Gigatoaster Posté(e) le 19 juin 2008 Partager Posté(e) le 19 juin 2008 Bonjour Suite à ce post (pb de trojan), on m'a dit de poster ici un log, le voici le voila : Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 15:15:43, on 19/06/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16674) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Intel\Wireless\Bin\EvtEng.exe C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program Files\ASUS\Wireless Console\wcourier.exe C:\Program Files\Synaptics\SynTP\SynTPLpr.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe C:\WINDOWS\ATK0100\HControl.exe C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe C:\WINDOWS\ATK0100\ATKOSD.exe C:\Program Files\Fichiers communs\EPSON\EBAPI\eEBSVC.exe C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe C:\WINDOWS\system32\cisvc.exe C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\cidaemon.exe C:\WINDOWS\system32\cidaemon.exe C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = escamote:3128 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O4 - HKLM\..\Run: [Wireless Console] C:\Program Files\ASUS\Wireless Console\wcourier.exe O4 - HKLM\..\Run: [synTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe O4 - HKLM\..\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [Power_Gear] C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe 1 O4 - HKLM\..\Run: [intelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" O4 - HKLM\..\Run: [intelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless O4 - HKLM\..\Run: [HControl] C:\WINDOWS\ATK0100\HControl.exe O4 - HKLM\..\Run: [EOUApp] "C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe" O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" O4 - HKLM\..\Run: [EPSON Stylus CX3200] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P19 "EPSON Stylus CX3200" /O6 "USB001" /M "Stylus CX3200" O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: Bluetooth Manager.lnk = ? O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra button: Antivirus Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O14 - IERESET.INF: START_PAGE_URL=http://www.asus.com O16 - DPF: {05D96F71-87C6-11D3-9BE4-00902742D6E0} (QuickPlace Class) - http://didagora.esc-rennes.fr/qp2.cab O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15030/CTSUEng.cab O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} - http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab O16 - DPF: {3451DEDE-631F-421C-8127-FD793AFC6CC8} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab O16 - DPF: {44990200-3C9D-426D-81DF-AAB636FA4345} (Symantec SmartIssue) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1151699783843 O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15030/CTPID.cab O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program Files\Fichiers communs\EPSON\EBAPI\eEBSVC.exe O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe O23 - Service: FreePOPs - Unknown owner - C:\Program Files\FreePOPs\freepopsservice.exe (file missing) O23 - Service: MMDK - Unknown owner - C:\DOCUME~1\GIGATO~1\LOCALS~1\Temp\MMDK.exe (file missing) O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe -- End of file - 8136 bytes Lien vers le commentaire Partager sur d’autres sites More sharing options...
snooky Posté(e) le 19 juin 2008 Auteur Partager Posté(e) le 19 juin 2008 services.msc dans Exécuter , désactive ce service , si présent : O23 - Service: MMDK - Unknown owner - C:\DOCUME~1\GIGATO~1\LOCALS~1\Temp\MMDK.exe (file missing) Lance Clean v2.0 by FRUiT , procédure 1. Désinstalle ta version de Kaspersky . Installe celle là et lance une analyse complète : ( coche Riskwares ) http://telecharger.kaspersky.fr/kavkis7/kav7.0.1.325fr.exe Lien vers le commentaire Partager sur d’autres sites More sharing options...
snooky Posté(e) le 19 juin 2008 Auteur Partager Posté(e) le 19 juin 2008 De Ben1610: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 18:07:38, on 19/06/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16674) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Acer\Acer eConsole\MediaServerService.exe C:\WINDOWS\ATKKBService.exe C:\Program Files\Acer TV-FM\Kernel\TV\CLCapSvc.exe C:\Program Files\Acer TV-FM\Kernel\CLML_NTService\CLMLServer.exe C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Program Files\CDBurnerXP\NMSAccessU.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\PnkBstrA.exe C:\WINDOWS\system32\PnkBstrB.exe C:\WINDOWS\System32\PAStiSvc.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Acer TV-FM\Kernel\TV\CLSched.exe C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\WINDOWS\RTHDCPL.EXE C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe C:\WINDOWS\system32\ctfmon.exe C:\Acer\Empowering Technology\eRecovery\Monitor.exe C:\Program Files\Acer\Acer eMode Management\AspireService.exe C:\Program Files\Acer\Acer eConsole\MediaSync.exe C:\Program Files\Acer TV-FM\PCMService.exe C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe C:\Program Files\D-Link\D-Link Wireless N DWA-140\AirNCFG.exe C:\Program Files\Fichiers communs\ErreurChasseur\strpmon.exe C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe C:\Program Files\ASUS\GamerOSD\GamerOSD.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\Windows Live\Messenger\usnsvc.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Windows Media Player\wmplayer.exe C:\WINDOWS\System32\svchost.exe C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files\Kaspersky Anti-Virus 7.0.1.325\French\setup.exe C:\Documents and Settings\benoit\Bureau\HiJackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.daemon-search.com/default R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://resultsmaster.com/SmartOffers/Servi...omeLeftPane.htm R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.fr.msn.be/0SEFRBE/SAOS01?FORM=TOOLBR R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens R3 - URLSearchHook: (no name) - {9CB65206-89C4-402c-BA80-02D8C59F9B1D} - C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: Search Assistant - {1648E328-3E5A-4EA5-A9C6-E5F09EE272DA} - C:\WINDOWS\system32\adssite_sidebar.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Mirar - {9A9C9B69-F908-4AAB-8D0C-10EA8997F37E} - C:\WINDOWS\system32\version69ie7fix.dll O2 - BHO: Ask Search Assistant BHO - {9CB65201-89C4-402c-BA80-02D8C59F9B1D} - C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll O2 - BHO: DbarBHO - {CC11617C-259E-429c-9063-7D70B8355EBD} - C:\Program Files\dbar\Deskbar.dll O2 - BHO: IEHlprObj Class - {F62A47A7-4CA3-9D00-95A3-6724d43a9E8C} - LineAudio.dll (file missing) O2 - BHO: Ask Toolbar BHO - {FE063DB1-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll O3 - Toolbar: Ask Toolbar - {FE063DB9-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL O3 - Toolbar: Mirar - {9A9C9B68-F908-4AAB-8D0C-10EA8997F37E} - C:\WINDOWS\system32\version69ie7fix.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll O4 - HKLM\..\Run: [LaunchApp] Alaunch O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE O4 - HKLM\..\Run: [ntiMUI] c:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" O4 - HKLM\..\Run: [iMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\Monitor.exe O4 - HKLM\..\Run: [AspireService] C:\Program Files\Acer\Acer eMode Management\AspireService.exe O4 - HKLM\..\Run: [MediaSync] C:\Program Files\Acer\Acer eConsole\MediaSync.exe O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Acer TV-FM\PCMService.exe" O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe O4 - HKLM\..\Run: [D-Link D-Link Wireless N DWA-140] C:\Program Files\D-Link\D-Link Wireless N DWA-140\AirNCFG.exe O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" O4 - HKLM\..\Run: [salestart] "C:\Program Files\Fichiers communs\ErreurChasseur\strpmon.exe" dm=http://erreurchasseur.com ad=http://erreurchasseur.com sd=http://repay.erreurchasseur.com O4 - HKLM\..\Run: [GameXL] "C:\Program Files\Game Accelerator\gamexl.exe" O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" O4 - HKLM\..\Run: [dbar_starter] C:\Documents and Settings\benoit\Application Data\Deskbar_{387FE8CE-22C5-4d48-BDBC-8B41A3B2653C}\starter.exe O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [ASUSGamerOSD] C:\Program Files\ASUS\GamerOSD\GamerOSD.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Nero\Lib\NMBgMonitor.exe" O4 - HKCU\..\Run: [WinUpdater] "C:\Program Files\winvi\update.exe" /background O4 - HKCU\..\Run: [WebSUpdater] "C:\Program Files\winvi\wupda.exe" /background O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun O4 - HKCU\..\Run: [ASUS SmartDoctor] C:\Program Files\ASUS\SmartDoctor\SmartDoctor.exe /start O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Global Startup: Lancement rapide de Microsoft Office OneNote 2003.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/...html?p=ZNfox000 O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-be\msntabres.dll.mui/229?752f93d6bfbc4e849616977ea521f549 O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-be\msntabres.dll.mui/230?752f93d6bfbc4e849616977ea521f549 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra button: (no name) - {85e1f530-48f4-11d9-9629-08ff2ffc9f67} - (no file) O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll O15 - Trusted Zone: http://click.getmirar.com (HKLM) O15 - Trusted Zone: http://click.mirarsearch.com (HKLM) O15 - Trusted Zone: http://redirect.mirarsearch.com (HKLM) O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM) O16 - DPF: {1F831FA7-42FC-11D4-95A6-0080AD30DCE1} (InstaFred) - file:///C:/Program%20Files/AutoCAD%20LT%202002%20Fra/InstFred.ocx O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-BE/a-UNO1/GAME_UNO1.cab O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} (Contrôle d'AcDcToday) - file:///C:/Program%20Files/AutoCAD%20LT%202002%20Fra/AcDcToday.ocx O16 - DPF: {AE563727-B4F5-11D4-A415-00108302FDFD} (NOXLATE-BANR) - file:///C:/Program%20Files/AutoCAD%20LT%202002%20Fra/InstBanr.ocx O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab57176.cab O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (Gestion d'AcPreview) - file:///C:/Program%20Files/AutoCAD%20LT%202002%20Fra/AcPreview.ocx O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab56986.cab O23 - Service: Acer Media Server - Acer Inc. - C:\Program Files\Acer\Acer eConsole\MediaServerService.exe O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Wireless Service - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\Acer TV-FM\Kernel\TV\CLCapSvc.exe O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\Acer TV-FM\Kernel\TV\CLSched.exe O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\Acer TV-FM\Kernel\CLML_NTService\CLMLServer.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe -- End of file - 14811 bytes Lien vers le commentaire Partager sur d’autres sites More sharing options...
snooky Posté(e) le 19 juin 2008 Auteur Partager Posté(e) le 19 juin 2008 @ Ben1610 : 1 / Désinstalle Avast via Ajout/suppr des programmes. 2/ Lance ce cleaner Avast : http://www.avast.com/fre/avast-uninstall-utility.html 3 /Coche et fixe ces lignes avec Hijackthis : R3 - URLSearchHook: (no name) - {9CB65206-89C4-402c-BA80-02D8C59F9B1D} - C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL O2 - BHO: Search Assistant - {1648E328-3E5A-4EA5-A9C6-E5F09EE272DA} - C:\WINDOWS\system32\adssite_sidebar.dll O2 - BHO: DbarBHO - {CC11617C-259E-429c-9063-7D70B8355EBD} - C:\Program Files\dbar\Deskbar.dll O2 - BHO: IEHlprObj Class - {F62A47A7-4CA3-9D00-95A3-6724d43a9E8C} - LineAudio.dll (file missing) O2 - BHO: Ask Toolbar BHO - {FE063DB1-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL O3 - Toolbar: Ask Toolbar - {FE063DB9-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL O3 - Toolbar: Mirar - {9A9C9B68-F908-4AAB-8D0C-10EA8997F37E} - C:\WINDOWS\system32\version69ie7fix.dll + toutes les lignes 04 ( j'ai bien dit TOUTES ! ) O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll O15 - Trusted Zone: http://click.getmirar.com (HKLM) O15 - Trusted Zone: http://click.mirarsearch.com (HKLM) O15 - Trusted Zone: http://redirect.mirarsearch.com (HKLM) O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM) O16 - DPF: {1F831FA7-42FC-11D4-95A6-0080AD30DCE1} (InstaFred) - file:///C:/Program%20Files/AutoCAD%20LT%202002%20Fra/InstFred.ocx O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-BE/a-UNO1/GAME_UNO1.cab O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} (Contrôle d'AcDcToday) - file:///C:/Program%20Files/AutoCAD%20LT%202002%20Fra/AcDcToday.ocx O16 - DPF: {AE563727-B4F5-11D4-A415-00108302FDFD} (NOXLATE-BANR) - file:///C:/Program%20Files/AutoCAD%20LT%202002%20Fra/InstBanr.ocx O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab57176.cab O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (Gestion d'AcPreview) - file:///C:/Program%20Files/AutoCAD%20LT%202002%20Fra/AcPreview.ocx O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab56986.cab 4/ Télécharge Clean de Malekal et redémarre en mode sans échec. http://www.malekal.com/download/clean.zip 5/ Lance Clean de Malekal , option 2 et poste le rapport créé. Lien vers le commentaire Partager sur d’autres sites More sharing options...
ben1610 Posté(e) le 19 juin 2008 Partager Posté(e) le 19 juin 2008 Rapport clean par Malekal_morte - http://www.malekal.com Script execute en mode sans echec jeu. 19/06/2008 a 18:50:58,17 Microsoft Windows XP [version 5.1.2600] *** Suppression des fichiers dans C: *** Suppression des fichiers dans C:\WINDOWS\ *** Suppression des fichiers dans C:\WINDOWS\system32 *** Suppression des fichiers dans C:\Program Files tentative de suppression de "C:\Program Files\AskTBar\" Impossible de supprimer "C:\Program Files\AskTBar\" tentative de suppression de "C:\Program Files\funwebproducts\" tentative de suppression de "C:\Program Files\MyWebSearch\" *** Suppression des clefs du registre effectuee.. *** Fin du rapport ! Lien vers le commentaire Partager sur d’autres sites More sharing options...
snooky Posté(e) le 19 juin 2008 Auteur Partager Posté(e) le 19 juin 2008 Lance CureIt de Dr Web : http://freedrweb.com/ Poste le rapport créé. Poste également un nouveau rapport Hijackthis . Lien vers le commentaire Partager sur d’autres sites More sharing options...
snooky Posté(e) le 20 juin 2008 Auteur Partager Posté(e) le 20 juin 2008 @ ben1610 : Poste un nouveau rapport Hijackthis. Lance ComboFix en mode sans échec et poste le rapport créé : http://download.bleepingcomputer.com/sUBs/ComboFix.exe Installe KAV v8 et lance une analyse complète : http://telecharger.kaspersky.fr/kavkis8/kav8.0.0.357fr.exe Lien vers le commentaire Partager sur d’autres sites More sharing options...
ben1610 Posté(e) le 20 juin 2008 Partager Posté(e) le 20 juin 2008 Rapport hijackthis: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 17:28:22, on 20/06/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16674) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Acer\Acer eConsole\MediaServerService.exe C:\WINDOWS\ATKKBService.exe C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe C:\Program Files\Acer TV-FM\Kernel\TV\CLCapSvc.exe C:\Program Files\Acer TV-FM\Kernel\CLML_NTService\CLMLServer.exe C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Program Files\CDBurnerXP\NMSAccessU.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\PnkBstrA.exe C:\WINDOWS\system32\PnkBstrB.exe C:\WINDOWS\System32\PAStiSvc.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Acer TV-FM\Kernel\TV\CLSched.exe C:\WINDOWS\Explorer.EXE C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe C:\Program Files\D-Link\D-Link Wireless N DWA-140\AirNCFG.exe C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\Program Files\Windows Live\Messenger\usnsvc.exe C:\Program Files\Windows Media Player\wmplayer.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\WISPTIS.EXE C:\Documents and Settings\benoit\Bureau\launch.exe C:\DOCUME~1\benoit\LOCALS~1\Temp\RarSFX0\_start.exe C:\DOCUME~1\benoit\LOCALS~1\Temp\RarSFX0\setup.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.daemon-search.com/default R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://resultsmaster.com/SmartOffers/Servi...omeLeftPane.htm R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.fr.msn.be/0SEFRBE/SAOS01?FORM=TOOLBR R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens R3 - URLSearchHook: (no name) - {9CB65206-89C4-402c-BA80-02D8C59F9B1D} - C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL (file missing) O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe O4 - HKLM\..\Run: [D-Link D-Link Wireless N DWA-140] C:\Program Files\D-Link\D-Link Wireless N DWA-140\AirNCFG.exe O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe" O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/...html?p=ZNfox000 O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-be\msntabres.dll.mui/229?752f93d6bfbc4e849616977ea521f549 O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-be\msntabres.dll.mui/230?752f93d6bfbc4e849616977ea521f549 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra button: Statistiques d’Anti-Virus Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll O9 - Extra button: (no name) - {85e1f530-48f4-11d9-9629-08ff2ffc9f67} - (no file) O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll O23 - Service: Acer Media Server - Acer Inc. - C:\Program Files\Acer\Acer eConsole\MediaServerService.exe O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Wireless Service - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe O23 - Service: Kaspersky Anti-Virus 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\Acer TV-FM\Kernel\TV\CLCapSvc.exe O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\Acer TV-FM\Kernel\TV\CLSched.exe O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\Acer TV-FM\Kernel\CLML_NTService\CLMLServer.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe -- End of file - 8071 bytes Lien vers le commentaire Partager sur d’autres sites More sharing options...
snooky Posté(e) le 20 juin 2008 Auteur Partager Posté(e) le 20 juin 2008 ... Tu fais toujours tout dans le désordre ? Coche et fixe cette ligne : R3 - URLSearchHook: (no name) - {9CB65206-89C4-402c-BA80-02D8C59F9B1D} - C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL (file missing) Créer un rapport GSI et donne le lien Web de ce rapport : http://gsi.kaspersky.fr/ Lien vers le commentaire Partager sur d’autres sites More sharing options...
ben1610 Posté(e) le 20 juin 2008 Partager Posté(e) le 20 juin 2008 ben heu celui la a été plus vite que l'autre dc je lais deja poster et l'autre es tj en cour Lien vers le commentaire Partager sur d’autres sites More sharing options...
snooky Posté(e) le 21 juin 2008 Auteur Partager Posté(e) le 21 juin 2008 :copain: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 03:23:49, on 21/06/2008 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16674) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe C:\Program Files\UPHClean\uphclean.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Hijackthis\HiJackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://elsap1.unicaen.fr/cgi-bin/cherches.cgi R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" O8 - Extra context menu item: Ajouter à Kaspersky Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll,C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll,C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe -- End of file - 1723 bytes ... il y a quelques programmes installés quand même : µTorrent 7-Zip 4.57 Adobe Flash Player ActiveX Adobe Flash Player Plugin Adobe Shockwave Player Adobe Shockwave Player 11 AlerteGPS G300 Apple Mobile Device Support Apple Software Update ArcSoft Panorama Maker 3 Aspell French Dictionary-0.50-3 AutoIt v3.2.10.0 Barbie® Super Sports Bibliothèques GTK+ 2.12.8 rev a (supprimer uniquement) Camtasia Studio 5 Canon i550 CCleaner (remove only) Client Windows Rights Management avec Service Pack 2 CloneCD Cloneur Expert Codeur Windows Media Série 9 CrossLoop 2.02 mod UltraVNC Debug Diagnostics Tool 1.1 (x86) Debugging Tools for Windows DeepBurner v1.8.0.224 DiscScanX v. 1.0.4.0 DivX Web Player Dora l'exploratrice : Les animaux de la jungle DVD Decoder Pak for Windows XP Easy Avi/Divx/Xvid to DVD Burner 2.4.6 EMCO MSI Package Builder Enable S3 for USB Device EnvoiFTP Eusing Free Registry Cleaner FairUse Wizard 2 ffdshow [rev 1650] [2007-11-28] FileZilla Client 3.0.5 Flash This FLIQLO Screen Saver Foxit Reader Free CD-DA Extractor FreeUndelete Freez FLV to MP3 Converter Gadwin PrintScreen Galerie de photos Windows Live GNU Aspell 0.50-3 GPL Ghostscript 8.61 GPL Ghostscript Fonts HiDownload HijackThis 2.0.2 Hijackthis Version Française HP USB Disk Storage Format Tool IconPackager Inkscape 0.45+0.46pre3 IrfanView (remove only) IsoBuster 2.3 iTunes Java 6 Update 10 Jing Kaspersky Internet Security 2009 KC Softwares IDPhotoStudio KC Softwares SUMo Le Monde de Nemo Lecteur Windows Media 11 Les Sims 2 Les Sims Superstar Les Sims⢠2 Bon Voyage Link200 v3.2 Malwarebytes' Anti-Malware Microsoft .NET Compact Framework 2.0 SP2 Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Hotfix (KB928366) Microsoft .NET Framework 2.0 Service Pack 1 Microsoft .NET Framework 2.0 Service Pack 1 Language Pack - FRA Microsoft .NET Framework 3.0 Service Pack 1 Microsoft .NET Framework 3.0 Service Pack 1 Language Pack - FRA Microsoft Bootvis Microsoft Office PowerPoint Viewer 2007 (French) Microsoft Office Publisher 2007 Microsoft Office XP Professional avec FrontPage Microsoft Silverlight Microsoft Software Update for Web Folders (French) 12 Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft Visual C++ 2005 Redistributable Microsoft Windows Media Video 9 VCM Microsoft XML Parser Mise à jour de logiciel pour les Dossiers Web Mozilla Firefox (3.0) MRU-Blaster v1.5 (Database 3/28/2004) MSXML 4.0 SP2 (KB927978) MSXML 4.0 SP2 (KB936181) MSXML 4.0 SP2 Parser and SDK MSXML 6.0 Parser (KB933579) My Drive Meter Nikon Message Center NTREGOPT 1.1j NVIDIA Drivers OE-QuoteFix OE-Tweak PartitionMagic PDFCreator PDFCreator Toolbar PDF-XChange PDF Viewer PhotoFiltre Picasa 2 Pidgin PL-2303 USB-to-Serial Pochette Express 2 PowerISO PowerQuest PartitionMagic 8.0 pyGrenouille 1.13 beta 4 Quicksys RegDefrag 1.3 QuickTime Real Alternative 1.7.5 Realtek AC'97 Audio REALTEK GbE & FE Ethernet PCI NIC Driver RTLSetup Runtimes 2.0.0 sala's WinXP SP2 Terminal Server Patch Scan2PDF 1.4 Scribus 1.3.3.11 StuffPlug 3 SUPER © Version 2008.bld.25 (Feb 5, 2008) Super Turbo Tango Patcher 7.08.2 TeamViewer 3 The KMPlayer v2.9.3.1359 FR TheWesterner Ulead COOL 360 1.0 Ulead COOL 360 Viewer Plugin Uniblue RegistryBooster 2 Universal Extractor 1.6 beta Unlocker 1.8.5 Url inspecteur 1.0 User Profile Hive Cleanup Service VideoLAN VLC media player 0.8.6d Virtual Desktop Manager Powertoy for Windows XP Virtual VCR VirtuaWin v4.0 VistaBootPRO 3.3 WebFldrs XP Windows Installer Clean Up Windows Live installer Windows Live Messenger Windows Live Sign-in Assistant Windows Live Writer Windows Media Format 11 runtime Windows Media Format 11 SDK Windows Media Player 9 Series Power Toy - Ratings Migration Windows Media Player Firefox Plugin Windows XP Service Pack 3 WinImage WinRAR archiver WPanorama xp-AntiSpy 3.96-8 Lien vers le commentaire Partager sur d’autres sites More sharing options...
freeman27 Posté(e) le 21 juin 2008 Partager Posté(e) le 21 juin 2008 Salut, Je solicite votre savoir faire, j'ai plus le net sur mon portable, enfin, les ping passent, les bureau distant et aussi msn, mais plus firefox et IE, c'est dingue, sur les autres pc sa fonctionne nikel. Voici mon log: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 10:38:50, on 21/06/2008 Platform: Windows Vista SP1 (WinNT 6.00.1905) MSIE: Internet Explorer v7.00 (7.00.6001.18000) Boot mode: Normal Running processes: C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Lenovo\NPDIRECT\tpfnf7sp.exe C:\Windows\System32\rundll32.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe C:\Windows\System32\TpShocks.exe C:\Program Files\ThinkPad\Utilities\EZEJMNAP.EXE C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe C:\Program Files\Lenovo\Zoom\TpScrex.exe C:\Program Files\Lenovo\AwayTask\AwaySch.EXE C:\Program Files\ThinkVantage\PrdCtr\LPMGR.EXE C:\Program Files\Lenovo\Drag-to-Disc\DrgToDsc.exe C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe C:\Utilitaires\Avast4\ashDisp.exe C:\Program Files\Microsoft IntelliPoint\ipoint.exe C:\Windows\System32\rundll32.exe C:\Program Files\ThinkVantage\PrdCtr\LPMLCHK.EXE C:\Program Files\Lenovo\Client Security Solution\cssauth.exe C:\Program Files\Logitech\Gaming Software\LWEMon.exe C:\Utilitaires\VmWare\vmware-tray.exe C:\Windows\System32\rundll32.exe C:\Utilitaires\VmWare\hqtray.exe C:\Utilitaires\Adobe CS3\Acrobat 8.0\Acrobat\Acrotray.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\MSN Messenger\msnmsgr.exe C:\Utilitaires\DAEMON Tools Lite\daemon.exe C:\Program Files\Synaptics\SynTP\SynTPLpr.exe C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe C:\Windows\ehome\ehtray.exe C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe C:\Users\Freeman\AppData\Local\Temp\Rar$EX00.794\Core Temp.exe C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe C:\Program Files\Google\Google Updater\GoogleUpdater.exe C:\Program Files\PDFCreator\PDFCreator.exe C:\Program Files\WiQuest\WiQuest WUSB\WQ_Tray.exe C:\Windows\ehome\ehmsas.exe C:\Program Files\ThinkPad\Bluetooth Software\BtStackServer.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Windows\system32\wbem\unsecapp.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Windows\System32\mstsc.exe S:\HiJackThis.exe C:\Windows\system32\NOTEPAD.EXE C:\Windows\system32\SearchFilterHost.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://lenovo.live.com R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.fr/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O1 - Hosts: ::1 localhost O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: ContributeBHO Class - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Utilitaires\Adobe CS3\/Adobe Contribute CS3/contributeieplugin.dll O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Utilitaires\Adobe CS3\Acrobat 8.0\Acrobat\AcroIEFavClient.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll O2 - BHO: PDFCreator Toolbar Helper - {C451C08A-EC37-45DF-AAAD-18B51AB5E837} - C:\Program Files\PDFCreator Toolbar\v3.3.0.1\PDFCreator_Toolbar.dll O3 - Toolbar: PDFCreator Toolbar - {31CF9EBE-5755-4A1D-AC25-2834D952D9B4} - C:\Program Files\PDFCreator Toolbar\v3.3.0.1\PDFCreator_Toolbar.dll O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Utilitaires\Adobe CS3\Acrobat 8.0\Acrobat\AcroIEFavClient.dll O3 - Toolbar: Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Utilitaires\Adobe CS3\/Adobe Contribute CS3/contributeieplugin.dll O4 - HKLM\..\Run: [TPFNF7] C:\PROGRA~1\Lenovo\NPDIRECT\TPFNF7SP.exe /r O4 - HKLM\..\Run: [PWMTRV] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWMTR32V.DLL,PwrMgrBkGndMonitor O4 - HKLM\..\Run: [bLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BTVLogEx.DLL,StartBattLog O4 - HKLM\..\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [TPHOTKEY] C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe O4 - HKLM\..\Run: [TpShocks] TpShocks.exe O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe" O4 - HKLM\..\Run: [AwaySch] C:\Program Files\Lenovo\AwayTask\AwaySch.EXE O4 - HKLM\..\Run: [LPManager] C:\PROGRA~1\THINKV~2\PrdCtr\LPMGR.exe O4 - HKLM\..\Run: [AMSG] C:\Program Files\ThinkVantage\AMSG\Amsg.exe /startup O4 - HKLM\..\Run: [RoxioDragToDisc] C:\Program Files\Lenovo\Drag-to-Disc\DrgToDsc.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" O4 - HKLM\..\Run: [ACTray] C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe O4 - HKLM\..\Run: [ACWLIcon] C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe O4 - HKLM\..\Run: [iaNvSrv] C:\Program Files\Intel\Intel Matrix Storage Manager\OROM\IaNvSrv\IaNvSrv.exe O4 - HKLM\..\Run: [avast!] C:\UTILIT~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [intelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe" O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [LPMailChecker] C:\PROGRA~1\THINKV~2\PrdCtr\LPMLCHK.exe O4 - HKLM\..\Run: [cssauth] "C:\Program Files\Lenovo\Client Security Solution\cssauth.exe" silent O4 - HKLM\..\Run: [start WingMan Profiler] C:\Program Files\Logitech\Gaming Software\LWEMon.exe /noui O4 - HKLM\..\Run: [vmware-tray] C:\Utilitaires\VmWare\vmware-tray.exe O4 - HKLM\..\Run: [VMware hqtray] "C:\Utilitaires\VmWare\hqtray.exe" O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Utilitaires\Adobe CS3\Acrobat 8.0\Acrobat\Acrotray.exe" O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [TVT Scheduler Proxy] C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe O4 - HKCU\..\Run: [sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Utilitaires\DAEMON Tools Lite\daemon.exe" -autorun O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe" -onlytray O4 - HKCU\..\Run: [Core Temp] C:\Users\Freeman\AppData\Local\Temp\Rar$EX00.794\Core Temp.exe O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'Default user') O4 - Global Startup: Bluetooth.lnk = ? O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe O4 - Global Startup: PDFCreator.lnk = C:\Program Files\PDFCreator\PDFCreator.exe O4 - Global Startup: Ultrawideband Control Center.lnk = C:\Program Files\WiQuest\WiQuest WUSB\WQ_Tray.exe O8 - Extra context menu item: Ajouter au fichier PDF existant - res://C:\Utilitaires\Adobe CS3\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: Convertir en Adobe PDF - res://C:\Utilitaires\Adobe CS3\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: Convertir la cible du lien en Adobe PDF - res://C:\Utilitaires\Adobe CS3\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: Convertir la cible du lien en un fichier PDF existant - res://C:\Utilitaires\Adobe CS3\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: Convertir la sélection en Adobe PDF - res://C:\Utilitaires\Adobe CS3\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: Convertir la sélection en un fichier PDF existant - res://C:\Utilitaires\Adobe CS3\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: Convertir les liens sélectionnés en fichier Adobe PDF - res://C:\Utilitaires\Adobe CS3\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html O8 - Extra context menu item: Convertir les liens sélectionnés en un fichier PDF existant - res://C:\Utilitaires\Adobe CS3\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\UTILIT~1\OFFICE~1\Office12\EXCEL.EXE/3000 O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\UTILIT~1\OFFICE~1\visio\Office12\REFIEBAR.DLL O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm O9 - Extra button: (no name) - {F4F55DC8-0B69-4DFE-BA94-CB677B88B2A3} - C:\Program Files\Lenovo\Client Security Solution\tvtpwm_ie_com.dll (file missing) O9 - Extra 'Tools' menuitem: Lenovo Password Manager... - {F4F55DC8-0B69-4DFE-BA94-CB677B88B2A3} - C:\Program Files\Lenovo\Client Security Solution\tvtpwm_ie_com.dll (file missing) O13 - Gopher Prefix: O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/dow...llerControl.cab O16 - DPF: {04CB5B64-5915-4629-B869-8945CEBADD21} (Module de délivrance de certificat MINEFI) - https://static.impots.gouv.fr/abos/static/s...te/certdgi1.cab O22 - SharedTaskScheduler: Windows DreamScene - {E31004D1-A431-41B8-826F-E902F9D95C81} - C:\Windows\System32\DreamScene.dll O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe O23 - Service: Ac Profile Manager Service (AcPrfMgrSvc) - Lenovo - C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe O23 - Service: Access Connections Main Service (AcSvc) - Lenovo - C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe O23 - Service: Adobe Version Cue CS3 {fr_FR} (Adobe Version Cue CS3) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe O23 - Service: Andrea ADI Filters Service (AEADIFilters) - Andrea Electronics Corporation - C:\Windows\system32\AEADISRV.EXE O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Utilitaires\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Utilitaires\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Utilitaires\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Utilitaires\Avast4\ashWebSv.exe O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: ThinkPad PM Service (IBMPMSVC) - Lenovo - C:\Windows\system32\ibmpmsvc.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: IPS Core Service (IPSSVC) - Lenovo Group Limited - C:\Windows\system32\IPSSVC.EXE O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Utilitaires\Néro 8\Nero 8\Nero BackItUp\NBService.exe O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe O23 - Service: System Update (SUService) - Lenovo Group Limited - c:\Program Files\Lenovo\System Update\SUService.exe O23 - Service: ThinkVantage Registry Monitor Service - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Lenovo. - C:\Windows\System32\TPHDEXLG.exe O23 - Service: On Screen Display (TPHKSVC) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe O23 - Service: TSS Core Service (TSSCoreService) - Lenovo - C:\Program Files\Lenovo\Client Security Solution\tvttcsd.exe O23 - Service: TVT Backup Protection Service - Unknown owner - C:\Program Files\Lenovo\Rescue and Recovery\rrpservice.exe O23 - Service: TVT Backup Service - Lenovo Group Limited - C:\Program Files\Lenovo\Rescue and Recovery\rrservice.exe O23 - Service: TVT Scheduler - Lenovo Group Limited - c:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe O23 - Service: tvtnetwk - Unknown owner - C:\Program Files\Lenovo\Rescue and Recovery\ADM\IUService.exe O23 - Service: VMware Converter Service (ufad-p2v) - VMware, Inc. - C:\Program Files\VMware\VMware Converter\vmware-ufad.exe O23 - Service: VMware Agent Service (ufad-ws60) - VMware, Inc. - C:\Utilitaires\VmWare\vmware-ufad.exe O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Utilitaires\VmWare\vmware-authd.exe O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\Windows\system32\vmnetdhcp.exe O23 - Service: VMware Virtual Mount Manager Extended (vmount2) - VMware, Inc. - C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe O23 - Service: VMware NAT Service - VMware, Inc. - C:\Windows\system32\vmnat.exe O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe -- End of file - 17594 bytes Merci Lien vers le commentaire Partager sur d’autres sites More sharing options...
D-Tune Posté(e) le 21 juin 2008 Partager Posté(e) le 21 juin 2008 Ca c'est du log hijackthis de vieux bourrin.... Lien vers le commentaire Partager sur d’autres sites More sharing options...
snooky Posté(e) le 21 juin 2008 Auteur Partager Posté(e) le 21 juin 2008 @ freeman27 : Désinstalle Avast et Ad-Aware . Coche et fixe toutes les lignes 04 avec Hijackthis . Lance Combofix et poste le rapport créé : http://download.bleepingcomputer.com/sUBs/ComboFix.exe Lien vers le commentaire Partager sur d’autres sites More sharing options...
freeman27 Posté(e) le 21 juin 2008 Partager Posté(e) le 21 juin 2008 Slut: Voila le rapport de combofix. Par contre j'ai pas virer tous les 04, j'en ai besoin au démarrage, non ?! Et le net fonctionne de nouveau! ComboFix 08-06-20.4 - Freeman 2008-06-21 14:04:44.2 - NTFSx86 Microsoft® Windows Vista™ Édition Intégrale 6.0.6001.1.1252.1.1033.18.1761 [GMT 2:00] Running from: S:\ComboFix.exe . ((((((((((((((((((((((((( Files Created from 2008-05-21 to 2008-06-21 ))))))))))))))))))))))))))))))) . 2008-06-21 14:07 . 2008-06-21 14:07 53,248 --a------ C:\Temp\catchme.dll 2008-06-21 10:29 . 2008-06-21 13:51 <REP> d-------- C:\Temp\vmware-Freeman 2008-06-20 22:36 . 2008-06-20 22:37 <REP> d-------- C:\Users\All Users\Lavasoft 2008-06-20 22:36 . 2008-06-20 22:37 <REP> d-------- C:\ProgramData\Lavasoft 2008-06-20 15:30 . 2008-06-20 20:24 1,024 --a------ C:\.rnd 2008-06-20 11:34 . 2008-06-20 11:35 <REP> d-------- C:\Users\Freeman\AppData\Roaming\Folding@home-x86 2008-06-20 11:06 . 2008-06-20 11:06 1,732 --a------ C:\tvtpktfilter.dat 2008-06-19 16:00 . 2008-06-19 16:00 <REP> d-------- C:\Users\Freeman\AppData\Roaming\Wireshark 2008-06-19 15:32 . 2008-06-19 15:32 <REP> d-------- C:\Program Files\Wireshark 2008-06-19 15:32 . 2008-06-19 15:32 <REP> d-------- C:\Program Files\WinPcap 2008-06-19 11:41 . 2008-06-19 11:41 <REP> d-------- C:\Program Files\Common Files\xing shared 2008-06-18 14:22 . 2008-06-18 14:22 <REP> d-------- C:\Program Files\StreamMyGame 2008-06-18 14:22 . 2007-03-23 04:05 29,272 -ra------ C:\Windows\System32\AdobePDF.dll 2008-06-17 20:03 . 2008-04-28 15:53 805,400 -ra------ C:\Windows\System32\tmpBA44.tmp 2008-06-17 20:02 . 2008-04-28 15:53 805,400 -ra------ C:\Windows\System32\tmpBA43.tmp 2008-06-17 18:47 . 2008-06-17 18:47 <REP> d-------- C:\Windows\San Andreas Mod Installer 2008-06-17 17:39 . 1999-12-17 08:13 86,016 --a------ C:\Windows\unvise32.exe 2008-06-15 22:28 . 2008-06-15 22:28 <REP> d-------- C:\Users\Freeman\AppData\Roaming\Nvu 2008-06-15 22:28 . 2008-06-15 22:28 <REP> d-------- C:\Program Files\Nvu 2008-06-15 15:29 . 2008-06-16 15:19 39 --a------ C:\Windows\vbaddin.ini 2008-06-15 15:05 . 2008-06-15 15:05 <REP> d-------- C:\Users\All Users\FLEXnet 2008-06-15 15:05 . 2008-06-15 15:05 <REP> d-------- C:\ProgramData\FLEXnet 2008-06-15 14:21 . 2008-06-15 14:21 <REP> d-------- C:\Program Files\Common Files\Control Panels 2008-06-15 14:20 . 2008-06-15 14:20 <REP> d-------- C:\Users\All Users\ALM 2008-06-15 14:20 . 2008-06-15 14:20 <REP> d-------- C:\ProgramData\ALM 2008-06-15 14:13 . 2008-06-15 14:13 <REP> d-------- C:\Program Files\QuickTime 2008-06-15 13:47 . 2008-06-15 13:47 <REP> d-------- C:\Program Files\Bonjour 2008-06-15 13:45 . 2008-06-15 13:45 <REP> d-------- C:\Program Files\Common Files\Macrovision Shared 2008-06-14 22:59 . 2008-06-14 22:59 <REP> d-------- C:\Program Files\WinSCP 2008-06-12 23:43 . 2008-05-22 14:57 805,400 -ra------ C:\Windows\System32\tmpC8EB.tmp 2008-06-12 23:43 . 2008-05-22 14:57 805,400 -ra------ C:\Windows\System32\tmpC8EA.tmp 2008-06-12 21:05 . 2008-06-12 21:05 <REP> d-------- C:\Users\Freeman\AppData\Roaming\Symantec 2008-06-12 21:03 . 2007-03-28 20:29 131,944 --a------ C:\Windows\System32\drivers\symsnap.sys 2008-06-12 21:03 . 2007-03-28 20:49 128,104 --a------ C:\Windows\System32\drivers\WimFltr.sys 2008-06-12 21:03 . 2007-03-28 20:29 37,864 --a------ C:\Windows\System32\drivers\v2imount.sys 2008-06-12 21:03 . 2007-03-28 20:23 14,072 --a------ C:\Windows\System32\drivers\vproeventmonitor.sys 2008-06-12 13:53 . 2008-06-12 13:53 <REP> d-------- C:\Users\Freeman\AppData\Roaming\Thunderbird 2008-06-12 13:53 . 2008-06-12 13:53 <REP> d-------- C:\Program Files\Mozilla Thunderbird 2008-06-11 13:31 . 2008-04-23 06:42 428,544 --a------ C:\Windows\System32\EncDec.dll 2008-06-11 13:31 . 2008-04-23 06:42 293,376 --a------ C:\Windows\System32\psisdecd.dll 2008-06-11 13:31 . 2008-04-23 06:41 218,624 --a------ C:\Windows\System32\psisrndr.ax 2008-06-11 13:31 . 2008-04-23 06:41 57,856 --a------ C:\Windows\System32\MSDvbNP.ax 2008-06-09 10:49 . 2008-06-09 10:49 0 --a------ C:\Windows\qfe516A.tmp 2008-06-06 23:38 . 2008-06-06 23:38 <REP> d-------- C:\Windows\1A8A214F6BAC4E01A27D25C19A484908.TMP 2008-06-06 23:14 . 2008-06-06 23:14 <REP> d-------- C:\Program Files\FMOD SoundSystem 2008-06-06 22:42 . 2008-06-06 22:41 103,736 --a------ C:\Windows\System32\PnkBstrB.exe 2008-06-06 22:42 . 2008-06-06 22:42 22,328 --a------ C:\Windows\System32\drivers\PnkBstrK.sys 2008-06-06 22:42 . 2008-06-06 22:42 22,328 --a------ C:\Users\Freeman\AppData\Roaming\PnkBstrK.sys 2008-06-06 22:41 . 2008-06-06 23:00 2,337,865 --a------ C:\Windows\System32\pbsvc.exe 2008-06-06 22:41 . 2008-06-06 23:00 66,872 --a------ C:\Windows\System32\PnkBstrA.exe 2008-06-04 18:04 . 2008-06-12 21:07 <REP> d-------- C:\Program Files\Common Files\Symantec Shared 2008-06-04 18:03 . 2008-06-12 21:07 <REP> d-------- C:\Users\All Users\Symantec 2008-06-04 18:03 . 2008-06-12 21:07 <REP> d-------- C:\ProgramData\Symantec 2008-06-02 21:33 . 2008-06-02 21:33 <REP> d--h----- C:\Users\All Users\CanonBJ 2008-06-02 21:33 . 2008-06-02 21:33 <REP> d--h----- C:\ProgramData\CanonBJ 2008-06-01 20:01 . 2008-06-01 20:01 <REP> d-------- C:\Users\Freeman\AppData\Roaming\DeepBurner 2008-06-01 20:01 . 2008-06-01 20:01 <REP> d-------- C:\Program Files\Astonsoft 2008-06-01 10:54 . 2008-06-01 11:15 <REP> d-------- C:\Windows\System32\Adobe 2008-05-28 22:11 . 2008-06-17 20:08 <REP> d-------- C:\Users\All Users\Codemasters 2008-05-28 22:11 . 2008-06-17 20:08 <REP> d-------- C:\ProgramData\Codemasters 2008-05-28 21:11 . 2008-05-28 21:11 <REP> d-a------ C:\Users\All Users\TEMP 2008-05-28 21:11 . 2008-05-28 21:11 <REP> d-a------ C:\ProgramData\TEMP 2008-05-28 19:55 . 2008-05-28 21:59 <REP> d-------- C:\Users\Freeman\AppData\Roaming\BPK 2008-05-28 19:55 . 2008-05-28 22:27 <REP> d-------- C:\Program Files\BPK 2008-05-28 18:49 . 2008-05-28 18:50 <REP> dr-h----- C:\Captures 2008-05-28 18:45 . 2008-05-28 18:45 <REP> d-a------ C:\Users\All Users\rkfree 2008-05-28 18:45 . 2008-05-28 18:45 <REP> d-a------ C:\ProgramData\rkfree 2008-05-28 08:19 . 2008-03-08 04:08 4,240,384 --a------ C:\Windows\System32\GameUXLegacyGDFs.dll 2008-05-28 08:19 . 2008-03-08 06:21 1,695,744 --a------ C:\Windows\System32\gameux.dll 2008-05-27 23:38 . 2008-05-27 23:38 <REP> d-------- C:\Program Files\OpenAL 2008-05-27 23:38 . 2008-04-28 12:29 805,400 -ra------ C:\Windows\System32\tmpD631.tmp 2008-05-27 23:37 . 2008-04-28 12:29 805,400 -ra------ C:\Windows\System32\tmpD5F1.tmp 2008-05-27 18:32 . 2008-05-27 18:32 <REP> d-------- C:\Program Files\RealVNC 2008-05-27 11:30 . 2008-05-27 11:30 <REP> d-------- C:\Program Files\PDFCreator Toolbar 2008-05-27 11:30 . 2008-05-27 11:30 <REP> d-------- C:\Program Files\PDFCreator 2008-05-27 11:30 . 2008-05-27 11:30 253,116 --a------ C:\Windows\PDFCreator_Toolbar_Uninstaller_3174.exe 2008-05-27 11:30 . 1998-07-13 01:08 141,312 --a------ C:\Windows\System32\MSCMCFR.DLL 2008-05-27 11:30 . 1998-06-24 00:00 137,000 --a------ C:\Windows\System32\MSMAPI32.OCX 2008-05-27 11:30 . 1998-07-13 01:08 119,568 --a------ C:\Windows\System32\VB6FR.DLL 2008-05-27 11:30 . 1998-07-13 01:08 59,904 --a------ C:\Windows\System32\MSCC2FR.DLL 2008-05-27 11:30 . 1998-07-06 00:00 23,552 --a------ C:\Windows\System32\MSMPIDE.DLL 2008-05-27 11:21 . 2008-06-21 14:07 <REP> d-------- C:\Temp 2008-05-27 09:44 . 2008-06-20 15:52 <REP> d-------- C:\Program Files\Look@LAN 2008-05-27 09:44 . 2008-05-27 09:43 720,896 --a------ C:\Windows\iun6002.exe 2008-05-25 13:17 . 2008-05-25 13:17 <REP> d-------- C:\Users\Freeman\AppData\Roaming\DameWare Development 2008-05-23 19:45 . 2008-05-23 19:53 <REP> d-------- C:\Program Files\Ripp-it_AM 2008-05-22 16:56 . 2008-05-22 16:56 0 --ah----- C:\Windows\System32\drivers\Msft_Kernel_ccdcmb_01005.Wdf 2008-05-22 15:51 . 2008-05-23 08:51 167 --a------ C:\Windows\ConverterCore.INI 2008-05-22 15:50 . 2008-05-23 16:25 <REP> d-------- C:\Users\Freeman\AppData\Roaming\SolidDocuments 2008-05-22 15:49 . 2008-05-22 15:49 <REP> d-------- C:\Users\All Users\SolidDocuments 2008-05-22 15:49 . 2008-05-22 15:49 <REP> d-------- C:\ProgramData\SolidDocuments 2008-05-21 21:27 . 2008-05-21 21:27 <REP> d-------- C:\Program Files\Microsoft Silverlight 2008-05-21 19:12 . 2008-05-21 19:12 <REP> d-------- C:\Users\Freeman\AppData\Roaming\Thinking Minds Budiling Bytes . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-06-21 12:02 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard 2008-06-21 11:51 --------- d-----w C:\Users\Freeman\AppData\Roaming\VMware 2008-06-21 11:51 --------- d-----w C:\ProgramData\VMware 2008-06-21 10:12 --------- d-----w C:\ProgramData\Google Updater 2008-06-20 13:46 --------- d-----w C:\Users\Freeman\AppData\Roaming\FileZilla 2008-06-20 13:30 --------- d-----w C:\Program Files\VMware 2008-06-19 19:26 68,049 ----a-w C:\Users\Freeman\AppData\Roaming\nvModes.dat 2008-06-19 19:23 --------- d-----w C:\Program Files\NVIDIA Corporation 2008-06-19 18:14 --------- d-----w C:\ProgramData\Test Drive Unlimited 2008-06-19 09:41 348,160 ----a-w C:\Windows\System32\msvcr71.dll 2008-06-19 09:41 --------- d-----w C:\Program Files\Common Files\Real 2008-06-17 18:03 444,952 ----a-w C:\Windows\System32\wrap_oal.dll 2008-06-17 18:03 109,080 ----a-w C:\Windows\System32\OpenAL32.dll 2008-06-17 17:49 --------- d--h--w C:\Program Files\InstallShield Installation Information 2008-06-16 13:20 --------- d-----w C:\ProgramData\Microsoft Help 2008-06-15 12:22 --------- d-----w C:\Program Files\Common Files\Adobe 2008-06-11 11:34 --------- d-----w C:\Program Files\Windows Mail 2008-05-28 20:11 107,888 ----a-w C:\Windows\System32\CmdLineExt.dll 2008-05-22 11:00 --------- d-----w C:\Users\Freeman\AppData\Roaming\dvdcss 2008-05-20 12:00 --------- d-----w C:\Users\Freeman\AppData\Roaming\AcWizard 2008-05-19 18:11 --------- d-----w C:\Program Files\Common Files\VMware 2008-05-19 16:06 --------- d-----w C:\Users\Freeman\AppData\Roaming\Nokia 2008-05-19 16:06 --------- d-----w C:\ProgramData\Installations 2008-05-19 15:57 --------- d-----w C:\Program Files\PC Connectivity Solution 2008-05-19 15:57 --------- d-----w C:\Program Files\Nokia 2008-05-19 15:57 --------- d-----w C:\Program Files\Common Files\PCSuite 2008-05-19 15:57 --------- d-----w C:\Program Files\Common Files\Nokia 2008-05-18 21:00 --------- d-----w C:\Users\Freeman\AppData\Roaming\THQ 2008-05-18 20:58 --------- d-----w C:\ProgramData\InstallShield 2008-05-18 20:49 --------- d-----w C:\Program Files\Common Files\InstallShield 2008-05-18 18:20 0 ---ha-w C:\Windows\system32\drivers\Msft_User_PCCSWpdDriver_01_05_00.Wdf 2008-05-18 18:19 --------- d-----w C:\Users\Freeman\AppData\Roaming\PC Suite 2008-05-18 18:19 --------- d-----w C:\ProgramData\PC Suite 2008-05-18 18:18 --------- d-----w C:\Program Files\DIFX 2008-05-18 13:43 --------- d-----w C:\Program Files\Logitech 2008-05-18 13:43 --------- d-----w C:\Program Files\Common Files\Logitech 2008-05-18 13:20 --------- d-----w C:\ProgramData\NVIDIA Corporation 2008-05-18 13:01 --------- d-----w C:\Users\Freeman\AppData\Roaming\LimeWire 2008-05-17 22:13 --------- d-----w C:\ProgramData\CyberLink 2008-05-17 22:06 --------- d-----w C:\Users\Freeman\AppData\Roaming\CyberLink 2008-05-17 22:05 --------- d-----w C:\Program Files\Common Files\CyberLink 2008-05-17 22:03 29,480 ----a-w C:\Windows\System32\msxml3a.dll 2008-05-16 18:41 --------- d-----w C:\Users\Freeman\AppData\Roaming\InterVideo 2008-05-16 17:03 --------- d-----w C:\ProgramData\Media Center Programs 2008-05-15 19:53 --------- d--h--r C:\Users\Freeman\AppData\Roaming\SecuROM 2008-05-15 19:09 --------- d-----w C:\ProgramData\GRAW2 2008-05-15 18:17 --------- d-----w C:\Users\Freeman\AppData\Roaming\Microsoft Games 2008-05-15 18:08 --------- d-----w C:\Program Files\Common Files\Microsoft Games 2008-05-15 16:45 --------- d-----w C:\Program Files\Microsoft Games 2008-05-15 09:07 --------- d-----w C:\Users\Freeman\AppData\Roaming\InstallShield Installation Information 2008-05-14 21:17 --------- d-----w C:\Program Files\MSN Messenger 2008-05-14 20:09 --------- d-----w C:\ProgramData\Lenovo 2008-05-14 20:09 --------- d-----w C:\Program Files\Windows Live Toolbar 2008-05-14 20:09 --------- d-----w C:\Program Files\Picasa2 2008-05-14 20:09 --------- d-----w C:\Program Files\PCDR5 2008-05-14 20:09 --------- d-----w C:\Program Files\Microsoft.NET 2008-05-14 20:09 --------- d-----w C:\Program Files\Microsoft Works 2008-05-14 20:09 --------- d-----w C:\Program Files\Microsoft SQL Server 2008-05-14 20:09 --------- d-----w C:\Program Files\Lenovo 2008-05-14 20:09 --------- d-----w C:\Program Files\InterVideo 2008-05-14 20:09 --------- d-----w C:\Program Files\Common Files\Lenovo 2008-05-14 20:09 --------- d-----w C:\Program Files\Analog Devices 2008-05-14 16:00 --------- d-----w C:\Users\Freeman\AppData\Roaming\Lenovo 2008-05-14 15:53 33,536 ----a-w C:\Windows\system32\drivers\tvtfilter.sys 2008-05-14 10:33 --------- d-----w C:\ProgramData\Intel 2008-05-14 10:33 --------- d-----w C:\Program Files\Cisco 2008-05-14 10:32 --------- d-----w C:\Program Files\Intel 2008-05-14 10:31 --------- d-----w C:\Program Files\NetWaiting 2008-05-14 10:31 --------- d-----w C:\Program Files\Digital Line Detect 2008-05-14 10:30 --------- d-----w C:\Users\Freeman\AppData\Roaming\InstallShield 2008-05-14 08:15 --------- d-----w C:\ProgramData\NVIDIA 2008-05-14 07:02 100 ----a-w C:\Windows\system32\drivers\Lenovo_6459_CTO.MRK 2008-05-13 21:40 --------- d-----w C:\Program Files\Common Files\Futuremark Shared 2008-05-13 21:38 --------- d-----w C:\Program Files\AGEIA Technologies 2008-05-13 21:12 --------- d-----w C:\Users\Freeman\AppData\Roaming\Nero 2008-05-13 21:11 --------- d-----w C:\Program Files\Common Files\Nero 2008-05-13 21:09 --------- d-----w C:\ProgramData\Nero 2008-05-13 20:33 --------- d-----w C:\Program Files\BitLocker 2008-05-13 20:29 --------- d-----w C:\Users\Freeman\AppData\Roaming\Leadertech 2008-05-13 20:23 --------- d-----w C:\Program Files\MSXML 4.0 2008-05-13 20:20 --------- d-----w C:\Users\Freeman\AppData\Roaming\Winamp 2008-05-13 20:09 --------- d-----w C:\Users\Freeman\AppData\Roaming\vlc 2008-05-13 20:06 --------- d-----w C:\Program Files\Microsoft IntelliPoint 2008-05-13 19:15 717,296 ----a-w C:\Windows\system32\drivers\sptd.sys 2008-05-13 19:14 --------- d-----w C:\Users\Freeman\AppData\Roaming\DAEMON Tools 2008-05-13 18:03 --------- d-----w C:\Program Files\Google 2008-05-13 18:02 --------- d-----w C:\Users\Freeman\AppData\Roaming\Talkback 2008-05-13 18:02 --------- d-----w C:\Program Files\Real 2008-05-13 17:56 --------- d-----w C:\Program Files\ToniArts 2008-05-13 17:17 --------- d-----w C:\Program Files\Windows Sidebar 2008-05-13 17:17 --------- d-----w C:\Program Files\Windows Photo Gallery 2008-05-13 17:17 --------- d-----w C:\Program Files\Windows Defender 2008-05-13 17:17 --------- d-----w C:\Program Files\Windows Collaboration 2008-05-13 17:17 --------- d-----w C:\Program Files\Windows Calendar 2008-05-13 16:48 --------- d-----w C:\Program Files\Java 2008-05-10 01:33 113,664 ----a-w C:\Windows\system32\drivers\rmcast.sys 2008-04-30 15:27 442,368 ----a-w C:\Windows\System32\nvuninst.exe 2008-04-29 03:54 181,760 ----a-w C:\Windows\System32\fsquirt.exe 2008-04-29 01:42 29,184 ----a-w C:\Windows\system32\drivers\BTHUSB.SYS 2008-04-29 01:42 220,160 ----a-w C:\Windows\system32\drivers\bthport.sys . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-21 04:21 1233920] "WindowsWelcomeCenter"="oobefldr.dll" [2008-01-21 04:21 2153472 C:\Windows\System32\oobefldr.dll] "MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 12:55 5674352] "DAEMON Tools Lite"="C:\Utilitaires\DAEMON Tools Lite\daemon.exe" [2008-04-01 11:39 486856] "ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2008-01-21 04:23 125952] "PC Suite Tray"="C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe" [2008-04-16 12:53 1079808] "Core Temp"="C:\Users\Freeman\AppData\Local\Temp\Rar$EX00.794\Core Temp.exe" [2008-05-19 00:37 256528] "CubeDesktop"="" [] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "TPFNF7"="C:\PROGRA~1\Lenovo\NPDIRECT\TPFNF7SP.exe" [2008-03-26 03:06 59680] "PWMTRV"="C:\PROGRA~1\ThinkPad\UTILIT~1\PWMTR32V.DLL" [2007-12-06 19:11 324896] "BLOG"="C:\PROGRA~1\ThinkPad\UTILIT~1\BTVLogEx.DLL" [2007-12-06 19:11 214576] "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2007-11-21 18:08 820520] "TPHOTKEY"="C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe" [2008-01-24 10:21 66928] "EZEJMNAP"="C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe" [2007-03-28 19:32 243248] "DiskeeperSystray"="C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe" [2006-11-16 01:21 217176] "AwaySch"="C:\Program Files\Lenovo\AwayTask\AwaySch.EXE" [2006-11-07 12:51 91688] "LPManager"="C:\PROGRA~1\THINKV~2\PrdCtr\LPMGR.exe" [2008-01-11 02:21 144728] "AMSG"="C:\Program Files\ThinkVantage\AMSG\Amsg.exe" [2007-02-01 20:00 419376] "RoxioDragToDisc"="C:\Program Files\Lenovo\Drag-to-Disc\DrgToDsc.exe" [2007-03-13 18:05 1116920] "ACTray"="C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe" [2008-03-17 13:37 431392] "ACWLIcon"="C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe" [2008-03-17 13:37 128288] "IaNvSrv"="C:\Program Files\Intel\Intel Matrix Storage Manager\OROM\IaNvSrv\IaNvSrv.exe" [2007-10-24 03:02 33304] "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792] "IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\ipoint.exe" [2007-08-31 12:01 1037736] "NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-12-10 21:03 86016] "NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-12-10 21:03 8501792] "NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2007-12-10 21:03 81920] "LPMailChecker"="C:\PROGRA~1\THINKV~2\PrdCtr\LPMLCHK.exe" [2008-01-11 02:21 124248] "cssauth"="C:\Program Files\Lenovo\Client Security Solution\cssauth.exe" [2007-11-29 18:36 2872632] "Start WingMan Profiler"="C:\Program Files\Logitech\Gaming Software\LWEMon.exe" [2008-04-04 11:38 88584] "vmware-tray"="C:\Utilitaires\VmWare\vmware-tray.exe" [2008-03-03 20:10 72240] "VMware hqtray"="C:\Utilitaires\VmWare\hqtray.exe" [2008-03-03 20:10 55856] "Acrobat Assistant 8.0"="C:\Utilitaires\Adobe CS3\Acrobat 8.0\Acrobat\Acrotray.exe" [2008-01-11 19:54 623992] "TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-06-19 11:41 185896] "TVT Scheduler Proxy"="C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe" [2007-07-10 22:16 540672] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "Nokia.PCSync"="C:\Utilitaires\Nokia PC suite\Nokia PC Suite 6\PcSync2.exe" [ ] C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ Bluetooth.lnk - C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe [2007-03-29 22:11:50 719664] Outil de mise … jour Google.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2008-05-13 19:56:22 125624] PDFCreator.lnk - C:\Program Files\PDFCreator\PDFCreator.exe [2008-05-27 11:30:22 2641920] Ultrawideband Control Center.lnk - C:\Program Files\WiQuest\WiQuest WUSB\WQ_Tray.exe [2007-08-24 19:41:42 1821752] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) "DisableCAD"= 1 (0x1) [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus] C:\Windows\system32\psqlpwd.dll 2007-03-15 07:17 89600 C:\Windows\System32\psqlpwd.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "vidc.yv12"= yv12vfw.dll [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender] --a------ 2008-01-21 04:21 1008184 C:\Program Files\Windows Defender\MSASCui.exe [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-608310825-3432132780-2050808395-1005] "EnableNotificationsRef"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules] "{6A17F5B5-5A45-470C-BFF3-D065571A44C7}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook "{51863291-F50B-447F-B823-BC5E5ADEDF73}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone) "{283AFA25-1F63-45FF-86AF-E1F8BBA13D53}"= TCP:6004|C:\Utilitaires\Office 2007\Office12\outlook.exe:Microsoft Office Outlook R0 iaNvStor;Intel® Turbo Memory Controller;C:\Windows\system32\DRIVERS\iaNvStor.sys [2007-10-02 12:53] R0 Shockprf;Shockprf;C:\Windows\system32\DRIVERS\Apsx86.sys [2007-10-17 03:33] R0 TPDIGIMN;TPDIGIMN;C:\Windows\system32\DRIVERS\ApsHM86.sys [2007-10-17 03:32] R1 DLARTL_M;DLARTL_M;C:\Windows\system32\Drivers\DLARTL_M.SYS [2007-02-09 05:05] R1 lenovo.smi;Lenovo System Interface Driver;C:\Windows\system32\DRIVERS\smiif32.sys [2006-08-30 12:04] R1 TPPWRIF;TPPWRIF;C:\Windows\system32\drivers\Tppwr32v.sys [2007-12-06 19:11] R2 AEADIFilters;Andrea ADI Filters Service;C:\Windows\system32\AEADISRV.EXE [2007-02-06 00:44] R2 NPF;NetGroup Packet Filter Driver;C:\Windows\system32\drivers\npf.sys [2007-11-06 22:22] R2 smihlp;SMI Helper Driver (smihlp);C:\Program Files\Common Files\ThinkVantage Fingerprint Software\Drivers\smihlp.sys [2007-03-15 07:10] R2 TPHKSVC;On Screen Display;C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe [2007-12-14 16:37] R2 TVT Backup Protection Service;TVT Backup Protection Service;"C:\Program Files\Lenovo\Rescue and Recovery\rrpservice.exe" [2007-07-10 21:56] R2 ufad-p2v;VMware Converter Service;"C:\Program Files\VMware\VMware Converter\vmware-ufad.exe" -d "C:\Program Files\VMware\VMware Converter\\" -s ufad-p2v.xml [] R2 vstor2-p2v30;Vstor2 P2V30 Virtual Storage Driver;C:\Program Files\VMware\VMware Converter\vstor2-p2v30.sys [2007-04-19 17:38] R3 btwaudio;Bluetooth Audio Device Service;C:\Windows\system32\drivers\btwaudio.sys [2007-03-29 20:46] R3 btwavdt;Bluetooth AVDT;C:\Windows\system32\drivers\btwavdt.sys [2007-02-27 07:20] R3 btwrchid;btwrchid;C:\Windows\system32\DRIVERS\btwrchid.sys [2007-02-27 07:20] R3 LenovoRd;LenovoRd;C:\Windows\system32\Drivers\LenovoRd.sys [2007-06-08 02:36] R3 TVTI2C;Lenovo SM bus driver;C:\Windows\system32\DRIVERS\Tvti2c.sys [2007-05-23 00:59] R3 WQ_USBHWA;WiQuest Host Wire Adapter driver;C:\Windows\system32\DRIVERS\WQ_hwa.sys [2007-08-24 19:35] R3 WQ_USBRCI;WiQuest UltraWideBand driver;C:\Windows\system32\DRIVERS\WQ_rci.sys [2007-08-24 19:35] S3 WQ_USBLOAD;WiQuest WUSB Loader driver;C:\Windows\system32\DRIVERS\WQ_ldr.sys [2007-08-24 19:35] S4 ErrDev;Microsoft Hardware Error Device Driver;C:\Windows\system32\drivers\errdev.sys [2008-01-21 04:21] S4 MegaSR;MegaSR;C:\Windows\system32\drivers\megasr.sys [2008-01-21 04:21] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] bthsvcs REG_MULTI_SZ BthServ GPSvcGroup REG_MULTI_SZ GPSvc [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7070D8E0-650A-46b3-B03C-9497582E6A74}] %SystemRoot%\system32\soundschemes.exe /AddRegistration . ************************************************************************** catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-06-21 14:07:05 Windows 6.0.6001 Service Pack 1 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2008-06-21 14:08:06 ComboFix-quarantined-files.txt 2008-06-21 12:07:48 Pre-Run: 34,558,840,832 octets libres Post-Run: 34,540,285,952 octets libres 312 --- E O F --- 2008-06-20 09:54:37 Merci Lien vers le commentaire Partager sur d’autres sites More sharing options...
2C.LiryC Posté(e) le 21 juin 2008 Partager Posté(e) le 21 juin 2008 Slut:...Par contre j'ai pas virer tous les 04, j'en ai besoin au démarrage, non ?! Et le net fonctionne de nouveau! ... Non, il n'y en a pas besoin. Quasiment la seule chose que ça fait c'est ralentir le démarrage de ta machine. Et les supprimer comme l'a demandé Snooky n'empêchera pas les applications de se lancer. Elles se chargeront seulement quand tu cliquera dessus. Quand on voit ton log, on hallucine un peu . Lien vers le commentaire Partager sur d’autres sites More sharing options...
guymauve Posté(e) le 22 juin 2008 Partager Posté(e) le 22 juin 2008 Bonjour à tous, On m'a prêté un PC histoire que je le nettoie mais là j'ai du trop lourd pour moi donc je fais appel à votre aide J'ai désinstallé Avast et kerio (je les remettrai une fois le pc propre) J'ai installé Kasp v7 scan non réalisé (manque de temps) J'ai un soucis de chemin de bureau : Et voici mon log Hijackthis : Logfile of HijackThis v1.99.1 Scan saved at 18:58:17, on 22/06/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16674) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\GSICON.EXE C:\WINDOWS\system32\dslagent.exe C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\WINDOWS\system32\NotifyPhoneBook.exe C:\WINDOWS\System32\drivers\CDAC11BA.EXE C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe C:\Program Files\Internet Explorer\iexplore.exe C:\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.be/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: Winamp Toolbar BHO - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll O2 - BHO: (no name) - {449c5929-0126-490b-abae-8c7efa854086} - (no file) O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll O4 - HKLM\..\Run: [AME_CSA] rundll32 amecsa.cpl,RUN_DLL O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [GSICONEXE] GSICON.EXE O4 - HKLM\..\Run: [DSLAGENTEXE] dslagent.exe USB O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe" O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [Windows update loader] C:\Windows\xpupdate.exe O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KEM.exe O8 - Extra context menu item: &Winamp Toolbar Search - C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll O9 - Extra button: Statistiques d’Anti-Virus Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing) O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O11 - Options group: [iNTERNATIONAL] International* O14 - IERESET.INF: START_PAGE_URL=http://www.skynet.be O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1146142651058 O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061...all/xscan53.cab O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse...pDownloader.cab O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (ASquaredScanForm Element) - http://www.windowsecurity.com/trojanscan/axscan.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{170A721C-5192-4799-B912-A1AC489340B2}: NameServer = 212.53.4.4 212.53.5.5 O17 - HKLM\System\CS1\Services\Tcpip\..\{170A721C-5192-4799-B912-A1AC489340B2}: NameServer = 212.53.4.4 212.53.5.5 O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~4\GOEC62~1.DLL O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O23 - Service: Kaspersky Anti-Virus 7.0 (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe" -r (file missing) O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe Encore merci à tous. Lien vers le commentaire Partager sur d’autres sites More sharing options...
snooky Posté(e) le 22 juin 2008 Auteur Partager Posté(e) le 22 juin 2008 Coche et fixe cette ligne : O4 - HKCU\..\Run: [Windows update loader] C:\Windows\xpupdate.exe Supprime avec Unlocker : xpupdate.exe Lance MBAM et poste le rapport créé : http://www.majorgeeks.com/Malwarebytes_Ant...ware_d5756.html Lien vers le commentaire Partager sur d’autres sites More sharing options...
guymauve Posté(e) le 22 juin 2008 Partager Posté(e) le 22 juin 2008 Merci à toi. Et pour le lien vers le Desktop ? Encore merci. Lien vers le commentaire Partager sur d’autres sites More sharing options...
snooky Posté(e) le 22 juin 2008 Auteur Partager Posté(e) le 22 juin 2008 Coche et fixe ces lignes : O2 - BHO: (no name) - {449c5929-0126-490b-abae-8c7efa854086} - (no file) O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll Désinstalle Spybot . !!! Lance Clean v2.0 , procédure 1 . Redémarre le pc et poste un nouveau rapport Hijackthis ( en plus du rapport MBAM ) Lien vers le commentaire Partager sur d’autres sites More sharing options...
K-Lee Posté(e) le 24 juin 2008 Partager Posté(e) le 24 juin 2008 Bonjour Dr Snoocky, j'ai besoin de votre aide Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 09:36:34, on 24/06/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16674) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe c:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe C:\WINDOWS\system32\slserv.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\system32\Rundll32.exe C:\Program Files\Larousse\Petit Larousse 2004\bin\HiPL2002popup.exe C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe C:\Program Files\iTunes\iTunesHelper.exe C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe C:\Program Files\MSN Messenger\msnmsgr.exe C:\WINDOWS\system32\ctfmon.exe C:\Windows\system32\sistray.exe C:\Program Files\iPod\bin\iPodService.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\% ^ ^^%% ^^ ^ % ^^ % ^%^^^^ %^%^^^ ^^%^ ^% %^^%^ ^.exe O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file) O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file) O4 - HKLM\..\Run: [siSUSBRG] C:\WINDOWS\SiSUSBrg.exe O4 - HKLM\..\Run: [siSPower] Rundll32.exe SiSPower.dll,ModeAgent O4 - HKLM\..\Run: [HyperappelPL2003] C:\Program Files\Larousse\Petit Larousse 2004\bin\HiPL2002popup.exe O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe" O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe" O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto O4 - HKLM\..\Run: [Flash Media] C:\WINDOWS\system32\% ^ ^^%% ^^ ^ % ^^ % ^%^^^^ %^%^^^ ^^%^ ^% %^^%^ ^.exe O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Global Startup: Utility Tray.lnk = C:\Windows\system32\sistray.exe O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\Office\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://www.new2.foto.com/ImageUploader5.cab O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1210275838218 O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://www.new2.foto.com/ImageUploader4.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe -- End of file - 5422 bytes Lien vers le commentaire Partager sur d’autres sites More sharing options...
snooky Posté(e) le 24 juin 2008 Auteur Partager Posté(e) le 24 juin 2008 @ K-Lee : Coche et fixe ces lignes : F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\% ^ ^^%% ^^ ^ % ^^ % ^%^^^^ %^%^^^ ^^%^ ^% %^^%^ ^.exe O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file) O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe" O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe" O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [Flash Media] C:\WINDOWS\system32\% ^ ^^%% ^^ ^ % ^^ % ^%^^^^ %^%^^^ ^^%^ ^% %^^%^ ^.exe Lance MBAM et poste le rapport créé : http://www.majorgeeks.com/downloadget.php?...fd909666f809b26 Lien vers le commentaire Partager sur d’autres sites More sharing options...
K-Lee Posté(e) le 24 juin 2008 Partager Posté(e) le 24 juin 2008 J'avais déjà fait tourner Clean en Procédure 1 et MSNFix, puis un scan avec Antivir... Voici le rapport de mbam Malwarebytes' Anti-Malware 1.18 Version de la base de données: 884 14:46:34 24/06/2008 mbam-log-6-24-2008 (14-46-34).txt Type de recherche: Examen rapide Eléments examinés: 38599 Temps écoulé: 5 minute(s), 4 second(s) Processus mémoire infecté(s): 0 Module(s) mémoire infecté(s): 0 Clé(s) du Registre infectée(s): 1 Valeur(s) du Registre infectée(s): 0 Elément(s) de données du Registre infecté(s): 0 Dossier(s) infecté(s): 6 Fichier(s) infecté(s): 20 Processus mémoire infecté(s): (Aucun élément nuisible détecté) Module(s) mémoire infecté(s): (Aucun élément nuisible détecté) Clé(s) du Registre infectée(s): HKEY_CLASSES_ROOT\CLSID\{014da6c9-189f-421a-88cd-07cfe51cff10} (Adware.MyWebSearch) -> Quarantined and deleted successfully. Valeur(s) du Registre infectée(s): (Aucun élément nuisible détecté) Elément(s) de données du Registre infecté(s): (Aucun élément nuisible détecté) Dossier(s) infecté(s): C:\Program Files\MyWay (Adware.MyWay) -> Quarantined and deleted successfully. C:\Program Files\MyWay\myBar (Adware.MyWay) -> Quarantined and deleted successfully. C:\Program Files\MyWay\myBar\1.bin (Adware.MyWay) -> Quarantined and deleted successfully. C:\Program Files\MyWay\myBar\Cache (Adware.MyWay) -> Quarantined and deleted successfully. C:\Program Files\MyWay\myBar\History (Adware.MyWay) -> Quarantined and deleted successfully. C:\Program Files\MyWay\myBar\Settings (Adware.MyWay) -> Quarantined and deleted successfully. Fichier(s) infecté(s): C:\Program Files\MyWay\myBar\1.bin\MYWAYPLUGINPROXY.CLASS (Adware.MyWay) -> Quarantined and deleted successfully. C:\Program Files\MyWay\myBar\1.bin\PARTNER.BMP (Adware.MyWay) -> Quarantined and deleted successfully. C:\Program Files\MyWay\myBar\1.bin\PARTNER.DAT (Adware.MyWay) -> Quarantined and deleted successfully. C:\Program Files\MyWay\myBar\1.bin\PARTNER2.DAT (Adware.MyWay) -> Quarantined and deleted successfully. C:\Program Files\MyWay\myBar\1.bin\PARTNER3.DAT (Adware.MyWay) -> Quarantined and deleted successfully. C:\Program Files\MyWay\myBar\1.bin\PARTNER4.DAT (Adware.MyWay) -> Quarantined and deleted successfully. C:\Program Files\MyWay\myBar\1.bin\PARTNER5.DAT (Adware.MyWay) -> Quarantined and deleted successfully. C:\Program Files\MyWay\myBar\1.bin\PARTNER6.DAT (Adware.MyWay) -> Quarantined and deleted successfully. C:\Program Files\MyWay\myBar\Cache02AA6F (Adware.MyWay) -> Quarantined and deleted successfully. C:\Program Files\MyWay\myBar\Cache3D773A.bmp (Adware.MyWay) -> Quarantined and deleted successfully. C:\Program Files\MyWay\myBar\Cache4927F7.bin (Adware.MyWay) -> Quarantined and deleted successfully. C:\Program Files\MyWay\myBar\Cache492A0A.bin (Adware.MyWay) -> Quarantined and deleted successfully. C:\Program Files\MyWay\myBar\Cache492C4C.bin (Adware.MyWay) -> Quarantined and deleted successfully. C:\Program Files\MyWay\myBar\Cache\files.ini (Adware.MyWay) -> Quarantined and deleted successfully. C:\Program Files\MyWay\myBar\History\search (Adware.MyWay) -> Quarantined and deleted successfully. C:\Program Files\MyWay\myBar\Settings\prevcfg.htm (Adware.MyWay) -> Quarantined and deleted successfully. C:\Program Files\MyWay\myBar\Settings\settings.dat (Adware.MyWay) -> Quarantined and deleted successfully. C:\Program Files\MyWay\myBar\Settings\settings.htm (Adware.MyWay) -> Quarantined and deleted successfully. C:\Windows\Fonts\acrsecB.fon (Trojan.Agent) -> Quarantined and deleted successfully. C:\Windows\Fonts\acrsecI.fon (Trojan.Agent) -> Quarantined and deleted successfully. Lien vers le commentaire Partager sur d’autres sites More sharing options...
snooky Posté(e) le 24 juin 2008 Auteur Partager Posté(e) le 24 juin 2008 @ K-Lee : Désinstalle MyWay si présent dans Ajout/suppr des programmes . Poste un nouveau rapport Hijackthis après redémarrage du pc . Lien vers le commentaire Partager sur d’autres sites More sharing options...
kardiakkris Posté(e) le 24 juin 2008 Partager Posté(e) le 24 juin 2008 Bonjour snooky, MBAM m'a trouvé un Trojan.Agent ( en tant que "vendeur" ) au niveau de autoexec.bat ( situé immédiatement après C:\ ) J'ai listé autoexec.bat, par "type" sous dos : rien. L'espace disque occupé par autoexec.bat est 0 octets, de même pour config.sys. "type", sous dos, ne renvoie rien pour ces 2 fichiers. Je poste ici avant d'autoriser MBAM à exclure ce qui correspond à ce Trojan.Agent car je préfère avoir ton avis. Lien vers le commentaire Partager sur d’autres sites More sharing options...
Messages recommandés
Archivé
Ce sujet est désormais archivé et ne peut plus recevoir de nouvelles réponses.