Se connecter avec
S'enregistrer | Connectez-vous

Pc infecté, rallentissements

Dernière réponse : dans Sécurité

Bonjour tout le monde, je suis chargé de récupérer un peu de vie au pc d'une copine, mais à distance :p  Elle un ordinateur qui est beaucoup ralentit et qui rame énormément.... Je suppose donc qu'elle a des virus, spyware ou autre choses malsaines ^^
Voici un rapport HJT de son pc :
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:41:14, on 29/08/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device

Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\System32\FTRTSVC.exe
C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Controle Parental\bin\optproxy.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\UltraVNC\WinVNC.exe
C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\VTtrayp.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Fichiers

communs\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\Msmsgs.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\iTunes\iTunes.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device

Support\bin\AppleMobileDeviceHelper.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\distnoted.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?linkid=677
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\UltraVNC\WinVNC.exe" -servicehelper
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [Part browse safe hold] C:\Documents and Settings\All Users\Application Data\Audio 4 part browse\active great.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\Msmsgs.exe" /background
O4 - HKCU\..\Run: [Sixth Trust] C:\DOCUME~1\Dom\APPLIC~1\2CAKEM~1\sendmathup.exe
O4 - HKCU\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/FacebookPhotoUpload...
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.ca...
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls...
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPACl...
O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: Control Parental (OPTENET_FILTER) - Contrôle Parental - C:\Program Files\Controle Parental\bin\optproxy.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: VNC Server (winvnc) - www.ultravnc.fr - C:\Program Files\UltraVNC\WinVNC.exe
--
End of file - 10669 bytes

Autres pages sur : infecte rallentissements

Lassé par la pub ? Créez un compte

Bonjour,

Télécharge Lop S&D.exe ([#ff0000]Eric_71[/#f]) sur ton Bureau.
  • Lance l'installation du programme en exécutant le fichier téléchargé.
  • Double-clique maintenant sur le raccourci de LopS&D.
  • Sélectionne la langue souhaitée en tapant la lettre de ton choix puis en validant avec la touche Entrée.
  • Choisis maintenant l'option 1 (Recherche). Patiente jusqu'à la fin de la recherche.
  • Poste le rapport généré (C:\lopR.txt*)

    (Si le Bureau ne réapparait pas presse Ctrl + Alt + Suppr , Onglet Fichier , Nouvelle tâche , tape explorer.exe et valide)
    * le nom de la partition peut changer


    --------------------\\ Lop S&D 4.2.3-8 XP/Vista

    Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 2
    X86-based PC ( Uniprocessor Free : Intel(R) Celeron(R) CPU 2.66GHz )
    BIOS : Phoenix - AwardBIOS v6.00PG
    USER : Dom ( Administrator )
    BOOT : Normal boot
    Antivirus : Avira AntiVir PersonalEdition 8.0.1.27 (Activated)

    "C:\Lop SD" ( MAJ : 31-08-2008|15:45 )
    Option : [1] ( 31/08/2008|22:43 )

    --------------------\\ Listing des dossiers dans APPLIC~1

    [25/12/2007|19:18] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
    [11/09/2007|21:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
    [11/09/2007|21:40] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
    [19/06/2008|20:07] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Audio 4 part browse
    [04/07/2008|19:24] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Avira
    [18/03/2007|12:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\desktop.ini
    [18/03/2007|15:53] C:\DOCUME~1\ALLUSE~1\APPLIC~1\HP
    [18/04/2008|19:43] C:\DOCUME~1\ALLUSE~1\APPLIC~1\hpzinstall.log
    [30/01/2008|21:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Logishrd
    [23/06/2007|17:22] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Logitech
    [19/06/2008|20:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!
    [25/06/2007|12:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
    [01/12/2007|20:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\QTSBandwidthCache
    [21/05/2008|11:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
    [18/03/2007|13:22] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec
    [18/03/2007|13:05] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
    [04/06/2007|22:05] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Live Toolbar
    [19/06/2008|19:55] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller

    [18/03/2007|12:49] C:\DOCUME~1\DEFAUL~1\APPLIC~1\desktop.ini
    [18/03/2007|12:15] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft

    [04/07/2008|20:03] C:\DOCUME~1\Dom\APPLIC~1\2 Cake Meet
    [07/06/2008|21:53] C:\DOCUME~1\Dom\APPLIC~1\Adobe
    [16/03/2008|14:58] C:\DOCUME~1\Dom\APPLIC~1\AdobeUM
    [12/07/2008|21:56] C:\DOCUME~1\Dom\APPLIC~1\Apple Computer
    [18/03/2007|12:49] C:\DOCUME~1\Dom\APPLIC~1\desktop.ini
    [05/06/2008|21:25] C:\DOCUME~1\Dom\APPLIC~1\dvdcss
    [02/08/2007|20:34] C:\DOCUME~1\Dom\APPLIC~1\Help
    [18/11/2007|15:49] C:\DOCUME~1\Dom\APPLIC~1\HP
    [18/03/2007|12:30] C:\DOCUME~1\Dom\APPLIC~1\Identities
    [18/03/2007|17:47] C:\DOCUME~1\Dom\APPLIC~1\Macromedia
    [11/03/2008|18:43] C:\DOCUME~1\Dom\APPLIC~1\Microsoft
    [18/03/2007|14:40] C:\DOCUME~1\Dom\APPLIC~1\Microsoft Web Folders
    [30/08/2008|11:02] C:\DOCUME~1\Dom\APPLIC~1\Mozilla
    [18/03/2007|17:54] C:\DOCUME~1\Dom\APPLIC~1\MSNInstaller
    [31/12/2007|23:17] C:\DOCUME~1\Dom\APPLIC~1\Screenshot Sender
    [10/06/2008|19:52] C:\DOCUME~1\Dom\APPLIC~1\Sun
    [19/03/2008|19:34] C:\DOCUME~1\Dom\APPLIC~1\Update_HP_RedboxHprblog_HPSU.log
    [11/06/2007|14:45] C:\DOCUME~1\Dom\APPLIC~1\vlc

    [03/07/2007|18:29] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft
    [20/06/2008|12:10] C:\DOCUME~1\LOCALS~1\APPLIC~1\Mozilla

    [18/03/2007|12:19] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft

    --------------------\\ Tâches planifiées dans C:\WINDOWS\tasks

    [09/08/2008 21:14][--a------] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
    [29/08/2008 19:56][--a------] C:\WINDOWS\tasks\Norton Security Scan.job
    [31/08/2008 21:44][--a------] C:\WINDOWS\tasks\V‚rifier les mises … jour de Windows Live Toolbar.job
    [31/08/2008 22:02][--ah-----] C:\WINDOWS\tasks\SA.DAT
    [05/08/2004 14:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini

    --------------------\\ Listing des dossiers dans C:\Program Files

    [19/06/2008|20:06] C:\Program Files\2 Cake Meet
    [16/03/2008|15:00] C:\Program Files\Adobe
    [18/03/2007|13:35] C:\Program Files\Ahead
    [09/08/2008|21:14] C:\Program Files\Apple Software Update
    [04/07/2008|19:24] C:\Program Files\Avira
    [12/07/2008|21:13] C:\Program Files\Bonjour
    [08/12/2007|18:42] C:\Program Files\CCleaner
    [04/07/2008|20:42] C:\Program Files\Circle Developement
    [28/06/2008|12:21] C:\Program Files\CleanUp!
    [18/03/2007|12:11] C:\Program Files\ComPlus Applications
    [18/03/2007|15:29] C:\Program Files\Controle Parental
    [18/03/2007|14:16] C:\Program Files\EA GAMES
    [19/06/2008|19:19] C:\Program Files\Fichiers communs
    [09/11/2007|23:31] C:\Program Files\Google
    [25/08/2008|08:54] C:\Program Files\HP
    [20/05/2008|18:17] C:\Program Files\InstallShield Installation Information
    [25/08/2008|11:05] C:\Program Files\Internet Explorer
    [02/08/2008|23:22] C:\Program Files\iPod
    [02/08/2008|23:23] C:\Program Files\iTunes
    [26/07/2008|16:58] C:\Program Files\Java
    [30/01/2008|21:09] C:\Program Files\Logitech
    [25/08/2008|11:08] C:\Program Files\Messenger
    [19/06/2008|20:06] C:\Program Files\Messenger Plus! Live
    [05/06/2007|19:00] C:\Program Files\Microsoft CAPICOM 2.1.0.2
    [18/03/2007|16:09] C:\Program Files\Microsoft Encarta
    [18/03/2007|12:15] C:\Program Files\microsoft frontpage
    [18/03/2007|14:40] C:\Program Files\Microsoft Office
    [18/03/2007|14:43] C:\Program Files\Microsoft Visual Studio
    [18/03/2007|12:11] C:\Program Files\Movie Maker
    [31/08/2008|22:29] C:\Program Files\Mozilla Firefox
    [19/06/2008|19:16] C:\Program Files\MSN
    [18/03/2007|12:10] C:\Program Files\MSN Gaming Zone
    [19/06/2008|20:06] C:\Program Files\MSN Messenger
    [19/03/2007|19:23] C:\Program Files\MSXML 4.0
    [18/03/2007|12:12] C:\Program Files\NetMeeting
    [29/08/2008|18:00] C:\Program Files\Norton Security Scan
    [18/03/2007|12:10] C:\Program Files\Online Services
    [13/06/2007|13:40] C:\Program Files\Outlook Express
    [05/10/2007|17:51] C:\Program Files\PhotoFiltre
    [25/08/2008|10:28] C:\Program Files\Picasa2
    [12/07/2008|21:12] C:\Program Files\QuickTime
    [18/03/2007|14:09] C:\Program Files\Realtek AC97
    [08/12/2007|17:14] C:\Program Files\RegCleaner
    [18/03/2007|14:02] C:\Program Files\S3
    [02/08/2008|23:03] C:\Program Files\Safari
    [25/12/2007|19:14] C:\Program Files\Samsung
    [08/03/2008|13:32] C:\Program Files\Services en ligne
    [21/05/2008|11:31] C:\Program Files\Spybot - Search & Destroy
    [04/06/2008|14:26] C:\Program Files\Sun
    [18/03/2007|13:22] C:\Program Files\Symantec
    [31/08/2008|22:04] C:\Program Files\Symantec AntiVirus
    [18/03/2007|13:31] C:\Program Files\ToniArts
    [29/08/2008|23:31] C:\Program Files\Trend Micro
    [20/05/2008|15:05] C:\Program Files\UltraVNC
    [18/03/2007|12:30] C:\Program Files\Uninstall Information
    [18/03/2007|14:04] C:\Program Files\VIA
    [18/03/2007|13:33] C:\Program Files\VideoLAN
    [20/05/2008|18:17] C:\Program Files\Wanadoo
    [19/06/2008|20:03] C:\Program Files\Windows Live
    [19/06/2008|20:01] C:\Program Files\Windows Live Favorites
    [19/06/2008|20:01] C:\Program Files\Windows Live Toolbar
    [18/03/2007|14:35] C:\Program Files\Windows Media Connect 2
    [18/03/2007|14:35] C:\Program Files\Windows Media Player
    [18/03/2007|12:10] C:\Program Files\Windows NT
    [18/03/2007|12:13] C:\Program Files\WindowsUpdate
    [18/03/2007|12:15] C:\Program Files\xerox

    --------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs

    [20/03/2007|20:01] C:\Program Files\Fichiers communs\Adobe
    [18/03/2007|13:35] C:\Program Files\Fichiers communs\Ahead
    [11/09/2007|21:37] C:\Program Files\Fichiers communs\Apple
    [18/03/2007|14:43] C:\Program Files\Fichiers communs\Designer
    [20/05/2008|18:17] C:\Program Files\Fichiers communs\InstallShield
    [04/06/2008|14:22] C:\Program Files\Fichiers communs\Java
    [30/01/2008|21:13] C:\Program Files\Fichiers communs\logishrd
    [19/06/2008|19:37] C:\Program Files\Fichiers communs\Microsoft Shared
    [18/03/2007|12:12] C:\Program Files\Fichiers communs\MSSoap
    [18/03/2007|12:49] C:\Program Files\Fichiers communs\ODBC
    [18/03/2007|12:12] C:\Program Files\Fichiers communs\Services
    [18/03/2007|12:49] C:\Program Files\Fichiers communs\SpeechEngines
    [29/06/2008|14:49] C:\Program Files\Fichiers communs\Symantec Shared
    [13/06/2007|13:40] C:\Program Files\Fichiers communs\System
    [19/06/2008|19:19] C:\Program Files\Fichiers communs\WindowsLiveInstaller

    --------------------\\ Process

    ( 55 Processus )

    IEXPLORE.EXE ~ [PID:3700]

    --------------------\\ Recherche avec S_Lop

    Aucun fichier / dossier Lop trouvé !

    --------------------\\ Recherche de Fichiers / Dossiers Lop

    C:\DOCUME~1\ALLUSE~1\APPLIC~1\Audio 4 part browse
    C:\DOCUME~1\ALLUSE~1\APPLIC~1\Audio 4 part browse\active great.exe
    C:\Program Files\Circle Developement

    --------------------\\ Verification du Registre

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Part browse safe hold"="C:\\Documents and Settings\\All Users\\Application Data\\Audio 4 part browse\\active great.exe"

    --------------------\\ Verification du fichier Hosts

    Fichier Hosts MODIFIE

    127.0.0.1 bin.errorprotector.com ## added by CiD
    127.0.0.1 br.errorsafe.com ## added by CiD
    127.0.0.1 br.winantivirus.com ## added by CiD
    127.0.0.1 br.winfixer.com ## added by CiD
    127.0.0.1 cdn.drivecleaner.com ## added by CiD
    127.0.0.1 cdn.errorsafe.com ## added by CiD
    127.0.0.1 cdn.winsoftware.com ## added by CiD
    127.0.0.1 de.errorsafe.com ## added by CiD
    127.0.0.1 de.winantivirus.com ## added by CiD
    127.0.0.1 download.cdn.drivecleaner.com ## added by CiD
    127.0.0.1 download.cdn.errorsafe.com ## added by CiD
    127.0.0.1 download.cdn.winsoftware.com ## added by CiD
    127.0.0.1 download.errorsafe.com ## added by CiD
    127.0.0.1 download.systemdoctor.com ## added by CiD
    127.0.0.1 download.winantispyware.com ## added by CiD
    127.0.0.1 download.windrivecleaner.com ## added by CiD
    127.0.0.1 download.winfixer.com ## added by CiD
    127.0.0.1 drivecleaner.com ## added by CiD
    127.0.0.1 dynamique.drivecleaner.com ## added by CiD
    127.0.0.1 errorprotector.com ## added by CiD
    127.0.0.1 errorsafe.com ## added by CiD
    127.0.0.1 es.winantivirus.com ## added by CiD
    127.0.0.1 fr.winantivirus.com ## added by CiD
    127.0.0.1 fr.winfixer.com ## added by CiD
    127.0.0.1 go.drivecleaner.com ## added by CiD
    127.0.0.1 go.errorsafe.com ## added by CiD
    127.0.0.1 go.winantispyware.com ## added by CiD
    127.0.0.1 go.winantivirus.com ## added by CiD
    127.0.0.1 hk.winantivirus.com ## added by CiD
    127.0.0.1 instlog.errorsafe.com ## added by CiD
    127.0.0.1 instlog.winantivirus.com ## added by CiD
    127.0.0.1 instlog.winfixer.com ## added by CiD
    127.0.0.1 jsp.drivecleaner.com ## added by CiD
    127.0.0.1 kb.errorsafe.com ## added by CiD
    127.0.0.1 kb.winantivirus.com ## added by CiD
    127.0.0.1 nl.errorsafe.com ## added by CiD
    127.0.0.1 se.errorsafe.com ## added by CiD
    127.0.0.1 secure.drivecleaner.com ## added by CiD
    127.0.0.1 secure.errorsafe.com ## added by CiD
    127.0.0.1 secure.winantispam.com ## added by CiD
    127.0.0.1 secure.winantispy.com ## added by CiD
    127.0.0.1 secure.winantivirus.com ## added by CiD
    127.0.0.1 support.winantivirus.com ## added by CiD
    127.0.0.1 trial.updates.winsoftware.com ## added by CiD
    127.0.0.1 ulog.winantivirus.com ## added by CiD
    127.0.0.1 utils.errorsafe.com ## added by CiD
    127.0.0.1 utils.winantivirus.com ## added by CiD
    127.0.0.1 utils.winfixer.com ## added by CiD
    127.0.0.1 winantispyware.com ## added by CiD
    127.0.0.1 winantivirus.com ## added by CiD
    127.0.0.1 winfixer.com ## added by CiD
    127.0.0.1 winfixer2006.com ## added by CiD
    127.0.0.1 winsoftware.com ## added by CiD
    127.0.0.1 www.drivecleaner.com ## added by CiD
    127.0.0.1 www.errorprotector.com ## added by CiD
    127.0.0.1 www.errorsafe.com ## added by CiD
    127.0.0.1 www.systemdoctor.com ## added by CiD
    127.0.0.1 www.utils.winfixer.com ## added by CiD
    127.0.0.1 www.win-anti-virus-pro.com ## added by CiD
    127.0.0.1 www.win-virus-pro.com ## added by CiD
    127.0.0.1 www.winantispam.com ## added by CiD
    127.0.0.1 www.winantispy.com ## added by CiD
    127.0.0.1 www.winantispyware.com ## added by CiD
    127.0.0.1 www.winantivirus.com ## added by CiD
    127.0.0.1 www.winantiviruspro.com ## added by CiD
    127.0.0.1 www.windrivecleaner.com ## added by CiD
    127.0.0.1 www.windrivesafe.com ## added by CiD
    127.0.0.1 www.winfixer.com ## added by CiD
    127.0.0.1 www.winfixer2006.com ## added by CiD
    127.0.0.1 www.winsoftware.com ## added by CiD

    -> 8332 [ 70 ## added by CiD ]

    --------------------\\ Recherche de fichiers avec Catchme

    catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-08-31 22:48:16
    Windows 5.1.2600 Service Pack 2 NTFS
    scanning hidden processes ...
    scanning hidden files ...
    scan completed successfully
    hidden processes: 0
    hidden files: 4415

    --------------------\\ Recherche d'autres infections


    Aucune autre infection trouvée !

    [F:41][D:3]-> C:\DOCUME~1\Dom\LOCALS~1\Temp
    [F:10][D:0]-> C:\DOCUME~1\Dom\Cookies
    [F:175][D:16]-> C:\DOCUME~1\Dom\LOCALS~1\TEMPOR~1\content.IE5

    1 - "C:\Lop SD\LopR_1.txt" - 31/08/2008|22:54 - Option : [1]

    --------------------\\ Fin du rapport a 22:54:24
    Voila voila :) 

    Re,

    Relance Lop S&D en double-cliquant sur le raccourci. Tape sur "2" puis valide en appuyant sur "Entrée".
    [#ff0000]! Ne ferme pas la fenêtre lors de la suppression ! [/#f]
    Un rapport sera généré, poste son contenu ici.

    NOTE : Si ton Bureau ne réapparait pas, appuie simultanément sur Ctrl+Alt+Suppr pour ouvrir le Gestionnaire des tâches.
    Rends-toi sur l'onglet "Processus". Clique en haut à gauche sur Fichier et choisis "Exécuter..."
    Tape explorer puis valide.

    Voila le rapport ;) 

    --------------------\\ Lop S&D 4.2.3-8 XP/Vista

    Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 2
    X86-based PC ( Uniprocessor Free : Intel(R) Celeron(R) CPU 2.66GHz )
    BIOS : Phoenix - AwardBIOS v6.00PG
    USER : Dom ( Administrator )
    BOOT : Normal boot
    Antivirus : Avira AntiVir PersonalEdition 8.0.1.27 (Activated)

    "C:\Lop SD" ( MAJ : 31-08-2008|15:45 )
    Option : [2] ( 01/09/2008|20:26 )


    \\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ SUPPRESSION

    Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\Audio 4 part browse\active great.exe
    Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\Audio 4 part browse
    Supprime! - C:\Program Files\Circle Developement
    -
    [ Fichier Hosts ] .. Restaure!

    \\\\\\\\\\\\\\\\\\\\\\\\\\\\\\


    --------------------\\ Listing des dossiers dans APPLIC~1

    [25/12/2007|19:18] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
    [11/09/2007|21:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
    [11/09/2007|21:40] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
    [04/07/2008|19:24] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Avira
    [18/03/2007|12:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\desktop.ini
    [18/03/2007|15:53] C:\DOCUME~1\ALLUSE~1\APPLIC~1\HP
    [18/04/2008|19:43] C:\DOCUME~1\ALLUSE~1\APPLIC~1\hpzinstall.log
    [30/01/2008|21:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Logishrd
    [23/06/2007|17:22] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Logitech
    [19/06/2008|20:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!
    [25/06/2007|12:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
    [01/12/2007|20:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\QTSBandwidthCache
    [21/05/2008|11:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
    [18/03/2007|13:22] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec
    [18/03/2007|13:05] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
    [04/06/2007|22:05] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Live Toolbar
    [19/06/2008|19:55] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller

    [18/03/2007|12:49] C:\DOCUME~1\DEFAUL~1\APPLIC~1\desktop.ini
    [18/03/2007|12:15] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft

    [04/07/2008|20:03] C:\DOCUME~1\Dom\APPLIC~1\2 Cake Meet
    [07/06/2008|21:53] C:\DOCUME~1\Dom\APPLIC~1\Adobe
    [16/03/2008|14:58] C:\DOCUME~1\Dom\APPLIC~1\AdobeUM
    [12/07/2008|21:56] C:\DOCUME~1\Dom\APPLIC~1\Apple Computer
    [18/03/2007|12:49] C:\DOCUME~1\Dom\APPLIC~1\desktop.ini
    [05/06/2008|21:25] C:\DOCUME~1\Dom\APPLIC~1\dvdcss
    [02/08/2007|20:34] C:\DOCUME~1\Dom\APPLIC~1\Help
    [18/11/2007|15:49] C:\DOCUME~1\Dom\APPLIC~1\HP
    [18/03/2007|12:30] C:\DOCUME~1\Dom\APPLIC~1\Identities
    [18/03/2007|17:47] C:\DOCUME~1\Dom\APPLIC~1\Macromedia
    [11/03/2008|18:43] C:\DOCUME~1\Dom\APPLIC~1\Microsoft
    [18/03/2007|14:40] C:\DOCUME~1\Dom\APPLIC~1\Microsoft Web Folders
    [30/08/2008|11:02] C:\DOCUME~1\Dom\APPLIC~1\Mozilla
    [18/03/2007|17:54] C:\DOCUME~1\Dom\APPLIC~1\MSNInstaller
    [31/12/2007|23:17] C:\DOCUME~1\Dom\APPLIC~1\Screenshot Sender
    [10/06/2008|19:52] C:\DOCUME~1\Dom\APPLIC~1\Sun
    [19/03/2008|19:34] C:\DOCUME~1\Dom\APPLIC~1\Update_HP_RedboxHprblog_HPSU.log
    [11/06/2007|14:45] C:\DOCUME~1\Dom\APPLIC~1\vlc

    [03/07/2007|18:29] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft
    [20/06/2008|12:10] C:\DOCUME~1\LOCALS~1\APPLIC~1\Mozilla

    [18/03/2007|12:19] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft

    --------------------\\ Tâches planifiées dans C:\WINDOWS\tasks

    [01/09/2008 12:06][--a------] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
    [29/08/2008 19:56][--a------] C:\WINDOWS\tasks\Norton Security Scan.job
    [01/09/2008 19:44][--a------] C:\WINDOWS\tasks\V‚rifier les mises … jour de Windows Live Toolbar.job
    [01/09/2008 11:18][--ah-----] C:\WINDOWS\tasks\SA.DAT
    [05/08/2004 14:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini

    --------------------\\ Listing des dossiers dans C:\Program Files

    [19/06/2008|20:06] C:\Program Files\2 Cake Meet
    [16/03/2008|15:00] C:\Program Files\Adobe
    [18/03/2007|13:35] C:\Program Files\Ahead
    [09/08/2008|21:14] C:\Program Files\Apple Software Update
    [04/07/2008|19:24] C:\Program Files\Avira
    [12/07/2008|21:13] C:\Program Files\Bonjour
    [08/12/2007|18:42] C:\Program Files\CCleaner
    [28/06/2008|12:21] C:\Program Files\CleanUp!
    [18/03/2007|12:11] C:\Program Files\ComPlus Applications
    [18/03/2007|15:29] C:\Program Files\Controle Parental
    [18/03/2007|14:16] C:\Program Files\EA GAMES
    [19/06/2008|19:19] C:\Program Files\Fichiers communs
    [09/11/2007|23:31] C:\Program Files\Google
    [25/08/2008|08:54] C:\Program Files\HP
    [20/05/2008|18:17] C:\Program Files\InstallShield Installation Information
    [25/08/2008|11:05] C:\Program Files\Internet Explorer
    [02/08/2008|23:22] C:\Program Files\iPod
    [02/08/2008|23:23] C:\Program Files\iTunes
    [26/07/2008|16:58] C:\Program Files\Java
    [30/01/2008|21:09] C:\Program Files\Logitech
    [25/08/2008|11:08] C:\Program Files\Messenger
    [19/06/2008|20:06] C:\Program Files\Messenger Plus! Live
    [05/06/2007|19:00] C:\Program Files\Microsoft CAPICOM 2.1.0.2
    [18/03/2007|16:09] C:\Program Files\Microsoft Encarta
    [18/03/2007|12:15] C:\Program Files\microsoft frontpage
    [18/03/2007|14:40] C:\Program Files\Microsoft Office
    [18/03/2007|14:43] C:\Program Files\Microsoft Visual Studio
    [18/03/2007|12:11] C:\Program Files\Movie Maker
    [01/09/2008|17:17] C:\Program Files\Mozilla Firefox
    [19/06/2008|19:16] C:\Program Files\MSN
    [18/03/2007|12:10] C:\Program Files\MSN Gaming Zone
    [19/06/2008|20:06] C:\Program Files\MSN Messenger
    [19/03/2007|19:23] C:\Program Files\MSXML 4.0
    [18/03/2007|12:12] C:\Program Files\NetMeeting
    [29/08/2008|18:00] C:\Program Files\Norton Security Scan
    [18/03/2007|12:10] C:\Program Files\Online Services
    [13/06/2007|13:40] C:\Program Files\Outlook Express
    [05/10/2007|17:51] C:\Program Files\PhotoFiltre
    [25/08/2008|10:28] C:\Program Files\Picasa2
    [12/07/2008|21:12] C:\Program Files\QuickTime
    [18/03/2007|14:09] C:\Program Files\Realtek AC97
    [08/12/2007|17:14] C:\Program Files\RegCleaner
    [18/03/2007|14:02] C:\Program Files\S3
    [02/08/2008|23:03] C:\Program Files\Safari
    [25/12/2007|19:14] C:\Program Files\Samsung
    [08/03/2008|13:32] C:\Program Files\Services en ligne
    [21/05/2008|11:31] C:\Program Files\Spybot - Search & Destroy
    [04/06/2008|14:26] C:\Program Files\Sun
    [18/03/2007|13:22] C:\Program Files\Symantec
    [01/09/2008|11:19] C:\Program Files\Symantec AntiVirus
    [18/03/2007|13:31] C:\Program Files\ToniArts
    [29/08/2008|23:31] C:\Program Files\Trend Micro
    [20/05/2008|15:05] C:\Program Files\UltraVNC
    [18/03/2007|12:30] C:\Program Files\Uninstall Information
    [18/03/2007|14:04] C:\Program Files\VIA
    [18/03/2007|13:33] C:\Program Files\VideoLAN
    [20/05/2008|18:17] C:\Program Files\Wanadoo
    [19/06/2008|20:03] C:\Program Files\Windows Live
    [19/06/2008|20:01] C:\Program Files\Windows Live Favorites
    [19/06/2008|20:01] C:\Program Files\Windows Live Toolbar
    [18/03/2007|14:35] C:\Program Files\Windows Media Connect 2
    [18/03/2007|14:35] C:\Program Files\Windows Media Player
    [18/03/2007|12:10] C:\Program Files\Windows NT
    [18/03/2007|12:13] C:\Program Files\WindowsUpdate
    [18/03/2007|12:15] C:\Program Files\xerox

    --------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs

    [20/03/2007|20:01] C:\Program Files\Fichiers communs\Adobe
    [18/03/2007|13:35] C:\Program Files\Fichiers communs\Ahead
    [11/09/2007|21:37] C:\Program Files\Fichiers communs\Apple
    [18/03/2007|14:43] C:\Program Files\Fichiers communs\Designer
    [20/05/2008|18:17] C:\Program Files\Fichiers communs\InstallShield
    [04/06/2008|14:22] C:\Program Files\Fichiers communs\Java
    [30/01/2008|21:13] C:\Program Files\Fichiers communs\logishrd
    [19/06/2008|19:37] C:\Program Files\Fichiers communs\Microsoft Shared
    [18/03/2007|12:12] C:\Program Files\Fichiers communs\MSSoap
    [18/03/2007|12:49] C:\Program Files\Fichiers communs\ODBC
    [18/03/2007|12:12] C:\Program Files\Fichiers communs\Services
    [18/03/2007|12:49] C:\Program Files\Fichiers communs\SpeechEngines
    [29/06/2008|14:49] C:\Program Files\Fichiers communs\Symantec Shared
    [13/06/2007|13:40] C:\Program Files\Fichiers communs\System
    [19/06/2008|19:19] C:\Program Files\Fichiers communs\WindowsLiveInstaller

    --------------------\\ Process

    ( 51 Processus )

    ... OK !

    --------------------\\ Recherche avec S_Lop

    Aucun fichier / dossier Lop trouvé !

    --------------------\\ Recherche de Fichiers / Dossiers Lop

    C:\DOCUME~1\Dom\Cookies\dom@32vegas[1].txt
    C:\DOCUME~1\Dom\Cookies\dom@banner.32vegas[2].txt

    --------------------\\ Verification du Registre

    ..... OK !

    --------------------\\ Verification du fichier Hosts

    Fichier Hosts PROPRE


    --------------------\\ Recherche de fichiers avec Catchme

    catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-09-01 20:29:24
    Windows 5.1.2600 Service Pack 2 NTFS
    scanning hidden processes ...
    scanning hidden files ...
    scan completed successfully
    hidden processes: 0
    hidden files: 4419

    --------------------\\ Recherche d'autres infections


    Aucune autre infection trouvée !

    [F:75][D:3]-> C:\DOCUME~1\Dom\LOCALS~1\Temp
    [F:17][D:0]-> C:\DOCUME~1\Dom\Cookies
    [F:383][D:16]-> C:\DOCUME~1\Dom\LOCALS~1\TEMPOR~1\content.IE5

    1 - "C:\Lop SD\LopR_1.txt" - 31/08/2008|22:54 - Option : [1]
    1 - 01/09/2008|20:38 - Option : [2]
    3 - "C:\Lop SD\LopR_3.txt" - 01/09/2008|20:38 - Option : [2]

    --------------------\\ Fin du rapport a 20:38:02

    Et Merci de l'aide :)  dites moi la suite de la procédure ;) 

    Re,

    Copie (Ctrl+C) le texte se situant dans le cadre ci-dessous :

    C:\DOCUME~1\Dom\APPLIC~1\2 Cake Meet
    C:\Program Files\2 Cake Meet


  • Relance Lop S&D.
  • Choisis cette fois-ci l'option 4 (LopScript). Une page blanche va s'ouvrir, colle (Ctrl+V) le texte précedemment copié.
  • Ferme cette page, il te sera demandé de l'enregistrer, accepte.
    [#ff0000]! Ne ferme pas la fenêtre lors de la suppression ![/#f]
  • Poste le rapport généré (C:\lopR.txt*)

    (Si le Bureau ne réapparaît pas, presse Ctrl + Alt + Suppr , Onglet Fichier , Nouvelle tâche , tape explorer.exe et valide)
    * le nom de la partition peut changer

    Encore un ^^ le voila encore une fois :p 

    --------------------\\ Lop S&D 4.2.3-8 XP/Vista

    Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 2
    X86-based PC ( Uniprocessor Free : Intel(R) Celeron(R) CPU 2.66GHz )
    BIOS : Phoenix - AwardBIOS v6.00PG
    USER : Dom ( Administrator )
    BOOT : Normal boot
    Antivirus : Avira AntiVir PersonalEdition 8.0.1.27 (Activated)

    "C:\Lop SD" ( MAJ : 31-08-2008|15:45 )
    Option : [4] ( 04/09/2008|14:18 )

    \\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ Lop Script

    C:\DOCUME~1\Dom\APPLIC~1\2 Cake Meet
    C:\Program Files\2 Cake Meet


    \\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ SUPPRESSION

    Supprime! - C:\DOCUME~1\Dom\APPLIC~1\2 Cake Meet
    Supprime! - C:\Program Files\2 Cake Meet
    Supprime! - C:\DOCUME~1\Dom\Cookies\dom@32vegas[1].txt
    Supprime! - C:\DOCUME~1\Dom\Cookies\dom@banner.32vegas[2].txt

    \\\\\\\\\\\\\\\\\\\\\\\\\\\\\\


    --------------------\\ Listing des dossiers dans APPLIC~1

    [25/12/2007|19:18] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
    [11/09/2007|21:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
    [11/09/2007|21:40] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
    [04/07/2008|19:24] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Avira
    [18/03/2007|12:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\desktop.ini
    [18/03/2007|15:53] C:\DOCUME~1\ALLUSE~1\APPLIC~1\HP
    [18/04/2008|19:43] C:\DOCUME~1\ALLUSE~1\APPLIC~1\hpzinstall.log
    [30/01/2008|21:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Logishrd
    [23/06/2007|17:22] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Logitech
    [19/06/2008|20:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!
    [25/06/2007|12:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
    [01/12/2007|20:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\QTSBandwidthCache
    [21/05/2008|11:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
    [18/03/2007|13:22] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec
    [18/03/2007|13:05] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
    [04/06/2007|22:05] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Live Toolbar
    [19/06/2008|19:55] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller

    [18/03/2007|12:49] C:\DOCUME~1\DEFAUL~1\APPLIC~1\desktop.ini
    [18/03/2007|12:15] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft

    [07/06/2008|21:53] C:\DOCUME~1\Dom\APPLIC~1\Adobe
    [16/03/2008|14:58] C:\DOCUME~1\Dom\APPLIC~1\AdobeUM
    [12/07/2008|21:56] C:\DOCUME~1\Dom\APPLIC~1\Apple Computer
    [18/03/2007|12:49] C:\DOCUME~1\Dom\APPLIC~1\desktop.ini
    [05/06/2008|21:25] C:\DOCUME~1\Dom\APPLIC~1\dvdcss
    [02/08/2007|20:34] C:\DOCUME~1\Dom\APPLIC~1\Help
    [18/11/2007|15:49] C:\DOCUME~1\Dom\APPLIC~1\HP
    [18/03/2007|12:30] C:\DOCUME~1\Dom\APPLIC~1\Identities
    [18/03/2007|17:47] C:\DOCUME~1\Dom\APPLIC~1\Macromedia
    [11/03/2008|18:43] C:\DOCUME~1\Dom\APPLIC~1\Microsoft
    [18/03/2007|14:40] C:\DOCUME~1\Dom\APPLIC~1\Microsoft Web Folders
    [30/08/2008|11:02] C:\DOCUME~1\Dom\APPLIC~1\Mozilla
    [18/03/2007|17:54] C:\DOCUME~1\Dom\APPLIC~1\MSNInstaller
    [31/12/2007|23:17] C:\DOCUME~1\Dom\APPLIC~1\Screenshot Sender
    [10/06/2008|19:52] C:\DOCUME~1\Dom\APPLIC~1\Sun
    [19/03/2008|19:34] C:\DOCUME~1\Dom\APPLIC~1\Update_HP_RedboxHprblog_HPSU.log
    [11/06/2007|14:45] C:\DOCUME~1\Dom\APPLIC~1\vlc

    [03/07/2007|18:29] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft
    [20/06/2008|12:10] C:\DOCUME~1\LOCALS~1\APPLIC~1\Mozilla

    [18/03/2007|12:19] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft

    --------------------\\ Tâches planifiées dans C:\WINDOWS\tasks

    [01/09/2008 12:06][--a------] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
    [03/09/2008 18:25][--a------] C:\WINDOWS\tasks\Norton Security Scan.job
    [03/09/2008 22:44][--a------] C:\WINDOWS\tasks\V‚rifier les mises … jour de Windows Live Toolbar.job
    [04/09/2008 14:06][--ah-----] C:\WINDOWS\tasks\SA.DAT
    [05/08/2004 14:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini

    --------------------\\ Listing des dossiers dans C:\Program Files

    [16/03/2008|15:00] C:\Program Files\Adobe
    [18/03/2007|13:35] C:\Program Files\Ahead
    [09/08/2008|21:14] C:\Program Files\Apple Software Update
    [04/07/2008|19:24] C:\Program Files\Avira
    [12/07/2008|21:13] C:\Program Files\Bonjour
    [08/12/2007|18:42] C:\Program Files\CCleaner
    [28/06/2008|12:21] C:\Program Files\CleanUp!
    [18/03/2007|12:11] C:\Program Files\ComPlus Applications
    [18/03/2007|15:29] C:\Program Files\Controle Parental
    [18/03/2007|14:16] C:\Program Files\EA GAMES
    [19/06/2008|19:19] C:\Program Files\Fichiers communs
    [09/11/2007|23:31] C:\Program Files\Google
    [25/08/2008|08:54] C:\Program Files\HP
    [20/05/2008|18:17] C:\Program Files\InstallShield Installation Information
    [25/08/2008|11:05] C:\Program Files\Internet Explorer
    [02/08/2008|23:22] C:\Program Files\iPod
    [02/08/2008|23:23] C:\Program Files\iTunes
    [26/07/2008|16:58] C:\Program Files\Java
    [30/01/2008|21:09] C:\Program Files\Logitech
    [25/08/2008|11:08] C:\Program Files\Messenger
    [19/06/2008|20:06] C:\Program Files\Messenger Plus! Live
    [05/06/2007|19:00] C:\Program Files\Microsoft CAPICOM 2.1.0.2
    [18/03/2007|16:09] C:\Program Files\Microsoft Encarta
    [18/03/2007|12:15] C:\Program Files\microsoft frontpage
    [18/03/2007|14:40] C:\Program Files\Microsoft Office
    [18/03/2007|14:43] C:\Program Files\Microsoft Visual Studio
    [18/03/2007|12:11] C:\Program Files\Movie Maker
    [03/09/2008|23:08] C:\Program Files\Mozilla Firefox
    [19/06/2008|19:16] C:\Program Files\MSN
    [18/03/2007|12:10] C:\Program Files\MSN Gaming Zone
    [19/06/2008|20:06] C:\Program Files\MSN Messenger
    [19/03/2007|19:23] C:\Program Files\MSXML 4.0
    [18/03/2007|12:12] C:\Program Files\NetMeeting
    [03/09/2008|18:00] C:\Program Files\Norton Security Scan
    [18/03/2007|12:10] C:\Program Files\Online Services
    [13/06/2007|13:40] C:\Program Files\Outlook Express
    [05/10/2007|17:51] C:\Program Files\PhotoFiltre
    [25/08/2008|10:28] C:\Program Files\Picasa2
    [12/07/2008|21:12] C:\Program Files\QuickTime
    [18/03/2007|14:09] C:\Program Files\Realtek AC97
    [08/12/2007|17:14] C:\Program Files\RegCleaner
    [18/03/2007|14:02] C:\Program Files\S3
    [02/08/2008|23:03] C:\Program Files\Safari
    [25/12/2007|19:14] C:\Program Files\Samsung
    [08/03/2008|13:32] C:\Program Files\Services en ligne
    [21/05/2008|11:31] C:\Program Files\Spybot - Search & Destroy
    [04/06/2008|14:26] C:\Program Files\Sun
    [18/03/2007|13:22] C:\Program Files\Symantec
    [04/09/2008|14:07] C:\Program Files\Symantec AntiVirus
    [18/03/2007|13:31] C:\Program Files\ToniArts
    [29/08/2008|23:31] C:\Program Files\Trend Micro
    [20/05/2008|15:05] C:\Program Files\UltraVNC
    [18/03/2007|12:30] C:\Program Files\Uninstall Information
    [18/03/2007|14:04] C:\Program Files\VIA
    [18/03/2007|13:33] C:\Program Files\VideoLAN
    [20/05/2008|18:17] C:\Program Files\Wanadoo
    [19/06/2008|20:03] C:\Program Files\Windows Live
    [19/06/2008|20:01] C:\Program Files\Windows Live Favorites
    [19/06/2008|20:01] C:\Program Files\Windows Live Toolbar
    [18/03/2007|14:35] C:\Program Files\Windows Media Connect 2
    [18/03/2007|14:35] C:\Program Files\Windows Media Player
    [18/03/2007|12:10] C:\Program Files\Windows NT
    [18/03/2007|12:13] C:\Program Files\WindowsUpdate
    [18/03/2007|12:15] C:\Program Files\xerox

    --------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs

    [20/03/2007|20:01] C:\Program Files\Fichiers communs\Adobe
    [18/03/2007|13:35] C:\Program Files\Fichiers communs\Ahead
    [11/09/2007|21:37] C:\Program Files\Fichiers communs\Apple
    [18/03/2007|14:43] C:\Program Files\Fichiers communs\Designer
    [20/05/2008|18:17] C:\Program Files\Fichiers communs\InstallShield
    [04/06/2008|14:22] C:\Program Files\Fichiers communs\Java
    [30/01/2008|21:13] C:\Program Files\Fichiers communs\logishrd
    [19/06/2008|19:37] C:\Program Files\Fichiers communs\Microsoft Shared
    [18/03/2007|12:12] C:\Program Files\Fichiers communs\MSSoap
    [18/03/2007|12:49] C:\Program Files\Fichiers communs\ODBC
    [18/03/2007|12:12] C:\Program Files\Fichiers communs\Services
    [18/03/2007|12:49] C:\Program Files\Fichiers communs\SpeechEngines
    [29/06/2008|14:49] C:\Program Files\Fichiers communs\Symantec Shared
    [13/06/2007|13:40] C:\Program Files\Fichiers communs\System
    [19/06/2008|19:19] C:\Program Files\Fichiers communs\WindowsLiveInstaller

    --------------------\\ Process

    ( 54 Processus )

    ... OK !

    --------------------\\ Recherche avec S_Lop

    Aucun fichier / dossier Lop trouvé !

    --------------------\\ Recherche de Fichiers / Dossiers Lop

    Aucun fichier / dossier Lop trouvé !

    --------------------\\ Verification du Registre

    ..... OK !

    --------------------\\ Verification du fichier Hosts

    Fichier Hosts PROPRE


    --------------------\\ Recherche de fichiers avec Catchme

    catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-09-04 14:23:35
    Windows 5.1.2600 Service Pack 2 NTFS
    scanning hidden processes ...
    scanning hidden files ...
    scan completed successfully
    hidden processes: 0
    hidden files: 4429

    --------------------\\ Recherche d'autres infections


    Aucune autre infection trouvée !

    [F:190][D:4]-> C:\DOCUME~1\Dom\LOCALS~1\Temp
    [F:27][D:0]-> C:\DOCUME~1\Dom\Cookies
    [F:676][D:16]-> C:\DOCUME~1\Dom\LOCALS~1\TEMPOR~1\content.IE5

    1 - "C:\Lop SD\LopR_1.txt" - 31/08/2008|22:54 - Option : [1]
    1 - 01/09/2008|20:38 - Option : [2]
    3 - "C:\Lop SD\LopR_3.txt" - 01/09/2008|20:38 - Option : [2]
    3 - 04/09/2008|14:32 - Option : [4]
    5 - "C:\Lop SD\LopR_5.txt" - 04/09/2008|14:32 - Option : [4]

    --------------------\\ Fin du rapport a 14:32:01

    ok ;) 
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 20:10:15, on 05/09/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16705)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
    C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Symantec AntiVirus\DefWatch.exe
    C:\WINDOWS\System32\FTRTSVC.exe
    C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
    C:\Program Files\Controle Parental\bin\optproxy.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Symantec AntiVirus\Rtvscan.exe
    C:\Program Files\UltraVNC\WinVNC.exe
    C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
    C:\PROGRA~1\SYMANT~1\VPTray.exe
    C:\WINDOWS\system32\VTTimer.exe
    C:\WINDOWS\system32\VTtrayp.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe
    C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Messenger\Msmsgs.exe
    C:\Program Files\Picasa2\PicasaMediaDetector.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\SoftwareDistribution\Download\23ec66f2314a80d718b5483ab6e865af\update\update.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\Program Files\MSN Messenger\usnsvc.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?linkid=677
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
    O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\UltraVNC\WinVNC.exe" -servicehelper
    O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
    O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
    O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\Msmsgs.exe" /background
    O4 - HKCU\..\Run: [Sixth Trust] C:\DOCUME~1\Dom\APPLIC~1\2CAKEM~1\sendmathup.exe
    O4 - HKCU\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
    O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/FacebookPhotoUpload...
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
    O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.ca...
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls...
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPACl...
    O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
    O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
    O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
    O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
    O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\SrvLnch\SrvLnch.exe
    O23 - Service: Control Parental (OPTENET_FILTER) - Contrôle Parental - C:\Program Files\Controle Parental\bin\optproxy.exe
    O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
    O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
    O23 - Service: VNC Server (winvnc) - www.ultravnc.fr - C:\Program Files\UltraVNC\WinVNC.exe

    --
    End of file - 10502 bytes

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 13:42:04, on 06/09/2008
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16705)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
    C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Symantec AntiVirus\DefWatch.exe
    C:\WINDOWS\System32\FTRTSVC.exe
    C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
    C:\Program Files\Controle Parental\bin\optproxy.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Symantec AntiVirus\Rtvscan.exe
    C:\Program Files\UltraVNC\WinVNC.exe
    C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
    C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
    C:\PROGRA~1\SYMANT~1\VPTray.exe
    C:\WINDOWS\system32\VTTimer.exe
    C:\WINDOWS\system32\VTtrayp.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe
    C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Messenger\Msmsgs.exe
    C:\Program Files\Picasa2\PicasaMediaDetector.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\Program Files\MSN Messenger\usnsvc.exe
    C:\Program Files\iTunes\iTunes.exe
    C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceHelper.exe
    C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\distnoted.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?linkid=677
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
    O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\UltraVNC\WinVNC.exe" -servicehelper
    O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
    O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
    O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\Msmsgs.exe" /background
    O4 - HKCU\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
    O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/FacebookPhotoUpload...
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
    O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.ca...
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls...
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPACl...
    O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
    O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
    O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
    O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
    O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\SrvLnch\SrvLnch.exe
    O23 - Service: Control Parental (OPTENET_FILTER) - Contrôle Parental - C:\Program Files\Controle Parental\bin\optproxy.exe
    O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
    O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
    O23 - Service: VNC Server (winvnc) - www.ultravnc.fr - C:\Program Files\UltraVNC\WinVNC.exe

    --
    End of file - 10530 bytes
    Lassé par la pub ? Créez un compte
    Tom's guide dans le monde