~1\..
[09/09/2007|21:37] C:\DOCUME~1\DEFAUL~1\APPLIC~1\desktop.ini
[09/09/2007|19:46] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
[09/09/2007|19:49] C:\DOCUME~1\LOCALS~1\APPLIC~1\.
[09/09/2007|19:49] C:\DOCUME~1\LOCALS~1\APPLIC~1\..
[29/09/2007|17:40] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft
[29/09/2007|17:36] C:\DOCUME~1\NETWOR~1\APPLIC~1\.
[29/09/2007|17:36] C:\DOCUME~1\NETWOR~1\APPLIC~1\..
[29/09/2007|17:36] C:\DOCUME~1\NETWOR~1\APPLIC~1\Identities
[29/09/2007|17:36] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft
----------------[ Tâches planifiées dans C:\WINDOWS\tasks ]---------------
[16/04/2008 21:36][--ah-----] C:\WINDOWS\tasks\SA.DAT
[02/10/2001 18:16][-r-h-----] C:\WINDOWS\tasks\desktop.ini
---------------[ Listing des dossiers dans C:\Program Files ]--------------
[16/04/2008|20:48] C:\Program Files\.
[16/04/2008|20:48] C:\Program Files\..
[14/02/2008|10:44] C:\Program Files\Adobe
[10/09/2007|21:00] C:\Program Files\Ahead
[09/09/2007|20:23] C:\Program Files\Alwil Software
[19/11/2007|18:39] C:\Program Files\Apple Software Update
[11/10/2007|23:12] C:\Program Files\aRPNCalc
[22/12/2007|17:55] C:\Program Files\Atari
[20/12/2007|19:08] C:\Program Files\B4Playing
[26/09/2007|21:01] C:\Program Files\BarreConfCMCIC
[16/04/2008|11:37] C:\Program Files\CA Yahoo! Anti-Spy
[13/10/2007|23:18] C:\Program Files\CCleaner
[08/03/2008|19:48] C:\Program Files\C-Media 3D Audio
[09/04/2008|10:12] C:\Program Files\Common Files
[09/09/2007|19:42] C:\Program Files\ComPlus Applications
[08/03/2008|19:34] C:\Program Files\Conduit
[16/09/2007|17:09] C:\Program Files\CyberLink
[12/12/2007|13:56] C:\Program Files\Disney Interactive
[16/04/2008|11:37] C:\Program Files\DivX
[28/10/2007|13:43] C:\Program Files\DK
[05/04/2008|11:36] C:\Program Files\Fichiers communs
[08/03/2008|19:34] C:\Program Files\free-downloads.net
[10/04/2008|09:08] C:\Program Files\funk draw rect
[21/12/2007|21:30] C:\Program Files\Google
[13/10/2007|22:18] C:\Program Files\Grisoft
[17/11/2007|13:41] C:\Program Files\Hewlett-Packard
[17/11/2007|17:35] C:\Program Files\HP
[16/11/2007|23:36] C:\Program Files\Incredijeux
[13/11/2007|15:58] C:\Program Files\IncrediMail
[08/03/2008|13:52] C:\Program Files\InstallShield Installation Information
[02/03/2008|23:07] C:\Program Files\Intel Desktop Board
[09/04/2008|18:00] C:\Program Files\Internet Explorer
[09/09/2007|19:54] C:\Program Files\Inventel
[16/01/2008|14:31] C:\Program Files\IVT Corporation
[04/04/2008|18:00] C:\Program Files\Java
[09/04/2008|13:25] C:\Program Files\Kiwee Toolbar2
[20/10/2007|16:54] C:\Program Files\Lavasoft
[01/03/2008|00:25] C:\Program Files\lecteur windows media 11
[10/04/2008|09:08] C:\Program Files\Messenger Plus! Live
[09/09/2007|19:47] C:\Program Files\microsoft frontpage
[19/11/2007|17:21] C:\Program Files\Microsoft Hardware
[04/12/2007|16:33] C:\Program Files\Microsoft Office
[29/09/2007|17:36] C:\Program Files\Microsoft SQL Server Compact Edition
[26/09/2007|11:46] C:\Program Files\Mindscape
[17/09/2007|20:27] C:\Program Files\Movie Maker
[16/04/2008|22:25] C:\Program Files\Mozilla Firefox
[09/09/2007|23:09] C:\Program Files\MSECache
[12/09/2007|21:54] C:\Program Files\MSI
[09/09/2007|19:42] C:\Program Files\MSN Gaming Zone
[24/10/2007|15:42] C:\Program Files\MSN Messenger
[17/11/2007|23:05] C:\Program Files\MSXML 4.0
[08/03/2008|19:55] C:\Program Files\Multimedia V3.54
[23/11/2007|13:16] C:\Program Files\Netlog 24
[09/09/2007|19:43] C:\Program Files\NetMeeting
[17/09/2007|20:27] C:\Program Files\Outlook Express
[28/01/2008|10:58] C:\Program Files\PhotoFiltre
[09/09/2007|22:36] C:\Program Files\QuickTime
[20/12/2007|18:47] C:\Program Files\ReflexiveArcade
[24/12/2007|16:43] C:\Program Files\SAMSUNG
[09/09/2007|19:44] C:\Program Files\Services en ligne
[25/10/2007|19:57] C:\Program Files\SiS7012
[08/03/2008|13:52] C:\Program Files\sisagp
[08/03/2008|19:46] C:\Program Files\SiSLan
[09/09/2007|20:20] C:\Program Files\Skype
[16/10/2007|10:11] C:\Program Files\Sunbelt Software
[16/04/2008|20:48] C:\Program Files\Trend Micro
[09/09/2007|19:50] C:\Program Files\Uninstall Information
[09/09/2007|19:57] C:\Program Files\Wanadoo
[26/10/2007|15:18] C:\Program Files\Windows Desktop Search
[11/04/2008|11:12] C:\Program Files\Windows Live
[08/04/2008|18:56] C:\Program Files\Windows Live Safety Center
[20/10/2007|16:44] C:\Program Files\Windows Live Toolbar
[11/03/2008|13:16] C:\Program Files\Windows Media Connect 2
[11/03/2008|13:40] C:\Program Files\Windows Media Player
[09/09/2007|19:41] C:\Program Files\Windows NT
[09/09/2007|19:44] C:\Program Files\WindowsUpdate
[09/09/2007|20:05] C:\Program Files\WinRAR
[09/09/2007|19:47] C:\Program Files\xerox
[09/04/2008|10:12] C:\Program Files\Yahoo!
------[ Listing des dossiers dans C:\Program Files\Fichiers communs ]------
[05/04/2008|11:36] C:\Program Files\Fichiers communs\.
[05/04/2008|11:36] C:\Program Files\Fichiers communs\..
[14/02/2008|10:45] C:\Program Files\Fichiers communs\Adobe
[10/09/2007|21:00] C:\Program Files\Fichiers communs\Ahead
[12/09/2007|15:23] C:\Program Files\Fichiers communs\Designer
[04/03/2008|20:00] C:\Program Files\Fichiers communs\DirectX
[09/09/2007|19:55] C:\Program Files\Fichiers communs\FDEUnInstaller.exe
[11/10/2007|23:18] C:\Program Files\Fichiers communs\GTK
[17/11/2007|13:36] C:\Program Files\Fichiers communs\Hewlett-Packard
[17/11/2007|17:35] C:\Program Files\Fichiers communs\HP
[30/09/2007|13:38] C:\Program Files\Fichiers communs\InstallShield
[20/09/2007|16:31] C:\Program Files\Fichiers communs\Java
[09/09/2007|20:49] C:\Program Files\Fichiers communs\Logitech
[17/01/2008|22:58] C:\Program Files\Fichiers communs\Microsoft Shared
[09/09/2007|19:43] C:\Program Files\Fichiers communs\MSSoap
[09/09/2007|21:37] C:\Program Files\Fichiers communs\ODBC
[05/04/2008|11:36] C:\Program Files\Fichiers communs\Scanner
[09/09/2007|19:43] C:\Program Files\Fichiers communs\Services
[09/09/2007|20:20] C:\Program Files\Fichiers communs\Skype
[09/09/2007|21:37] C:\Program Files\Fichiers communs\SpeechEngines
[16/09/2007|22:16] C:\Program Files\Fichiers communs\System
[03/01/2008|21:45] C:\Program Files\Fichiers communs\Vivendi Universal Games
[17/01/2008|22:56] C:\Program Files\Fichiers communs\WindowsLiveInstaller
----------------------[ Recherche avec S_Lop ]---------------------
Aucun fichier / dossier Lop trouvé !
-----------------[ Recherche de Fichiers / Dossiers Lop ]-----------------
Aucun fichier / dossier Lop trouvé !
----------------------[ Verification du Registre ]----------------------
..... OK !
--------------------[ Verification du fichier Hosts ]---------------------
Fichier Hosts PROPRE
----------------[ Recherche de fichiers avec Catchme ]-----------------
catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-16 22:29:10
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 0
--------------------[ Recherche d'autres infections ]---------------------
Aucune autre infection trouvée !
/!\ [Fich:69][Doss:7] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp
/!\ [Fich:13][Doss:0] C:\DOCUME~1\ADMINI~1\Cookies
/!\ [Fich:38][Doss:5] C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMPOR~1\content.IE5
--------------------[ Fin du rapport a 22:30:29,90 ]----------------------
Re,
Tu as un Windows piraté ?
Fix la ligne dans le cadre ci-dessous avec Hijackthis : AIDE EN IMAGES
O4 - HKCU\..\Run: [City meet] C:\DOCUME~1\ADMINI~1\APPLIC~1\FUNKDR~1\Internetdrivemail.exe |
&
Télécharge OTMoveIt (d'OldTimer). Sauvegarde-le sur ton Bureau.
Sélectionne tous les emplacements dans le cadre ci-dessous :
C:\DOCUME~1\ADMINI~1\APPLIC~1\funk draw rect
|
---> Clique-droit puis Copier (ou Ctrl+C)
Double-clique sur OTMoveIt.exe afin de le lancer.
Fais un Clique-droit sur le cadre de gauche puis choisis Coller (ou Ctrl+V).
Clique maintenant sur MoveIt!
Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
Accepte en cliquant sur YES.
Poste le rapport situé dans ce dossier : C:\_OTMoveIt\MovedFiles\
Le nom du rapport correspond au moment de sa création : date_heure.log
->Informations sur le logiciel<-
Répondre à Angeldark
C:\DOCUME~1\ADMINI~1\APPLIC~1\funk draw rect moved successfully.
C:\Program Files\funk draw rect moved successfully.
OTMoveIt2 by OldTimer - Version 1.0.4.1 log created on 04172008_214234
pour mon logiciel oui car j'ai eu un arlerte de microsoft car je fait les mises a jour mais je nen savais rien car c un pc je jai eu d'occasion
Message édité par mag14100 le 17-04-2008 à 22:02:49
Reposte un rapport Hijackthis.
Répondre à Angeldark
bonsoir voici le log que tu ma demander et merci de ta patience
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:06:18, on 18/04/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
C:\Program Files\Controle Parental\bin\optproxy.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\WgaTray.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\sistray.EXE
C:\WINDOWS\system32\keyhook.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Orange\Systray\SystrayApp.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\PROGRA~1\CONTRO~1\bin\optgui.exe
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
C:\Program Files\Netlog 24\Notifier\Netlog24Notifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
C:\PROGRA~1\INCRED~1\bin\IMApp.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Orange\Launcher\Launcher.exe
C:\Program Files\Orange\connectivity\connectivitymanager.exe
C:\Program Files\Orange\connectivity\CoreCom\CoreCom.exe
C:\Program Files\Orange\connectivity\CoreCom\OraConfigRecover.exe
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTCOMModule\0\FTCOMModule.exe
D:\eMule\emule.exe
C:\Program Files\Orange\Deskboard\deskboard.exe
C:\Program Files\Orange\browser\browser.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.orange.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Favoris
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\Orange\SearchURLHook\SearchPageURL.dll
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [CamMonitor] C:\Program Files\Hewlett-Packard\Digital Imaging\\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SiS Tray] C:\WINDOWS\system32\sistray.EXE
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\system32\keyhook.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SystrayORAHSS] "C:\Program Files\Orange\Systray\SystrayApp.exe"
O4 - HKLM\..\Run: [ORAHSSSessionManager] C:\Program Files\Orange\SessionManager\SessionManager.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [OPTENET_GUI] C:\PROGRA~1\CONTRO~1\bin\optgui.exe
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Netlog 24] "C:\Program Files\Netlog 24\Notifier\Netlog24Notifier.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [City meet] C:\DOCUME~1\ADMINI~1\APPLIC~1\FUNKDR~1\Internetdrivemail.exe
O4 - HKUS\S-1-5-19\..\RunOnce: [XPPro4.0] %systemroot%\REG\run.cmd (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\RunOnce: [XPPro4.0] %systemroot%\REG\run.cmd (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [Picasa Media Detector] D:\montage\Picasa2\PicasaMediaDetector.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [XPPro4.0] %systemroot%\REG\run.cmd (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Picasa Media Detector] D:\montage\Picasa2\PicasaMediaDetector.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [XPPro4.0] %systemroot%\REG\run.cmd (User 'Default user')
O4 - Global Startup: BlueSoleil.lnk = C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O15 - Trusted Zone: http://www.msi.com.tw
O15 - Trusted Zone: http://www.orange.fr
O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/too [...] ontrol.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-F [...] E_UNO1.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/r [...] se4009.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://copainsdavant.linternaute.c [...] oader4.cab
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - http://www.touslesdrivers.com/fich [...] _0_4_9.cab
O16 - DPF: {BD8667B7-38D8-4C77-B580-18C3E146372C} (Creative Toolbox Plug-in) - http://kiw.imgag.com/imgag/cp/inst [...] -kiwen.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/bina [...] b56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/bina [...] b56986.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: Orange Contrôle Parental (OPTENET_FILTER) - Orange - C:\Program Files\Controle Parental\bin\optproxy.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
--
End of file - 11909 bytes
Message édité par mag14100 le 18-04-2008 à 21:08:27
Supprime ta version de LopSD, retélécharge-la. Puis passe l'option 1.
Répondre à Angeldark
peut tu m'envoyer un lien pour le telecharger
dit moi je telecharge le meme
Message édité par mag14100 le 18-04-2008 à 21:22:33
C'est le même lien hein.
Répondre à Angeldark
-----------------------[ Lop S&D 4.1.1-3 XP/Vista ]---------------------
[ Windows XP (NT 5.1) Build 2600, Service Pack 2 ]
[ USER : Administrateur ] [ "C:\Lop SD" ]
[ 18/04/2008 | 21:26:58,71 ] [ PC : XPSP2-F87D6FB42 ]
[ MAJ : 17-04-2008 | 19:51 ]
-------------[ Listing des dossiers dans Application Data ]------------
[17/04/2008|21:55] C:\DOCUME~1\ADMINI~1\APPLIC~1\.
[17/04/2008|21:55] C:\DOCUME~1\ADMINI~1\APPLIC~1\..
[16/02/2008|23:12] C:\DOCUME~1\ADMINI~1\APPLIC~1\Adobe
[18/09/2007|13:40] C:\DOCUME~1\ADMINI~1\APPLIC~1\AdobeUM
[10/09/2007|21:36] C:\DOCUME~1\ADMINI~1\APPLIC~1\Ahead
[23/09/2007|11:32] C:\DOCUME~1\ADMINI~1\APPLIC~1\Apple Computer
[20/12/2007|18:50] C:\DOCUME~1\ADMINI~1\APPLIC~1\Chessmaster Challenge
[16/09/2007|17:10] C:\DOCUME~1\ADMINI~1\APPLIC~1\CyberLink
[09/09/2007|21:37] C:\DOCUME~1\ADMINI~1\APPLIC~1\desktop.ini
[16/04/2008|21:33] C:\DOCUME~1\ADMINI~1\APPLIC~1\DivX
[09/09/2007|20:48] C:\DOCUME~1\ADMINI~1\APPLIC~1\Dossier de t‚l‚chargement Share-to-Web
[12/09/2007|21:30] C:\DOCUME~1\ADMINI~1\APPLIC~1\Dossier de t‚l‚chargement Share-to-Web
[17/04/2008|21:55] C:\DOCUME~1\ADMINI~1\APPLIC~1\funk draw rect
[06/01/2008|23:58] C:\DOCUME~1\ADMINI~1\APPLIC~1\GDIPFONTCACHEV1.DAT
[09/09/2007|23:02] C:\DOCUME~1\ADMINI~1\APPLIC~1\Google
[13/10/2007|22:18] C:\DOCUME~1\ADMINI~1\APPLIC~1\Grisoft
[19/12/2007|16:03] C:\DOCUME~1\ADMINI~1\APPLIC~1\Help
[11/09/2007|14:46] C:\DOCUME~1\ADMINI~1\APPLIC~1\Hewlett-Packard
[17/11/2007|17:11] C:\DOCUME~1\ADMINI~1\APPLIC~1\HP
[22/03/2008|20:12] C:\DOCUME~1\ADMINI~1\APPLIC~1\Identities
[13/03/2008|16:56] C:\DOCUME~1\ADMINI~1\APPLIC~1\Image Zone Express
[25/01/2008|19:21] C:\DOCUME~1\ADMINI~1\APPLIC~1\IMBooster
[20/10/2007|16:54] C:\DOCUME~1\ADMINI~1\APPLIC~1\Lavasoft
[22/09/2007|01:07] C:\DOCUME~1\ADMINI~1\APPLIC~1\Leadertech
[31/10/2007|18:17] C:\DOCUME~1\ADMINI~1\APPLIC~1\LimeWire
[26/03/2008|14:38] C:\DOCUME~1\ADMINI~1\APPLIC~1\Macromedia
[15/04/2008|19:54] C:\DOCUME~1\ADMINI~1\APPLIC~1\Malwarebytes
[01/11/2007|17:59] C:\DOCUME~1\ADMINI~1\APPLIC~1\Media Player Classic
[27/03/2008|12:55] C:\DOCUME~1\ADMINI~1\APPLIC~1\Microsoft
[09/09/2007|22:35] C:\DOCUME~1\ADMINI~1\APPLIC~1\Mindscape
[12/09/2007|09:06] C:\DOCUME~1\ADMINI~1\APPLIC~1\Mozilla
[08/04/2008|19:16] C:\DOCUME~1\ADMINI~1\APPLIC~1\Plopp1.2
[17/11/2007|17:35] C:\DOCUME~1\ADMINI~1\APPLIC~1\Printer Info Cache
[06/03/2008|21:05] C:\DOCUME~1\ADMINI~1\APPLIC~1\Skype
[14/10/2007|23:06] C:\DOCUME~1\ADMINI~1\APPLIC~1\Sun
[12/09/2007|09:06] C:\DOCUME~1\ADMINI~1\APPLIC~1\Talkback
[16/09/2007|11:47] C:\DOCUME~1\ADMINI~1\APPLIC~1\TuxPaint
[21/12/2007|11:51] C:\DOCUME~1\ADMINI~1\APPLIC~1\Uniblue
[29/09/2007|17:46] C:\DOCUME~1\ADMINI~1\APPLIC~1\Windows Live Writer
[15/04/2008|15:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\.
[15/04/2008|15:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\..
[14/02/2008|10:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[09/09/2007|22:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[16/01/2008|14:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Bluetooth
[16/09/2007|17:10] C:\DOCUME~1\ALLUSE~1\APPLIC~1\CyberLink
[09/09/2007|21:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\desktop.ini
[01/03/2008|09:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Downloaded Installations
[09/09/2007|20:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
[13/10/2007|22:18] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Grisoft
[17/11/2007|13:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\HP
[28/03/2008|22:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\HPSSUPPLY
[28/03/2008|22:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\hpzinstall.log
[15/04/2008|19:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Malwarebytes
[07/03/2008|12:10] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!
[11/03/2008|17:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[12/09/2007|09:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Mozilla
[12/11/2007|09:23] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MumboJumbo
[05/04/2008|12:33] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Plopp1.2
[16/02/2008|17:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\QTSBandwidthCache
[09/09/2007|20:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Skype
[15/04/2008|10:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
[16/11/2007|23:01] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
[12/09/2007|11:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[10/10/2007|20:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Live Toolbar
[24/03/2008|22:38] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
[09/09/2007|21:37] C:\DOCUME~1\DEFAUL~1\APPLIC~1\.
[09/09/2007|21:37] C:\DOCUME~1\DEFAUL~1\APPLIC~1\..
[09/09/2007|21:37] C:\DOCUME~1\DEFAUL~1\APPLIC~1\desktop.ini
[09/09/2007|19:46] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
[09/09/2007|19:49] C:\DOCUME~1\LOCALS~1\APPLIC~1\.
[09/09/2007|19:49] C:\DOCUME~1\LOCALS~1\APPLIC~1\..
[29/09/2007|17:40] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft
[29/09/2007|17:36] C:\DOCUME~1\NETWOR~1\APPLIC~1\.
[29/09/2007|17:36] C:\DOCUME~1\NETWOR~1\APPLIC~1\..
[29/09/2007|17:36] C:\DOCUME~1\NETWOR~1\APPLIC~1\Identities
[29/09/2007|17:36] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft
----------------[ Tâches planifiées dans C:\WINDOWS\tasks ]---------------
[18/04/2008 11:37][--ah-----] C:\WINDOWS\tasks\SA.DAT
[02/10/2001 18:16][-r-h-----] C:\WINDOWS\tasks\desktop.ini
---------------[ Listing des dossiers dans C:\Program Files ]--------------
[18/04/2008|11:33] C:\Program Files\.
[18/04/2008|11:33] C:\Program Files\..
[14/02/2008|10:44] C:\Program Files\Adobe
[10/09/2007|21:00] C:\Program Files\Ahead
[09/09/2007|20:23] C:\Program Files\Alwil Software
[19/11/2007|18:39] C:\Program Files\Apple Software Update
[11/10/2007|23:12] C:\Program Files\aRPNCalc
[22/12/2007|17:55] C:\Program Files\Atari
[20/12/2007|19:08] C:\Program Files\B4Playing
[26/09/2007|21:01] C:\Program Files\BarreConfCMCIC
[16/04/2008|11:37] C:\Program Files\CA Yahoo! Anti-Spy
[13/10/2007|23:18] C:\Program Files\CCleaner
[08/03/2008|19:48] C:\Program Files\C-Media 3D Audio
[09/04/2008|10:12] C:\Program Files\Common Files
[09/09/2007|19:42] C:\Program Files\ComPlus Applications
[08/03/2008|19:34] C:\Program Files\Conduit
[18/04/2008|11:35] C:\Program Files\Controle Parental
[16/09/2007|17:09] C:\Program Files\CyberLink
[12/12/2007|13:56] C:\Program Files\Disney Interactive
[16/04/2008|11:37] C:\Program Files\DivX
[28/10/2007|13:43] C:\Program Files\DK
[17/04/2008|09:17] C:\Program Files\Fichiers communs
[08/03/2008|19:34] C:\Program Files\free-downloads.net
[21/12/2007|21:30] C:\Program Files\Google
[13/10/2007|22:18] C:\Program Files\Grisoft
[17/11/2007|13:41] C:\Program Files\Hewlett-Packard
[17/11/2007|17:35] C:\Program Files\HP
[16/11/2007|23:36] C:\Program Files\Incredijeux
[13/11/2007|15:58] C:\Program Files\IncrediMail
[18/04/2008|11:33] C:\Program Files\InstallShield Installation Information
[02/03/2008|23:07] C:\Program Files\Intel Desktop Board
[09/04/2008|18:00] C:\Program Files\Internet Explorer
[09/09/2007|19:54] C:\Program Files\Inventel
[16/01/2008|14:31] C:\Program Files\IVT Corporation
[17/04/2008|11:57] C:\Program Files\Java
[09/04/2008|13:25] C:\Program Files\Kiwee Toolbar2
[20/10/2007|16:54] C:\Program Files\Lavasoft
[01/03/2008|00:25] C:\Program Files\lecteur windows media 11
[10/04/2008|09:08] C:\Program Files\Messenger Plus! Live
[09/09/2007|19:47] C:\Program Files\microsoft frontpage
[19/11/2007|17:21] C:\Program Files\Microsoft Hardware
[04/12/2007|16:33] C:\Program Files\Microsoft Office
[29/09/2007|17:36] C:\Program Files\Microsoft SQL Server Compact Edition
[26/09/2007|11:46] C:\Program Files\Mindscape
[17/09/2007|20:27] C:\Program Files\Movie Maker
[17/04/2008|11:55] C:\Program Files\Mozilla Firefox
[09/09/2007|23:09] C:\Program Files\MSECache
[12/09/2007|21:54] C:\Program Files\MSI
[09/09/2007|19:42] C:\Program Files\MSN Gaming Zone
[24/10/2007|15:42] C:\Program Files\MSN Messenger
[17/11/2007|23:05] C:\Program Files\MSXML 4.0
[08/03/2008|19:55] C:\Program Files\Multimedia V3.54
[23/11/2007|13:16] C:\Program Files\Netlog 24
[09/09/2007|19:43] C:\Program Files\NetMeeting
[17/04/2008|09:20] C:\Program Files\Orange
[17/09/2007|20:27] C:\Program Files\Outlook Express
[28/01/2008|10:58] C:\Program Files\PhotoFiltre
[09/09/2007|22:36] C:\Program Files\QuickTime
[20/12/2007|18:47] C:\Program Files\ReflexiveArcade
[24/12/2007|16:43] C:\Program Files\SAMSUNG
[09/09/2007|19:44] C:\Program Files\Services en ligne
[25/10/2007|19:57] C:\Program Files\SiS7012
[08/03/2008|13:52] C:\Program Files\sisagp
[08/03/2008|19:46] C:\Program Files\SiSLan
[09/09/2007|20:20] C:\Program Files\Skype
[16/10/2007|10:11] C:\Program Files\Sunbelt Software
[16/04/2008|20:48] C:\Program Files\Trend Micro
[09/09/2007|19:50] C:\Program Files\Uninstall Information
[09/09/2007|19:57] C:\Program Files\Wanadoo
[26/10/2007|15:18] C:\Program Files\Windows Desktop Search
[11/04/2008|11:12] C:\Program Files\Windows Live
[08/04/2008|18:56] C:\Program Files\Windows Live Safety Center
[20/10/2007|16:44] C:\Program Files\Windows Live Toolbar
[11/03/2008|13:16] C:\Program Files\Windows Media Connect 2
[11/03/2008|13:40] C:\Program Files\Windows Media Player
[09/09/2007|19:41] C:\Program Files\Windows NT
[09/09/2007|19:44] C:\Program Files\WindowsUpdate
[09/09/2007|20:05] C:\Program Files\WinRAR
[09/09/2007|19:47] C:\Program Files\xerox
[17/04/2008|11:56] C:\Program Files\Yahoo!
------[ Listing des dossiers dans C:\Program Files\Fichiers communs ]------
[17/04/2008|09:17] C:\Program Files\Fichiers communs\.
[17/04/2008|09:17] C:\Program Files\Fichiers communs\..
[14/02/2008|10:45] C:\Program Files\Fichiers communs\Adobe
[10/09/2007|21:00] C:\Program Files\Fichiers communs\Ahead
[12/09/2007|15:23] C:\Program Files\Fichiers communs\Designer
[04/03/2008|20:00] C:\Program Files\Fichiers communs\DirectX
[09/09/2007|19:55] C:\Program Files\Fichiers communs\FDEUnInstaller.exe
[17/04/2008|09:17] C:\Program Files\Fichiers communs\France Telecom
[11/10/2007|23:18] C:\Program Files\Fichiers communs\GTK
[17/11/2007|13:36] C:\Program Files\Fichiers communs\Hewlett-Packard
[17/11/2007|17:35] C:\Program Files\Fichiers communs\HP
[30/09/2007|13:38] C:\Program Files\Fichiers communs\InstallShield
[20/09/2007|16:31] C:\Program Files\Fichiers communs\Java
[09/09/2007|20:49] C:\Program Files\Fichiers communs\Logitech
[17/01/2008|22:58] C:\Program Files\Fichiers communs\Microsoft Shared
[09/09/2007|19:43] C:\Program Files\Fichiers communs\MSSoap
[09/09/2007|21:37] C:\Program Files\Fichiers communs\ODBC
[05/04/2008|11:36] C:\Program Files\Fichiers communs\Scanner
[09/09/2007|19:43] C:\Program Files\Fichiers communs\Services
[09/09/2007|20:20] C:\Program Files\Fichiers communs\Skype
[09/09/2007|21:37] C:\Program Files\Fichiers communs\SpeechEngines
[16/09/2007|22:16] C:\Program Files\Fichiers communs\System
[03/01/2008|21:45] C:\Program Files\Fichiers communs\Vivendi Universal Games
[17/01/2008|22:56] C:\Program Files\Fichiers communs\WindowsLiveInstaller
----------------------[ Recherche avec S_Lop ]---------------------
Aucun fichier / dossier Lop trouvé !
-----------------[ Recherche de Fichiers / Dossiers Lop ]-----------------
C:\DOCUME~1\ADMINI~1\APPLIC~1\funk draw rect
----------------------[ Verification du Registre ]----------------------
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
..... OK !
--------------------[ Verification du fichier Hosts ]---------------------
Fichier Hosts PROPRE
----------------[ Recherche de fichiers avec Catchme ]-----------------
catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-18 21:28:57
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 0
--------------------[ Recherche d'autres infections ]---------------------
Aucune autre infection trouvée !
/!\ [Fich:110][Doss:34] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp
/!\ [Fich:133][Doss:0] C:\DOCUME~1\ADMINI~1\Cookies
/!\ [Fich:7441][Doss:9] C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMPOR~1\content.IE5
--------------------[ Fin du rapport a 21:30:37,46 ]----------------------
ok merci mais dit moi a chaque fois que je lance une analyse avec ce logiciel avast detecte un tojan win32:inject-EV[trj]que je mets en quarantaine
Message édité par mag14100 le 18-04-2008 à 21:36:21
Passe l'option 2.
Message édité par Angeldark le 18-04-2008 à 21:56:20
Répondre à Angeldark
-----------------------[ Lop S&D 4.1.1-3 XP/Vista ]---------------------
[ Windows XP (NT 5.1) Build 2600, Service Pack 2 ]
[ USER : Administrateur ] [ "C:\Lop SD" ]
[ 18/04/2008 | 22:16:51,70 ] [ PC : XPSP2-F87D6FB42 ]
[ MAJ : 17-04-2008 | 19:51 ]
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ SUPPRESSION /////////////////////////////
Supprimé! - C:\DOCUME~1\ADMINI~1\APPLIC~1\funk draw rect
//////////////////////////////////////-\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
-------------[ Listing des dossiers dans Application Data ]------------
[18/04/2008|22:16] C:\DOCUME~1\ADMINI~1\APPLIC~1\.
[18/04/2008|22:16] C:\DOCUME~1\ADMINI~1\APPLIC~1\..
[16/02/2008|23:12] C:\DOCUME~1\ADMINI~1\APPLIC~1\Adobe
[18/09/2007|13:40] C:\DOCUME~1\ADMINI~1\APPLIC~1\AdobeUM
[10/09/2007|21:36] C:\DOCUME~1\ADMINI~1\APPLIC~1\Ahead
[23/09/2007|11:32] C:\DOCUME~1\ADMINI~1\APPLIC~1\Apple Computer
[20/12/2007|18:50] C:\DOCUME~1\ADMINI~1\APPLIC~1\Chessmaster Challenge
[16/09/2007|17:10] C:\DOCUME~1\ADMINI~1\APPLIC~1\CyberLink
[09/09/2007|21:37] C:\DOCUME~1\ADMINI~1\APPLIC~1\desktop.ini
[16/04/2008|21:33] C:\DOCUME~1\ADMINI~1\APPLIC~1\DivX
[09/09/2007|20:48] C:\DOCUME~1\ADMINI~1\APPLIC~1\Dossier de t‚l‚chargement Share-to-Web
[12/09/2007|21:30] C:\DOCUME~1\ADMINI~1\APPLIC~1\Dossier de t‚l‚chargement Share-to-Web
[06/01/2008|23:58] C:\DOCUME~1\ADMINI~1\APPLIC~1\GDIPFONTCACHEV1.DAT
[09/09/2007|23:02] C:\DOCUME~1\ADMINI~1\APPLIC~1\Google
[13/10/2007|22:18] C:\DOCUME~1\ADMINI~1\APPLIC~1\Grisoft
[19/12/2007|16:03] C:\DOCUME~1\ADMINI~1\APPLIC~1\Help
[11/09/2007|14:46] C:\DOCUME~1\ADMINI~1\APPLIC~1\Hewlett-Packard
[17/11/2007|17:11] C:\DOCUME~1\ADMINI~1\APPLIC~1\HP
[22/03/2008|20:12] C:\DOCUME~1\ADMINI~1\APPLIC~1\Identities
[13/03/2008|16:56] C:\DOCUME~1\ADMINI~1\APPLIC~1\Image Zone Express
[25/01/2008|19:21] C:\DOCUME~1\ADMINI~1\APPLIC~1\IMBooster
[20/10/2007|16:54] C:\DOCUME~1\ADMINI~1\APPLIC~1\Lavasoft
[22/09/2007|01:07] C:\DOCUME~1\ADMINI~1\APPLIC~1\Leadertech
[31/10/2007|18:17] C:\DOCUME~1\ADMINI~1\APPLIC~1\LimeWire
[26/03/2008|14:38] C:\DOCUME~1\ADMINI~1\APPLIC~1\Macromedia
[15/04/2008|19:54] C:\DOCUME~1\ADMINI~1\APPLIC~1\Malwarebytes
[01/11/2007|17:59] C:\DOCUME~1\ADMINI~1\APPLIC~1\Media Player Classic
[27/03/2008|12:55] C:\DOCUME~1\ADMINI~1\APPLIC~1\Microsoft
[09/09/2007|22:35] C:\DOCUME~1\ADMINI~1\APPLIC~1\Mindscape
[12/09/2007|09:06] C:\DOCUME~1\ADMINI~1\APPLIC~1\Mozilla
[08/04/2008|19:16] C:\DOCUME~1\ADMINI~1\APPLIC~1\Plopp1.2
[17/11/2007|17:35] C:\DOCUME~1\ADMINI~1\APPLIC~1\Printer Info Cache
[06/03/2008|21:05] C:\DOCUME~1\ADMINI~1\APPLIC~1\Skype
[14/10/2007|23:06] C:\DOCUME~1\ADMINI~1\APPLIC~1\Sun
[12/09/2007|09:06] C:\DOCUME~1\ADMINI~1\APPLIC~1\Talkback
[16/09/2007|11:47] C:\DOCUME~1\ADMINI~1\APPLIC~1\TuxPaint
[21/12/2007|11:51] C:\DOCUME~1\ADMINI~1\APPLIC~1\Uniblue
[29/09/2007|17:46] C:\DOCUME~1\ADMINI~1\APPLIC~1\Windows Live Writer
[15/04/2008|15:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\.
[15/04/2008|15:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\..
[14/02/2008|10:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[09/09/2007|22:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[16/01/2008|14:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Bluetooth
[16/09/2007|17:10] C:\DOCUME~1\ALLUSE~1\APPLIC~1\CyberLink
[09/09/2007|21:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\desktop.ini
[01/03/2008|09:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Downloaded Installations
[09/09/2007|20:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
[13/10/2007|22:18] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Grisoft
[17/11/2007|13:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\HP
[28/03/2008|22:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\HPSSUPPLY
[28/03/2008|22:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\hpzinstall.log
[15/04/2008|19:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Malwarebytes
[07/03/2008|12:10] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!
[11/03/2008|17:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[12/09/2007|09:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Mozilla
[12/11/2007|09:23] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MumboJumbo
[05/04/2008|12:33] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Plopp1.2
[16/02/2008|17:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\QTSBandwidthCache
[09/09/2007|20:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Skype
[15/04/2008|10:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
[16/11/2007|23:01] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
[12/09/2007|11:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[10/10/2007|20:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Live Toolbar
[24/03/2008|22:38] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
[09/09/2007|21:37] C:\DOCUME~1\DEFAUL~1\APPLIC~1\.
[09/09/2007|21:37] C:\DOCUME~1\DEFAUL~1\APPLIC~1\..
[09/09/2007|21:37] C:\DOCUME~1\DEFAUL~1\APPLIC~1\desktop.ini
[09/09/2007|19:46] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
[09/09/2007|19:49] C:\DOCUME~1\LOCALS~1\APPLIC~1\.
[09/09/2007|19:49] C:\DOCUME~1\LOCALS~1\APPLIC~1\..
[29/09/2007|17:40] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft
[29/09/2007|17:36] C:\DOCUME~1\NETWOR~1\APPLIC~1\.
[29/09/2007|17:36] C:\DOCUME~1\NETWOR~1\APPLIC~1\..
[29/09/2007|17:36] C:\DOCUME~1\NETWOR~1\APPLIC~1\Identities
[29/09/2007|17:36] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft
----------------[ Tâches planifiées dans C:\WINDOWS\tasks ]---------------
[18/04/2008 11:37][--ah-----] C:\WINDOWS\tasks\SA.DAT
[02/10/2001 18:16][-r-h-----] C:\WINDOWS\tasks\desktop.ini
---------------[ Listing des dossiers dans C:\Program Files ]--------------
[18/04/2008|11:33] C:\Program Files\.
[18/04/2008|11:33] C:\Program Files\..
[14/02/2008|10:44] C:\Program Files\Adobe
[10/09/2007|21:00] C:\Program Files\Ahead
[09/09/2007|20:23] C:\Program Files\Alwil Software
[19/11/2007|18:39] C:\Program Files\Apple Software Update
[11/10/2007|23:12] C:\Program Files\aRPNCalc
[22/12/2007|17:55] C:\Program Files\Atari
[20/12/2007|19:08] C:\Program Files\B4Playing
[26/09/2007|21:01] C:\Program Files\BarreConfCMCIC
[16/04/2008|11:37] C:\Program Files\CA Yahoo! Anti-Spy
[13/10/2007|23:18] C:\Program Files\CCleaner
[08/03/2008|19:48] C:\Program Files\C-Media 3D Audio
[09/04/2008|10:12] C:\Program Files\Common Files
[09/09/2007|19:42] C:\Program Files\ComPlus Applications
[08/03/2008|19:34] C:\Program Files\Conduit
[18/04/2008|11:35] C:\Program Files\Controle Parental
[16/09/2007|17:09] C:\Program Files\CyberLink
[12/12/2007|13:56] C:\Program Files\Disney Interactive
[16/04/2008|11:37] C:\Program Files\DivX
[28/10/2007|13:43] C:\Program Files\DK
[17/04/2008|09:17] C:\Program Files\Fichiers communs
[08/03/2008|19:34] C:\Program Files\free-downloads.net
[21/12/2007|21:30] C:\Program Files\Google
[13/10/2007|22:18] C:\Program Files\Grisoft
[17/11/2007|13:41] C:\Program Files\Hewlett-Packard
[17/11/2007|17:35] C:\Program Files\HP
[16/11/2007|23:36] C:\Program Files\Incredijeux
[13/11/2007|15:58] C:\Program Files\IncrediMail
[18/04/2008|11:33] C:\Program Files\InstallShield Installation Information
[02/03/2008|23:07] C:\Program Files\Intel Desktop Board
[09/04/2008|18:00] C:\Program Files\Internet Explorer
[09/09/2007|19:54] C:\Program Files\Inventel
[16/01/2008|14:31] C:\Program Files\IVT Corporation
[17/04/2008|11:57] C:\Program Files\Java
[09/04/2008|13:25] C:\Program Files\Kiwee Toolbar2
[20/10/2007|16:54] C:\Program Files\Lavasoft
[01/03/2008|00:25] C:\Program Files\lecteur windows media 11
[10/04/2008|09:08] C:\Program Files\Messenger Plus! Live
[09/09/2007|19:47] C:\Program Files\microsoft frontpage
[19/11/2007|17:21] C:\Program Files\Microsoft Hardware
[04/12/2007|16:33] C:\Program Files\Microsoft Office
[29/09/2007|17:36] C:\Program Files\Microsoft SQL Server Compact Edition
[26/09/2007|11:46] C:\Program Files\Mindscape
[17/09/2007|20:27] C:\Program Files\Movie Maker
[17/04/2008|11:55] C:\Program Files\Mozilla Firefox
[09/09/2007|23:09] C:\Program Files\MSECache
[12/09/2007|21:54] C:\Program Files\MSI
[09/09/2007|19:42] C:\Program Files\MSN Gaming Zone
[24/10/2007|15:42] C:\Program Files\MSN Messenger
[17/11/2007|23:05] C:\Program Files\MSXML 4.0
[08/03/2008|19:55] C:\Program Files\Multimedia V3.54
[23/11/2007|13:16] C:\Program Files\Netlog 24
[09/09/2007|19:43] C:\Program Files\NetMeeting
[17/04/2008|09:20] C:\Program Files\Orange
[17/09/2007|20:27] C:\Program Files\Outlook Express
[28/01/2008|10:58] C:\Program Files\PhotoFiltre
[09/09/2007|22:36] C:\Program Files\QuickTime
[20/12/2007|18:47] C:\Program Files\ReflexiveArcade
[24/12/2007|16:43] C:\Program Files\SAMSUNG
[09/09/2007|19:44] C:\Program Files\Services en ligne
[25/10/2007|19:57] C:\Program Files\SiS7012
[08/03/2008|13:52] C:\Program Files\sisagp
[08/03/2008|19:46] C:\Program Files\SiSLan
[09/09/2007|20:20] C:\Program Files\Skype
[16/10/2007|10:11] C:\Program Files\Sunbelt Software
[16/04/2008|20:48] C:\Program Files\Trend Micro
[09/09/2007|19:50] C:\Program Files\Uninstall Information
[09/09/2007|19:57] C:\Program Files\Wanadoo
[26/10/2007|15:18] C:\Program Files\Windows Desktop Search
[11/04/2008|11:12] C:\Program Files\Windows Live
[08/04/2008|18:56] C:\Program Files\Windows Live Safety Center
[20/10/2007|16:44] C:\Program Files\Windows Live Toolbar
[11/03/2008|13:16] C:\Program Files\Windows Media Connect 2
[11/03/2008|13:40] C:\Program Files\Windows Media Player
[09/09/2007|19:41] C:\Program Files\Windows NT
[09/09/2007|19:44] C:\Program Files\WindowsUpdate
[09/09/2007|20:05] C:\Program Files\WinRAR
[09/09/2007|19:47] C:\Program Files\xerox
[17/04/2008|11:56] C:\Program Files\Yahoo!
------[ Listing des dossiers dans C:\Program Files\Fichiers communs ]------
[17/04/2008|09:17] C:\Program Files\Fichiers communs\.
[17/04/2008|09:17] C:\Program Files\Fichiers communs\..
[14/02/2008|10:45] C:\Program Files\Fichiers communs\Adobe
[10/09/2007|21:00] C:\Program Files\Fichiers communs\Ahead
[12/09/2007|15:23] C:\Program Files\Fichiers communs\Designer
[04/03/2008|20:00] C:\Program Files\Fichiers communs\DirectX
[09/09/2007|19:55] C:\Program Files\Fichiers communs\FDEUnInstaller.exe
[17/04/2008|09:17] C:\Program Files\Fichiers communs\France Telecom
[11/10/2007|23:18] C:\Program Files\Fichiers communs\GTK
[17/11/2007|13:36] C:\Program Files\Fichiers communs\Hewlett-Packard
[17/11/2007|17:35] C:\Program Files\Fichiers communs\HP
[30/09/2007|13:38] C:\Program Files\Fichiers communs\InstallShield
[20/09/2007|16:31] C:\Program Files\Fichiers communs\Java
[09/09/2007|20:49] C:\Program Files\Fichiers communs\Logitech
[17/01/2008|22:58] C:\Program Files\Fichiers communs\Microsoft Shared
[09/09/2007|19:43] C:\Program Files\Fichiers communs\MSSoap
[09/09/2007|21:37] C:\Program Files\Fichiers communs\ODBC
[05/04/2008|11:36] C:\Program Files\Fichiers communs\Scanner
[09/09/2007|19:43] C:\Program Files\Fichiers communs\Services
[09/09/2007|20:20] C:\Program Files\Fichiers communs\Skype
[09/09/2007|21:37] C:\Program Files\Fichiers communs\SpeechEngines
[16/09/2007|22:16] C:\Program Files\Fichiers communs\System
[03/01/2008|21:45] C:\Program Files\Fichiers communs\Vivendi Universal Games
[17/01/2008|22:56] C:\Program Files\Fichiers communs\WindowsLiveInstaller
----------------------[ Recherche avec S_Lop ]---------------------
Aucun fichier / dossier Lop trouvé !
-----------------[ Recherche de Fichiers / Dossiers Lop ]-----------------
Aucun fichier / dossier Lop trouvé !
----------------------[ Verification du Registre ]----------------------
..... OK !
--------------------[ Verification du fichier Hosts ]---------------------
Fichier Hosts PROPRE
----------------[ Recherche de fichiers avec Catchme ]-----------------
catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-18 22:18:38
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 0
--------------------[ Recherche d'autres infections ]---------------------
Aucune autre infection trouvée !
/!\ [Fich:110][Doss:34] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp
/!\ [Fich:135][Doss:0] C:\DOCUME~1\ADMINI~1\Cookies
/!\ [Fich:7652][Doss:9] C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMPOR~1\content.IE5
--------------------[ Fin du rapport a 22:20:15,21 ]----------------------
jai encore eu l'alerte d'avast
Reposte un rapport Hijackthis.
Répondre à Angeldark
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:39:24, on 19/04/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
C:\Program Files\Controle Parental\bin\optproxy.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\WgaTray.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\sistray.EXE
C:\WINDOWS\system32\keyhook.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Orange\Systray\SystrayApp.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\PROGRA~1\CONTRO~1\bin\optgui.exe
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
C:\Program Files\Netlog 24\Notifier\Netlog24Notifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
C:\PROGRA~1\INCRED~1\bin\IMApp.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Orange\Launcher\Launcher.exe
C:\Program Files\Orange\connectivity\connectivitymanager.exe
C:\Program Files\Orange\connectivity\CoreCom\CoreCom.exe
C:\Program Files\Orange\connectivity\CoreCom\OraConfigRecover.exe
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTCOMModule\0\FTCOMModule.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Orange\Deskboard\deskboard.exe
C:\Program Files\Orange\browser\browser.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.orange.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Favoris
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\Orange\SearchURLHook\SearchPageURL.dll
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [CamMonitor] C:\Program Files\Hewlett-Packard\Digital Imaging\\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SiS Tray] C:\WINDOWS\system32\sistray.EXE
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\system32\keyhook.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SystrayORAHSS] "C:\Program Files\Orange\Systray\SystrayApp.exe"
O4 - HKLM\..\Run: [ORAHSSSessionManager] C:\Program Files\Orange\SessionManager\SessionManager.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [OPTENET_GUI] C:\PROGRA~1\CONTRO~1\bin\optgui.exe
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Netlog 24] "C:\Program Files\Netlog 24\Notifier\Netlog24Notifier.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\RunOnce: [XPPro4.0] %systemroot%\REG\run.cmd (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\RunOnce: [XPPro4.0] %systemroot%\REG\run.cmd (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [Picasa Media Detector] D:\montage\Picasa2\PicasaMediaDetector.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [XPPro4.0] %systemroot%\REG\run.cmd (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Picasa Media Detector] D:\montage\Picasa2\PicasaMediaDetector.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [XPPro4.0] %systemroot%\REG\run.cmd (User 'Default user')
O4 - Global Startup: BlueSoleil.lnk = C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O15 - Trusted Zone: http://www.msi.com.tw
O15 - Trusted Zone: http://www.orange.fr
O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/too [...] ontrol.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-F [...] E_UNO1.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/r [...] se4009.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://copainsdavant.linternaute.c [...] oader4.cab
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - http://www.touslesdrivers.com/fich [...] _0_4_9.cab
O16 - DPF: {BD8667B7-38D8-4C77-B580-18C3E146372C} (Creative Toolbox Plug-in) - http://kiw.imgag.com/imgag/cp/inst [...] -kiwen.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/bina [...] b56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/bina [...] b56986.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: Orange Contrôle Parental (OPTENET_FILTER) - Orange - C:\Program Files\Controle Parental\bin\optproxy.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
--
End of file - 11790 bytes
Re,
Désinstalle correctement Avast! pour le remplacer par AntiVir.
Pourquoi changer ? Avast! vs AntiVir
Fais un scan complet puis poste le rapport en fin d'analyse.
AIDE : Tutorial sur l'antivirus AntiVir Personal Edition Classic
Répondre à Angeldark
Avira AntiVir Personal
Report file date: dimanche 20 avril 2008 12:47
Scanning for 1218459 virus strains and unwanted programs.
Licensed to: Avira AntiVir PersonalEdition Classic
Serial number: 0000149996-ADJIE-0001
Platform: Windows XP
Windows version: (Service Pack 2) [5.1.2600]
Boot mode: Normally booted
Username: SYSTEM
Computer name: XPSP2-F87D6FB42
Version information:
BUILD.DAT : 8.1.00.295 16479 Bytes 09/04/2008 16:24:00
AVSCAN.EXE : 8.1.2.12 311553 Bytes 20/04/2008 10:45:49
AVSCAN.DLL : 8.1.1.0 53505 Bytes 20/04/2008 10:45:49
LUKE.DLL : 8.1.2.9 151809 Bytes 20/04/2008 10:45:49
LUKERES.DLL : 8.1.2.1 12033 Bytes 20/04/2008 10:45:49
ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 13:27:15
ANTIVIR1.VDF : 7.0.3.2 5447168 Bytes 07/03/2008 10:45:50
ANTIVIR2.VDF : 7.0.3.156 795136 Bytes 11/04/2008 10:45:50
ANTIVIR3.VDF : 7.0.3.188 342016 Bytes 18/04/2008 10:45:50
Engineversion : 8.1.0.32
AEVDF.DLL : 8.1.0.5 102772 Bytes 20/04/2008 10:45:50
AESCRIPT.DLL : 8.1.0.26 233850 Bytes 20/04/2008 10:45:50
AESCN.DLL : 8.1.0.14 119156 Bytes 20/04/2008 10:45:50
AERDL.DLL : 8.1.0.19 418164 Bytes 20/04/2008 10:45:50
AEPACK.DLL : 8.1.1.2 364917 Bytes 20/04/2008 10:45:50
AEOFFICE.DLL : 8.1.0.18 192890 Bytes 20/04/2008 10:45:50
AEHEUR.DLL : 8.1.0.18 1167735 Bytes 20/04/2008 10:45:50
AEHELP.DLL : 8.1.0.14 115063 Bytes 20/04/2008 10:45:50
AEGEN.DLL : 8.1.0.17 299380 Bytes 20/04/2008 10:45:50
AEEMU.DLL : 8.1.0.5 430450 Bytes 20/04/2008 10:45:50
AECORE.DLL : 8.1.0.27 168310 Bytes 20/04/2008 10:45:50
AVWINLL.DLL : 1.0.0.7 14593 Bytes 20/04/2008 10:45:49
AVPREF.DLL : 8.0.0.1 25857 Bytes 20/04/2008 10:45:49
AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 12:16:24
AVREG.DLL : 8.0.0.0 30977 Bytes 20/04/2008 10:45:49
AVARKT.DLL : 1.0.0.23 307457 Bytes 20/04/2008 10:45:49
AVEVTLOG.DLL : 8.0.0.11 114945 Bytes 20/04/2008 10:45:49
SQLITE3.DLL : 3.3.17.1 339968 Bytes 20/04/2008 10:45:49
SMTPLIB.DLL : 1.2.0.19 28929 Bytes 20/04/2008 10:45:49
NETNT.DLL : 8.0.0.1 7937 Bytes 20/04/2008 10:45:49
RCIMAGE.DLL : 8.0.0.35 2371841 Bytes 20/04/2008 10:45:46
RCTEXT.DLL : 8.0.32.0 86273 Bytes 20/04/2008 10:45:46
Configuration settings for the scan:
Jobname..........................: Complete system scan
Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
Logging..........................: low
Primary action...................: interactive
Secondary action.................: ignore
Scan master boot sector..........: on
Scan boot sector.................: on
Boot sectors.....................: C:, D:,
Scan memory......................: on
Process scan.....................: on
Scan registry....................: on
Search for rootkits..............: off
Scan all files...................: Intelligent file selection
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Macro heuristic..................: on
File heuristic...................: medium
Start of the scan: dimanche 20 avril 2008 12:47
The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'sched.exe' - '1' Module(s) have been scanned
Scan process 'avgnt.exe' - '1' Module(s) have been scanned
Scan process 'avguard.exe' - '1' Module(s) have been scanned
Scan process 'rundll32.exe' - '1' Module(s) have been scanned
Scan process 'WgaTray.exe' - '1' Module(s) have been scanned
Scan process 'wscntfy.exe' - '1' Module(s) have been scanned
Scan process 'alg.exe' - '1' Module(s) have been scanned
Scan process 'hpqste08.exe' - '1' Module(s) have been scanned
Scan process 'ImApp.exe' - '1' Module(s) have been scanned
Scan process 'AlertModule.exe' - '1' Module(s) have been scanned
Scan process 'hpqtra08.exe' - '1' Module(s) have been scanned
Scan process 'BlueSoleil.exe' - '1' Module(s) have been scanned
Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
Scan process 'hpgs2wnf.exe' - '1' Module(s) have been scanned
Scan process 'Netlog24Notifier.exe' - '1' Module(s) have been scanned
Scan process 'msnmsgr.exe' - '1' Module(s) have been scanned
Scan process 'OPTGui.exe' - '1' Module(s) have been scanned
Scan process 'jusched.exe' - '1' Module(s) have been scanned
Scan process 'SystrayApp.exe' - '1' Module(s) have been scanned
Scan process 'hpwuSchd2.exe' - '1' Module(s) have been scanned
Scan process 'Keyhook.exe' - '1' Module(s) have been scanned
Scan process 'sistray.exe' - '1' Module(s) have been scanned
Scan process 'avgas.exe' - '1' Module(s) have been scanned
Scan process 'PDVDServ.exe' - '1' Module(s) have been scanned
Scan process 'qttask.exe' - '1' Module(s) have been scanned
Scan process 'hpgs2wnd.exe' - '1' Module(s) have been scanned
Scan process 'HpqCmon.exe' - '1' Module(s) have been scanned
Scan process 'LVCOMSX.EXE' - '1' Module(s) have been scanned
Scan process 'rundll32.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'RichVideo.exe' - '1' Module(s) have been scanned
Scan process 'optproxy.exe' - '1' Module(s) have been scanned
Scan process 'FTRTSVC.exe' - '1' Module(s) have been scanned
Scan process 'guard.exe' - '1' Module(s) have been scanned
Scan process 'LVPrcSrv.exe' - '1' Module(s) have been scanned
Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
49 processes with 49 modules were scanned
Starting master boot sector scan:
Master boot sector HD0
[INFO] No virus was found!
Start scanning boot sectors:
Boot sector 'C:\'
[INFO] No virus was found!
Boot sector 'D:\'
[INFO] No virus was found!
Starting to scan the registry.
The registry was scanned ( '40' files ).
Starting the file scan:
Begin scan in 'C:\'
C:\pagefile.sys
[WARNING] The file could not be opened!
C:\Lop SD\Backup-Lop\F\Uninstall.exe
[DETECTION] Is the Trojan horse TR/Dldr.Swizzor.Gen
[NOTE] The file was moved to '487421a5.qua'!
C:\System Volume Information\_restore{9272FC26-9981-4FAA-AD90-B83A803EB8CB}\RP239\A0031095.exe
[DETECTION] Is the Trojan horse TR/Dldr.Swizzor.Gen
[NOTE] The file was moved to '483b2354.qua'!
C:\System Volume Information\_restore{9272FC26-9981-4FAA-AD90-B83A803EB8CB}\RP239\A0031115.exe
[DETECTION] Is the Trojan horse TR/Dldr.Swizzor.Gen
[NOTE] The file was moved to '483b2357.qua'!
C:\System Volume Information\_restore{9272FC26-9981-4FAA-AD90-B83A803EB8CB}\RP240\A0031140.exe
[DETECTION] Is the Trojan horse TR/Dldr.Swizzor.Gen
[NOTE] The file was moved to '483b235c.qua'!
C:\System Volume Information\_restore{9272FC26-9981-4FAA-AD90-B83A803EB8CB}\RP240\A0031175.exe
[DETECTION] Is the Trojan horse TR/Dldr.Swizzor.Gen
[NOTE] The file was moved to '483b235f.qua'!
C:\System Volume Information\_restore{9272FC26-9981-4FAA-AD90-B83A803EB8CB}\RP242\A0031492.exe
[DETECTION] Is the Trojan horse TR/Dldr.Swizzor.Gen
[NOTE] The file was moved to '483b236f.qua'!
C:\System Volume Information\_restore{9272FC26-9981-4FAA-AD90-B83A803EB8CB}\RP245\A0033067.exe
[DETECTION] Is the Trojan horse TR/Dldr.Swizzor.Gen
[NOTE] The file was moved to '483b238c.qua'!
C:\System Volume Information\_restore{9272FC26-9981-4FAA-AD90-B83A803EB8CB}\RP253\A0034111.exe
[DETECTION] Is the Trojan horse TR/Dldr.Swizzor.Gen
[NOTE] The file was moved to '483b23af.qua'!
C:\WINDOWS\system32\drivers\sptd.sys
[WARNING] The file could not be opened!
C:\_OTMoveIt\MovedFiles\04172008_214234\DOCUME~1\ADMINI~1\APPLIC~1\funk draw rect\Bird Download Safe Trans.exe
[DETECTION] Is the Trojan horse TR/Dldr.Swizzor.Gen
[NOTE] The file was moved to '487d258b.qua'!
C:\_OTMoveIt\MovedFiles\04172008_214234\DOCUME~1\ADMINI~1\APPLIC~1\funk draw rect\vqtjkvlv.exe
[DETECTION] Is the Trojan horse TR/Dldr.Swizzor.Gen
[NOTE] The file was moved to '487f2596.qua'!
Begin scan in 'D:\'
End of the scan: dimanche 20 avril 2008 13:16
Used time: 29:04 min
The scan has been done completely.
5620 Scanning directories
118822 Files were scanned
10 viruses and/or unwanted programs were found
0 Files were classified as suspicious:
0 files were deleted
0 files were repaired
10 files were moved to quarantine
0 files were renamed
2 Files cannot be scanned
118812 Files not concerned
1314 Archives were scanned
2 Warnings
10 Notes
Reposte un rapport Hijackthis.
Répondre à Angeldark
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:06:40, on 20/04/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
C:\Program Files\Controle Parental\bin\optproxy.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\sistray.EXE
C:\WINDOWS\system32\keyhook.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Orange\Systray\SystrayApp.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\PROGRA~1\CONTRO~1\bin\optgui.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Netlog 24\Notifier\Netlog24Notifier.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
C:\PROGRA~1\INCRED~1\bin\IMApp.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\WgaTray.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
c:\program files\avira\antivir personaledition classic\avcenter.exe
c:\program files\avira\antivir personaledition classic\avcenter.exe
C:\Program Files\Orange\Launcher\Launcher.exe
C:\Program Files\Orange\connectivity\connectivitymanager.exe
C:\Program Files\Orange\Deskboard\deskboard.exe
C:\Program Files\Orange\connectivity\CoreCom\CoreCom.exe
C:\Program Files\Orange\connectivity\CoreCom\OraConfigRecover.exe
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTCOMModule\0\FTCOMModule.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Orange\browser\browser.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.orange.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Favoris
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\Orange\SearchURLHook\SearchPageURL.dll
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [CamMonitor] C:\Program Files\Hewlett-Packard\Digital Imaging\\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SiS Tray] C:\WINDOWS\system32\sistray.EXE
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\system32\keyhook.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SystrayORAHSS] "C:\Program Files\Orange\Systray\SystrayApp.exe"
O4 - HKLM\..\Run: [ORAHSSSessionManager] C:\Program Files\Orange\SessionManager\SessionManager.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [OPTENET_GUI] C:\PROGRA~1\CONTRO~1\bin\optgui.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Netlog 24] "C:\Program Files\Netlog 24\Notifier\Netlog24Notifier.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\RunOnce: [XPPro4.0] %systemroot%\REG\run.cmd (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\RunOnce: [XPPro4.0] %systemroot%\REG\run.cmd (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [Picasa Media Detector] D:\montage\Picasa2\PicasaMediaDetector.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [XPPro4.0] %systemroot%\REG\run.cmd (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Picasa Media Detector] D:\montage\Picasa2\PicasaMediaDetector.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [XPPro4.0] %systemroot%\REG\run.cmd (User 'Default user')
O4 - Global Startup: BlueSoleil.lnk = C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O15 - Trusted Zone: http://www.msi.com.tw
O15 - Trusted Zone: http://www.orange.fr
O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/too [...] ontrol.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-F [...] E_UNO1.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/r [...] se4009.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://copainsdavant.linternaute.c [...] oader4.cab
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - http://www.touslesdrivers.com/fich [...] _0_4_9.cab
O16 - DPF: {BD8667B7-38D8-4C77-B580-18C3E146372C} (Creative Toolbox Plug-in) - http://kiw.imgag.com/imgag/cp/inst [...] -kiwen.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/bina [...] b56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/bina [...] b56986.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: Orange Contrôle Parental (OPTENET_FILTER) - Orange - C:\Program Files\Controle Parental\bin\optproxy.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
--
End of file - 11834 bytes
Encore des soucis ?
Répondre à Angeldark
non j'ai plus de soucis
je te remercie pour tout
amicalement magali
Bon surf
- Télécharge ToolsCleaner sur ton Bureau.
- Clique sur Recherche et laisse le scan se terminer.
- Clique sur Suppression pour finaliser.
- Clique sur Quitter, pour que le rapport puisse se créer.
- Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\)
Désactive puis réactive la restauration du système : Voir aide
Ajoute maintenant [Résolu] au titre. Pour cela :
* Clique, dans ton premier message, sur le bouton "Editer"
* Rajoute la mention [Résolu] au titre
* Clique ensuite sur "Valider votre message"
Lis le dossier dossier sur la prévention et la protection pour ne plus avoir ce genre de problème en cliquant sur l'image ci-dessous :
Répondre à Angeldark
-->- Recherche:
C:\Lop SD: trouvé !
C:\_OtMoveIt: trouvé !
C:\Documents and Settings\Administrateur\Bureau\HijackThis.lnk: trouvé !
C:\Documents and Settings\Administrateur\Bureau\Lop S&D.lnk: trouvé !
C:\Documents and Settings\Administrateur\Bureau\LopSD.exe: trouvé !
C:\Documents and Settings\Administrateur\Bureau\OtMoveIt2.exe: trouvé !
C:\Documents and Settings\Administrateur\Bureau\HJTInstall.exe: trouvé !
C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\Lop S&D: trouvé !
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis: trouvé !
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis\HijackThis.lnk: trouvé !
C:\Lop SD\Lop S&D.lnk: trouvé !
C:\Program Files\Trend Micro\HijackThis: trouvé !
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: trouvé !
---------------------------------
-->- Suppression:
C:\Documents and Settings\Administrateur\Bureau\HijackThis.lnk: supprimé !
C:\Documents and Settings\Administrateur\Bureau\Lop S&D.lnk: supprimé !
C:\Documents and Settings\Administrateur\Bureau\LopSD.exe: supprimé !
C:\Documents and Settings\Administrateur\Bureau\OtMoveIt2.exe: supprimé !
C:\Documents and Settings\Administrateur\Bureau\HJTInstall.exe: supprimé !
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis\HijackThis.lnk: supprimé !
C:\Lop SD\Lop S&D.lnk: supprimé !
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: supprimé !
C:\Lop SD: supprimé !
C:\_OtMoveIt: supprimé !
C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\Lop S&D: supprimé !
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis: supprimé !
C:\Program Files\Trend Micro\HijackThis: supprimé !
Il y a 497 utilisateurs connus et inconnus. Pour voir la liste des connectés connus, cliquez ici.
