Tom's Guide > Forum > Sécurité - Virus > fenetres intempestives[résolu]
Mot :    Pseudo :           
 

bonjour je suis envahis de fenetre de pub casino banque et autres
merci de votre aide
magali


Message édité par mag14100 le 20-04-2008 à 21:53:25
Liens sponsorisés
Inscrivez-vous ou connectez-vous pour masquer ceci.


voici un log hijackthis
merci

Logfile of HijackThis v1.99.1


Scan saved at 11:16:29, on 15/04/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\WgaTray.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\sistray.EXE
C:\WINDOWS\system32\keyhook.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
C:\PROGRA~1\INCRED~1\bin\IMApp.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe
C:\PROGRA~1\Mozilla Firefox\firefox.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\Administrateur\Bureau\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Favoris
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [CamMonitor] C:\Program Files\Hewlett-Packard\Digital Imaging\\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SiS Tray] C:\WINDOWS\system32\sistray.EXE
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\system32\keyhook.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [bend logo clock film] C:\Documents and Settings\All Users\Application Data\Frag great bend logo\bone book.exe
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Netlog 24] "C:\Program Files\Netlog 24\Notifier\Netlog24Notifier.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [City meet] C:\DOCUME~1\ADMINI~1\APPLIC~1\FUNKDR~1\Internetdrivemail.exe
O4 - Global Startup: BlueSoleil.lnk = C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O11 - Options group: [INTERNATIONAL] International*
O15 - Trusted Zone: http://www.msi.com.tw
O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/too [...] ontrol.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-F [...] E_UNO1.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/r [...] se4009.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://copainsdavant.linternaute.c [...] oader4.cab
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - http://www.touslesdrivers.com/fich [...] _0_4_9.cab
O16 - DPF: {BD8667B7-38D8-4C77-B580-18C3E146372C} (Creative Toolbox Plug-in) - http://kiw.imgag.com/imgag/cp/inst [...] -kiwen.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/bina [...] b56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/bina [...] b56986.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe

Répondre à mag14100

Bonjour,

Télécharge Lop S&D.exe sur ton Bureau.

  • Double-clique dessus pour lancer l'installation
  • Puis double-clique sur le raccourci Lop S&D présent sur ton Bureau
  • Séléctionne la langue souhaitée , puis choisis l'option 1 (Recherche)
  • Patiente jusqu'à la fin du scan
  • Poste le rapport généré (C:\lopR.txt)


(Si le Bureau ne réapparait pas presse Ctrl + Alt + Suppr , Onglet Fichier , Nouvelle tâche , tape explorer.exe et valide)

------------------------------ Prévention & Protection||Vous m'aimez ? Cliquez :o
Répondre à Angeldark


-----------------------[ Lop S&D 4.1.1-0 XP/Vista ]---------------------

[ Windows XP (NT 5.1) Build 2600, Service Pack 2 ]
[ USER : Administrateur ] [ "C:\Lop SD" ]
[ 15/04/2008 | 14:47:38,09 ] [ PC : XPSP2-F87D6FB42 ]
[ MAJ : 14-04-2008 | 20:30 ]

-------------[ Listing des dossiers dans Application Data ]------------

[11/04/2008|17:32] C:\DOCUME~1\ADMINI~1\APPLIC~1\.
[11/04/2008|17:32] C:\DOCUME~1\ADMINI~1\APPLIC~1\..
[16/02/2008|23:12] C:\DOCUME~1\ADMINI~1\APPLIC~1\Adobe
[18/09/2007|13:40] C:\DOCUME~1\ADMINI~1\APPLIC~1\AdobeUM
[10/09/2007|21:36] C:\DOCUME~1\ADMINI~1\APPLIC~1\Ahead
[23/09/2007|11:32] C:\DOCUME~1\ADMINI~1\APPLIC~1\Apple Computer
[20/12/2007|18:50] C:\DOCUME~1\ADMINI~1\APPLIC~1\Chessmaster Challenge
[16/09/2007|17:10] C:\DOCUME~1\ADMINI~1\APPLIC~1\CyberLink
[09/09/2007|21:37] C:\DOCUME~1\ADMINI~1\APPLIC~1\desktop.ini
[14/10/2007|22:14] C:\DOCUME~1\ADMINI~1\APPLIC~1\DivX
[09/09/2007|20:48] C:\DOCUME~1\ADMINI~1\APPLIC~1\Dossier de t‚l‚chargement Share-to-Web
[12/09/2007|21:30] C:\DOCUME~1\ADMINI~1\APPLIC~1\Dossier de t‚l‚chargement Share-to-Web
[10/04/2008|09:09] C:\DOCUME~1\ADMINI~1\APPLIC~1\funk draw rect
[06/01/2008|23:58] C:\DOCUME~1\ADMINI~1\APPLIC~1\GDIPFONTCACHEV1.DAT
[09/09/2007|23:02] C:\DOCUME~1\ADMINI~1\APPLIC~1\Google
[13/10/2007|22:18] C:\DOCUME~1\ADMINI~1\APPLIC~1\Grisoft
[19/12/2007|16:03] C:\DOCUME~1\ADMINI~1\APPLIC~1\Help
[11/09/2007|14:46] C:\DOCUME~1\ADMINI~1\APPLIC~1\Hewlett-Packard
[17/11/2007|17:11] C:\DOCUME~1\ADMINI~1\APPLIC~1\HP
[22/03/2008|20:12] C:\DOCUME~1\ADMINI~1\APPLIC~1\Identities
[13/03/2008|16:56] C:\DOCUME~1\ADMINI~1\APPLIC~1\Image Zone Express
[25/01/2008|19:21] C:\DOCUME~1\ADMINI~1\APPLIC~1\IMBooster
[20/10/2007|16:54] C:\DOCUME~1\ADMINI~1\APPLIC~1\Lavasoft
[22/09/2007|01:07] C:\DOCUME~1\ADMINI~1\APPLIC~1\Leadertech
[31/10/2007|18:17] C:\DOCUME~1\ADMINI~1\APPLIC~1\LimeWire
[26/03/2008|14:38] C:\DOCUME~1\ADMINI~1\APPLIC~1\Macromedia
[01/11/2007|17:59] C:\DOCUME~1\ADMINI~1\APPLIC~1\Media Player Classic
[27/03/2008|12:55] C:\DOCUME~1\ADMINI~1\APPLIC~1\Microsoft
[09/09/2007|22:35] C:\DOCUME~1\ADMINI~1\APPLIC~1\Mindscape
[12/09/2007|09:06] C:\DOCUME~1\ADMINI~1\APPLIC~1\Mozilla
[08/04/2008|19:16] C:\DOCUME~1\ADMINI~1\APPLIC~1\Plopp1.2
[17/11/2007|17:35] C:\DOCUME~1\ADMINI~1\APPLIC~1\Printer Info Cache
[06/03/2008|21:05] C:\DOCUME~1\ADMINI~1\APPLIC~1\Skype
[14/10/2007|23:06] C:\DOCUME~1\ADMINI~1\APPLIC~1\Sun
[12/09/2007|09:06] C:\DOCUME~1\ADMINI~1\APPLIC~1\Talkback
[16/09/2007|11:47] C:\DOCUME~1\ADMINI~1\APPLIC~1\TuxPaint
[21/12/2007|11:51] C:\DOCUME~1\ADMINI~1\APPLIC~1\Uniblue
[29/09/2007|17:46] C:\DOCUME~1\ADMINI~1\APPLIC~1\Windows Live Writer

[11/04/2008|14:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\.
[11/04/2008|14:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\..
[14/02/2008|10:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[09/09/2007|22:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[16/01/2008|14:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Bluetooth
[16/09/2007|17:10] C:\DOCUME~1\ALLUSE~1\APPLIC~1\CyberLink
[09/09/2007|21:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\desktop.ini
[01/03/2008|09:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Downloaded Installations
[10/04/2008|09:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Frag great bend logo
[09/09/2007|20:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
[13/10/2007|22:18] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Grisoft
[17/11/2007|13:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\HP
[28/03/2008|22:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\HPSSUPPLY
[28/03/2008|22:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\hpzinstall.log
[07/03/2008|12:10] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!
[11/03/2008|17:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[12/09/2007|09:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Mozilla
[12/11/2007|09:23] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MumboJumbo
[05/04/2008|12:33] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Plopp1.2
[16/02/2008|17:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\QTSBandwidthCache
[09/09/2007|20:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Skype
[15/04/2008|10:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
[16/11/2007|23:01] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
[12/09/2007|11:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[10/10/2007|20:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Live Toolbar
[24/03/2008|22:38] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
[01/04/2008|13:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Yahoo! Companion

[09/09/2007|21:37] C:\DOCUME~1\DEFAUL~1\APPLIC~1\.
[09/09/2007|21:37] C:\DOCUME~1\DEFAUL~1\APPLIC~1\..
[09/09/2007|21:37] C:\DOCUME~1\DEFAUL~1\APPLIC~1\desktop.ini
[09/09/2007|19:46] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft

[09/09/2007|19:49] C:\DOCUME~1\LOCALS~1\APPLIC~1\.
[09/09/2007|19:49] C:\DOCUME~1\LOCALS~1\APPLIC~1\..
[29/09/2007|17:40] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft

[29/09/2007|17:36] C:\DOCUME~1\NETWOR~1\APPLIC~1\.
[29/09/2007|17:36] C:\DOCUME~1\NETWOR~1\APPLIC~1\..
[29/09/2007|17:36] C:\DOCUME~1\NETWOR~1\APPLIC~1\Identities
[29/09/2007|17:36] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft

----------------[ Tâches planifiées dans C:\WINDOWS\tasks ]---------------

[15/04/2008 14:00][--ah-----] C:\WINDOWS\tasks\A9031E3E91849592.job
[15/04/2008 14:42][--ah-----] C:\WINDOWS\tasks\SA.DAT
[02/10/2001 18:16][-r-h-----] C:\WINDOWS\tasks\desktop.ini

---------------[ Listing des dossiers dans C:\Program Files ]--------------

[10/04/2008|09:08] C:\Program Files\.
[10/04/2008|09:08] C:\Program Files\..
[14/02/2008|10:44] C:\Program Files\Adobe
[10/09/2007|21:00] C:\Program Files\Ahead
[09/09/2007|20:23] C:\Program Files\Alwil Software
[19/11/2007|18:39] C:\Program Files\Apple Software Update
[11/10/2007|23:12] C:\Program Files\aRPNCalc
[22/12/2007|17:55] C:\Program Files\Atari
[20/12/2007|19:08] C:\Program Files\B4Playing
[26/09/2007|21:01] C:\Program Files\BarreConfCMCIC
[05/04/2008|11:38] C:\Program Files\CA Yahoo! Anti-Spy
[13/10/2007|23:18] C:\Program Files\CCleaner
[10/04/2008|09:08] C:\Program Files\Circle Developement
[08/03/2008|19:48] C:\Program Files\C-Media 3D Audio
[09/04/2008|10:12] C:\Program Files\Common Files
[09/09/2007|19:42] C:\Program Files\ComPlus Applications
[08/03/2008|19:34] C:\Program Files\Conduit
[16/09/2007|17:09] C:\Program Files\CyberLink
[12/12/2007|13:56] C:\Program Files\Disney Interactive
[27/12/2007|18:31] C:\Program Files\DivX
[28/10/2007|13:43] C:\Program Files\DK
[18/01/2008|01:36] C:\Program Files\Dot1XCfg
[05/04/2008|11:36] C:\Program Files\Fichiers communs
[08/03/2008|19:34] C:\Program Files\free-downloads.net
[10/04/2008|09:08] C:\Program Files\funk draw rect
[21/12/2007|21:30] C:\Program Files\Google
[13/10/2007|22:18] C:\Program Files\Grisoft
[17/11/2007|13:41] C:\Program Files\Hewlett-Packard
[17/11/2007|17:35] C:\Program Files\HP
[16/11/2007|23:36] C:\Program Files\Incredijeux
[13/11/2007|15:58] C:\Program Files\IncrediMail
[08/03/2008|13:52] C:\Program Files\InstallShield Installation Information
[02/03/2008|23:07] C:\Program Files\Intel Desktop Board
[09/04/2008|18:00] C:\Program Files\Internet Explorer
[09/09/2007|19:54] C:\Program Files\Inventel
[16/01/2008|14:31] C:\Program Files\IVT Corporation
[04/04/2008|18:00] C:\Program Files\Java
[09/04/2008|13:25] C:\Program Files\Kiwee Toolbar2
[20/10/2007|16:54] C:\Program Files\Lavasoft
[01/03/2008|00:25] C:\Program Files\lecteur windows media 11
[10/04/2008|09:08] C:\Program Files\Messenger Plus! Live
[09/09/2007|19:47] C:\Program Files\microsoft frontpage
[19/11/2007|17:21] C:\Program Files\Microsoft Hardware
[04/12/2007|16:33] C:\Program Files\Microsoft Office
[29/09/2007|17:36] C:\Program Files\Microsoft SQL Server Compact Edition
[26/09/2007|11:46] C:\Program Files\Mindscape
[17/09/2007|20:27] C:\Program Files\Movie Maker
[15/04/2008|14:45] C:\Program Files\Mozilla Firefox
[09/09/2007|23:09] C:\Program Files\MSECache
[12/09/2007|21:54] C:\Program Files\MSI
[09/09/2007|19:42] C:\Program Files\MSN Gaming Zone
[24/10/2007|15:42] C:\Program Files\MSN Messenger
[17/11/2007|23:05] C:\Program Files\MSXML 4.0
[08/03/2008|19:55] C:\Program Files\Multimedia V3.54
[29/03/2008|22:14] C:\Program Files\Netlog
[23/11/2007|13:16] C:\Program Files\Netlog 24
[09/09/2007|19:43] C:\Program Files\NetMeeting
[17/09/2007|20:27] C:\Program Files\Outlook Express
[28/01/2008|10:58] C:\Program Files\PhotoFiltre
[09/09/2007|22:36] C:\Program Files\QuickTime
[20/12/2007|18:47] C:\Program Files\ReflexiveArcade
[24/12/2007|16:43] C:\Program Files\SAMSUNG
[09/09/2007|19:44] C:\Program Files\Services en ligne
[25/10/2007|19:57] C:\Program Files\SiS7012
[08/03/2008|13:52] C:\Program Files\sisagp
[08/03/2008|19:46] C:\Program Files\SiSLan
[09/09/2007|20:20] C:\Program Files\Skype
[16/10/2007|10:11] C:\Program Files\Sunbelt Software
[09/09/2007|19:50] C:\Program Files\Uninstall Information
[09/09/2007|19:57] C:\Program Files\Wanadoo
[26/10/2007|15:18] C:\Program Files\Windows Desktop Search
[11/04/2008|11:12] C:\Program Files\Windows Live
[08/04/2008|18:56] C:\Program Files\Windows Live Safety Center
[20/10/2007|16:44] C:\Program Files\Windows Live Toolbar
[11/03/2008|13:16] C:\Program Files\Windows Media Connect 2
[11/03/2008|13:40] C:\Program Files\Windows Media Player
[09/09/2007|19:41] C:\Program Files\Windows NT
[09/09/2007|19:44] C:\Program Files\WindowsUpdate
[09/09/2007|20:05] C:\Program Files\WinRAR
[09/09/2007|19:47] C:\Program Files\xerox
[09/04/2008|10:12] C:\Program Files\Yahoo!

------[ Listing des dossiers dans C:\Program Files\Fichiers communs ]------

[05/04/2008|11:36] C:\Program Files\Fichiers communs\.
[05/04/2008|11:36] C:\Program Files\Fichiers communs\..
[14/02/2008|10:45] C:\Program Files\Fichiers communs\Adobe
[10/09/2007|21:00] C:\Program Files\Fichiers communs\Ahead
[12/09/2007|15:23] C:\Program Files\Fichiers communs\Designer
[04/03/2008|20:00] C:\Program Files\Fichiers communs\DirectX
[09/09/2007|19:55] C:\Program Files\Fichiers communs\FDEUnInstaller.exe
[11/10/2007|23:18] C:\Program Files\Fichiers communs\GTK
[17/11/2007|13:36] C:\Program Files\Fichiers communs\Hewlett-Packard
[17/11/2007|17:35] C:\Program Files\Fichiers communs\HP
[30/09/2007|13:38] C:\Program Files\Fichiers communs\InstallShield
[20/09/2007|16:31] C:\Program Files\Fichiers communs\Java
[09/09/2007|20:49] C:\Program Files\Fichiers communs\Logitech
[17/01/2008|22:58] C:\Program Files\Fichiers communs\Microsoft Shared
[09/09/2007|19:43] C:\Program Files\Fichiers communs\MSSoap
[09/09/2007|21:37] C:\Program Files\Fichiers communs\ODBC
[05/04/2008|11:36] C:\Program Files\Fichiers communs\Scanner
[09/09/2007|19:43] C:\Program Files\Fichiers communs\Services
[09/09/2007|20:20] C:\Program Files\Fichiers communs\Skype
[09/09/2007|21:37] C:\Program Files\Fichiers communs\SpeechEngines
[16/09/2007|22:16] C:\Program Files\Fichiers communs\System
[03/01/2008|21:45] C:\Program Files\Fichiers communs\Vivendi Universal Games
[17/01/2008|22:56] C:\Program Files\Fichiers communs\WindowsLiveInstaller

----------------------[ Recherche avec S_Lop ]---------------------

Aucun fichier / dossier Lop trouvé !

-----------------[ Recherche de Fichiers / Dossiers Lop ]-----------------

C:\DOCUME~1\ALLUSE~1\APPLIC~1\Frag great bend logo
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Frag great bend logo\bone book.exe
C:\Program Files\Circle Developement
C:\Program Files\Circle Developement\Uninstall.exe
C:\WINDOWS\Tasks\A9031E3E91849592.job

----------------------[ Verification du Registre ]----------------------

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"bend logo clock film"="C:\\Documents and Settings\\All Users\\Application Data\\Frag great bend logo\\bone book.exe"

--------------------[ Verification du fichier Hosts ]---------------------

Fichier Hosts MODIFIE

127.0.0.1 bin.errorprotector.com ## added by CiD
127.0.0.1 br.errorsafe.com ## added by CiD
127.0.0.1 br.winantivirus.com ## added by CiD
127.0.0.1 br.winfixer.com ## added by CiD
127.0.0.1 cdn.drivecleaner.com ## added by CiD
127.0.0.1 cdn.errorsafe.com ## added by CiD
127.0.0.1 cdn.winsoftware.com ## added by CiD
127.0.0.1 de.errorsafe.com ## added by CiD
127.0.0.1 de.winantivirus.com ## added by CiD
127.0.0.1 download.cdn.drivecleaner.com ## added by CiD
127.0.0.1 download.cdn.errorsafe.com ## added by CiD
127.0.0.1 download.cdn.winsoftware.com ## added by CiD
127.0.0.1 download.errorsafe.com ## added by CiD
127.0.0.1 download.systemdoctor.com ## added by CiD
127.0.0.1 download.winantispyware.com ## added by CiD
127.0.0.1 download.windrivecleaner.com ## added by CiD
127.0.0.1 download.winfixer.com ## added by CiD
127.0.0.1 drivecleaner.com ## added by CiD
127.0.0.1 dynamique.drivecleaner.com ## added by CiD
127.0.0.1 errorprotector.com ## added by CiD
127.0.0.1 errorsafe.com ## added by CiD
127.0.0.1 es.winantivirus.com ## added by CiD
127.0.0.1 fr.winantivirus.com ## added by CiD
127.0.0.1 fr.winfixer.com ## added by CiD
127.0.0.1 go.drivecleaner.com ## added by CiD
127.0.0.1 go.errorsafe.com ## added by CiD
127.0.0.1 go.winantispyware.com ## added by CiD
127.0.0.1 go.winantivirus.com ## added by CiD
127.0.0.1 hk.winantivirus.com ## added by CiD
127.0.0.1 instlog.errorsafe.com ## added by CiD
127.0.0.1 instlog.winantivirus.com ## added by CiD
127.0.0.1 instlog.winfixer.com ## added by CiD
127.0.0.1 jsp.drivecleaner.com ## added by CiD
127.0.0.1 kb.errorsafe.com ## added by CiD
127.0.0.1 kb.winantivirus.com ## added by CiD
127.0.0.1 nl.errorsafe.com ## added by CiD
127.0.0.1 se.errorsafe.com ## added by CiD
127.0.0.1 secure.drivecleaner.com ## added by CiD
127.0.0.1 secure.errorsafe.com ## added by CiD
127.0.0.1 secure.winantispam.com ## added by CiD
127.0.0.1 secure.winantispy.com ## added by CiD
127.0.0.1 secure.winantivirus.com ## added by CiD
127.0.0.1 support.winantivirus.com ## added by CiD
127.0.0.1 trial.updates.winsoftware.com ## added by CiD
127.0.0.1 ulog.winantivirus.com ## added by CiD
127.0.0.1 utils.errorsafe.com ## added by CiD
127.0.0.1 utils.winantivirus.com ## added by CiD
127.0.0.1 utils.winfixer.com ## added by CiD
127.0.0.1 winantispyware.com ## added by CiD
127.0.0.1 winantivirus.com ## added by CiD
127.0.0.1 winfixer.com ## added by CiD
127.0.0.1 winfixer2006.com ## added by CiD
127.0.0.1 winsoftware.com ## added by CiD
127.0.0.1 www.drivecleaner.com ## added by CiD
127.0.0.1 www.errorprotector.com ## added by CiD
127.0.0.1 www.errorsafe.com ## added by CiD
127.0.0.1 www.systemdoctor.com ## added by CiD
127.0.0.1 www.utils.winfixer.com ## added by CiD
127.0.0.1 www.win-anti-virus-pro.com ## added by CiD
127.0.0.1 www.win-virus-pro.com ## added by CiD
127.0.0.1 www.winantispam.com ## added by CiD
127.0.0.1 www.winantispy.com ## added by CiD
127.0.0.1 www.winantispyware.com ## added by CiD
127.0.0.1 www.winantivirus.com ## added by CiD
127.0.0.1 www.winantiviruspro.com ## added by CiD
127.0.0.1 www.windrivecleaner.com ## added by CiD
127.0.0.1 www.windrivesafe.com ## added by CiD
127.0.0.1 www.winfixer.com ## added by CiD
127.0.0.1 www.winfixer2006.com ## added by CiD
127.0.0.1 www.winsoftware.com ## added by CiD

-> 8070 ( 70 ## added by CiD )

/!\ 1 Not 127.0.0.1 !!

----------------[ Recherche de fichiers avec Catchme ]-----------------

catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-15 14:48:45
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 0

--------------------[ Recherche d'autres infections ]---------------------

C:\Program Files\Dot1XCfg
! Virus MSN !


/!\ [Fich:70][Doss:16] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp
/!\ [Fich:58][Doss:0] C:\DOCUME~1\ADMINI~1\Cookies
/!\ [Fich:768][Doss:5] C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMPOR~1\content.IE5

--------------------[ Fin du rapport a 14:50:18,50 ]----------------------

Répondre à mag14100

Re,

Relance Lop S&D

  • Choisis cette fois ci l'Option 2 (Suppression)
  • Ne ferme pas la fenêtre lors de la suppression !
  • Poste le rapport généré (C:\lopR.txt)


(Si le Bureau ne réapparaît pas, presse Ctrl + Alt + Suppr , Onglet Fichier , Nouvelle tâche , tape explorer.exe et valide)

------------------------------ Prévention & Protection||Vous m'aimez ? Cliquez :o
Répondre à Angeldark


-----------------------[ Lop S&D 4.1.1-0 XP/Vista ]---------------------

[ Windows XP (NT 5.1) Build 2600, Service Pack 2 ]
[ USER : Administrateur ] [ "C:\Lop SD" ]
[ 15/04/2008 | 15:27:37,29 ] [ PC : XPSP2-F87D6FB42 ]
[ MAJ : 14-04-2008 | 20:30 ]

\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ SUPPRESSION /////////////////////////////

Supprimé! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\Frag great bend logo\bone book.exe
Supprimé! - C:\Program Files\Circle Developement\Uninstall.exe
Supprimé! - C:\WINDOWS\Tasks\A9031E3E91849592.job
Supprimé! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\Frag great bend logo
Supprimé! - C:\Program Files\Circle Developement
Restauré! - Fichier Hosts

//////////////////////////////////////-\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\


-------------[ Listing des dossiers dans Application Data ]------------

[11/04/2008|17:32] C:\DOCUME~1\ADMINI~1\APPLIC~1\.
[11/04/2008|17:32] C:\DOCUME~1\ADMINI~1\APPLIC~1\..
[16/02/2008|23:12] C:\DOCUME~1\ADMINI~1\APPLIC~1\Adobe
[18/09/2007|13:40] C:\DOCUME~1\ADMINI~1\APPLIC~1\AdobeUM
[10/09/2007|21:36] C:\DOCUME~1\ADMINI~1\APPLIC~1\Ahead
[23/09/2007|11:32] C:\DOCUME~1\ADMINI~1\APPLIC~1\Apple Computer
[20/12/2007|18:50] C:\DOCUME~1\ADMINI~1\APPLIC~1\Chessmaster Challenge
[16/09/2007|17:10] C:\DOCUME~1\ADMINI~1\APPLIC~1\CyberLink
[09/09/2007|21:37] C:\DOCUME~1\ADMINI~1\APPLIC~1\desktop.ini
[14/10/2007|22:14] C:\DOCUME~1\ADMINI~1\APPLIC~1\DivX
[09/09/2007|20:48] C:\DOCUME~1\ADMINI~1\APPLIC~1\Dossier de t‚l‚chargement Share-to-Web
[12/09/2007|21:30] C:\DOCUME~1\ADMINI~1\APPLIC~1\Dossier de t‚l‚chargement Share-to-Web
[10/04/2008|09:09] C:\DOCUME~1\ADMINI~1\APPLIC~1\funk draw rect
[06/01/2008|23:58] C:\DOCUME~1\ADMINI~1\APPLIC~1\GDIPFONTCACHEV1.DAT
[09/09/2007|23:02] C:\DOCUME~1\ADMINI~1\APPLIC~1\Google
[13/10/2007|22:18] C:\DOCUME~1\ADMINI~1\APPLIC~1\Grisoft
[19/12/2007|16:03] C:\DOCUME~1\ADMINI~1\APPLIC~1\Help
[11/09/2007|14:46] C:\DOCUME~1\ADMINI~1\APPLIC~1\Hewlett-Packard
[17/11/2007|17:11] C:\DOCUME~1\ADMINI~1\APPLIC~1\HP
[22/03/2008|20:12] C:\DOCUME~1\ADMINI~1\APPLIC~1\Identities
[13/03/2008|16:56] C:\DOCUME~1\ADMINI~1\APPLIC~1\Image Zone Express
[25/01/2008|19:21] C:\DOCUME~1\ADMINI~1\APPLIC~1\IMBooster
[20/10/2007|16:54] C:\DOCUME~1\ADMINI~1\APPLIC~1\Lavasoft
[22/09/2007|01:07] C:\DOCUME~1\ADMINI~1\APPLIC~1\Leadertech
[31/10/2007|18:17] C:\DOCUME~1\ADMINI~1\APPLIC~1\LimeWire
[26/03/2008|14:38] C:\DOCUME~1\ADMINI~1\APPLIC~1\Macromedia
[01/11/2007|17:59] C:\DOCUME~1\ADMINI~1\APPLIC~1\Media Player Classic
[27/03/2008|12:55] C:\DOCUME~1\ADMINI~1\APPLIC~1\Microsoft
[09/09/2007|22:35] C:\DOCUME~1\ADMINI~1\APPLIC~1\Mindscape
[12/09/2007|09:06] C:\DOCUME~1\ADMINI~1\APPLIC~1\Mozilla
[08/04/2008|19:16] C:\DOCUME~1\ADMINI~1\APPLIC~1\Plopp1.2
[17/11/2007|17:35] C:\DOCUME~1\ADMINI~1\APPLIC~1\Printer Info Cache
[06/03/2008|21:05] C:\DOCUME~1\ADMINI~1\APPLIC~1\Skype
[14/10/2007|23:06] C:\DOCUME~1\ADMINI~1\APPLIC~1\Sun
[12/09/2007|09:06] C:\DOCUME~1\ADMINI~1\APPLIC~1\Talkback
[16/09/2007|11:47] C:\DOCUME~1\ADMINI~1\APPLIC~1\TuxPaint
[21/12/2007|11:51] C:\DOCUME~1\ADMINI~1\APPLIC~1\Uniblue
[29/09/2007|17:46] C:\DOCUME~1\ADMINI~1\APPLIC~1\Windows Live Writer

[15/04/2008|15:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\.
[15/04/2008|15:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\..
[14/02/2008|10:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[09/09/2007|22:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[16/01/2008|14:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Bluetooth
[16/09/2007|17:10] C:\DOCUME~1\ALLUSE~1\APPLIC~1\CyberLink
[09/09/2007|21:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\desktop.ini
[01/03/2008|09:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Downloaded Installations
[09/09/2007|20:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
[13/10/2007|22:18] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Grisoft
[17/11/2007|13:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\HP
[28/03/2008|22:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\HPSSUPPLY
[28/03/2008|22:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\hpzinstall.log
[07/03/2008|12:10] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!
[11/03/2008|17:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[12/09/2007|09:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Mozilla
[12/11/2007|09:23] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MumboJumbo
[05/04/2008|12:33] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Plopp1.2
[16/02/2008|17:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\QTSBandwidthCache
[09/09/2007|20:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Skype
[15/04/2008|10:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
[16/11/2007|23:01] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
[12/09/2007|11:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[10/10/2007|20:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Live Toolbar
[24/03/2008|22:38] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
[01/04/2008|13:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Yahoo! Companion

[09/09/2007|21:37] C:\DOCUME~1\DEFAUL~1\APPLIC~1\.
[09/09/2007|21:37] C:\DOCUME~1\DEFAUL~1\APPLIC~1\..
[09/09/2007|21:37] C:\DOCUME~1\DEFAUL~1\APPLIC~1\desktop.ini
[09/09/2007|19:46] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft

[09/09/2007|19:49] C:\DOCUME~1\LOCALS~1\APPLIC~1\.
[09/09/2007|19:49] C:\DOCUME~1\LOCALS~1\APPLIC~1\..
[29/09/2007|17:40] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft

[29/09/2007|17:36] C:\DOCUME~1\NETWOR~1\APPLIC~1\.
[29/09/2007|17:36] C:\DOCUME~1\NETWOR~1\APPLIC~1\..
[29/09/2007|17:36] C:\DOCUME~1\NETWOR~1\APPLIC~1\Identities
[29/09/2007|17:36] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft

----------------[ Tâches planifiées dans C:\WINDOWS\tasks ]---------------

[15/04/2008 14:42][--ah-----] C:\WINDOWS\tasks\SA.DAT
[02/10/2001 18:16][-r-h-----] C:\WINDOWS\tasks\desktop.ini

---------------[ Listing des dossiers dans C:\Program Files ]--------------

[15/04/2008|15:27] C:\Program Files\.
[15/04/2008|15:27] C:\Program Files\..
[14/02/2008|10:44] C:\Program Files\Adobe
[10/09/2007|21:00] C:\Program Files\Ahead
[09/09/2007|20:23] C:\Program Files\Alwil Software
[19/11/2007|18:39] C:\Program Files\Apple Software Update
[11/10/2007|23:12] C:\Program Files\aRPNCalc
[22/12/2007|17:55] C:\Program Files\Atari
[20/12/2007|19:08] C:\Program Files\B4Playing
[26/09/2007|21:01] C:\Program Files\BarreConfCMCIC
[05/04/2008|11:38] C:\Program Files\CA Yahoo! Anti-Spy
[13/10/2007|23:18] C:\Program Files\CCleaner
[08/03/2008|19:48] C:\Program Files\C-Media 3D Audio
[09/04/2008|10:12] C:\Program Files\Common Files
[09/09/2007|19:42] C:\Program Files\ComPlus Applications
[08/03/2008|19:34] C:\Program Files\Conduit
[16/09/2007|17:09] C:\Program Files\CyberLink
[12/12/2007|13:56] C:\Program Files\Disney Interactive
[27/12/2007|18:31] C:\Program Files\DivX
[28/10/2007|13:43] C:\Program Files\DK
[18/01/2008|01:36] C:\Program Files\Dot1XCfg
[05/04/2008|11:36] C:\Program Files\Fichiers communs
[08/03/2008|19:34] C:\Program Files\free-downloads.net
[10/04/2008|09:08] C:\Program Files\funk draw rect
[21/12/2007|21:30] C:\Program Files\Google
[13/10/2007|22:18] C:\Program Files\Grisoft
[17/11/2007|13:41] C:\Program Files\Hewlett-Packard
[17/11/2007|17:35] C:\Program Files\HP
[16/11/2007|23:36] C:\Program Files\Incredijeux
[13/11/2007|15:58] C:\Program Files\IncrediMail
[08/03/2008|13:52] C:\Program Files\InstallShield Installation Information
[02/03/2008|23:07] C:\Program Files\Intel Desktop Board
[09/04/2008|18:00] C:\Program Files\Internet Explorer
[09/09/2007|19:54] C:\Program Files\Inventel
[16/01/2008|14:31] C:\Program Files\IVT Corporation
[04/04/2008|18:00] C:\Program Files\Java
[09/04/2008|13:25] C:\Program Files\Kiwee Toolbar2
[20/10/2007|16:54] C:\Program Files\Lavasoft
[01/03/2008|00:25] C:\Program Files\lecteur windows media 11
[10/04/2008|09:08] C:\Program Files\Messenger Plus! Live
[09/09/2007|19:47] C:\Program Files\microsoft frontpage
[19/11/2007|17:21] C:\Program Files\Microsoft Hardware
[04/12/2007|16:33] C:\Program Files\Microsoft Office
[29/09/2007|17:36] C:\Program Files\Microsoft SQL Server Compact Edition
[26/09/2007|11:46] C:\Program Files\Mindscape
[17/09/2007|20:27] C:\Program Files\Movie Maker
[15/04/2008|15:14] C:\Program Files\Mozilla Firefox
[09/09/2007|23:09] C:\Program Files\MSECache
[12/09/2007|21:54] C:\Program Files\MSI
[09/09/2007|19:42] C:\Program Files\MSN Gaming Zone
[24/10/2007|15:42] C:\Program Files\MSN Messenger
[17/11/2007|23:05] C:\Program Files\MSXML 4.0
[08/03/2008|19:55] C:\Program Files\Multimedia V3.54
[23/11/2007|13:16] C:\Program Files\Netlog 24
[09/09/2007|19:43] C:\Program Files\NetMeeting
[17/09/2007|20:27] C:\Program Files\Outlook Express
[28/01/2008|10:58] C:\Program Files\PhotoFiltre
[09/09/2007|22:36] C:\Program Files\QuickTime
[20/12/2007|18:47] C:\Program Files\ReflexiveArcade
[24/12/2007|16:43] C:\Program Files\SAMSUNG
[09/09/2007|19:44] C:\Program Files\Services en ligne
[25/10/2007|19:57] C:\Program Files\SiS7012
[08/03/2008|13:52] C:\Program Files\sisagp
[08/03/2008|19:46] C:\Program Files\SiSLan
[09/09/2007|20:20] C:\Program Files\Skype
[16/10/2007|10:11] C:\Program Files\Sunbelt Software
[09/09/2007|19:50] C:\Program Files\Uninstall Information
[09/09/2007|19:57] C:\Program Files\Wanadoo
[26/10/2007|15:18] C:\Program Files\Windows Desktop Search
[11/04/2008|11:12] C:\Program Files\Windows Live
[08/04/2008|18:56] C:\Program Files\Windows Live Safety Center
[20/10/2007|16:44] C:\Program Files\Windows Live Toolbar
[11/03/2008|13:16] C:\Program Files\Windows Media Connect 2
[11/03/2008|13:40] C:\Program Files\Windows Media Player
[09/09/2007|19:41] C:\Program Files\Windows NT
[09/09/2007|19:44] C:\Program Files\WindowsUpdate
[09/09/2007|20:05] C:\Program Files\WinRAR
[09/09/2007|19:47] C:\Program Files\xerox
[09/04/2008|10:12] C:\Program Files\Yahoo!

------[ Listing des dossiers dans C:\Program Files\Fichiers communs ]------

[05/04/2008|11:36] C:\Program Files\Fichiers communs\.
[05/04/2008|11:36] C:\Program Files\Fichiers communs\..
[14/02/2008|10:45] C:\Program Files\Fichiers communs\Adobe
[10/09/2007|21:00] C:\Program Files\Fichiers communs\Ahead
[12/09/2007|15:23] C:\Program Files\Fichiers communs\Designer
[04/03/2008|20:00] C:\Program Files\Fichiers communs\DirectX
[09/09/2007|19:55] C:\Program Files\Fichiers communs\FDEUnInstaller.exe
[11/10/2007|23:18] C:\Program Files\Fichiers communs\GTK
[17/11/2007|13:36] C:\Program Files\Fichiers communs\Hewlett-Packard
[17/11/2007|17:35] C:\Program Files\Fichiers communs\HP
[30/09/2007|13:38] C:\Program Files\Fichiers communs\InstallShield
[20/09/2007|16:31] C:\Program Files\Fichiers communs\Java
[09/09/2007|20:49] C:\Program Files\Fichiers communs\Logitech
[17/01/2008|22:58] C:\Program Files\Fichiers communs\Microsoft Shared
[09/09/2007|19:43] C:\Program Files\Fichiers communs\MSSoap
[09/09/2007|21:37] C:\Program Files\Fichiers communs\ODBC
[05/04/2008|11:36] C:\Program Files\Fichiers communs\Scanner
[09/09/2007|19:43] C:\Program Files\Fichiers communs\Services
[09/09/2007|20:20] C:\Program Files\Fichiers communs\Skype
[09/09/2007|21:37] C:\Program Files\Fichiers communs\SpeechEngines
[16/09/2007|22:16] C:\Program Files\Fichiers communs\System
[03/01/2008|21:45] C:\Program Files\Fichiers communs\Vivendi Universal Games
[17/01/2008|22:56] C:\Program Files\Fichiers communs\WindowsLiveInstaller

----------------------[ Recherche avec S_Lop ]---------------------

Aucun fichier / dossier Lop trouvé !

-----------------[ Recherche de Fichiers / Dossiers Lop ]-----------------

Aucun fichier / dossier Lop trouvé !

----------------------[ Verification du Registre ]----------------------

..... OK !

--------------------[ Verification du fichier Hosts ]---------------------

Fichier Hosts PROPRE


----------------[ Recherche de fichiers avec Catchme ]-----------------

catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-15 15:28:40
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 0

--------------------[ Recherche d'autres infections ]---------------------

C:\Program Files\Dot1XCfg
! Virus MSN !


/!\ [Fich:70][Doss:16] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp
/!\ [Fich:65][Doss:0] C:\DOCUME~1\ADMINI~1\Cookies
/!\ [Fich:1076][Doss:5] C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMPOR~1\content.IE5

--------------------[ Fin du rapport a 15:29:53,18 ]----------------------
voila le log merci

Répondre à mag14100

Re,

Télécharge MSNFix.zip (!aur3n7) sur ton Bureau.
Décompresse-le sur ton bureau (Clique-Droit/Extraire tout).

Ouvre le dossier MSNFix puis double-clique sur MSNFix.bat.
- Exécute l'option R.
-- Si l'infection est détectée, presse une touche pour lancer le nettoyage.

Si une erreur de suppression est détectée un message s'affichera demandant de redémarrer l'ordinateur afin de terminer les opérations.
Dans ce cas il suffit de redémarrer l'ordinateur manuellement.


Poste le rapport situé dans le dossier MSNFix.
Le nom du rapport correspond au moment de sa création : date_heure.log

------------------------------ Prévention & Protection||Vous m'aimez ? Cliquez :o
Répondre à Angeldark

MSNFix 1.705

C:\Documents and Settings\Administrateur\Bureau\MSNFix
Fix exécuté le 15/04/2008 - 15:35:15,82 By Administrateur
mode normal

************************ Recherche les fichiers présents

Aucun Fichier trouvé

************************ Recherche les dossiers présents

Aucun dossier trouvé


************************ Fichiers suspects

Aucun Fichier trouvé


************************ HKLM\...\Winlogon\Userinit

Userinit = C:\WINDOWS\system32\userinit.exe,


------------------------------------------------------------------------
Auteur : !aur3n7 Contact: http://changelog.fr
------------------------------------------------------------------------

--------------------------------------------- END ---------------------------------------------

Répondre à mag14100

Reposte un rapport Hijackthis.

------------------------------ Prévention & Protection||Vous m'aimez ? Cliquez :o
Répondre à Angeldark

voila
Logfile of HijackThis v1.99.1
Scan saved at 16:25:54, on 15/04/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\sistray.EXE
C:\WINDOWS\system32\keyhook.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Program Files\Netlog 24\Notifier\Netlog24Notifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\PROGRA~1\INCRED~1\bin\IMApp.exe
C:\Documents and Settings\Administrateur\Bureau\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Favoris
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [CamMonitor] C:\Program Files\Hewlett-Packard\Digital Imaging\\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SiS Tray] C:\WINDOWS\system32\sistray.EXE
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\system32\keyhook.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Netlog 24] "C:\Program Files\Netlog 24\Notifier\Netlog24Notifier.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [City meet] C:\DOCUME~1\ADMINI~1\APPLIC~1\FUNKDR~1\Internetdrivemail.exe
O4 - Global Startup: BlueSoleil.lnk = C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O11 - Options group: [INTERNATIONAL] International*
O15 - Trusted Zone: http://www.msi.com.tw
O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/too [...] ontrol.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-F [...] E_UNO1.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/r [...] se4009.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://copainsdavant.linternaute.c [...] oader4.cab
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - http://www.touslesdrivers.com/fich [...] _0_4_9.cab
O16 - DPF: {BD8667B7-38D8-4C77-B580-18C3E146372C} (Creative Toolbox Plug-in) - http://kiw.imgag.com/imgag/cp/inst [...] -kiwen.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/bina [...] b56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/bina [...] b56986.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe

Répondre à mag14100

Re,

Télécharge MalwareByte's Anti-Malware sur ton Bureau.
Installe-le en double-cliquant sur le fichier Download_mbam-setup.exe.

Une fois l'installation et la mise à jour effectuées, redémarre en mode sans échec.
AIDE : Redémarrer en mode sans échec

  • Exécute maintenant MalwareByte's Anti-Malware. Si cela n'est pas déjà fait, sélectionne "Exécuter un examen complet".
  • Afin de lancer la recherche, clic sur"Rechercher".
  • Une fois le scan terminé, une fenêtre s'ouvre, clic sur OK. Deux possibilités s'offrent à toi :

-- si le programme n'a rien trouvé, appuie sur OK. Un rapport va apparaître, ferme-le.
-- si des infections sont présentes, clic sur "Afficher les résultats" puis sur "Supprimer la sélection". Enregistre le rapport sur ton Bureau afin de le poster dans ta prochaine réponse.
REMARQUE : Si MalwareByte's Anti-Malware a besoin de redémarrer pour terminer la suppression, accepte en cliquant sur Ok.

AIDE : Tuto en images sur MBAM

------------------------------ Prévention & Protection||Vous m'aimez ? Cliquez :o
Répondre à Angeldark

Malwarebytes' Anti-Malware 1.11
Version de la base de données: 633

Type de recherche: Examen complet (C:\|D:\|)
Eléments examinés: 73967
Temps écoulé: 21 minute(s), 45 second(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 1
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 1
Fichier(s) infecté(s): 0

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):
HKEY_CURRENT_USER\Software\MediaHoldings (Adware.PlayMP3Z) -> Quarantined and deleted successfully.

Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)

Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)

Dossier(s) infecté(s):
C:\Program Files\Dot1XCfg (Trojan.Downloader) -> Quarantined and deleted successfully.

Fichier(s) infecté(s):
(Aucun élément nuisible détecté)

Répondre à mag14100

Reposte un rapport Hijackthis.

------------------------------ Prévention & Protection||Vous m'aimez ? Cliquez :o
Répondre à Angeldark

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:49:12, on 16/04/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\sistray.EXE
C:\WINDOWS\system32\keyhook.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Netlog 24\Notifier\Netlog24Notifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
C:\PROGRA~1\INCRED~1\bin\IMApp.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe
D:\eMule\emule.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Favoris
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [CamMonitor] C:\Program Files\Hewlett-Packard\Digital Imaging\\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SiS Tray] C:\WINDOWS\system32\sistray.EXE
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\system32\keyhook.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Netlog 24] "C:\Program Files\Netlog 24\Notifier\Netlog24Notifier.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [City meet] C:\DOCUME~1\ADMINI~1\APPLIC~1\FUNKDR~1\Internetdrivemail.exe
O4 - HKUS\S-1-5-19\..\RunOnce: [XPPro4.0] %systemroot%\REG\run.cmd (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\RunOnce: [XPPro4.0] %systemroot%\REG\run.cmd (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [Picasa Media Detector] D:\montage\Picasa2\PicasaMediaDetector.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [XPPro4.0] %systemroot%\REG\run.cmd (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Picasa Media Detector] D:\montage\Picasa2\PicasaMediaDetector.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [XPPro4.0] %systemroot%\REG\run.cmd (User 'Default user')
O4 - Global Startup: BlueSoleil.lnk = C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O15 - Trusted Zone: http://www.msi.com.tw
O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/too [...] ontrol.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-F [...] E_UNO1.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/r [...] se4009.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://copainsdavant.linternaute.c [...] oader4.cab
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - http://www.touslesdrivers.com/fich [...] _0_4_9.cab
O16 - DPF: {BD8667B7-38D8-4C77-B580-18C3E146372C} (Creative Toolbox Plug-in) - http://kiw.imgag.com/imgag/cp/inst [...] -kiwen.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/bina [...] b56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/bina [...] b56986.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe

--
End of file - 11081 bytes
merci beaucoup car je n'est plus ces pubs qui m'envahissaient
mag

Répondre à mag14100

Refais un scan LopSD. Ne met pas résolu quand cela ne l'est pas :)

------------------------------ Prévention & Protection||Vous m'aimez ? Cliquez :o
Répondre à Angeldark

désolé mais je croyez que ct bon
je te remet çà tout de suite

Répondre à mag14100


-----------------------[ Lop S&D 4.1.1-2 XP/Vista ]---------------------

[ Windows XP (NT 5.1) Build 2600, Service Pack 2 ]
[ USER : Administrateur ] [ "C:\Lop SD" ]
[ 16/04/2008 | 22:27:46,57 ] [ PC : XPSP2-F87D6FB42 ]
[ MAJ : 16-04-2008 | 20:05 ]

-------------[ Listing des dossiers dans Application Data ]------------

[15/04/2008|19:54] C:\DOCUME~1\ADMINI~1\APPLIC~1\.
[15/04/2008|19:54] C:\DOCUME~1\ADMINI~1\APPLIC~1\..
[16/02/2008|23:12] C:\DOCUME~1\ADMINI~1\APPLIC~1\Adobe
[18/09/2007|13:40] C:\DOCUME~1\ADMINI~1\APPLIC~1\AdobeUM
[10/09/2007|21:36] C:\DOCUME~1\ADMINI~1\APPLIC~1\Ahead
[23/09/2007|11:32] C:\DOCUME~1\ADMINI~1\APPLIC~1\Apple Computer
[20/12/2007|18:50] C:\DOCUME~1\ADMINI~1\APPLIC~1\Chessmaster Challenge
[16/09/2007|17:10] C:\DOCUME~1\ADMINI~1\APPLIC~1\CyberLink
[09/09/2007|21:37] C:\DOCUME~1\ADMINI~1\APPLIC~1\desktop.ini
[16/04/2008|21:33] C:\DOCUME~1\ADMINI~1\APPLIC~1\DivX
[09/09/2007|20:48] C:\DOCUME~1\ADMINI~1\APPLIC~1\Dossier de t‚l‚chargement Share-to-Web
[12/09/2007|21:30] C:\DOCUME~1\ADMINI~1\APPLIC~1\Dossier de t‚l‚chargement Share-to-Web
[10/04/2008|09:09] C:\DOCUME~1\ADMINI~1\APPLIC~1\funk draw rect
[06/01/2008|23:58] C:\DOCUME~1\ADMINI~1\APPLIC~1\GDIPFONTCACHEV1.DAT
[09/09/2007|23:02] C:\DOCUME~1\ADMINI~1\APPLIC~1\Google
[13/10/2007|22:18] C:\DOCUME~1\ADMINI~1\APPLIC~1\Grisoft
[19/12/2007|16:03] C:\DOCUME~1\ADMINI~1\APPLIC~1\Help
[11/09/2007|14:46] C:\DOCUME~1\ADMINI~1\APPLIC~1\Hewlett-Packard
[17/11/2007|17:11] C:\DOCUME~1\ADMINI~1\APPLIC~1\HP
[22/03/2008|20:12] C:\DOCUME~1\ADMINI~1\APPLIC~1\Identities
[13/03/2008|16:56] C:\DOCUME~1\ADMINI~1\APPLIC~1\Image Zone Express
[25/01/2008|19:21] C:\DOCUME~1\ADMINI~1\APPLIC~1\IMBooster
[20/10/2007|16:54] C:\DOCUME~1\ADMINI~1\APPLIC~1\Lavasoft
[22/09/2007|01:07] C:\DOCUME~1\ADMINI~1\APPLIC~1\Leadertech
[31/10/2007|18:17] C:\DOCUME~1\ADMINI~1\APPLIC~1\LimeWire
[26/03/2008|14:38] C:\DOCUME~1\ADMINI~1\APPLIC~1\Macromedia
[15/04/2008|19:54] C:\DOCUME~1\ADMINI~1\APPLIC~1\Malwarebytes
[01/11/2007|17:59] C:\DOCUME~1\ADMINI~1\APPLIC~1\Media Player Classic
[27/03/2008|12:55] C:\DOCUME~1\ADMINI~1\APPLIC~1\Microsoft
[09/09/2007|22:35] C:\DOCUME~1\ADMINI~1\APPLIC~1\Mindscape
[12/09/2007|09:06] C:\DOCUME~1\ADMINI~1\APPLIC~1\Mozilla
[08/04/2008|19:16] C:\DOCUME~1\ADMINI~1\APPLIC~1\Plopp1.2
[17/11/2007|17:35] C:\DOCUME~1\ADMINI~1\APPLIC~1\Printer Info Cache
[06/03/2008|21:05] C:\DOCUME~1\ADMINI~1\APPLIC~1\Skype
[14/10/2007|23:06] C:\DOCUME~1\ADMINI~1\APPLIC~1\Sun
[12/09/2007|09:06] C:\DOCUME~1\ADMINI~1\APPLIC~1\Talkback
[16/09/2007|11:47] C:\DOCUME~1\ADMINI~1\APPLIC~1\TuxPaint
[21/12/2007|11:51] C:\DOCUME~1\ADMINI~1\APPLIC~1\Uniblue
[29/09/2007|17:46] C:\DOCUME~1\ADMINI~1\APPLIC~1\Windows Live Writer

[15/04/2008|15:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\.
[15/04/2008|15:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\..
[14/02/2008|10:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[09/09/2007|22:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[16/01/2008|14:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Bluetooth
[16/09/2007|17:10] C:\DOCUME~1\ALLUSE~1\APPLIC~1\CyberLink
[09/09/2007|21:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\desktop.ini
[01/03/2008|09:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Downloaded Installations
[09/09/2007|20:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
[13/10/2007|22:18] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Grisoft
[17/11/2007|13:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\HP
[28/03/2008|22:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\HPSSUPPLY
[28/03/2008|22:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\hpzinstall.log
[15/04/2008|19:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Malwarebytes
[07/03/2008|12:10] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!
[11/03/2008|17:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[12/09/2007|09:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Mozilla
[12/11/2007|09:23] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MumboJumbo
[05/04/2008|12:33] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Plopp1.2
[16/02/2008|17:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\QTSBandwidthCache
[09/09/2007|20:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Skype
[15/04/2008|10:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
[16/11/2007|23:01] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
[12/09/2007|11:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[10/10/2007|20:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Live Toolbar
[24/03/2008|22:38] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
[01/04/2008|13:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Yahoo! Companion

[09/09/2007|21:37] C:\DOCUME~1\DEFAUL~1\APPLIC~1\.
[09/09/2007|21:37] C:\DOCUME~1\DEFAUL~1\APPLIC~1\..
[09/09/2007|21:37] C:\DOCUME~1\DEFAUL~1\APPLIC~1\desktop.ini
[09/09/2007|19:46] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft

[09/09/2007|19:49] C:\DOCUME~1\LOCALS~1\APPLIC~1\.
[09/09/2007|19:49] C:\DOCUME~1\LOCALS~1\APPLIC~1\..
[29/09/2007|17:40] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft

[29/09/2007|17:36] C:\DOCUME~1\NETWOR~1\APPLIC~1\.
[29/09/2007|17:36] C:\DOCUME~1\NETWOR~1\APPLIC~1\..
[29/09/2007|17:36] C:\DOCUME~1\NETWOR~1\APPLIC~1\Identities
[29/09/2007|17:36] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft

----------------[ Tâches planifiées dans C:\WINDOWS\tasks ]---------------

[16/04/2008 21:36][--ah-----] C:\WINDOWS\tasks\SA.DAT
[02/10/2001 18:16][-r-h-----] C:\WINDOWS\tasks\desktop.ini

---------------[ Listing des dossiers dans C:\Program Files ]--------------

[16/04/2008|20:48] C:\Program Files\.
[16/04/2008|20:48] C:\Program Files\..
[14/02/2008|10:44] C:\Program Files\Adobe
[10/09/2007|21:00] C:\Program Files\Ahead
[09/09/2007|20:23] C:\Program Files\Alwil Software
[19/11/2007|18:39] C:\Program Files\Apple Software Update
[11/10/2007|23:12] C:\Program Files\aRPNCalc
[22/12/2007|17:55] C:\Program Files\Atari
[20/12/2007|19:08] C:\Program Files\B4Playing
[26/09/2007|21:01] C:\Program Files\BarreConfCMCIC
[16/04/2008|11:37] C:\Program Files\CA Yahoo! Anti-Spy
[13/10/2007|23:18] C:\Program Files\CCleaner
[08/03/2008|19:48] C:\Program Files\C-Media 3D Audio
[09/04/2008|10:12] C:\Program Files\Common Files
[09/09/2007|19:42] C:\Program Files\ComPlus Applications
[08/03/2008|19:34] C:\Program Files\Conduit
[16/09/2007|17:09] C:\Program Files\CyberLink
[12/12/2007|13:56] C:\Program Files\Disney Interactive
[16/04/2008|11:37] C:\Program Files\DivX
[28/10/2007|13:43] C:\Program Files\DK
[05/04/2008|11:36] C:\Program Files\Fichiers communs
[08/03/2008|19:34] C:\Program Files\free-downloads.net
[10/04/2008|09:08] C:\Program Files\funk draw rect
[21/12/2007|21:30] C:\Program Files\Google
[13/10/2007|22:18] C:\Program Files\Grisoft
[17/11/2007|13:41] C:\Program Files\Hewlett-Packard
[17/11/2007|17:35] C:\Program Files\HP
[16/11/2007|23:36] C:\Program Files\Incredijeux
[13/11/2007|15:58] C:\Program Files\IncrediMail
[08/03/2008|13:52] C:\Program Files\InstallShield Installation Information
[02/03/2008|23:07] C:\Program Files\Intel Desktop Board
[09/04/2008|18:00] C:\Program Files\Internet Explorer
[09/09/2007|19:54] C:\Program Files\Inventel
[16/01/2008|14:31] C:\Program Files\IVT Corporation
[04/04/2008|18:00] C:\Program Files\Java
[09/04/2008|13:25] C:\Program Files\Kiwee Toolbar2
[20/10/2007|16:54] C:\Program Files\Lavasoft
[01/03/2008|00:25] C:\Program Files\lecteur windows media 11
[10/04/2008|09:08] C:\Program Files\Messenger Plus! Live
[09/09/2007|19:47] C:\Program Files\microsoft frontpage
[19/11/2007|17:21] C:\Program Files\Microsoft Hardware
[04/12/2007|16:33] C:\Program Files\Microsoft Office
[29/09/2007|17:36] C:\Program Files\Microsoft SQL Server Compact Edition
[26/09/2007|11:46] C:\Program Files\Mindscape
[17/09/2007|20:27] C:\Program Files\Movie Maker
[16/04/2008|22:25] C:\Program Files\Mozilla Firefox
[09/09/2007|23:09] C:\Program Files\MSECache
[12/09/2007|21:54] C:\Program Files\MSI
[09/09/2007|19:42] C:\Program Files\MSN Gaming Zone
[24/10/2007|15:42] C:\Program Files\MSN Messenger
[17/11/2007|23:05] C:\Program Files\MSXML 4.0
[08/03/2008|19:55] C:\Program Files\Multimedia V3.54
[23/11/2007|13:16] C:\Program Files\Netlog 24
[09/09/2007|19:43] C:\Program Files\NetMeeting
[17/09/2007|20:27] C:\Program Files\Outlook Express
[28/01/2008|10:58] C:\Program Files\PhotoFiltre
[09/09/2007|22:36] C:\Program Files\QuickTime
[20/12/2007|18:47] C:\Program Files\ReflexiveArcade
[24/12/2007|16:43] C:\Program Files\SAMSUNG
[09/09/2007|19:44] C:\Program Files\Services en ligne
[25/10/2007|19:57] C:\Program Files\SiS7012
[08/03/2008|13:52] C:\Program Files\sisagp
[08/03/2008|19:46] C:\Program Files\SiSLan
[09/09/2007|20:20] C:\Program Files\Skype
[16/10/2007|10:11] C:\Program Files\Sunbelt Software
[16/04/2008|20:48] C:\Program Files\Trend Micro
[09/09/2007|19:50] C:\Program Files\Uninstall Information
[09/09/2007|19:57] C:\Program Files\Wanadoo
[26/10/2007|15:18] C:\Program Files\Windows Desktop Search
[11/04/2008|11:12] C:\Program Files\Windows Live
[08/04/2008|18:56] C:\Program Files\Windows Live Safety Center
[20/10/2007|16:44] C:\Program Files\Windows Live Toolbar
[11/03/2008|13:16] C:\Program Files\Windows Media Connect 2
[11/03/2008|13:40] C:\Program Files\Windows Media Player
[09/09/2007|19:41] C:\Program Files\Windows NT
[09/09/2007|19:44] C:\Program Files\WindowsUpdate
[09/09/2007|20:05] C:\Program Files\WinRAR
[09/09/2007|19:47] C:\Program Files\xerox
[09/04/2008|10:12] C:\Program Files\Yahoo!

------[ Listing des dossiers dans C:\Program Files\Fichiers communs ]------

[05/04/2008|11:36] C:\Program Files\Fichiers communs\.
[05/04/2008|11:36] C:\Program Files\Fichiers communs\..
[14/02/2008|10:45] C:\Program Files\Fichiers communs\Adobe
[10/09/2007|21:00] C:\Program Files\Fichiers communs\Ahead
[12/09/2007|15:23] C:\Program Files\Fichiers communs\Designer
[04/03/2008|20:00] C:\Program Files\Fichiers communs\DirectX
[09/09/2007|19:55] C:\Program Files\Fichiers communs\FDEUnInstaller.exe
[11/10/2007|23:18] C:\Program Files\Fichiers communs\GTK
[17/11/2007|13:36] C:\Program Files\Fichiers communs\Hewlett-Packard
[17/11/2007|17:35] C:\Program Files\Fichiers communs\HP
[30/09/2007|13:38] C:\Program Files\Fichiers communs\InstallShield
[20/09/2007|16:31] C:\Program Files\Fichiers communs\Java
[09/09/2007|20:49] C:\Program Files\Fichiers communs\Logitech
[17/01/2008|22:58] C:\Program Files\Fichiers communs\Microsoft Shared
[09/09/2007|19:43] C:\Program Files\Fichiers communs\MSSoap
[09/09/2007|21:37] C:\Program Files\Fichiers communs\ODBC
[05/04/2008|11:36] C:\Program Files\Fichiers communs\Scanner
[09/09/2007|19:43] C:\Program Files\Fichiers communs\Services
[09/09/2007|20:20] C:\Program Files\Fichiers communs\Skype
[09/09/2007|21:37] C:\Program Files\Fichiers communs\SpeechEngines
[16/09/2007|22:16] C:\Program Files\Fichiers communs\System
[03/01/2008|21:45] C:\Program Files\Fichiers communs\Vivendi Universal Games
[17/01/2008|22:56] C:\Program Files\Fichiers communs\WindowsLiveInstaller

----------------------[ Recherche avec S_Lop ]---------------------

Aucun fichier / dossier Lop trouvé !

-----------------[ Recherche de Fichiers / Dossiers Lop ]-----------------

Aucun fichier / dossier Lop trouvé !

----------------------[ Verification du Registre ]----------------------

..... OK !

--------------------[ Verification du fichier Hosts ]---------------------

Fichier Hosts PROPRE


----------------[ Recherche de fichiers avec Catchme ]-----------------

catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-16 22:29:10
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 0

--------------------[ Recherche d'autres infections ]---------------------

Aucune autre infection trouvée !

/!\ [Fich:69][Doss:7] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp
/!\ [Fich:13][Doss:0] C:\DOCUME~1\ADMINI~1\Cookies
/!\ [Fich:38][Doss:5] C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMPOR~1\content.IE5

--------------------[ Fin du rapport a 22:30:29,90 ]----------------------

Répondre à mag14100

Re,

Tu as un Windows piraté ?

Fix la ligne dans le cadre ci-dessous avec Hijackthis : AIDE EN IMAGES

O4 - HKCU\..\Run: [City meet] C:\DOCUME~1\ADMINI~1\APPLIC~1\FUNKDR~1\Internetdrivemail.exe



&

Télécharge OTMoveIt (d'OldTimer). Sauvegarde-le sur ton Bureau.
Sélectionne tous les emplacements dans le cadre ci-dessous :

C:\DOCUME~1\ADMINI~1\APPLIC~1\funk draw rect
C:\Program Files\funk draw rect


---> Clique-droit puis Copier (ou Ctrl+C)

Double-clique sur OTMoveIt.exe afin de le lancer.
Fais un Clique-droit sur le cadre de gauche puis choisis Coller (ou Ctrl+V).
Clique maintenant sur MoveIt!

Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
Accepte en cliquant sur YES.


Poste le rapport situé dans ce dossier : C:\_OTMoveIt\MovedFiles\
Le nom du rapport correspond au moment de sa création : date_heure.log

->Informations sur le logiciel<-

------------------------------ Prévention & Protection||Vous m'aimez ? Cliquez :o
Répondre à Angeldark

C:\DOCUME~1\ADMINI~1\APPLIC~1\funk draw rect moved successfully.
C:\Program Files\funk draw rect moved successfully.

OTMoveIt2 by OldTimer - Version 1.0.4.1 log created on 04172008_214234

pour mon logiciel oui car j'ai eu un arlerte de microsoft car je fait les mises a jour mais je nen savais rien car c un pc je jai eu d'occasion


Message édité par mag14100 le 17-04-2008 à 22:02:49
Répondre à mag14100

Reposte un rapport Hijackthis.

------------------------------ Prévention & Protection||Vous m'aimez ? Cliquez :o
Répondre à Angeldark

bonsoir voici le log que tu ma demander et merci de ta patience


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:06:18, on 18/04/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
C:\Program Files\Controle Parental\bin\optproxy.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\WgaTray.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\sistray.EXE
C:\WINDOWS\system32\keyhook.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Orange\Systray\SystrayApp.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\PROGRA~1\CONTRO~1\bin\optgui.exe
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
C:\Program Files\Netlog 24\Notifier\Netlog24Notifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
C:\PROGRA~1\INCRED~1\bin\IMApp.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Orange\Launcher\Launcher.exe
C:\Program Files\Orange\connectivity\connectivitymanager.exe
C:\Program Files\Orange\connectivity\CoreCom\CoreCom.exe
C:\Program Files\Orange\connectivity\CoreCom\OraConfigRecover.exe
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTCOMModule\0\FTCOMModule.exe
D:\eMule\emule.exe
C:\Program Files\Orange\Deskboard\deskboard.exe
C:\Program Files\Orange\browser\browser.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.orange.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Favoris
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\Orange\SearchURLHook\SearchPageURL.dll
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [CamMonitor] C:\Program Files\Hewlett-Packard\Digital Imaging\\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SiS Tray] C:\WINDOWS\system32\sistray.EXE
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\system32\keyhook.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SystrayORAHSS] "C:\Program Files\Orange\Systray\SystrayApp.exe"
O4 - HKLM\..\Run: [ORAHSSSessionManager] C:\Program Files\Orange\SessionManager\SessionManager.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [OPTENET_GUI] C:\PROGRA~1\CONTRO~1\bin\optgui.exe
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Netlog 24] "C:\Program Files\Netlog 24\Notifier\Netlog24Notifier.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [City meet] C:\DOCUME~1\ADMINI~1\APPLIC~1\FUNKDR~1\Internetdrivemail.exe
O4 - HKUS\S-1-5-19\..\RunOnce: [XPPro4.0] %systemroot%\REG\run.cmd (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\RunOnce: [XPPro4.0] %systemroot%\REG\run.cmd (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [Picasa Media Detector] D:\montage\Picasa2\PicasaMediaDetector.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [XPPro4.0] %systemroot%\REG\run.cmd (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Picasa Media Detector] D:\montage\Picasa2\PicasaMediaDetector.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [XPPro4.0] %systemroot%\REG\run.cmd (User 'Default user')
O4 - Global Startup: BlueSoleil.lnk = C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O15 - Trusted Zone: http://www.msi.com.tw
O15 - Trusted Zone: http://www.orange.fr
O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/too [...] ontrol.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-F [...] E_UNO1.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/r [...] se4009.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://copainsdavant.linternaute.c [...] oader4.cab
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - http://www.touslesdrivers.com/fich [...] _0_4_9.cab
O16 - DPF: {BD8667B7-38D8-4C77-B580-18C3E146372C} (Creative Toolbox Plug-in) - http://kiw.imgag.com/imgag/cp/inst [...] -kiwen.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/bina [...] b56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/bina [...] b56986.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: Orange Contrôle Parental (OPTENET_FILTER) - Orange - C:\Program Files\Controle Parental\bin\optproxy.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe

--
End of file - 11909 bytes


Message édité par mag14100 le 18-04-2008 à 21:08:27
Répondre à mag14100

Supprime ta version de LopSD, retélécharge-la. Puis passe l'option 1.

------------------------------ Prévention & Protection||Vous m'aimez ? Cliquez :o
Répondre à Angeldark

peut tu m'envoyer un lien pour le telecharger
dit moi je telecharge le meme


Message édité par mag14100 le 18-04-2008 à 21:22:33
Répondre à mag14100

C'est le même lien hein.

------------------------------ Prévention & Protection||Vous m'aimez ? Cliquez :o
Répondre à Angeldark


-----------------------[ Lop S&D 4.1.1-3 XP/Vista ]---------------------

[ Windows XP (NT 5.1) Build 2600, Service Pack 2 ]
[ USER : Administrateur ] [ "C:\Lop SD" ]
[ 18/04/2008 | 21:26:58,71 ] [ PC : XPSP2-F87D6FB42 ]
[ MAJ : 17-04-2008 | 19:51 ]

-------------[ Listing des dossiers dans Application Data ]------------

[17/04/2008|21:55] C:\DOCUME~1\ADMINI~1\APPLIC~1\.
[17/04/2008|21:55] C:\DOCUME~1\ADMINI~1\APPLIC~1\..
[16/02/2008|23:12] C:\DOCUME~1\ADMINI~1\APPLIC~1\Adobe
[18/09/2007|13:40] C:\DOCUME~1\ADMINI~1\APPLIC~1\AdobeUM
[10/09/2007|21:36] C:\DOCUME~1\ADMINI~1\APPLIC~1\Ahead
[23/09/2007|11:32] C:\DOCUME~1\ADMINI~1\APPLIC~1\Apple Computer
[20/12/2007|18:50] C:\DOCUME~1\ADMINI~1\APPLIC~1\Chessmaster Challenge
[16/09/2007|17:10] C:\DOCUME~1\ADMINI~1\APPLIC~1\CyberLink
[09/09/2007|21:37] C:\DOCUME~1\ADMINI~1\APPLIC~1\desktop.ini
[16/04/2008|21:33] C:\DOCUME~1\ADMINI~1\APPLIC~1\DivX
[09/09/2007|20:48] C:\DOCUME~1\ADMINI~1\APPLIC~1\Dossier de t‚l‚chargement Share-to-Web
[12/09/2007|21:30] C:\DOCUME~1\ADMINI~1\APPLIC~1\Dossier de t‚l‚chargement Share-to-Web
[17/04/2008|21:55] C:\DOCUME~1\ADMINI~1\APPLIC~1\funk draw rect
[06/01/2008|23:58] C:\DOCUME~1\ADMINI~1\APPLIC~1\GDIPFONTCACHEV1.DAT
[09/09/2007|23:02] C:\DOCUME~1\ADMINI~1\APPLIC~1\Google
[13/10/2007|22:18] C:\DOCUME~1\ADMINI~1\APPLIC~1\Grisoft
[19/12/2007|16:03] C:\DOCUME~1\ADMINI~1\APPLIC~1\Help
[11/09/2007|14:46] C:\DOCUME~1\ADMINI~1\APPLIC~1\Hewlett-Packard
[17/11/2007|17:11] C:\DOCUME~1\ADMINI~1\APPLIC~1\HP
[22/03/2008|20:12] C:\DOCUME~1\ADMINI~1\APPLIC~1\Identities
[13/03/2008|16:56] C:\DOCUME~1\ADMINI~1\APPLIC~1\Image Zone Express
[25/01/2008|19:21] C:\DOCUME~1\ADMINI~1\APPLIC~1\IMBooster
[20/10/2007|16:54] C:\DOCUME~1\ADMINI~1\APPLIC~1\Lavasoft
[22/09/2007|01:07] C:\DOCUME~1\ADMINI~1\APPLIC~1\Leadertech
[31/10/2007|18:17] C:\DOCUME~1\ADMINI~1\APPLIC~1\LimeWire
[26/03/2008|14:38] C:\DOCUME~1\ADMINI~1\APPLIC~1\Macromedia
[15/04/2008|19:54] C:\DOCUME~1\ADMINI~1\APPLIC~1\Malwarebytes
[01/11/2007|17:59] C:\DOCUME~1\ADMINI~1\APPLIC~1\Media Player Classic
[27/03/2008|12:55] C:\DOCUME~1\ADMINI~1\APPLIC~1\Microsoft
[09/09/2007|22:35] C:\DOCUME~1\ADMINI~1\APPLIC~1\Mindscape
[12/09/2007|09:06] C:\DOCUME~1\ADMINI~1\APPLIC~1\Mozilla
[08/04/2008|19:16] C:\DOCUME~1\ADMINI~1\APPLIC~1\Plopp1.2
[17/11/2007|17:35] C:\DOCUME~1\ADMINI~1\APPLIC~1\Printer Info Cache
[06/03/2008|21:05] C:\DOCUME~1\ADMINI~1\APPLIC~1\Skype
[14/10/2007|23:06] C:\DOCUME~1\ADMINI~1\APPLIC~1\Sun
[12/09/2007|09:06] C:\DOCUME~1\ADMINI~1\APPLIC~1\Talkback
[16/09/2007|11:47] C:\DOCUME~1\ADMINI~1\APPLIC~1\TuxPaint
[21/12/2007|11:51] C:\DOCUME~1\ADMINI~1\APPLIC~1\Uniblue
[29/09/2007|17:46] C:\DOCUME~1\ADMINI~1\APPLIC~1\Windows Live Writer

[15/04/2008|15:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\.
[15/04/2008|15:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\..
[14/02/2008|10:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[09/09/2007|22:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[16/01/2008|14:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Bluetooth
[16/09/2007|17:10] C:\DOCUME~1\ALLUSE~1\APPLIC~1\CyberLink
[09/09/2007|21:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\desktop.ini
[01/03/2008|09:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Downloaded Installations
[09/09/2007|20:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
[13/10/2007|22:18] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Grisoft
[17/11/2007|13:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\HP
[28/03/2008|22:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\HPSSUPPLY
[28/03/2008|22:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\hpzinstall.log
[15/04/2008|19:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Malwarebytes
[07/03/2008|12:10] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!
[11/03/2008|17:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[12/09/2007|09:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Mozilla
[12/11/2007|09:23] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MumboJumbo
[05/04/2008|12:33] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Plopp1.2
[16/02/2008|17:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\QTSBandwidthCache
[09/09/2007|20:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Skype
[15/04/2008|10:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
[16/11/2007|23:01] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
[12/09/2007|11:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[10/10/2007|20:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Live Toolbar
[24/03/2008|22:38] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller

[09/09/2007|21:37] C:\DOCUME~1\DEFAUL~1\APPLIC~1\.
[09/09/2007|21:37] C:\DOCUME~1\DEFAUL~1\APPLIC~1\..
[09/09/2007|21:37] C:\DOCUME~1\DEFAUL~1\APPLIC~1\desktop.ini
[09/09/2007|19:46] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft

[09/09/2007|19:49] C:\DOCUME~1\LOCALS~1\APPLIC~1\.
[09/09/2007|19:49] C:\DOCUME~1\LOCALS~1\APPLIC~1\..
[29/09/2007|17:40] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft

[29/09/2007|17:36] C:\DOCUME~1\NETWOR~1\APPLIC~1\.
[29/09/2007|17:36] C:\DOCUME~1\NETWOR~1\APPLIC~1\..
[29/09/2007|17:36] C:\DOCUME~1\NETWOR~1\APPLIC~1\Identities
[29/09/2007|17:36] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft

----------------[ Tâches planifiées dans C:\WINDOWS\tasks ]---------------

[18/04/2008 11:37][--ah-----] C:\WINDOWS\tasks\SA.DAT
[02/10/2001 18:16][-r-h-----] C:\WINDOWS\tasks\desktop.ini

---------------[ Listing des dossiers dans C:\Program Files ]--------------

[18/04/2008|11:33] C:\Program Files\.
[18/04/2008|11:33] C:\Program Files\..
[14/02/2008|10:44] C:\Program Files\Adobe
[10/09/2007|21:00] C:\Program Files\Ahead
[09/09/2007|20:23] C:\Program Files\Alwil Software
[19/11/2007|18:39] C:\Program Files\Apple Software Update
[11/10/2007|23:12] C:\Program Files\aRPNCalc
[22/12/2007|17:55] C:\Program Files\Atari
[20/12/2007|19:08] C:\Program Files\B4Playing
[26/09/2007|21:01] C:\Program Files\BarreConfCMCIC
[16/04/2008|11:37] C:\Program Files\CA Yahoo! Anti-Spy
[13/10/2007|23:18] C:\Program Files\CCleaner
[08/03/2008|19:48] C:\Program Files\C-Media 3D Audio
[09/04/2008|10:12] C:\Program Files\Common Files
[09/09/2007|19:42] C:\Program Files\ComPlus Applications
[08/03/2008|19:34] C:\Program Files\Conduit
[18/04/2008|11:35] C:\Program Files\Controle Parental
[16/09/2007|17:09] C:\Program Files\CyberLink
[12/12/2007|13:56] C:\Program Files\Disney Interactive
[16/04/2008|11:37] C:\Program Files\DivX
[28/10/2007|13:43] C:\Program Files\DK
[17/04/2008|09:17] C:\Program Files\Fichiers communs
[08/03/2008|19:34] C:\Program Files\free-downloads.net
[21/12/2007|21:30] C:\Program Files\Google
[13/10/2007|22:18] C:\Program Files\Grisoft
[17/11/2007|13:41] C:\Program Files\Hewlett-Packard
[17/11/2007|17:35] C:\Program Files\HP
[16/11/2007|23:36] C:\Program Files\Incredijeux
[13/11/2007|15:58] C:\Program Files\IncrediMail
[18/04/2008|11:33] C:\Program Files\InstallShield Installation Information
[02/03/2008|23:07] C:\Program Files\Intel Desktop Board
[09/04/2008|18:00] C:\Program Files\Internet Explorer
[09/09/2007|19:54] C:\Program Files\Inventel
[16/01/2008|14:31] C:\Program Files\IVT Corporation
[17/04/2008|11:57] C:\Program Files\Java
[09/04/2008|13:25] C:\Program Files\Kiwee Toolbar2
[20/10/2007|16:54] C:\Program Files\Lavasoft
[01/03/2008|00:25] C:\Program Files\lecteur windows media 11
[10/04/2008|09:08] C:\Program Files\Messenger Plus! Live
[09/09/2007|19:47] C:\Program Files\microsoft frontpage
[19/11/2007|17:21] C:\Program Files\Microsoft Hardware
[04/12/2007|16:33] C:\Program Files\Microsoft Office
[29/09/2007|17:36] C:\Program Files\Microsoft SQL Server Compact Edition
[26/09/2007|11:46] C:\Program Files\Mindscape
[17/09/2007|20:27] C:\Program Files\Movie Maker
[17/04/2008|11:55] C:\Program Files\Mozilla Firefox
[09/09/2007|23:09] C:\Program Files\MSECache
[12/09/2007|21:54] C:\Program Files\MSI
[09/09/2007|19:42] C:\Program Files\MSN Gaming Zone
[24/10/2007|15:42] C:\Program Files\MSN Messenger
[17/11/2007|23:05] C:\Program Files\MSXML 4.0
[08/03/2008|19:55] C:\Program Files\Multimedia V3.54
[23/11/2007|13:16] C:\Program Files\Netlog 24
[09/09/2007|19:43] C:\Program Files\NetMeeting
[17/04/2008|09:20] C:\Program Files\Orange
[17/09/2007|20:27] C:\Program Files\Outlook Express
[28/01/2008|10:58] C:\Program Files\PhotoFiltre
[09/09/2007|22:36] C:\Program Files\QuickTime
[20/12/2007|18:47] C:\Program Files\ReflexiveArcade
[24/12/2007|16:43] C:\Program Files\SAMSUNG
[09/09/2007|19:44] C:\Program Files\Services en ligne
[25/10/2007|19:57] C:\Program Files\SiS7012
[08/03/2008|13:52] C:\Program Files\sisagp
[08/03/2008|19:46] C:\Program Files\SiSLan
[09/09/2007|20:20] C:\Program Files\Skype
[16/10/2007|10:11] C:\Program Files\Sunbelt Software
[16/04/2008|20:48] C:\Program Files\Trend Micro
[09/09/2007|19:50] C:\Program Files\Uninstall Information
[09/09/2007|19:57] C:\Program Files\Wanadoo
[26/10/2007|15:18] C:\Program Files\Windows Desktop Search
[11/04/2008|11:12] C:\Program Files\Windows Live
[08/04/2008|18:56] C:\Program Files\Windows Live Safety Center
[20/10/2007|16:44] C:\Program Files\Windows Live Toolbar
[11/03/2008|13:16] C:\Program Files\Windows Media Connect 2
[11/03/2008|13:40] C:\Program Files\Windows Media Player
[09/09/2007|19:41] C:\Program Files\Windows NT
[09/09/2007|19:44] C:\Program Files\WindowsUpdate
[09/09/2007|20:05] C:\Program Files\WinRAR
[09/09/2007|19:47] C:\Program Files\xerox
[17/04/2008|11:56] C:\Program Files\Yahoo!

------[ Listing des dossiers dans C:\Program Files\Fichiers communs ]------

[17/04/2008|09:17] C:\Program Files\Fichiers communs\.
[17/04/2008|09:17] C:\Program Files\Fichiers communs\..
[14/02/2008|10:45] C:\Program Files\Fichiers communs\Adobe
[10/09/2007|21:00] C:\Program Files\Fichiers communs\Ahead
[12/09/2007|15:23] C:\Program Files\Fichiers communs\Designer
[04/03/2008|20:00] C:\Program Files\Fichiers communs\DirectX
[09/09/2007|19:55] C:\Program Files\Fichiers communs\FDEUnInstaller.exe
[17/04/2008|09:17] C:\Program Files\Fichiers communs\France Telecom
[11/10/2007|23:18] C:\Program Files\Fichiers communs\GTK
[17/11/2007|13:36] C:\Program Files\Fichiers communs\Hewlett-Packard
[17/11/2007|17:35] C:\Program Files\Fichiers communs\HP
[30/09/2007|13:38] C:\Program Files\Fichiers communs\InstallShield
[20/09/2007|16:31] C:\Program Files\Fichiers communs\Java
[09/09/2007|20:49] C:\Program Files\Fichiers communs\Logitech
[17/01/2008|22:58] C:\Program Files\Fichiers communs\Microsoft Shared
[09/09/2007|19:43] C:\Program Files\Fichiers communs\MSSoap
[09/09/2007|21:37] C:\Program Files\Fichiers communs\ODBC
[05/04/2008|11:36] C:\Program Files\Fichiers communs\Scanner
[09/09/2007|19:43] C:\Program Files\Fichiers communs\Services
[09/09/2007|20:20] C:\Program Files\Fichiers communs\Skype
[09/09/2007|21:37] C:\Program Files\Fichiers communs\SpeechEngines
[16/09/2007|22:16] C:\Program Files\Fichiers communs\System
[03/01/2008|21:45] C:\Program Files\Fichiers communs\Vivendi Universal Games
[17/01/2008|22:56] C:\Program Files\Fichiers communs\WindowsLiveInstaller

----------------------[ Recherche avec S_Lop ]---------------------

Aucun fichier / dossier Lop trouvé !

-----------------[ Recherche de Fichiers / Dossiers Lop ]-----------------

C:\DOCUME~1\ADMINI~1\APPLIC~1\funk draw rect

----------------------[ Verification du Registre ]----------------------

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

..... OK !

--------------------[ Verification du fichier Hosts ]---------------------

Fichier Hosts PROPRE


----------------[ Recherche de fichiers avec Catchme ]-----------------

catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-18 21:28:57
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 0

--------------------[ Recherche d'autres infections ]---------------------

Aucune autre infection trouvée !

/!\ [Fich:110][Doss:34] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp
/!\ [Fich:133][Doss:0] C:\DOCUME~1\ADMINI~1\Cookies
/!\ [Fich:7441][Doss:9] C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMPOR~1\content.IE5

--------------------[ Fin du rapport a 21:30:37,46 ]----------------------

Répondre à mag14100

ok merci mais dit moi a chaque fois que je lance une analyse avec ce logiciel avast detecte un tojan win32:inject-EV[trj]que je mets en quarantaine


Message édité par mag14100 le 18-04-2008 à 21:36:21
Répondre à mag14100

Passe l'option 2.


Message édité par Angeldark le 18-04-2008 à 21:56:20
------------------------------ Prévention & Protection||Vous m'aimez ? Cliquez :o
Répondre à Angeldark


-----------------------[ Lop S&D 4.1.1-3 XP/Vista ]---------------------

[ Windows XP (NT 5.1) Build 2600, Service Pack 2 ]
[ USER : Administrateur ] [ "C:\Lop SD" ]
[ 18/04/2008 | 22:16:51,70 ] [ PC : XPSP2-F87D6FB42 ]
[ MAJ : 17-04-2008 | 19:51 ]

\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ SUPPRESSION /////////////////////////////

Supprimé! - C:\DOCUME~1\ADMINI~1\APPLIC~1\funk draw rect

//////////////////////////////////////-\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\


-------------[ Listing des dossiers dans Application Data ]------------

[18/04/2008|22:16] C:\DOCUME~1\ADMINI~1\APPLIC~1\.
[18/04/2008|22:16] C:\DOCUME~1\ADMINI~1\APPLIC~1\..
[16/02/2008|23:12] C:\DOCUME~1\ADMINI~1\APPLIC~1\Adobe
[18/09/2007|13:40] C:\DOCUME~1\ADMINI~1\APPLIC~1\AdobeUM
[10/09/2007|21:36] C:\DOCUME~1\ADMINI~1\APPLIC~1\Ahead
[23/09/2007|11:32] C:\DOCUME~1\ADMINI~1\APPLIC~1\Apple Computer
[20/12/2007|18:50] C:\DOCUME~1\ADMINI~1\APPLIC~1\Chessmaster Challenge
[16/09/2007|17:10] C:\DOCUME~1\ADMINI~1\APPLIC~1\CyberLink
[09/09/2007|21:37] C:\DOCUME~1\ADMINI~1\APPLIC~1\desktop.ini
[16/04/2008|21:33] C:\DOCUME~1\ADMINI~1\APPLIC~1\DivX
[09/09/2007|20:48] C:\DOCUME~1\ADMINI~1\APPLIC~1\Dossier de t‚l‚chargement Share-to-Web
[12/09/2007|21:30] C:\DOCUME~1\ADMINI~1\APPLIC~1\Dossier de t‚l‚chargement Share-to-Web
[06/01/2008|23:58] C:\DOCUME~1\ADMINI~1\APPLIC~1\GDIPFONTCACHEV1.DAT
[09/09/2007|23:02] C:\DOCUME~1\ADMINI~1\APPLIC~1\Google
[13/10/2007|22:18] C:\DOCUME~1\ADMINI~1\APPLIC~1\Grisoft
[19/12/2007|16:03] C:\DOCUME~1\ADMINI~1\APPLIC~1\Help
[11/09/2007|14:46] C:\DOCUME~1\ADMINI~1\APPLIC~1\Hewlett-Packard
[17/11/2007|17:11] C:\DOCUME~1\ADMINI~1\APPLIC~1\HP
[22/03/2008|20:12] C:\DOCUME~1\ADMINI~1\APPLIC~1\Identities
[13/03/2008|16:56] C:\DOCUME~1\ADMINI~1\APPLIC~1\Image Zone Express
[25/01/2008|19:21] C:\DOCUME~1\ADMINI~1\APPLIC~1\IMBooster
[20/10/2007|16:54] C:\DOCUME~1\ADMINI~1\APPLIC~1\Lavasoft
[22/09/2007|01:07] C:\DOCUME~1\ADMINI~1\APPLIC~1\Leadertech
[31/10/2007|18:17] C:\DOCUME~1\ADMINI~1\APPLIC~1\LimeWire
[26/03/2008|14:38] C:\DOCUME~1\ADMINI~1\APPLIC~1\Macromedia
[15/04/2008|19:54] C:\DOCUME~1\ADMINI~1\APPLIC~1\Malwarebytes
[01/11/2007|17:59] C:\DOCUME~1\ADMINI~1\APPLIC~1\Media Player Classic
[27/03/2008|12:55] C:\DOCUME~1\ADMINI~1\APPLIC~1\Microsoft
[09/09/2007|22:35] C:\DOCUME~1\ADMINI~1\APPLIC~1\Mindscape
[12/09/2007|09:06] C:\DOCUME~1\ADMINI~1\APPLIC~1\Mozilla
[08/04/2008|19:16] C:\DOCUME~1\ADMINI~1\APPLIC~1\Plopp1.2
[17/11/2007|17:35] C:\DOCUME~1\ADMINI~1\APPLIC~1\Printer Info Cache
[06/03/2008|21:05] C:\DOCUME~1\ADMINI~1\APPLIC~1\Skype
[14/10/2007|23:06] C:\DOCUME~1\ADMINI~1\APPLIC~1\Sun
[12/09/2007|09:06] C:\DOCUME~1\ADMINI~1\APPLIC~1\Talkback
[16/09/2007|11:47] C:\DOCUME~1\ADMINI~1\APPLIC~1\TuxPaint
[21/12/2007|11:51] C:\DOCUME~1\ADMINI~1\APPLIC~1\Uniblue
[29/09/2007|17:46] C:\DOCUME~1\ADMINI~1\APPLIC~1\Windows Live Writer

[15/04/2008|15:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\.
[15/04/2008|15:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\..
[14/02/2008|10:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[09/09/2007|22:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[16/01/2008|14:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Bluetooth
[16/09/2007|17:10] C:\DOCUME~1\ALLUSE~1\APPLIC~1\CyberLink
[09/09/2007|21:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\desktop.ini
[01/03/2008|09:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Downloaded Installations
[09/09/2007|20:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
[13/10/2007|22:18] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Grisoft
[17/11/2007|13:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\HP
[28/03/2008|22:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\HPSSUPPLY
[28/03/2008|22:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\hpzinstall.log
[15/04/2008|19:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Malwarebytes
[07/03/2008|12:10] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!
[11/03/2008|17:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[12/09/2007|09:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Mozilla
[12/11/2007|09:23] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MumboJumbo
[05/04/2008|12:33] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Plopp1.2
[16/02/2008|17:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\QTSBandwidthCache
[09/09/2007|20:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Skype
[15/04/2008|10:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
[16/11/2007|23:01] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
[12/09/2007|11:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[10/10/2007|20:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Live Toolbar
[24/03/2008|22:38] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller

[09/09/2007|21:37] C:\DOCUME~1\DEFAUL~1\APPLIC~1\.
[09/09/2007|21:37] C:\DOCUME~1\DEFAUL~1\APPLIC~1\..
[09/09/2007|21:37] C:\DOCUME~1\DEFAUL~1\APPLIC~1\desktop.ini
[09/09/2007|19:46] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft

[09/09/2007|19:49] C:\DOCUME~1\LOCALS~1\APPLIC~1\.
[09/09/2007|19:49] C:\DOCUME~1\LOCALS~1\APPLIC~1\..
[29/09/2007|17:40] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft

[29/09/2007|17:36] C:\DOCUME~1\NETWOR~1\APPLIC~1\.
[29/09/2007|17:36] C:\DOCUME~1\NETWOR~1\APPLIC~1\..
[29/09/2007|17:36] C:\DOCUME~1\NETWOR~1\APPLIC~1\Identities
[29/09/2007|17:36] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft

----------------[ Tâches planifiées dans C:\WINDOWS\tasks ]---------------

[18/04/2008 11:37][--ah-----] C:\WINDOWS\tasks\SA.DAT
[02/10/2001 18:16][-r-h-----] C:\WINDOWS\tasks\desktop.ini

---------------[ Listing des dossiers dans C:\Program Files ]--------------

[18/04/2008|11:33] C:\Program Files\.
[18/04/2008|11:33] C:\Program Files\..
[14/02/2008|10:44] C:\Program Files\Adobe
[10/09/2007|21:00] C:\Program Files\Ahead
[09/09/2007|20:23] C:\Program Files\Alwil Software
[19/11/2007|18:39] C:\Program Files\Apple Software Update
[11/10/2007|23:12] C:\Program Files\aRPNCalc
[22/12/2007|17:55] C:\Program Files\Atari
[20/12/2007|19:08] C:\Program Files\B4Playing
[26/09/2007|21:01] C:\Program Files\BarreConfCMCIC
[16/04/2008|11:37] C:\Program Files\CA Yahoo! Anti-Spy
[13/10/2007|23:18] C:\Program Files\CCleaner
[08/03/2008|19:48] C:\Program Files\C-Media 3D Audio
[09/04/2008|10:12] C:\Program Files\Common Files
[09/09/2007|19:42] C:\Program Files\ComPlus Applications
[08/03/2008|19:34] C:\Program Files\Conduit
[18/04/2008|11:35] C:\Program Files\Controle Parental
[16/09/2007|17:09] C:\Program Files\CyberLink
[12/12/2007|13:56] C:\Program Files\Disney Interactive
[16/04/2008|11:37] C:\Program Files\DivX
[28/10/2007|13:43] C:\Program Files\DK
[17/04/2008|09:17] C:\Program Files\Fichiers communs
[08/03/2008|19:34] C:\Program Files\free-downloads.net
[21/12/2007|21:30] C:\Program Files\Google
[13/10/2007|22:18] C:\Program Files\Grisoft
[17/11/2007|13:41] C:\Program Files\Hewlett-Packard
[17/11/2007|17:35] C:\Program Files\HP
[16/11/2007|23:36] C:\Program Files\Incredijeux
[13/11/2007|15:58] C:\Program Files\IncrediMail
[18/04/2008|11:33] C:\Program Files\InstallShield Installation Information
[02/03/2008|23:07] C:\Program Files\Intel Desktop Board
[09/04/2008|18:00] C:\Program Files\Internet Explorer
[09/09/2007|19:54] C:\Program Files\Inventel
[16/01/2008|14:31] C:\Program Files\IVT Corporation
[17/04/2008|11:57] C:\Program Files\Java
[09/04/2008|13:25] C:\Program Files\Kiwee Toolbar2
[20/10/2007|16:54] C:\Program Files\Lavasoft
[01/03/2008|00:25] C:\Program Files\lecteur windows media 11
[10/04/2008|09:08] C:\Program Files\Messenger Plus! Live
[09/09/2007|19:47] C:\Program Files\microsoft frontpage
[19/11/2007|17:21] C:\Program Files\Microsoft Hardware
[04/12/2007|16:33] C:\Program Files\Microsoft Office
[29/09/2007|17:36] C:\Program Files\Microsoft SQL Server Compact Edition
[26/09/2007|11:46] C:\Program Files\Mindscape
[17/09/2007|20:27] C:\Program Files\Movie Maker
[17/04/2008|11:55] C:\Program Files\Mozilla Firefox
[09/09/2007|23:09] C:\Program Files\MSECache
[12/09/2007|21:54] C:\Program Files\MSI
[09/09/2007|19:42] C:\Program Files\MSN Gaming Zone
[24/10/2007|15:42] C:\Program Files\MSN Messenger
[17/11/2007|23:05] C:\Program Files\MSXML 4.0
[08/03/2008|19:55] C:\Program Files\Multimedia V3.54
[23/11/2007|13:16] C:\Program Files\Netlog 24
[09/09/2007|19:43] C:\Program Files\NetMeeting
[17/04/2008|09:20] C:\Program Files\Orange
[17/09/2007|20:27] C:\Program Files\Outlook Express
[28/01/2008|10:58] C:\Program Files\PhotoFiltre
[09/09/2007|22:36] C:\Program Files\QuickTime
[20/12/2007|18:47] C:\Program Files\ReflexiveArcade
[24/12/2007|16:43] C:\Program Files\SAMSUNG
[09/09/2007|19:44] C:\Program Files\Services en ligne
[25/10/2007|19:57] C:\Program Files\SiS7012
[08/03/2008|13:52] C:\Program Files\sisagp
[08/03/2008|19:46] C:\Program Files\SiSLan
[09/09/2007|20:20] C:\Program Files\Skype
[16/10/2007|10:11] C:\Program Files\Sunbelt Software
[16/04/2008|20:48] C:\Program Files\Trend Micro
[09/09/2007|19:50] C:\Program Files\Uninstall Information
[09/09/2007|19:57] C:\Program Files\Wanadoo
[26/10/2007|15:18] C:\Program Files\Windows Desktop Search
[11/04/2008|11:12] C:\Program Files\Windows Live
[08/04/2008|18:56] C:\Program Files\Windows Live Safety Center
[20/10/2007|16:44] C:\Program Files\Windows Live Toolbar
[11/03/2008|13:16] C:\Program Files\Windows Media Connect 2
[11/03/2008|13:40] C:\Program Files\Windows Media Player
[09/09/2007|19:41] C:\Program Files\Windows NT
[09/09/2007|19:44] C:\Program Files\WindowsUpdate
[09/09/2007|20:05] C:\Program Files\WinRAR
[09/09/2007|19:47] C:\Program Files\xerox
[17/04/2008|11:56] C:\Program Files\Yahoo!

------[ Listing des dossiers dans C:\Program Files\Fichiers communs ]------

[17/04/2008|09:17] C:\Program Files\Fichiers communs\.
[17/04/2008|09:17] C:\Program Files\Fichiers communs\..
[14/02/2008|10:45] C:\Program Files\Fichiers communs\Adobe
[10/09/2007|21:00] C:\Program Files\Fichiers communs\Ahead
[12/09/2007|15:23] C:\Program Files\Fichiers communs\Designer
[04/03/2008|20:00] C:\Program Files\Fichiers communs\DirectX
[09/09/2007|19:55] C:\Program Files\Fichiers communs\FDEUnInstaller.exe
[17/04/2008|09:17] C:\Program Files\Fichiers communs\France Telecom
[11/10/2007|23:18] C:\Program Files\Fichiers communs\GTK
[17/11/2007|13:36] C:\Program Files\Fichiers communs\Hewlett-Packard
[17/11/2007|17:35] C:\Program Files\Fichiers communs\HP
[30/09/2007|13:38] C:\Program Files\Fichiers communs\InstallShield
[20/09/2007|16:31] C:\Program Files\Fichiers communs\Java
[09/09/2007|20:49] C:\Program Files\Fichiers communs\Logitech
[17/01/2008|22:58] C:\Program Files\Fichiers communs\Microsoft Shared
[09/09/2007|19:43] C:\Program Files\Fichiers communs\MSSoap
[09/09/2007|21:37] C:\Program Files\Fichiers communs\ODBC
[05/04/2008|11:36] C:\Program Files\Fichiers communs\Scanner
[09/09/2007|19:43] C:\Program Files\Fichiers communs\Services
[09/09/2007|20:20] C:\Program Files\Fichiers communs\Skype
[09/09/2007|21:37] C:\Program Files\Fichiers communs\SpeechEngines
[16/09/2007|22:16] C:\Program Files\Fichiers communs\System
[03/01/2008|21:45] C:\Program Files\Fichiers communs\Vivendi Universal Games
[17/01/2008|22:56] C:\Program Files\Fichiers communs\WindowsLiveInstaller

----------------------[ Recherche avec S_Lop ]---------------------

Aucun fichier / dossier Lop trouvé !

-----------------[ Recherche de Fichiers / Dossiers Lop ]-----------------

Aucun fichier / dossier Lop trouvé !

----------------------[ Verification du Registre ]----------------------

..... OK !

--------------------[ Verification du fichier Hosts ]---------------------

Fichier Hosts PROPRE


----------------[ Recherche de fichiers avec Catchme ]-----------------

catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-18 22:18:38
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 0

--------------------[ Recherche d'autres infections ]---------------------

Aucune autre infection trouvée !

/!\ [Fich:110][Doss:34] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp
/!\ [Fich:135][Doss:0] C:\DOCUME~1\ADMINI~1\Cookies
/!\ [Fich:7652][Doss:9] C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMPOR~1\content.IE5

--------------------[ Fin du rapport a 22:20:15,21 ]----------------------
jai encore eu l'alerte d'avast

Répondre à mag14100

Reposte un rapport Hijackthis.

------------------------------ Prévention & Protection||Vous m'aimez ? Cliquez :o
Répondre à Angeldark

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:39:24, on 19/04/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
C:\Program Files\Controle Parental\bin\optproxy.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\WgaTray.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\sistray.EXE
C:\WINDOWS\system32\keyhook.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Orange\Systray\SystrayApp.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\PROGRA~1\CONTRO~1\bin\optgui.exe
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
C:\Program Files\Netlog 24\Notifier\Netlog24Notifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
C:\PROGRA~1\INCRED~1\bin\IMApp.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Orange\Launcher\Launcher.exe
C:\Program Files\Orange\connectivity\connectivitymanager.exe
C:\Program Files\Orange\connectivity\CoreCom\CoreCom.exe
C:\Program Files\Orange\connectivity\CoreCom\OraConfigRecover.exe
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTCOMModule\0\FTCOMModule.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Orange\Deskboard\deskboard.exe
C:\Program Files\Orange\browser\browser.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.orange.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Favoris
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\Orange\SearchURLHook\SearchPageURL.dll
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [CamMonitor] C:\Program Files\Hewlett-Packard\Digital Imaging\\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SiS Tray] C:\WINDOWS\system32\sistray.EXE
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\system32\keyhook.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SystrayORAHSS] "C:\Program Files\Orange\Systray\SystrayApp.exe"
O4 - HKLM\..\Run: [ORAHSSSessionManager] C:\Program Files\Orange\SessionManager\SessionManager.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [OPTENET_GUI] C:\PROGRA~1\CONTRO~1\bin\optgui.exe
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Netlog 24] "C:\Program Files\Netlog 24\Notifier\Netlog24Notifier.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\RunOnce: [XPPro4.0] %systemroot%\REG\run.cmd (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\RunOnce: [XPPro4.0] %systemroot%\REG\run.cmd (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [Picasa Media Detector] D:\montage\Picasa2\PicasaMediaDetector.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [XPPro4.0] %systemroot%\REG\run.cmd (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Picasa Media Detector] D:\montage\Picasa2\PicasaMediaDetector.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [XPPro4.0] %systemroot%\REG\run.cmd (User 'Default user')
O4 - Global Startup: BlueSoleil.lnk = C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O15 - Trusted Zone: http://www.msi.com.tw
O15 - Trusted Zone: http://www.orange.fr
O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/too [...] ontrol.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-F [...] E_UNO1.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/r [...] se4009.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://copainsdavant.linternaute.c [...] oader4.cab
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - http://www.touslesdrivers.com/fich [...] _0_4_9.cab
O16 - DPF: {BD8667B7-38D8-4C77-B580-18C3E146372C} (Creative Toolbox Plug-in) - http://kiw.imgag.com/imgag/cp/inst [...] -kiwen.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/bina [...] b56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/bina [...] b56986.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: Orange Contrôle Parental (OPTENET_FILTER) - Orange - C:\Program Files\Controle Parental\bin\optproxy.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe

--
End of file - 11790 bytes

Répondre à mag14100

Re,

Désinstalle correctement Avast! pour le remplacer par AntiVir.
Pourquoi changer ? Avast! vs AntiVir

Fais un scan complet puis poste le rapport en fin d'analyse.
AIDE : Tutorial sur l'antivirus AntiVir Personal Edition Classic

------------------------------ Prévention & Protection||Vous m'aimez ? Cliquez :o
Répondre à Angeldark



Avira AntiVir Personal
Report file date: dimanche 20 avril 2008 12:47

Scanning for 1218459 virus strains and unwanted programs.

Licensed to: Avira AntiVir PersonalEdition Classic
Serial number: 0000149996-ADJIE-0001
Platform: Windows XP
Windows version: (Service Pack 2) [5.1.2600]
Boot mode: Normally booted
Username: SYSTEM
Computer name: XPSP2-F87D6FB42

Version information:
BUILD.DAT : 8.1.00.295 16479 Bytes 09/04/2008 16:24:00
AVSCAN.EXE : 8.1.2.12 311553 Bytes 20/04/2008 10:45:49
AVSCAN.DLL : 8.1.1.0 53505 Bytes 20/04/2008 10:45:49
LUKE.DLL : 8.1.2.9 151809 Bytes 20/04/2008 10:45:49
LUKERES.DLL : 8.1.2.1 12033 Bytes 20/04/2008 10:45:49
ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 13:27:15
ANTIVIR1.VDF : 7.0.3.2 5447168 Bytes 07/03/2008 10:45:50
ANTIVIR2.VDF : 7.0.3.156 795136 Bytes 11/04/2008 10:45:50
ANTIVIR3.VDF : 7.0.3.188 342016 Bytes 18/04/2008 10:45:50
Engineversion : 8.1.0.32
AEVDF.DLL : 8.1.0.5 102772 Bytes 20/04/2008 10:45:50
AESCRIPT.DLL : 8.1.0.26 233850 Bytes 20/04/2008 10:45:50
AESCN.DLL : 8.1.0.14 119156 Bytes 20/04/2008 10:45:50
AERDL.DLL : 8.1.0.19 418164 Bytes 20/04/2008 10:45:50
AEPACK.DLL : 8.1.1.2 364917 Bytes 20/04/2008 10:45:50
AEOFFICE.DLL : 8.1.0.18 192890 Bytes 20/04/2008 10:45:50
AEHEUR.DLL : 8.1.0.18 1167735 Bytes 20/04/2008 10:45:50
AEHELP.DLL : 8.1.0.14 115063 Bytes 20/04/2008 10:45:50
AEGEN.DLL : 8.1.0.17 299380 Bytes 20/04/2008 10:45:50
AEEMU.DLL : 8.1.0.5 430450 Bytes 20/04/2008 10:45:50
AECORE.DLL : 8.1.0.27 168310 Bytes 20/04/2008 10:45:50
AVWINLL.DLL : 1.0.0.7 14593 Bytes 20/04/2008 10:45:49
AVPREF.DLL : 8.0.0.1 25857 Bytes 20/04/2008 10:45:49
AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 12:16:24
AVREG.DLL : 8.0.0.0 30977 Bytes 20/04/2008 10:45:49
AVARKT.DLL : 1.0.0.23 307457 Bytes 20/04/2008 10:45:49
AVEVTLOG.DLL : 8.0.0.11 114945 Bytes 20/04/2008 10:45:49
SQLITE3.DLL : 3.3.17.1 339968 Bytes 20/04/2008 10:45:49
SMTPLIB.DLL : 1.2.0.19 28929 Bytes 20/04/2008 10:45:49
NETNT.DLL : 8.0.0.1 7937 Bytes 20/04/2008 10:45:49
RCIMAGE.DLL : 8.0.0.35 2371841 Bytes 20/04/2008 10:45:46
RCTEXT.DLL : 8.0.32.0 86273 Bytes 20/04/2008 10:45:46

Configuration settings for the scan:
Jobname..........................: Complete system scan
Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
Logging..........................: low
Primary action...................: interactive
Secondary action.................: ignore
Scan master boot sector..........: on
Scan boot sector.................: on
Boot sectors.....................: C:, D:,
Scan memory......................: on
Process scan.....................: on
Scan registry....................: on
Search for rootkits..............: off
Scan all files...................: Intelligent file selection
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Macro heuristic..................: on
File heuristic...................: medium

Start of the scan: dimanche 20 avril 2008 12:47

The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'sched.exe' - '1' Module(s) have been scanned
Scan process 'avgnt.exe' - '1' Module(s) have been scanned
Scan process 'avguard.exe' - '1' Module(s) have been scanned
Scan process 'rundll32.exe' - '1' Module(s) have been scanned
Scan process 'WgaTray.exe' - '1' Module(s) have been scanned
Scan process 'wscntfy.exe' - '1' Module(s) have been scanned
Scan process 'alg.exe' - '1' Module(s) have been scanned
Scan process 'hpqste08.exe' - '1' Module(s) have been scanned
Scan process 'ImApp.exe' - '1' Module(s) have been scanned
Scan process 'AlertModule.exe' - '1' Module(s) have been scanned
Scan process 'hpqtra08.exe' - '1' Module(s) have been scanned
Scan process 'BlueSoleil.exe' - '1' Module(s) have been scanned
Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
Scan process 'hpgs2wnf.exe' - '1' Module(s) have been scanned
Scan process 'Netlog24Notifier.exe' - '1' Module(s) have been scanned
Scan process 'msnmsgr.exe' - '1' Module(s) have been scanned
Scan process 'OPTGui.exe' - '1' Module(s) have been scanned
Scan process 'jusched.exe' - '1' Module(s) have been scanned
Scan process 'SystrayApp.exe' - '1' Module(s) have been scanned
Scan process 'hpwuSchd2.exe' - '1' Module(s) have been scanned
Scan process 'Keyhook.exe' - '1' Module(s) have been scanned
Scan process 'sistray.exe' - '1' Module(s) have been scanned
Scan process 'avgas.exe' - '1' Module(s) have been scanned
Scan process 'PDVDServ.exe' - '1' Module(s) have been scanned
Scan process 'qttask.exe' - '1' Module(s) have been scanned
Scan process 'hpgs2wnd.exe' - '1' Module(s) have been scanned
Scan process 'HpqCmon.exe' - '1' Module(s) have been scanned
Scan process 'LVCOMSX.EXE' - '1' Module(s) have been scanned
Scan process 'rundll32.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'RichVideo.exe' - '1' Module(s) have been scanned
Scan process 'optproxy.exe' - '1' Module(s) have been scanned
Scan process 'FTRTSVC.exe' - '1' Module(s) have been scanned
Scan process 'guard.exe' - '1' Module(s) have been scanned
Scan process 'LVPrcSrv.exe' - '1' Module(s) have been scanned
Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
49 processes with 49 modules were scanned

Starting master boot sector scan:
Master boot sector HD0
[INFO] No virus was found!

Start scanning boot sectors:
Boot sector 'C:\'
[INFO] No virus was found!
Boot sector 'D:\'
[INFO] No virus was found!

Starting to scan the registry.
The registry was scanned ( '40' files ).


Starting the file scan:

Begin scan in 'C:\'
C:\pagefile.sys
[WARNING] The file could not be opened!
C:\Lop SD\Backup-Lop\F\Uninstall.exe
[DETECTION] Is the Trojan horse TR/Dldr.Swizzor.Gen
[NOTE] The file was moved to '487421a5.qua'!
C:\System Volume Information\_restore{9272FC26-9981-4FAA-AD90-B83A803EB8CB}\RP239\A0031095.exe
[DETECTION] Is the Trojan horse TR/Dldr.Swizzor.Gen
[NOTE] The file was moved to '483b2354.qua'!
C:\System Volume Information\_restore{9272FC26-9981-4FAA-AD90-B83A803EB8CB}\RP239\A0031115.exe
[DETECTION] Is the Trojan horse TR/Dldr.Swizzor.Gen
[NOTE] The file was moved to '483b2357.qua'!
C:\System Volume Information\_restore{9272FC26-9981-4FAA-AD90-B83A803EB8CB}\RP240\A0031140.exe
[DETECTION] Is the Trojan horse TR/Dldr.Swizzor.Gen
[NOTE] The file was moved to '483b235c.qua'!
C:\System Volume Information\_restore{9272FC26-9981-4FAA-AD90-B83A803EB8CB}\RP240\A0031175.exe
[DETECTION] Is the Trojan horse TR/Dldr.Swizzor.Gen
[NOTE] The file was moved to '483b235f.qua'!
C:\System Volume Information\_restore{9272FC26-9981-4FAA-AD90-B83A803EB8CB}\RP242\A0031492.exe
[DETECTION] Is the Trojan horse TR/Dldr.Swizzor.Gen
[NOTE] The file was moved to '483b236f.qua'!
C:\System Volume Information\_restore{9272FC26-9981-4FAA-AD90-B83A803EB8CB}\RP245\A0033067.exe
[DETECTION] Is the Trojan horse TR/Dldr.Swizzor.Gen
[NOTE] The file was moved to '483b238c.qua'!
C:\System Volume Information\_restore{9272FC26-9981-4FAA-AD90-B83A803EB8CB}\RP253\A0034111.exe
[DETECTION] Is the Trojan horse TR/Dldr.Swizzor.Gen
[NOTE] The file was moved to '483b23af.qua'!
C:\WINDOWS\system32\drivers\sptd.sys
[WARNING] The file could not be opened!
C:\_OTMoveIt\MovedFiles\04172008_214234\DOCUME~1\ADMINI~1\APPLIC~1\funk draw rect\Bird Download Safe Trans.exe
[DETECTION] Is the Trojan horse TR/Dldr.Swizzor.Gen
[NOTE] The file was moved to '487d258b.qua'!
C:\_OTMoveIt\MovedFiles\04172008_214234\DOCUME~1\ADMINI~1\APPLIC~1\funk draw rect\vqtjkvlv.exe
[DETECTION] Is the Trojan horse TR/Dldr.Swizzor.Gen
[NOTE] The file was moved to '487f2596.qua'!
Begin scan in 'D:\'


End of the scan: dimanche 20 avril 2008 13:16
Used time: 29:04 min

The scan has been done completely.

5620 Scanning directories
118822 Files were scanned
10 viruses and/or unwanted programs were found
0 Files were classified as suspicious:
0 files were deleted
0 files were repaired
10 files were moved to quarantine
0 files were renamed
2 Files cannot be scanned
118812 Files not concerned
1314 Archives were scanned
2 Warnings
10 Notes

Répondre à mag14100

Reposte un rapport Hijackthis.

------------------------------ Prévention & Protection||Vous m'aimez ? Cliquez :o
Répondre à Angeldark

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:06:40, on 20/04/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
C:\Program Files\Controle Parental\bin\optproxy.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\sistray.EXE
C:\WINDOWS\system32\keyhook.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Orange\Systray\SystrayApp.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\PROGRA~1\CONTRO~1\bin\optgui.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Netlog 24\Notifier\Netlog24Notifier.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
C:\PROGRA~1\INCRED~1\bin\IMApp.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\WgaTray.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
c:\program files\avira\antivir personaledition classic\avcenter.exe
c:\program files\avira\antivir personaledition classic\avcenter.exe
C:\Program Files\Orange\Launcher\Launcher.exe
C:\Program Files\Orange\connectivity\connectivitymanager.exe
C:\Program Files\Orange\Deskboard\deskboard.exe
C:\Program Files\Orange\connectivity\CoreCom\CoreCom.exe
C:\Program Files\Orange\connectivity\CoreCom\OraConfigRecover.exe
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTCOMModule\0\FTCOMModule.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Orange\browser\browser.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.orange.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Favoris
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\Orange\SearchURLHook\SearchPageURL.dll
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [CamMonitor] C:\Program Files\Hewlett-Packard\Digital Imaging\\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SiS Tray] C:\WINDOWS\system32\sistray.EXE
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\system32\keyhook.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SystrayORAHSS] "C:\Program Files\Orange\Systray\SystrayApp.exe"
O4 - HKLM\..\Run: [ORAHSSSessionManager] C:\Program Files\Orange\SessionManager\SessionManager.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [OPTENET_GUI] C:\PROGRA~1\CONTRO~1\bin\optgui.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Netlog 24] "C:\Program Files\Netlog 24\Notifier\Netlog24Notifier.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\RunOnce: [XPPro4.0] %systemroot%\REG\run.cmd (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\RunOnce: [XPPro4.0] %systemroot%\REG\run.cmd (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [Picasa Media Detector] D:\montage\Picasa2\PicasaMediaDetector.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [XPPro4.0] %systemroot%\REG\run.cmd (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Picasa Media Detector] D:\montage\Picasa2\PicasaMediaDetector.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [XPPro4.0] %systemroot%\REG\run.cmd (User 'Default user')
O4 - Global Startup: BlueSoleil.lnk = C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O15 - Trusted Zone: http://www.msi.com.tw
O15 - Trusted Zone: http://www.orange.fr
O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/too [...] ontrol.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-F [...] E_UNO1.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/r [...] se4009.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://copainsdavant.linternaute.c [...] oader4.cab
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - http://www.touslesdrivers.com/fich [...] _0_4_9.cab
O16 - DPF: {BD8667B7-38D8-4C77-B580-18C3E146372C} (Creative Toolbox Plug-in) - http://kiw.imgag.com/imgag/cp/inst [...] -kiwen.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/bina [...] b56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/bina [...] b56986.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: Orange Contrôle Parental (OPTENET_FILTER) - Orange - C:\Program Files\Controle Parental\bin\optproxy.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe

--
End of file - 11834 bytes

Répondre à mag14100

non j'ai plus de soucis
je te remercie pour tout
amicalement magali

Répondre à mag14100

Bon surf :)

  • Télécharge ToolsCleaner sur ton Bureau.
  • Clique sur Recherche et laisse le scan se terminer.
  • Clique sur Suppression pour finaliser.
  • Clique sur Quitter, pour que le rapport puisse se créer.
  • Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\)


Désactive puis réactive la restauration du système : Voir aide

Ajoute maintenant [Résolu] au titre. Pour cela :
* Clique, dans ton premier message, sur le bouton "Editer" http://img.infos-du-net.com/forum/themes_static/images_forum/3/edit.gif
* Rajoute la mention [Résolu] au titre
* Clique ensuite sur "Valider votre message"

Lis le dossier dossier sur la prévention et la protection pour ne plus avoir ce genre de problème en cliquant sur l'image ci-dessous :


http://www.malekal.com/fichiers/projetantimalwares/reagir_miniban.gif

------------------------------ Prévention & Protection||Vous m'aimez ? Cliquez :o
Répondre à Angeldark

-->- Recherche:

C:\Lop SD: trouvé !
C:\_OtMoveIt: trouvé !
C:\Documents and Settings\Administrateur\Bureau\HijackThis.lnk: trouvé !
C:\Documents and Settings\Administrateur\Bureau\Lop S&D.lnk: trouvé !
C:\Documents and Settings\Administrateur\Bureau\LopSD.exe: trouvé !
C:\Documents and Settings\Administrateur\Bureau\OtMoveIt2.exe: trouvé !
C:\Documents and Settings\Administrateur\Bureau\HJTInstall.exe: trouvé !
C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\Lop S&D: trouvé !
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis: trouvé !
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis\HijackThis.lnk: trouvé !
C:\Lop SD\Lop S&D.lnk: trouvé !
C:\Program Files\Trend Micro\HijackThis: trouvé !
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: trouvé !

---------------------------------
-->- Suppression:

C:\Documents and Settings\Administrateur\Bureau\HijackThis.lnk: supprimé !
C:\Documents and Settings\Administrateur\Bureau\Lop S&D.lnk: supprimé !
C:\Documents and Settings\Administrateur\Bureau\LopSD.exe: supprimé !
C:\Documents and Settings\Administrateur\Bureau\OtMoveIt2.exe: supprimé !
C:\Documents and Settings\Administrateur\Bureau\HJTInstall.exe: supprimé !
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis\HijackThis.lnk: supprimé !
C:\Lop SD\Lop S&D.lnk: supprimé !
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: supprimé !
C:\Lop SD: supprimé !
C:\_OtMoveIt: supprimé !
C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\Lop S&D: supprimé !
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis: supprimé !
C:\Program Files\Trend Micro\HijackThis: supprimé !

Répondre à mag14100
Tom's Guide > Forum > Sécurité - Virus > fenetres intempestives[résolu]
Aller à :

Il y a 497 utilisateurs connus et inconnus. Pour voir la liste des connectés connus, cliquez ici.

Attention

Vous allez répondre sur un sujet resté inactif pendant plus de 6 mois.
Assurez-vous d'apporter des éléments nouveaux à la discussion avant de poursuivre.

Répondre Annuler
Liens