comment enlever right media ?
Dernière réponse : dans Sécurité
bonjour a tous !
récemment, spybot a détecter right media sur mon PC.
depuis, mon ordinateur est plus lent et je n'arrête pas de recevoir des pubs lorsque je suis sur internet.
J'aurais donc besoin de votre aide pour m'enlever ce virus s'il vous plait.
voici le rapport hijackthis :
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:53:51, on 13/09/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\acs.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Winamp Remote\bin\OrbTray.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Florian\Bureau\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [ROAD ITCH AMOK PING] C:\Documents and Settings\All Users\Application Data\Long slow road itch\Bits start.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Orb] "C:\Program Files\Winamp Remote\bin\OrbTray.exe" /background
O4 - HKCU\..\Run: [Barb mfcd] C:\DOCUME~1\Florian\APPLIC~1\PEAKDE~1\inter copy bib.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/Install...
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Service de configuration Atheros (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
--
End of file - 8021 bytes
D'avance merci
récemment, spybot a détecter right media sur mon PC.
depuis, mon ordinateur est plus lent et je n'arrête pas de recevoir des pubs lorsque je suis sur internet.
J'aurais donc besoin de votre aide pour m'enlever ce virus s'il vous plait.
voici le rapport hijackthis :
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:53:51, on 13/09/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\acs.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Winamp Remote\bin\OrbTray.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Florian\Bureau\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [ROAD ITCH AMOK PING] C:\Documents and Settings\All Users\Application Data\Long slow road itch\Bits start.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Orb] "C:\Program Files\Winamp Remote\bin\OrbTray.exe" /background
O4 - HKCU\..\Run: [Barb mfcd] C:\DOCUME~1\Florian\APPLIC~1\PEAKDE~1\inter copy bib.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/Install...
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Service de configuration Atheros (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
--
End of file - 8021 bytes
D'avance merci
Autres pages sur : enlever right media
Lassé par la pub ? Créez un compte
Bonjour,
Télécharge Lop S&D.exe ([#ff0000]Eric_71[/#f]) sur ton Bureau.
Lance l'installation du programme en exécutant le fichier téléchargé.
Double-clique maintenant sur le raccourci de LopS&D.
Sélectionne la langue souhaitée en tapant la lettre de ton choix puis en validant avec la touche Entrée.
Choisis maintenant l'option 1 (Recherche). Patiente jusqu'à la fin de la recherche.
Poste le rapport généré (C:\lopR.txt*)
(Si le Bureau ne réapparait pas presse Ctrl + Alt + Suppr , Onglet Fichier , Nouvelle tâche , tape explorer.exe et valide)
* le nom de la partition peut changer
Télécharge Lop S&D.exe ([#ff0000]Eric_71[/#f]) sur ton Bureau.
(Si le Bureau ne réapparait pas presse Ctrl + Alt + Suppr , Onglet Fichier , Nouvelle tâche , tape explorer.exe et valide)
* le nom de la partition peut changer
Enfin me revoilà !
Enfin, j'ai emmené reparé mon ordinateur. Tout refonctionne.
Je reposte donc un rapport hijackthis car il me semble bien être infecté.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:48:31, on 04/11/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Winamp Remote\bin\OrbTray.exe
C:\WINDOWS\system32\acs.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Florian\Bureau\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [ROAD ITCH AMOK PING] C:\Documents and Settings\All Users\Application Data\Long slow road itch\Bits start.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Orb] "C:\Program Files\Winamp Remote\bin\OrbTray.exe" /background
O4 - HKCU\..\Run: [Barb mfcd] C:\DOCUME~1\Florian\APPLIC~1\PEAKDE~1\inter copy bib.exe
O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\NPSWF32_FlashUtil.exe -p
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/Install...
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Service de configuration Atheros (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
--
End of file - 8022 bytes
d'avance merci
Enfin, j'ai emmené reparé mon ordinateur. Tout refonctionne.
Je reposte donc un rapport hijackthis car il me semble bien être infecté.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:48:31, on 04/11/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Winamp Remote\bin\OrbTray.exe
C:\WINDOWS\system32\acs.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Florian\Bureau\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [ROAD ITCH AMOK PING] C:\Documents and Settings\All Users\Application Data\Long slow road itch\Bits start.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Orb] "C:\Program Files\Winamp Remote\bin\OrbTray.exe" /background
O4 - HKCU\..\Run: [Barb mfcd] C:\DOCUME~1\Florian\APPLIC~1\PEAKDE~1\inter copy bib.exe
O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\NPSWF32_FlashUtil.exe -p
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/Install...
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Service de configuration Atheros (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
--
End of file - 8022 bytes
d'avance merci
Est-ce que je doit quand même suivre la procédure que m'avait donné angeldrak ci-dessous ?
Télécharge Lop S&D.exe (Eric_71) sur ton Bureau.
* Lance l'installation du programme en exécutant le fichier téléchargé.
* Double-clique maintenant sur le raccourci de LopS&D.
* Sélectionne la langue souhaitée en tapant la lettre de ton choix puis en validant avec la touche Entrée.
* Choisis maintenant l'option 1 (Recherche). Patiente jusqu'à la fin de la recherche.
* Poste le rapport généré (C:\lopR.txt*)
Télécharge Lop S&D.exe (Eric_71) sur ton Bureau.
* Lance l'installation du programme en exécutant le fichier téléchargé.
* Double-clique maintenant sur le raccourci de LopS&D.
* Sélectionne la langue souhaitée en tapant la lettre de ton choix puis en validant avec la touche Entrée.
* Choisis maintenant l'option 1 (Recherche). Patiente jusqu'à la fin de la recherche.
* Poste le rapport généré (C:\lopR.txt*)
le voici
--------------------\\ Lop S&D 4.2.4-9c XP/Vista
Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 2
X86-based PC ( Multiprocessor Free : Genuine Intel(R) CPU T2060 @ 1.60GHz )
BIOS : Phoenix NoteBIOS 4.0 Release 6.1
USER : Florian ( Administrator )
BOOT : Normal boot
Antivirus : Avira AntiVir PersonalEdition 8.0.1.30 (Activated)
C:\ (Local Disk) - NTFS - Total:73 Go (Free:57 Go)
D:\ (CD or DVD)
"C:\Lop SD" ( MAJ : 01-11-2008|16:30 )
Option : [1] ( 05/11/2008|20:03 )
--------------------\\ Listing des dossiers dans APPLIC~1
[21/03/2008|17:05] C:\DOCUME~1\ADMINI~1\APPLIC~1\Microsoft
[30/06/2008|11:59] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
[30/06/2008|11:59] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[21/03/2008|18:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Atheros
[27/06/2008|11:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Avira
[21/03/2008|18:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Bluebeam Software
[29/03/2008|12:08] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Grisoft
[09/07/2008|19:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Installations
[30/03/2008|13:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ktghsbij
[26/03/2008|21:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
[16/08/2008|11:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Logishrd
[16/08/2008|11:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Logitech
[30/08/2008|18:56] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Long slow road itch
[30/03/2008|16:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Malwarebytes
[22/03/2008|17:40] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!
[17/04/2008|11:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[20/06/2008|12:42] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft Help
[11/05/2008|10:11] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Nokia
[02/07/2008|18:23] C:\DOCUME~1\ALLUSE~1\APPLIC~1\OrbNetworks
[17/04/2008|11:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\PC Suite
[22/03/2008|13:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Sony Ericsson
[26/03/2008|21:15] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
[26/03/2008|20:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
[17/04/2008|12:53] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[22/03/2008|10:57] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
[21/03/2008|17:05] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
[10/07/2008|16:31] C:\DOCUME~1\Florian\APPLIC~1\Adobe
[05/04/2008|20:34] C:\DOCUME~1\Florian\APPLIC~1\Ambient Design
[30/06/2008|12:04] C:\DOCUME~1\Florian\APPLIC~1\Apple Computer
[21/04/2008|11:41] C:\DOCUME~1\Florian\APPLIC~1\Google
[07/05/2008|14:33] C:\DOCUME~1\Florian\APPLIC~1\Grisoft
[21/03/2008|17:48] C:\DOCUME~1\Florian\APPLIC~1\Help
[21/03/2008|17:12] C:\DOCUME~1\Florian\APPLIC~1\Identities
[21/03/2008|18:03] C:\DOCUME~1\Florian\APPLIC~1\InstallShield
[16/08/2008|11:17] C:\DOCUME~1\Florian\APPLIC~1\Leadertech
[19/08/2008|11:57] C:\DOCUME~1\Florian\APPLIC~1\LimeWire
[22/03/2008|11:34] C:\DOCUME~1\Florian\APPLIC~1\Macromedia
[30/03/2008|16:37] C:\DOCUME~1\Florian\APPLIC~1\Malwarebytes
[15/08/2008|16:40] C:\DOCUME~1\Florian\APPLIC~1\Microsoft
[18/06/2008|19:31] C:\DOCUME~1\Florian\APPLIC~1\Mozilla
[21/03/2008|21:16] C:\DOCUME~1\Florian\APPLIC~1\MSNInstaller
[17/04/2008|14:29] C:\DOCUME~1\Florian\APPLIC~1\Nokia
[09/07/2008|20:19] C:\DOCUME~1\Florian\APPLIC~1\Nokia Multimedia Player
[11/05/2008|10:28] C:\DOCUME~1\Florian\APPLIC~1\PC Suite
[04/11/2008|18:40] C:\DOCUME~1\Florian\APPLIC~1\Peak Dead Date
[04/07/2008|18:04] C:\DOCUME~1\Florian\APPLIC~1\RetinaX
[21/03/2008|18:32] C:\DOCUME~1\Florian\APPLIC~1\SolidWorks
[06/07/2008|16:15] C:\DOCUME~1\Florian\APPLIC~1\Sun
[17/04/2008|13:58] C:\DOCUME~1\Florian\APPLIC~1\vlc
[02/07/2008|17:05] C:\DOCUME~1\Florian\APPLIC~1\Winamp
[21/03/2008|17:05] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft
[21/03/2008|17:05] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft
--------------------\\ Tâches planifiées dans C:\WINDOWS\tasks
[05/11/2008 20:00][--ah-----] C:\WINDOWS\tasks\A4FF41879184FBF3.job
[21/08/2008 12:09][--a------] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[05/11/2008 18:14][--ah-----] C:\WINDOWS\tasks\SA.DAT
[30/08/2002 13:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini
( A4FF41879184FBF3.job )=( c:\docume~1\florian\applic~1\peakde~1\1optionsixth.exe )
--------------------\\ Listing des dossiers dans C:\Program Files
[30/03/2008|16:25] C:\Program Files\Alwil Software
[05/04/2008|20:17] C:\Program Files\Ambient Design
[30/06/2008|11:59] C:\Program Files\Apple Software Update
[21/03/2008|18:50] C:\Program Files\Atheros
[21/03/2008|17:46] C:\Program Files\ATI Technologies
[17/07/2008|09:16] C:\Program Files\Audacity
[27/06/2008|11:48] C:\Program Files\Avira
[02/04/2008|14:47] C:\Program Files\AviSynth 2.5
[21/03/2008|18:29] C:\Program Files\Bluebeam Software
[22/07/2008|12:32] C:\Program Files\Capturino 1.4
[30/03/2008|19:16] C:\Program Files\CCleaner
[30/08/2008|18:55] C:\Program Files\Circle Developement
[21/03/2008|17:01] C:\Program Files\ComPlus Applications
[02/04/2008|16:30] C:\Program Files\Conduit
[16/04/2008|17:46] C:\Program Files\DIFX
[25/07/2008|20:42] C:\Program Files\eMule
[02/04/2008|14:47] C:\Program Files\eRightSoft
[15/08/2008|16:40] C:\Program Files\Fichiers communs
[17/07/2008|09:37] C:\Program Files\Free Audio Pack
[06/05/2008|21:35] C:\Program Files\FusionSoft DVD Player XP
[21/04/2008|11:40] C:\Program Files\Google
[07/05/2008|14:32] C:\Program Files\Grisoft
[10/04/2008|11:48] C:\Program Files\GT Interactive
[16/08/2008|11:18] C:\Program Files\InstallShield Installation Information
[20/06/2008|12:44] C:\Program Files\Internet Explorer
[30/03/2008|19:46] C:\Program Files\IVCsoft
[20/07/2008|09:39] C:\Program Files\Java
[16/08/2008|11:13] C:\Program Files\Labtec
[20/06/2008|15:17] C:\Program Files\Lavalys
[26/03/2008|21:28] C:\Program Files\Lavasoft
[04/07/2008|11:14] C:\Program Files\LimeWire
[16/08/2008|11:18] C:\Program Files\Logitech
[21/03/2008|18:01] C:\Program Files\ltmoh
[02/04/2008|16:30] C:\Program Files\Magic-Radio
[30/03/2008|16:37] C:\Program Files\Malwarebytes' Anti-Malware
[02/07/2008|16:42] C:\Program Files\MediaMonkey
[02/04/2008|20:38] C:\Program Files\Messenger
[30/08/2008|18:55] C:\Program Files\Messenger Plus! Live
[21/03/2008|17:06] C:\Program Files\microsoft frontpage
[21/03/2008|18:41] C:\Program Files\Microsoft Office
[21/03/2008|18:40] C:\Program Files\Microsoft Visual Studio
[21/03/2008|18:41] C:\Program Files\Microsoft Works
[21/03/2008|17:03] C:\Program Files\Movie Maker
[05/11/2008|18:45] C:\Program Files\Mozilla Firefox
[15/06/2008|10:32] C:\Program Files\mp3DirectCut
[21/03/2008|18:41] C:\Program Files\MSBuild
[21/03/2008|21:16] C:\Program Files\MSN
[21/03/2008|17:01] C:\Program Files\MSN Gaming Zone
[02/04/2008|15:53] C:\Program Files\MSXML 4.0
[11/05/2008|10:11] C:\Program Files\MSXML 6.0
[21/03/2008|17:03] C:\Program Files\NetMeeting
[09/07/2008|19:20] C:\Program Files\Nokia
[21/03/2008|17:01] C:\Program Files\Online Services
[02/04/2008|20:38] C:\Program Files\Outlook Express
[16/04/2008|17:46] C:\Program Files\PC Connectivity Solution
[04/07/2008|17:46] C:\Program Files\PC Health Optimizer Free Edition
[30/08/2008|18:55] C:\Program Files\Peak Dead Date
[17/04/2008|18:09] C:\Program Files\PhotoFiltre
[30/06/2008|12:00] C:\Program Files\QuickTime
[21/03/2008|17:52] C:\Program Files\Realtek
[21/03/2008|17:04] C:\Program Files\Services en ligne
[05/11/2008|20:01] C:\Program Files\Sim AQUARIUM 2
[04/11/2008|19:59] C:\Program Files\SolidWorks
[22/03/2008|13:14] C:\Program Files\Sony Ericsson
[09/07/2008|15:17] C:\Program Files\SpeedFan
[26/03/2008|20:13] C:\Program Files\Spybot - Search & Destroy
[04/07/2008|11:18] C:\Program Files\Sun
[30/03/2008|19:10] C:\Program Files\Trend Micro
[21/03/2008|17:12] C:\Program Files\Uninstall Information
[18/04/2008|20:33] C:\Program Files\Valve Lan
[17/04/2008|13:55] C:\Program Files\VideoLAN
[17/07/2008|09:10] C:\Program Files\VirtualDJ
[02/07/2008|16:48] C:\Program Files\Winamp
[02/07/2008|16:46] C:\Program Files\Winamp Remote
[28/03/2008|18:54] C:\Program Files\Windows Live
[08/04/2008|11:08] C:\Program Files\Windows Media Connect 2
[08/04/2008|11:08] C:\Program Files\Windows Media Player
[21/03/2008|17:01] C:\Program Files\Windows NT
[21/03/2008|17:04] C:\Program Files\WindowsUpdate
[21/03/2008|17:06] C:\Program Files\xerox
--------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs
[21/03/2008|18:29] C:\Program Files\Fichiers communs\Bluebeam Software
[21/03/2008|18:25] C:\Program Files\Fichiers communs\Designer
[22/03/2008|13:13] C:\Program Files\Fichiers communs\InstallShield
[04/07/2008|11:16] C:\Program Files\Fichiers communs\Java
[15/08/2008|16:40] C:\Program Files\Fichiers communs\Labtec
[16/08/2008|11:18] C:\Program Files\Fichiers communs\LogiShrd
[11/05/2008|10:09] C:\Program Files\Fichiers communs\Microsoft Shared
[21/03/2008|17:03] C:\Program Files\Fichiers communs\MSSoap
[09/07/2008|19:18] C:\Program Files\Fichiers communs\Nokia
[21/03/2008|17:52] C:\Program Files\Fichiers communs\ODBC
[16/04/2008|17:47] C:\Program Files\Fichiers communs\PCSuite
[21/03/2008|17:03] C:\Program Files\Fichiers communs\Services
[21/03/2008|18:20] C:\Program Files\Fichiers communs\Solidworks Data
[21/03/2008|18:26] C:\Program Files\Fichiers communs\SolidWorks Shared
[21/03/2008|17:52] C:\Program Files\Fichiers communs\SpeechEngines
[02/04/2008|20:38] C:\Program Files\Fichiers communs\System
[22/03/2008|13:14] C:\Program Files\Fichiers communs\Teleca Shared
[10/07/2008|16:21] C:\Program Files\Fichiers communs\Vbox
[22/03/2008|10:58] C:\Program Files\Fichiers communs\WindowsLiveInstaller
[26/03/2008|21:27] C:\Program Files\Fichiers communs\Wise Installation Wizard
--------------------\\ Process
( 47 Processes )
IEXPLORE.EXE ~ [PID:552]
--------------------\\ Recherche avec S_Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Recherche de Fichiers / Dossiers Lop
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Long slow road itch
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Long slow road itch\Bits start.exe
C:\DOCUME~1\Florian\APPLIC~1\Peak Dead Date
C:\Program Files\Peak Dead Date
C:\DOCUME~1\Florian\APPLIC~1\peakde~1
C:\Program Files\peakde~1
C:\Program Files\Circle Developement
C:\Program Files\Circle Developement\Uninstall.exe
C:\DOCUME~1\Florian\Cookies\florian@bigpoint[1].txt
C:\DOCUME~1\Florian\Cookies\florian@fr1.darkorbit.bigpoint[1].txt
C:\DOCUME~1\Florian\Cookies\florian@adopt.euroclick[2].txt
C:\DOCUME~1\Florian\Cookies\florian@pacificpoker[1].txt
C:\WINDOWS\Tasks\A4FF41879184FBF3.job
--------------------\\ Verification du Registre
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Barb mfcd"="C:\\DOCUME~1\\Florian\\APPLIC~1\\PEAKDE~1\\inter copy bib.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ROAD ITCH AMOK PING"="C:\\Documents and Settings\\All Users\\Application Data\\Long slow road itch\\Bits start.exe"
--------------------\\ Verification du fichier Hosts
Fichier Hosts PROPRE
--------------------\\ Recherche de fichiers avec Catchme
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-05 20:05:33
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 32
--------------------\\ Recherche d'autres infections
Aucune autre infection trouvée !
[F:93][D:8]-> C:\DOCUME~1\Florian\LOCALS~1\Temp
[F:33][D:0]-> C:\DOCUME~1\Florian\Cookies
[F:732][D:4]-> C:\DOCUME~1\Florian\LOCALS~1\TEMPOR~1\content.IE5
1 - "C:\Lop SD\LopR_1.txt" - 05/11/2008|20:07 - Option : [1]
--------------------\\ Fin du rapport a 20:07:03
--------------------\\ Lop S&D 4.2.4-9c XP/Vista
Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 2
X86-based PC ( Multiprocessor Free : Genuine Intel(R) CPU T2060 @ 1.60GHz )
BIOS : Phoenix NoteBIOS 4.0 Release 6.1
USER : Florian ( Administrator )
BOOT : Normal boot
Antivirus : Avira AntiVir PersonalEdition 8.0.1.30 (Activated)
C:\ (Local Disk) - NTFS - Total:73 Go (Free:57 Go)
D:\ (CD or DVD)
"C:\Lop SD" ( MAJ : 01-11-2008|16:30 )
Option : [1] ( 05/11/2008|20:03 )
--------------------\\ Listing des dossiers dans APPLIC~1
[21/03/2008|17:05] C:\DOCUME~1\ADMINI~1\APPLIC~1\Microsoft
[30/06/2008|11:59] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
[30/06/2008|11:59] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[21/03/2008|18:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Atheros
[27/06/2008|11:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Avira
[21/03/2008|18:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Bluebeam Software
[29/03/2008|12:08] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Grisoft
[09/07/2008|19:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Installations
[30/03/2008|13:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ktghsbij
[26/03/2008|21:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
[16/08/2008|11:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Logishrd
[16/08/2008|11:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Logitech
[30/08/2008|18:56] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Long slow road itch
[30/03/2008|16:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Malwarebytes
[22/03/2008|17:40] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!
[17/04/2008|11:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[20/06/2008|12:42] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft Help
[11/05/2008|10:11] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Nokia
[02/07/2008|18:23] C:\DOCUME~1\ALLUSE~1\APPLIC~1\OrbNetworks
[17/04/2008|11:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\PC Suite
[22/03/2008|13:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Sony Ericsson
[26/03/2008|21:15] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
[26/03/2008|20:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
[17/04/2008|12:53] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[22/03/2008|10:57] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
[21/03/2008|17:05] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
[10/07/2008|16:31] C:\DOCUME~1\Florian\APPLIC~1\Adobe
[05/04/2008|20:34] C:\DOCUME~1\Florian\APPLIC~1\Ambient Design
[30/06/2008|12:04] C:\DOCUME~1\Florian\APPLIC~1\Apple Computer
[21/04/2008|11:41] C:\DOCUME~1\Florian\APPLIC~1\Google
[07/05/2008|14:33] C:\DOCUME~1\Florian\APPLIC~1\Grisoft
[21/03/2008|17:48] C:\DOCUME~1\Florian\APPLIC~1\Help
[21/03/2008|17:12] C:\DOCUME~1\Florian\APPLIC~1\Identities
[21/03/2008|18:03] C:\DOCUME~1\Florian\APPLIC~1\InstallShield
[16/08/2008|11:17] C:\DOCUME~1\Florian\APPLIC~1\Leadertech
[19/08/2008|11:57] C:\DOCUME~1\Florian\APPLIC~1\LimeWire
[22/03/2008|11:34] C:\DOCUME~1\Florian\APPLIC~1\Macromedia
[30/03/2008|16:37] C:\DOCUME~1\Florian\APPLIC~1\Malwarebytes
[15/08/2008|16:40] C:\DOCUME~1\Florian\APPLIC~1\Microsoft
[18/06/2008|19:31] C:\DOCUME~1\Florian\APPLIC~1\Mozilla
[21/03/2008|21:16] C:\DOCUME~1\Florian\APPLIC~1\MSNInstaller
[17/04/2008|14:29] C:\DOCUME~1\Florian\APPLIC~1\Nokia
[09/07/2008|20:19] C:\DOCUME~1\Florian\APPLIC~1\Nokia Multimedia Player
[11/05/2008|10:28] C:\DOCUME~1\Florian\APPLIC~1\PC Suite
[04/11/2008|18:40] C:\DOCUME~1\Florian\APPLIC~1\Peak Dead Date
[04/07/2008|18:04] C:\DOCUME~1\Florian\APPLIC~1\RetinaX
[21/03/2008|18:32] C:\DOCUME~1\Florian\APPLIC~1\SolidWorks
[06/07/2008|16:15] C:\DOCUME~1\Florian\APPLIC~1\Sun
[17/04/2008|13:58] C:\DOCUME~1\Florian\APPLIC~1\vlc
[02/07/2008|17:05] C:\DOCUME~1\Florian\APPLIC~1\Winamp
[21/03/2008|17:05] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft
[21/03/2008|17:05] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft
--------------------\\ Tâches planifiées dans C:\WINDOWS\tasks
[05/11/2008 20:00][--ah-----] C:\WINDOWS\tasks\A4FF41879184FBF3.job
[21/08/2008 12:09][--a------] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[05/11/2008 18:14][--ah-----] C:\WINDOWS\tasks\SA.DAT
[30/08/2002 13:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini
( A4FF41879184FBF3.job )=( c:\docume~1\florian\applic~1\peakde~1\1optionsixth.exe )
--------------------\\ Listing des dossiers dans C:\Program Files
[30/03/2008|16:25] C:\Program Files\Alwil Software
[05/04/2008|20:17] C:\Program Files\Ambient Design
[30/06/2008|11:59] C:\Program Files\Apple Software Update
[21/03/2008|18:50] C:\Program Files\Atheros
[21/03/2008|17:46] C:\Program Files\ATI Technologies
[17/07/2008|09:16] C:\Program Files\Audacity
[27/06/2008|11:48] C:\Program Files\Avira
[02/04/2008|14:47] C:\Program Files\AviSynth 2.5
[21/03/2008|18:29] C:\Program Files\Bluebeam Software
[22/07/2008|12:32] C:\Program Files\Capturino 1.4
[30/03/2008|19:16] C:\Program Files\CCleaner
[30/08/2008|18:55] C:\Program Files\Circle Developement
[21/03/2008|17:01] C:\Program Files\ComPlus Applications
[02/04/2008|16:30] C:\Program Files\Conduit
[16/04/2008|17:46] C:\Program Files\DIFX
[25/07/2008|20:42] C:\Program Files\eMule
[02/04/2008|14:47] C:\Program Files\eRightSoft
[15/08/2008|16:40] C:\Program Files\Fichiers communs
[17/07/2008|09:37] C:\Program Files\Free Audio Pack
[06/05/2008|21:35] C:\Program Files\FusionSoft DVD Player XP
[21/04/2008|11:40] C:\Program Files\Google
[07/05/2008|14:32] C:\Program Files\Grisoft
[10/04/2008|11:48] C:\Program Files\GT Interactive
[16/08/2008|11:18] C:\Program Files\InstallShield Installation Information
[20/06/2008|12:44] C:\Program Files\Internet Explorer
[30/03/2008|19:46] C:\Program Files\IVCsoft
[20/07/2008|09:39] C:\Program Files\Java
[16/08/2008|11:13] C:\Program Files\Labtec
[20/06/2008|15:17] C:\Program Files\Lavalys
[26/03/2008|21:28] C:\Program Files\Lavasoft
[04/07/2008|11:14] C:\Program Files\LimeWire
[16/08/2008|11:18] C:\Program Files\Logitech
[21/03/2008|18:01] C:\Program Files\ltmoh
[02/04/2008|16:30] C:\Program Files\Magic-Radio
[30/03/2008|16:37] C:\Program Files\Malwarebytes' Anti-Malware
[02/07/2008|16:42] C:\Program Files\MediaMonkey
[02/04/2008|20:38] C:\Program Files\Messenger
[30/08/2008|18:55] C:\Program Files\Messenger Plus! Live
[21/03/2008|17:06] C:\Program Files\microsoft frontpage
[21/03/2008|18:41] C:\Program Files\Microsoft Office
[21/03/2008|18:40] C:\Program Files\Microsoft Visual Studio
[21/03/2008|18:41] C:\Program Files\Microsoft Works
[21/03/2008|17:03] C:\Program Files\Movie Maker
[05/11/2008|18:45] C:\Program Files\Mozilla Firefox
[15/06/2008|10:32] C:\Program Files\mp3DirectCut
[21/03/2008|18:41] C:\Program Files\MSBuild
[21/03/2008|21:16] C:\Program Files\MSN
[21/03/2008|17:01] C:\Program Files\MSN Gaming Zone
[02/04/2008|15:53] C:\Program Files\MSXML 4.0
[11/05/2008|10:11] C:\Program Files\MSXML 6.0
[21/03/2008|17:03] C:\Program Files\NetMeeting
[09/07/2008|19:20] C:\Program Files\Nokia
[21/03/2008|17:01] C:\Program Files\Online Services
[02/04/2008|20:38] C:\Program Files\Outlook Express
[16/04/2008|17:46] C:\Program Files\PC Connectivity Solution
[04/07/2008|17:46] C:\Program Files\PC Health Optimizer Free Edition
[30/08/2008|18:55] C:\Program Files\Peak Dead Date
[17/04/2008|18:09] C:\Program Files\PhotoFiltre
[30/06/2008|12:00] C:\Program Files\QuickTime
[21/03/2008|17:52] C:\Program Files\Realtek
[21/03/2008|17:04] C:\Program Files\Services en ligne
[05/11/2008|20:01] C:\Program Files\Sim AQUARIUM 2
[04/11/2008|19:59] C:\Program Files\SolidWorks
[22/03/2008|13:14] C:\Program Files\Sony Ericsson
[09/07/2008|15:17] C:\Program Files\SpeedFan
[26/03/2008|20:13] C:\Program Files\Spybot - Search & Destroy
[04/07/2008|11:18] C:\Program Files\Sun
[30/03/2008|19:10] C:\Program Files\Trend Micro
[21/03/2008|17:12] C:\Program Files\Uninstall Information
[18/04/2008|20:33] C:\Program Files\Valve Lan
[17/04/2008|13:55] C:\Program Files\VideoLAN
[17/07/2008|09:10] C:\Program Files\VirtualDJ
[02/07/2008|16:48] C:\Program Files\Winamp
[02/07/2008|16:46] C:\Program Files\Winamp Remote
[28/03/2008|18:54] C:\Program Files\Windows Live
[08/04/2008|11:08] C:\Program Files\Windows Media Connect 2
[08/04/2008|11:08] C:\Program Files\Windows Media Player
[21/03/2008|17:01] C:\Program Files\Windows NT
[21/03/2008|17:04] C:\Program Files\WindowsUpdate
[21/03/2008|17:06] C:\Program Files\xerox
--------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs
[21/03/2008|18:29] C:\Program Files\Fichiers communs\Bluebeam Software
[21/03/2008|18:25] C:\Program Files\Fichiers communs\Designer
[22/03/2008|13:13] C:\Program Files\Fichiers communs\InstallShield
[04/07/2008|11:16] C:\Program Files\Fichiers communs\Java
[15/08/2008|16:40] C:\Program Files\Fichiers communs\Labtec
[16/08/2008|11:18] C:\Program Files\Fichiers communs\LogiShrd
[11/05/2008|10:09] C:\Program Files\Fichiers communs\Microsoft Shared
[21/03/2008|17:03] C:\Program Files\Fichiers communs\MSSoap
[09/07/2008|19:18] C:\Program Files\Fichiers communs\Nokia
[21/03/2008|17:52] C:\Program Files\Fichiers communs\ODBC
[16/04/2008|17:47] C:\Program Files\Fichiers communs\PCSuite
[21/03/2008|17:03] C:\Program Files\Fichiers communs\Services
[21/03/2008|18:20] C:\Program Files\Fichiers communs\Solidworks Data
[21/03/2008|18:26] C:\Program Files\Fichiers communs\SolidWorks Shared
[21/03/2008|17:52] C:\Program Files\Fichiers communs\SpeechEngines
[02/04/2008|20:38] C:\Program Files\Fichiers communs\System
[22/03/2008|13:14] C:\Program Files\Fichiers communs\Teleca Shared
[10/07/2008|16:21] C:\Program Files\Fichiers communs\Vbox
[22/03/2008|10:58] C:\Program Files\Fichiers communs\WindowsLiveInstaller
[26/03/2008|21:27] C:\Program Files\Fichiers communs\Wise Installation Wizard
--------------------\\ Process
( 47 Processes )
IEXPLORE.EXE ~ [PID:552]
--------------------\\ Recherche avec S_Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Recherche de Fichiers / Dossiers Lop
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Long slow road itch
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Long slow road itch\Bits start.exe
C:\DOCUME~1\Florian\APPLIC~1\Peak Dead Date
C:\Program Files\Peak Dead Date
C:\DOCUME~1\Florian\APPLIC~1\peakde~1
C:\Program Files\peakde~1
C:\Program Files\Circle Developement
C:\Program Files\Circle Developement\Uninstall.exe
C:\DOCUME~1\Florian\Cookies\florian@bigpoint[1].txt
C:\DOCUME~1\Florian\Cookies\florian@fr1.darkorbit.bigpoint[1].txt
C:\DOCUME~1\Florian\Cookies\florian@adopt.euroclick[2].txt
C:\DOCUME~1\Florian\Cookies\florian@pacificpoker[1].txt
C:\WINDOWS\Tasks\A4FF41879184FBF3.job
--------------------\\ Verification du Registre
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Barb mfcd"="C:\\DOCUME~1\\Florian\\APPLIC~1\\PEAKDE~1\\inter copy bib.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ROAD ITCH AMOK PING"="C:\\Documents and Settings\\All Users\\Application Data\\Long slow road itch\\Bits start.exe"
--------------------\\ Verification du fichier Hosts
Fichier Hosts PROPRE
--------------------\\ Recherche de fichiers avec Catchme
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-05 20:05:33
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 32
--------------------\\ Recherche d'autres infections
Aucune autre infection trouvée !
[F:93][D:8]-> C:\DOCUME~1\Florian\LOCALS~1\Temp
[F:33][D:0]-> C:\DOCUME~1\Florian\Cookies
[F:732][D:4]-> C:\DOCUME~1\Florian\LOCALS~1\TEMPOR~1\content.IE5
1 - "C:\Lop SD\LopR_1.txt" - 05/11/2008|20:07 - Option : [1]
--------------------\\ Fin du rapport a 20:07:03
désolé pour le retard mais je suis interne donc je n'ai pas pu répondre avant.
Voici le rapport :
--------------------\\ Lop S&D 4.2.4-9c XP/Vista
Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 2
X86-based PC ( Multiprocessor Free : Genuine Intel(R) CPU T2060 @ 1.60GHz )
BIOS : Phoenix NoteBIOS 4.0 Release 6.1
USER : Florian ( Administrator )
BOOT : Normal boot
Antivirus : Avira AntiVir PersonalEdition 8.0.1.30 (Activated)
C:\ (Local Disk) - NTFS - Total:73 Go (Free:57 Go)
D:\ (CD or DVD)
"C:\Lop SD" ( MAJ : 01-11-2008|16:30 )
Option : [2] ( 08/11/2008|10:51 )
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ SUPPRESSION
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\Long slow road itch\Bits start.exe
Supprime! - C:\Program Files\Circle Developement\Uninstall.exe
Supprime! - C:\DOCUME~1\Florian\Cookies\florian@bigpoint[1].txt
Supprime! - C:\DOCUME~1\Florian\Cookies\florian@fr1.darkorbit.bigpoint[1].txt
Supprime! - C:\DOCUME~1\Florian\Cookies\florian@adopt.euroclick[2].txt
Supprime! - C:\DOCUME~1\Florian\Cookies\florian@pacificpoker[1].txt
Supprime! - C:\WINDOWS\Tasks\A4FF41879184FBF3.job
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\Long slow road itch
Supprime! - C:\DOCUME~1\Florian\APPLIC~1\Peak Dead Date
Supprime! - C:\Program Files\Peak Dead Date
Supprime! - C:\Program Files\Circle Developement
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
--------------------\\ Listing des dossiers dans APPLIC~1
[21/03/2008|17:05] C:\DOCUME~1\ADMINI~1\APPLIC~1\Microsoft
[30/06/2008|11:59] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
[30/06/2008|11:59] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[21/03/2008|18:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Atheros
[27/06/2008|11:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Avira
[21/03/2008|18:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Bluebeam Software
[29/03/2008|12:08] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Grisoft
[09/07/2008|19:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Installations
[30/03/2008|13:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ktghsbij
[26/03/2008|21:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
[08/11/2008|10:46] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Logishrd
[16/08/2008|11:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Logitech
[30/03/2008|16:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Malwarebytes
[22/03/2008|17:40] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!
[17/04/2008|11:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[20/06/2008|12:42] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft Help
[11/05/2008|10:11] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Nokia
[02/07/2008|18:23] C:\DOCUME~1\ALLUSE~1\APPLIC~1\OrbNetworks
[17/04/2008|11:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\PC Suite
[22/03/2008|13:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Sony Ericsson
[26/03/2008|21:15] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
[26/03/2008|20:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
[17/04/2008|12:53] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[22/03/2008|10:57] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
[21/03/2008|17:05] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
[10/07/2008|16:31] C:\DOCUME~1\Florian\APPLIC~1\Adobe
[05/04/2008|20:34] C:\DOCUME~1\Florian\APPLIC~1\Ambient Design
[30/06/2008|12:04] C:\DOCUME~1\Florian\APPLIC~1\Apple Computer
[21/04/2008|11:41] C:\DOCUME~1\Florian\APPLIC~1\Google
[07/05/2008|14:33] C:\DOCUME~1\Florian\APPLIC~1\Grisoft
[21/03/2008|17:48] C:\DOCUME~1\Florian\APPLIC~1\Help
[21/03/2008|17:12] C:\DOCUME~1\Florian\APPLIC~1\Identities
[21/03/2008|18:03] C:\DOCUME~1\Florian\APPLIC~1\InstallShield
[16/08/2008|11:17] C:\DOCUME~1\Florian\APPLIC~1\Leadertech
[19/08/2008|11:57] C:\DOCUME~1\Florian\APPLIC~1\LimeWire
[22/03/2008|11:34] C:\DOCUME~1\Florian\APPLIC~1\Macromedia
[30/03/2008|16:37] C:\DOCUME~1\Florian\APPLIC~1\Malwarebytes
[15/08/2008|16:40] C:\DOCUME~1\Florian\APPLIC~1\Microsoft
[18/06/2008|19:31] C:\DOCUME~1\Florian\APPLIC~1\Mozilla
[21/03/2008|21:16] C:\DOCUME~1\Florian\APPLIC~1\MSNInstaller
[17/04/2008|14:29] C:\DOCUME~1\Florian\APPLIC~1\Nokia
[09/07/2008|20:19] C:\DOCUME~1\Florian\APPLIC~1\Nokia Multimedia Player
[11/05/2008|10:28] C:\DOCUME~1\Florian\APPLIC~1\PC Suite
[04/07/2008|18:04] C:\DOCUME~1\Florian\APPLIC~1\RetinaX
[21/03/2008|18:32] C:\DOCUME~1\Florian\APPLIC~1\SolidWorks
[06/07/2008|16:15] C:\DOCUME~1\Florian\APPLIC~1\Sun
[17/04/2008|13:58] C:\DOCUME~1\Florian\APPLIC~1\vlc
[02/07/2008|17:05] C:\DOCUME~1\Florian\APPLIC~1\Winamp
[21/03/2008|17:05] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft
[21/03/2008|17:05] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft
--------------------\\ Tâches planifiées dans C:\WINDOWS\tasks
[21/08/2008 12:09][--a------] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[08/11/2008 10:43][--ah-----] C:\WINDOWS\tasks\SA.DAT
[30/08/2002 13:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini
--------------------\\ Listing des dossiers dans C:\Program Files
[30/03/2008|16:25] C:\Program Files\Alwil Software
[05/04/2008|20:17] C:\Program Files\Ambient Design
[30/06/2008|11:59] C:\Program Files\Apple Software Update
[21/03/2008|18:50] C:\Program Files\Atheros
[21/03/2008|17:46] C:\Program Files\ATI Technologies
[17/07/2008|09:16] C:\Program Files\Audacity
[27/06/2008|11:48] C:\Program Files\Avira
[02/04/2008|14:47] C:\Program Files\AviSynth 2.5
[21/03/2008|18:29] C:\Program Files\Bluebeam Software
[22/07/2008|12:32] C:\Program Files\Capturino 1.4
[30/03/2008|19:16] C:\Program Files\CCleaner
[21/03/2008|17:01] C:\Program Files\ComPlus Applications
[02/04/2008|16:30] C:\Program Files\Conduit
[16/04/2008|17:46] C:\Program Files\DIFX
[25/07/2008|20:42] C:\Program Files\eMule
[02/04/2008|14:47] C:\Program Files\eRightSoft
[15/08/2008|16:40] C:\Program Files\Fichiers communs
[17/07/2008|09:37] C:\Program Files\Free Audio Pack
[06/05/2008|21:35] C:\Program Files\FusionSoft DVD Player XP
[21/04/2008|11:40] C:\Program Files\Google
[07/05/2008|14:32] C:\Program Files\Grisoft
[10/04/2008|11:48] C:\Program Files\GT Interactive
[16/08/2008|11:18] C:\Program Files\InstallShield Installation Information
[20/06/2008|12:44] C:\Program Files\Internet Explorer
[30/03/2008|19:46] C:\Program Files\IVCsoft
[20/07/2008|09:39] C:\Program Files\Java
[16/08/2008|11:13] C:\Program Files\Labtec
[20/06/2008|15:17] C:\Program Files\Lavalys
[26/03/2008|21:28] C:\Program Files\Lavasoft
[04/07/2008|11:14] C:\Program Files\LimeWire
[16/08/2008|11:18] C:\Program Files\Logitech
[21/03/2008|18:01] C:\Program Files\ltmoh
[02/04/2008|16:30] C:\Program Files\Magic-Radio
[30/03/2008|16:37] C:\Program Files\Malwarebytes' Anti-Malware
[02/07/2008|16:42] C:\Program Files\MediaMonkey
[02/04/2008|20:38] C:\Program Files\Messenger
[30/08/2008|18:55] C:\Program Files\Messenger Plus! Live
[21/03/2008|17:06] C:\Program Files\microsoft frontpage
[21/03/2008|18:41] C:\Program Files\Microsoft Office
[21/03/2008|18:40] C:\Program Files\Microsoft Visual Studio
[21/03/2008|18:41] C:\Program Files\Microsoft Works
[21/03/2008|17:03] C:\Program Files\Movie Maker
[08/11/2008|10:46] C:\Program Files\Mozilla Firefox
[15/06/2008|10:32] C:\Program Files\mp3DirectCut
[21/03/2008|18:41] C:\Program Files\MSBuild
[21/03/2008|21:16] C:\Program Files\MSN
[21/03/2008|17:01] C:\Program Files\MSN Gaming Zone
[02/04/2008|15:53] C:\Program Files\MSXML 4.0
[11/05/2008|10:11] C:\Program Files\MSXML 6.0
[21/03/2008|17:03] C:\Program Files\NetMeeting
[09/07/2008|19:20] C:\Program Files\Nokia
[21/03/2008|17:01] C:\Program Files\Online Services
[02/04/2008|20:38] C:\Program Files\Outlook Express
[16/04/2008|17:46] C:\Program Files\PC Connectivity Solution
[04/07/2008|17:46] C:\Program Files\PC Health Optimizer Free Edition
[17/04/2008|18:09] C:\Program Files\PhotoFiltre
[30/06/2008|12:00] C:\Program Files\QuickTime
[21/03/2008|17:52] C:\Program Files\Realtek
[21/03/2008|17:04] C:\Program Files\Services en ligne
[05/11/2008|20:01] C:\Program Files\Sim AQUARIUM 2
[04/11/2008|19:59] C:\Program Files\SolidWorks
[09/07/2008|15:17] C:\Program Files\SpeedFan
[26/03/2008|20:13] C:\Program Files\Spybot - Search & Destroy
[04/07/2008|11:18] C:\Program Files\Sun
[30/03/2008|19:10] C:\Program Files\Trend Micro
[21/03/2008|17:12] C:\Program Files\Uninstall Information
[18/04/2008|20:33] C:\Program Files\Valve Lan
[17/04/2008|13:55] C:\Program Files\VideoLAN
[17/07/2008|09:10] C:\Program Files\VirtualDJ
[02/07/2008|16:48] C:\Program Files\Winamp
[02/07/2008|16:46] C:\Program Files\Winamp Remote
[28/03/2008|18:54] C:\Program Files\Windows Live
[08/04/2008|11:08] C:\Program Files\Windows Media Connect 2
[08/04/2008|11:08] C:\Program Files\Windows Media Player
[21/03/2008|17:01] C:\Program Files\Windows NT
[21/03/2008|17:04] C:\Program Files\WindowsUpdate
[21/03/2008|17:06] C:\Program Files\xerox
--------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs
[21/03/2008|18:29] C:\Program Files\Fichiers communs\Bluebeam Software
[21/03/2008|18:25] C:\Program Files\Fichiers communs\Designer
[22/03/2008|13:13] C:\Program Files\Fichiers communs\InstallShield
[04/07/2008|11:16] C:\Program Files\Fichiers communs\Java
[15/08/2008|16:40] C:\Program Files\Fichiers communs\Labtec
[16/08/2008|11:18] C:\Program Files\Fichiers communs\LogiShrd
[11/05/2008|10:09] C:\Program Files\Fichiers communs\Microsoft Shared
[21/03/2008|17:03] C:\Program Files\Fichiers communs\MSSoap
[09/07/2008|19:18] C:\Program Files\Fichiers communs\Nokia
[21/03/2008|17:52] C:\Program Files\Fichiers communs\ODBC
[16/04/2008|17:47] C:\Program Files\Fichiers communs\PCSuite
[21/03/2008|17:03] C:\Program Files\Fichiers communs\Services
[21/03/2008|18:20] C:\Program Files\Fichiers communs\Solidworks Data
[21/03/2008|18:26] C:\Program Files\Fichiers communs\SolidWorks Shared
[21/03/2008|17:52] C:\Program Files\Fichiers communs\SpeechEngines
[02/04/2008|20:38] C:\Program Files\Fichiers communs\System
[22/03/2008|13:14] C:\Program Files\Fichiers communs\Teleca Shared
[10/07/2008|16:21] C:\Program Files\Fichiers communs\Vbox
[22/03/2008|10:58] C:\Program Files\Fichiers communs\WindowsLiveInstaller
[26/03/2008|21:27] C:\Program Files\Fichiers communs\Wise Installation Wizard
--------------------\\ Process
( 51 Processes )
... OK !
--------------------\\ Recherche avec S_Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Recherche de Fichiers / Dossiers Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Verification du Registre
..... OK !
--------------------\\ Verification du fichier Hosts
Fichier Hosts PROPRE
--------------------\\ Recherche de fichiers avec Catchme
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-08 10:52:37
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden files ...
C:\DOCUME~1\Florian\LOCALS~1\APPLIC~1\Mozilla\Firefox\Profiles\z222hf83.default\Cache\0E531983d01 80258 bytes
C:\DOCUME~1\Florian\LOCALS~1\APPLIC~1\Mozilla\Firefox\Profiles\z222hf83.default\Cache\A8AEC5FAd01 30191 bytes
C:\DOCUME~1\Florian\LOCALS~1\APPLIC~1\Mozilla\Firefox\Profiles\z222hf83.default\Cache\7FC91319d01 28449 bytes
C:\DOCUME~1\Florian\LOCALS~1\APPLIC~1\Mozilla\Firefox\Profiles\z222hf83.default\Cache\5E9BB88Cd01 36156 bytes
C:\DOCUME~1\Florian\LOCALS~1\APPLIC~1\Mozilla\Firefox\Profiles\z222hf83.default\Cache\5E9DB88Cd01 32230 bytes
C:\DOCUME~1\Florian\LOCALS~1\APPLIC~1\Mozilla\Firefox\Profiles\z222hf83.default\Cache\33828438d01 42683 bytes
C:\DOCUME~1\Florian\LOCALS~1\APPLIC~1\Mozilla\Firefox\Profiles\z222hf83.default\Cache\9113BFCFd01 64132 bytes
C:\DOCUME~1\Florian\LOCALS~1\APPLIC~1\Mozilla\Firefox\Profiles\z222hf83.default\Cache\E0A649DAd01 25087 bytes
scan completed successfully
hidden processes: 0
hidden files: 40
--------------------\\ Recherche d'autres infections
Aucune autre infection trouvée !
[F:90][D:8]-> C:\DOCUME~1\Florian\LOCALS~1\Temp
[F:29][D:0]-> C:\DOCUME~1\Florian\Cookies
[F:732][D:4]-> C:\DOCUME~1\Florian\LOCALS~1\TEMPOR~1\content.IE5
1 - "C:\Lop SD\LopR_1.txt" - 05/11/2008|20:07 - Option : [1]
2 - "C:\Lop SD\LopR_2.txt" - 08/11/2008|10:54 - Option : [2]
--------------------\\ Fin du rapport a 10:54:13
Voici le rapport :
--------------------\\ Lop S&D 4.2.4-9c XP/Vista
Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 2
X86-based PC ( Multiprocessor Free : Genuine Intel(R) CPU T2060 @ 1.60GHz )
BIOS : Phoenix NoteBIOS 4.0 Release 6.1
USER : Florian ( Administrator )
BOOT : Normal boot
Antivirus : Avira AntiVir PersonalEdition 8.0.1.30 (Activated)
C:\ (Local Disk) - NTFS - Total:73 Go (Free:57 Go)
D:\ (CD or DVD)
"C:\Lop SD" ( MAJ : 01-11-2008|16:30 )
Option : [2] ( 08/11/2008|10:51 )
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ SUPPRESSION
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\Long slow road itch\Bits start.exe
Supprime! - C:\Program Files\Circle Developement\Uninstall.exe
Supprime! - C:\DOCUME~1\Florian\Cookies\florian@bigpoint[1].txt
Supprime! - C:\DOCUME~1\Florian\Cookies\florian@fr1.darkorbit.bigpoint[1].txt
Supprime! - C:\DOCUME~1\Florian\Cookies\florian@adopt.euroclick[2].txt
Supprime! - C:\DOCUME~1\Florian\Cookies\florian@pacificpoker[1].txt
Supprime! - C:\WINDOWS\Tasks\A4FF41879184FBF3.job
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\Long slow road itch
Supprime! - C:\DOCUME~1\Florian\APPLIC~1\Peak Dead Date
Supprime! - C:\Program Files\Peak Dead Date
Supprime! - C:\Program Files\Circle Developement
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
--------------------\\ Listing des dossiers dans APPLIC~1
[21/03/2008|17:05] C:\DOCUME~1\ADMINI~1\APPLIC~1\Microsoft
[30/06/2008|11:59] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
[30/06/2008|11:59] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[21/03/2008|18:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Atheros
[27/06/2008|11:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Avira
[21/03/2008|18:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Bluebeam Software
[29/03/2008|12:08] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Grisoft
[09/07/2008|19:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Installations
[30/03/2008|13:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ktghsbij
[26/03/2008|21:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
[08/11/2008|10:46] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Logishrd
[16/08/2008|11:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Logitech
[30/03/2008|16:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Malwarebytes
[22/03/2008|17:40] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!
[17/04/2008|11:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[20/06/2008|12:42] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft Help
[11/05/2008|10:11] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Nokia
[02/07/2008|18:23] C:\DOCUME~1\ALLUSE~1\APPLIC~1\OrbNetworks
[17/04/2008|11:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\PC Suite
[22/03/2008|13:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Sony Ericsson
[26/03/2008|21:15] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
[26/03/2008|20:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
[17/04/2008|12:53] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[22/03/2008|10:57] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
[21/03/2008|17:05] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
[10/07/2008|16:31] C:\DOCUME~1\Florian\APPLIC~1\Adobe
[05/04/2008|20:34] C:\DOCUME~1\Florian\APPLIC~1\Ambient Design
[30/06/2008|12:04] C:\DOCUME~1\Florian\APPLIC~1\Apple Computer
[21/04/2008|11:41] C:\DOCUME~1\Florian\APPLIC~1\Google
[07/05/2008|14:33] C:\DOCUME~1\Florian\APPLIC~1\Grisoft
[21/03/2008|17:48] C:\DOCUME~1\Florian\APPLIC~1\Help
[21/03/2008|17:12] C:\DOCUME~1\Florian\APPLIC~1\Identities
[21/03/2008|18:03] C:\DOCUME~1\Florian\APPLIC~1\InstallShield
[16/08/2008|11:17] C:\DOCUME~1\Florian\APPLIC~1\Leadertech
[19/08/2008|11:57] C:\DOCUME~1\Florian\APPLIC~1\LimeWire
[22/03/2008|11:34] C:\DOCUME~1\Florian\APPLIC~1\Macromedia
[30/03/2008|16:37] C:\DOCUME~1\Florian\APPLIC~1\Malwarebytes
[15/08/2008|16:40] C:\DOCUME~1\Florian\APPLIC~1\Microsoft
[18/06/2008|19:31] C:\DOCUME~1\Florian\APPLIC~1\Mozilla
[21/03/2008|21:16] C:\DOCUME~1\Florian\APPLIC~1\MSNInstaller
[17/04/2008|14:29] C:\DOCUME~1\Florian\APPLIC~1\Nokia
[09/07/2008|20:19] C:\DOCUME~1\Florian\APPLIC~1\Nokia Multimedia Player
[11/05/2008|10:28] C:\DOCUME~1\Florian\APPLIC~1\PC Suite
[04/07/2008|18:04] C:\DOCUME~1\Florian\APPLIC~1\RetinaX
[21/03/2008|18:32] C:\DOCUME~1\Florian\APPLIC~1\SolidWorks
[06/07/2008|16:15] C:\DOCUME~1\Florian\APPLIC~1\Sun
[17/04/2008|13:58] C:\DOCUME~1\Florian\APPLIC~1\vlc
[02/07/2008|17:05] C:\DOCUME~1\Florian\APPLIC~1\Winamp
[21/03/2008|17:05] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft
[21/03/2008|17:05] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft
--------------------\\ Tâches planifiées dans C:\WINDOWS\tasks
[21/08/2008 12:09][--a------] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[08/11/2008 10:43][--ah-----] C:\WINDOWS\tasks\SA.DAT
[30/08/2002 13:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini
--------------------\\ Listing des dossiers dans C:\Program Files
[30/03/2008|16:25] C:\Program Files\Alwil Software
[05/04/2008|20:17] C:\Program Files\Ambient Design
[30/06/2008|11:59] C:\Program Files\Apple Software Update
[21/03/2008|18:50] C:\Program Files\Atheros
[21/03/2008|17:46] C:\Program Files\ATI Technologies
[17/07/2008|09:16] C:\Program Files\Audacity
[27/06/2008|11:48] C:\Program Files\Avira
[02/04/2008|14:47] C:\Program Files\AviSynth 2.5
[21/03/2008|18:29] C:\Program Files\Bluebeam Software
[22/07/2008|12:32] C:\Program Files\Capturino 1.4
[30/03/2008|19:16] C:\Program Files\CCleaner
[21/03/2008|17:01] C:\Program Files\ComPlus Applications
[02/04/2008|16:30] C:\Program Files\Conduit
[16/04/2008|17:46] C:\Program Files\DIFX
[25/07/2008|20:42] C:\Program Files\eMule
[02/04/2008|14:47] C:\Program Files\eRightSoft
[15/08/2008|16:40] C:\Program Files\Fichiers communs
[17/07/2008|09:37] C:\Program Files\Free Audio Pack
[06/05/2008|21:35] C:\Program Files\FusionSoft DVD Player XP
[21/04/2008|11:40] C:\Program Files\Google
[07/05/2008|14:32] C:\Program Files\Grisoft
[10/04/2008|11:48] C:\Program Files\GT Interactive
[16/08/2008|11:18] C:\Program Files\InstallShield Installation Information
[20/06/2008|12:44] C:\Program Files\Internet Explorer
[30/03/2008|19:46] C:\Program Files\IVCsoft
[20/07/2008|09:39] C:\Program Files\Java
[16/08/2008|11:13] C:\Program Files\Labtec
[20/06/2008|15:17] C:\Program Files\Lavalys
[26/03/2008|21:28] C:\Program Files\Lavasoft
[04/07/2008|11:14] C:\Program Files\LimeWire
[16/08/2008|11:18] C:\Program Files\Logitech
[21/03/2008|18:01] C:\Program Files\ltmoh
[02/04/2008|16:30] C:\Program Files\Magic-Radio
[30/03/2008|16:37] C:\Program Files\Malwarebytes' Anti-Malware
[02/07/2008|16:42] C:\Program Files\MediaMonkey
[02/04/2008|20:38] C:\Program Files\Messenger
[30/08/2008|18:55] C:\Program Files\Messenger Plus! Live
[21/03/2008|17:06] C:\Program Files\microsoft frontpage
[21/03/2008|18:41] C:\Program Files\Microsoft Office
[21/03/2008|18:40] C:\Program Files\Microsoft Visual Studio
[21/03/2008|18:41] C:\Program Files\Microsoft Works
[21/03/2008|17:03] C:\Program Files\Movie Maker
[08/11/2008|10:46] C:\Program Files\Mozilla Firefox
[15/06/2008|10:32] C:\Program Files\mp3DirectCut
[21/03/2008|18:41] C:\Program Files\MSBuild
[21/03/2008|21:16] C:\Program Files\MSN
[21/03/2008|17:01] C:\Program Files\MSN Gaming Zone
[02/04/2008|15:53] C:\Program Files\MSXML 4.0
[11/05/2008|10:11] C:\Program Files\MSXML 6.0
[21/03/2008|17:03] C:\Program Files\NetMeeting
[09/07/2008|19:20] C:\Program Files\Nokia
[21/03/2008|17:01] C:\Program Files\Online Services
[02/04/2008|20:38] C:\Program Files\Outlook Express
[16/04/2008|17:46] C:\Program Files\PC Connectivity Solution
[04/07/2008|17:46] C:\Program Files\PC Health Optimizer Free Edition
[17/04/2008|18:09] C:\Program Files\PhotoFiltre
[30/06/2008|12:00] C:\Program Files\QuickTime
[21/03/2008|17:52] C:\Program Files\Realtek
[21/03/2008|17:04] C:\Program Files\Services en ligne
[05/11/2008|20:01] C:\Program Files\Sim AQUARIUM 2
[04/11/2008|19:59] C:\Program Files\SolidWorks
[09/07/2008|15:17] C:\Program Files\SpeedFan
[26/03/2008|20:13] C:\Program Files\Spybot - Search & Destroy
[04/07/2008|11:18] C:\Program Files\Sun
[30/03/2008|19:10] C:\Program Files\Trend Micro
[21/03/2008|17:12] C:\Program Files\Uninstall Information
[18/04/2008|20:33] C:\Program Files\Valve Lan
[17/04/2008|13:55] C:\Program Files\VideoLAN
[17/07/2008|09:10] C:\Program Files\VirtualDJ
[02/07/2008|16:48] C:\Program Files\Winamp
[02/07/2008|16:46] C:\Program Files\Winamp Remote
[28/03/2008|18:54] C:\Program Files\Windows Live
[08/04/2008|11:08] C:\Program Files\Windows Media Connect 2
[08/04/2008|11:08] C:\Program Files\Windows Media Player
[21/03/2008|17:01] C:\Program Files\Windows NT
[21/03/2008|17:04] C:\Program Files\WindowsUpdate
[21/03/2008|17:06] C:\Program Files\xerox
--------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs
[21/03/2008|18:29] C:\Program Files\Fichiers communs\Bluebeam Software
[21/03/2008|18:25] C:\Program Files\Fichiers communs\Designer
[22/03/2008|13:13] C:\Program Files\Fichiers communs\InstallShield
[04/07/2008|11:16] C:\Program Files\Fichiers communs\Java
[15/08/2008|16:40] C:\Program Files\Fichiers communs\Labtec
[16/08/2008|11:18] C:\Program Files\Fichiers communs\LogiShrd
[11/05/2008|10:09] C:\Program Files\Fichiers communs\Microsoft Shared
[21/03/2008|17:03] C:\Program Files\Fichiers communs\MSSoap
[09/07/2008|19:18] C:\Program Files\Fichiers communs\Nokia
[21/03/2008|17:52] C:\Program Files\Fichiers communs\ODBC
[16/04/2008|17:47] C:\Program Files\Fichiers communs\PCSuite
[21/03/2008|17:03] C:\Program Files\Fichiers communs\Services
[21/03/2008|18:20] C:\Program Files\Fichiers communs\Solidworks Data
[21/03/2008|18:26] C:\Program Files\Fichiers communs\SolidWorks Shared
[21/03/2008|17:52] C:\Program Files\Fichiers communs\SpeechEngines
[02/04/2008|20:38] C:\Program Files\Fichiers communs\System
[22/03/2008|13:14] C:\Program Files\Fichiers communs\Teleca Shared
[10/07/2008|16:21] C:\Program Files\Fichiers communs\Vbox
[22/03/2008|10:58] C:\Program Files\Fichiers communs\WindowsLiveInstaller
[26/03/2008|21:27] C:\Program Files\Fichiers communs\Wise Installation Wizard
--------------------\\ Process
( 51 Processes )
... OK !
--------------------\\ Recherche avec S_Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Recherche de Fichiers / Dossiers Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Verification du Registre
..... OK !
--------------------\\ Verification du fichier Hosts
Fichier Hosts PROPRE
--------------------\\ Recherche de fichiers avec Catchme
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-08 10:52:37
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden files ...
C:\DOCUME~1\Florian\LOCALS~1\APPLIC~1\Mozilla\Firefox\Profiles\z222hf83.default\Cache\0E531983d01 80258 bytes
C:\DOCUME~1\Florian\LOCALS~1\APPLIC~1\Mozilla\Firefox\Profiles\z222hf83.default\Cache\A8AEC5FAd01 30191 bytes
C:\DOCUME~1\Florian\LOCALS~1\APPLIC~1\Mozilla\Firefox\Profiles\z222hf83.default\Cache\7FC91319d01 28449 bytes
C:\DOCUME~1\Florian\LOCALS~1\APPLIC~1\Mozilla\Firefox\Profiles\z222hf83.default\Cache\5E9BB88Cd01 36156 bytes
C:\DOCUME~1\Florian\LOCALS~1\APPLIC~1\Mozilla\Firefox\Profiles\z222hf83.default\Cache\5E9DB88Cd01 32230 bytes
C:\DOCUME~1\Florian\LOCALS~1\APPLIC~1\Mozilla\Firefox\Profiles\z222hf83.default\Cache\33828438d01 42683 bytes
C:\DOCUME~1\Florian\LOCALS~1\APPLIC~1\Mozilla\Firefox\Profiles\z222hf83.default\Cache\9113BFCFd01 64132 bytes
C:\DOCUME~1\Florian\LOCALS~1\APPLIC~1\Mozilla\Firefox\Profiles\z222hf83.default\Cache\E0A649DAd01 25087 bytes
scan completed successfully
hidden processes: 0
hidden files: 40
--------------------\\ Recherche d'autres infections
Aucune autre infection trouvée !
[F:90][D:8]-> C:\DOCUME~1\Florian\LOCALS~1\Temp
[F:29][D:0]-> C:\DOCUME~1\Florian\Cookies
[F:732][D:4]-> C:\DOCUME~1\Florian\LOCALS~1\TEMPOR~1\content.IE5
1 - "C:\Lop SD\LopR_1.txt" - 05/11/2008|20:07 - Option : [1]
2 - "C:\Lop SD\LopR_2.txt" - 08/11/2008|10:54 - Option : [2]
--------------------\\ Fin du rapport a 10:54:13
le voila :
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:53:57, on 08/11/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Winamp Remote\bin\OrbTray.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\WINDOWS\system32\acs.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Documents and Settings\Florian\Bureau\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Orb] "C:\Program Files\Winamp Remote\bin\OrbTray.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/Install...
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Service de configuration Atheros (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
--
End of file - 7669 bytes
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:53:57, on 08/11/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Winamp Remote\bin\OrbTray.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\WINDOWS\system32\acs.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Documents and Settings\Florian\Bureau\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Orb] "C:\Program Files\Winamp Remote\bin\OrbTray.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/Install...
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Service de configuration Atheros (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
--
End of file - 7669 bytes
Re,
Télécharge MalwareByte's Anti-Malware sur ton Bureau.
Installe-le en double-cliquant sur le fichier Download_mbam-setup.exe.
Une fois l'installation et la mise à jour effectuées, redémarre en mode sans échec.
AIDE : Redémarrer en mode sans échec
Exécute maintenant MalwareByte's Anti-Malware. Si cela n'est pas déjà fait, sélectionne "Exécuter un examen complet".
Afin de lancer la recherche, clic sur"Rechercher".
Une fois le scan terminé, une fenêtre s'ouvre, clic sur OK. Deux possibilités s'offrent à toi :
-- si le programme n'a rien trouvé, appuie sur OK. Un rapport va apparaître, ferme-le.
-- si des infections sont présentes, clic sur "Afficher les résultats" puis sur "Supprimer la sélection". Enregistre le rapport sur ton Bureau afin de le poster dans ta prochaine réponse.
[#ff0000]REMARQUE : Si MalwareByte's Anti-Malware a besoin de redémarrer pour terminer la suppression, accepte en cliquant sur Ok.[/#f]
AIDE : Tuto en images sur MBAM
Télécharge MalwareByte's Anti-Malware sur ton Bureau.
Installe-le en double-cliquant sur le fichier Download_mbam-setup.exe.
Une fois l'installation et la mise à jour effectuées, redémarre en mode sans échec.
AIDE : Redémarrer en mode sans échec
-- si le programme n'a rien trouvé, appuie sur OK. Un rapport va apparaître, ferme-le.
-- si des infections sont présentes, clic sur "Afficher les résultats" puis sur "Supprimer la sélection". Enregistre le rapport sur ton Bureau afin de le poster dans ta prochaine réponse.
[#ff0000]REMARQUE : Si MalwareByte's Anti-Malware a besoin de redémarrer pour terminer la suppression, accepte en cliquant sur Ok.[/#f]
AIDE : Tuto en images sur MBAM
euh j'ai un problème c'est que lorsque j'apui sur F5, il me lance un truc qui est bleu claire et bleu foncé et c'est écrit en haut "phoenixBIOS setup utility" or qu'avant, il ne m'écrivait pas sa.
sa m'écrivait un menu ou je pouvais choisir le mode sans echec.
je ne peut donc pas redémarrer en mode sans echec du moins je n'arrive pas a redémarrer en mode sans echec.
merci pour toutes tes réponses
sa m'écrivait un menu ou je pouvais choisir le mode sans echec.
je ne peut donc pas redémarrer en mode sans echec du moins je n'arrive pas a redémarrer en mode sans echec.
merci pour toutes tes réponses
Il y avait des infections donc je poste le rapport :
Malwarebytes' Anti-Malware 1.30
Version de la base de données: 1373
Windows 5.1.2600 Service Pack 2
09/11/2008 10:59:42
mbam-log-2008-11-09 (10-59-42).txt
Type de recherche: Examen complet (C:\|)
Eléments examinés: 92819
Temps écoulé: 2 hour(s), 33 minute(s), 24 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 5
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 1
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 1
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{9034a523-d068-4be8-a284-9df278be776e} (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3084a75f-5350-4d8b-bc5f-6b378035c133} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{7c109800-a5d5-438f-9640-18d17e168b88} (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{db9fba9d-ab1b-4cc6-9745-f3b549d64e40} (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{74f7db6b-86e9-4b91-9d9f-b0d954d7aa5b} (Trojan.Zlob) -> Quarantined and deleted successfully.
Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Elément(s) de données du Registre infecté(s):
HKEY_CLASSES_ROOT\regfile\shell\open\command\ (Broken.OpenCommand) -> Bad: (regedit.exe"%1" %*) Good: (regedit.exe "%1") -> Quarantined and deleted successfully.
Dossier(s) infecté(s):
(Aucun élément nuisible détecté)
Fichier(s) infecté(s):
C:\xmp.bat (Trojan.Downloader) -> Quarantined and deleted successfully.
Malwarebytes' Anti-Malware 1.30
Version de la base de données: 1373
Windows 5.1.2600 Service Pack 2
09/11/2008 10:59:42
mbam-log-2008-11-09 (10-59-42).txt
Type de recherche: Examen complet (C:\|)
Eléments examinés: 92819
Temps écoulé: 2 hour(s), 33 minute(s), 24 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 5
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 1
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 1
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{9034a523-d068-4be8-a284-9df278be776e} (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3084a75f-5350-4d8b-bc5f-6b378035c133} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{7c109800-a5d5-438f-9640-18d17e168b88} (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{db9fba9d-ab1b-4cc6-9745-f3b549d64e40} (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{74f7db6b-86e9-4b91-9d9f-b0d954d7aa5b} (Trojan.Zlob) -> Quarantined and deleted successfully.
Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Elément(s) de données du Registre infecté(s):
HKEY_CLASSES_ROOT\regfile\shell\open\command\ (Broken.OpenCommand) -> Bad: (regedit.exe"%1" %*) Good: (regedit.exe "%1") -> Quarantined and deleted successfully.
Dossier(s) infecté(s):
(Aucun élément nuisible détecté)
Fichier(s) infecté(s):
C:\xmp.bat (Trojan.Downloader) -> Quarantined and deleted successfully.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:56:01, on 09/11/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Winamp Remote\bin\OrbTray.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\WINDOWS\system32\acs.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Florian\Bureau\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Orb] "C:\Program Files\Winamp Remote\bin\OrbTray.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/Install...
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Service de configuration Atheros (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
--
End of file - 7713 bytes
Scan saved at 18:56:01, on 09/11/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Winamp Remote\bin\OrbTray.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\WINDOWS\system32\acs.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Florian\Bureau\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Orb] "C:\Program Files\Winamp Remote\bin\OrbTray.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/Install...
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Service de configuration Atheros (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
--
End of file - 7713 bytes
Lassé par la pub ? Créez un compte
- Contenus similaires :
Tags :
- ForumSpyware right media
- ForumEliminer right media
- ForumRight media virus
- ForumSupprimer définitivement right media
- ForumVirus right media
- ForumRight media supprimer
- ForumQu est ce que right media
- ForumComment retirer right media
- ForumComment se debarrasser de right media
- ForumSpybot right media
- Voir plus