Problème securité

clubtissier -  
pimprenelle27 Messages postés 22182 Statut Contributeur sécurité -
Bonjour,
Aprés avoir controler mon pc avec smitfraudfix ,ce dernier ma généré 3 rapports que dois-je en faire de ces derniers ?
Mon PC me montre encore le méssage : You have a security probleme, do you wannt scan.... enfin truc dans le genre.
Merci à lâme charitable qui pourrait m'aider.
Salutations
Configuration: Windows XP
Internet Explorer 7.0

11 réponses

  1. pimprenelle27 Messages postés 22182 Statut Contributeur sécurité 2 503
     
    poste moi le 1er rapport smithfraud ensuite ceci :

    Bonjour,

    Pour commencer : faire un petit nettoyage de l'ordi et du registre avec Ccleaner, regarde bien le Tuto CCleaner

    Ensuite :

    Télécharge le fichier d'installation d'HijackThis.

    Enregistre HJTInstall.exe sur ton bureau.

    Renomme Hijackthis en Tutu

    Double-clique sur HJTInstall.exe (tutu) pour lancer le programme

    Par défaut, il s'installera là :
    C:\Program Files\Trend Micro\HijackThis

    Accepte la licence en cliquant sur le bouton "I Accept"

    Choisis l'option "Do a system scan and save a log file"

    Clique sur "Save log" pour enregistrer le rapport qui s'ouvrira avec le bloc-note

    Clique sur "Edition -> Sélectionner tout", puis sur "Edition -> Copier" pour copier tout le contenu du rapport

    Colle le rapport que tu viens de copier sur ce forum

    Ne fixe encore AUCUNE ligne, cela pourrait empêcher ton PC de fonctionner correctement

    Tutoriaux (ne fixe rien pour le moment !!)

    Pour ceux qui ont vista, ne pas oublier de désactiver Le contrôle des comptes utilisateurs
    0
  2. clubtissier
     
    Bonsoir,
    Comme convenu voici le premier rapport:

    SmitFraudFix v2.320

    Rapport fait à 18:43:32,98, 10/03/2009
    Executé à partir de C:\Documents and Settings\tissier\Bureau\SmitfraudFix
    OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
    Le type du système de fichiers est NTFS
    Fix executé en mode normal

    »»»»»»»»»»»»»»»»»»»»»»»» Process

    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\userinit.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Windows Live\Family Safety\fsssvc.exe
    C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
    C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\Program Files\Windows Live\Family Safety\fsui.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
    C:\Program Files\Windows Live\Contacts\wlcomm.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\system32\cmd.exe

    »»»»»»»»»»»»»»»»»»»»»»»» hosts

    »»»»»»»»»»»»»»»»»»»»»»»» C:\

    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles

    »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\tissier

    »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\tissier\Application Data

    »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

    »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\tissier\Favoris

    »»»»»»»»»»»»»»»»»»»»»»»» Bureau

    »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

    »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

    »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
    "Source"="About:Home"
    "SubscribedURL"="About:Home"
    "FriendlyName"="Ma page d'accueil"

    »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

    IEDFix
    Credits: Malware Analysis & Diagnostic
    Code: S!Ri

    »»»»»»»»»»»»»»»»»»»»»»»» VACFix
    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

    VACFix
    Credits: Malware Analysis & Diagnostic
    Code: S!Ri

    »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

    404Fix
    Credits: Malware Analysis & Diagnostic
    Code: S!Ri

    »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

    SrchSTS.exe by S!Ri
    Search SharedTaskScheduler's .dll

    »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
    "AppInit_DLLs"="C:\\PROGRA~1\\KASPER~1\\KASPER~1\\mzvkbd.dll,C:\\PROGRA~1\\KASPER~1\\KASPER~1\\mzvkbd3.dll,C:\\PROGRA~1\\KASPER~1\\KASPER~1\\adialhk.dll,C:\\PROGRA~1\\KASPER~1\\KASPER~1\\kloehk.dll"

    »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
    "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
    "System"=""

    »»»»»»»»»»»»»»»»»»»»»»»» Rustock

    »»»»»»»»»»»»»»»»»»»»»»»» DNS

    Description: Carte réseau Fast Ethernet PCI Realtek RTL8139 Family
    DNS Server Search Order: 192.168.1.1

    HKLM\SYSTEM\CCS\Services\Tcpip\..\{485DB833-EEEC-4201-9FBA-0C38320A2205}: DhcpNameServer=192.168.1.1
    HKLM\SYSTEM\CS1\Services\Tcpip\..\{485DB833-EEEC-4201-9FBA-0C38320A2205}: DhcpNameServer=192.168.1.1
    HKLM\SYSTEM\CS2\Services\Tcpip\..\{485DB833-EEEC-4201-9FBA-0C38320A2205}: DhcpNameServer=192.168.1.1
    HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
    HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
    HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1

    »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

    »»»»»»»»»»»»»»»»»»»»»»»» Fin

    Merci de me tenir au courant de la marche à suivre quand vous le pourrez.
    0
    1. pimprenelle27 Messages postés 22182 Statut Contributeur sécurité 2 503
       
      Redémarre en mode sans échec comme indiqué ici ; Choisis ta session courante.

      Relance SmitfraudFix Puis choisir l'option 2 suppression et me poster le rapport.
      0
  3. clubtissier
     
    Rebonsoir,
    Voici le rapport N°1 de hijackthis :

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 21:07:05, on 12/03/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16791)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\userinit.exe
    C:\Program Files\Windows Live\Family Safety\fsssvc.exe
    C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\Program Files\Windows Live\Family Safety\fsui.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\Fichiers communs\Real\Update_OB\RealOneMessageCenter.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\Program Files\Windows Live\Contacts\wlcomm.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\Windows Live\Toolbar\wltuser.exe
    C:\Program Files\HP\Smart Web Printing\hpswp_clipbook.exe
    C:\Documents and Settings\tissier\Mes documents\Mes fichiers reçus\HiJackThis.exe
    C:\WINDOWS\system32\wuauclt.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll
    O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
    O2 - BHO: Windows Live Family Safety Browser Helper - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll
    O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ievkbd.dll
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
    O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
    O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
    O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
    O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
    O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [fssui] "C:\Program Files\Windows Live\Family Safety\fsui.exe" -autorun
    O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe"
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: Ajouter à Kaspersky Anti-Bannière - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: Statistiques de la protection du trafic Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\SCIEPlgn.dll
    O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra button: Livre de reliures HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
    O9 - Extra button: Sélection intelligente HP - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
    O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - https://www.nvidia.com/content/DriverDownload/srl/3.0.0.0/srl_bin/sysreqlab3.cab
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/resources/MSNPUpld.cab
    O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll,C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll,C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll,C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll
    O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
    0
  4. clubtissier
     
    Bonsoir,
    Aprés avoir redémarré mon pc en mode sans echec et avoir fais un nettoyage avec smitfraudfix , voici le deuxième Rapport.
    SmitFraudFix v2.320

    Rapport fait à 20:45:18,98, 13/03/2009
    Executé à partir de C:\Documents and Settings\tissier\Bureau\SmitfraudFix
    OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
    Le type du système de fichiers est NTFS
    Fix executé en mode sans echec

    »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Avant SmitFraudFix
    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

    SrchSTS.exe by S!Ri
    Search SharedTaskScheduler's .dll

    »»»»»»»»»»»»»»»»»»»»»»»» Arret des processus

    »»»»»»»»»»»»»»»»»»»»»»»» hosts

    127.0.0.1 localhost

    »»»»»»»»»»»»»»»»»»»»»»»» VACFix

    VACFix
    Credits: Malware Analysis & Diagnostic
    Code: S!Ri

    »»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

    S!Ri's WS2Fix: LSP not Found.

    »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

    GenericRenosFix by S!Ri

    »»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés

    »»»»»»»»»»»»»»»»»»»»»»»» IEDFix

    IEDFix
    Credits: Malware Analysis & Diagnostic
    Code: S!Ri

    »»»»»»»»»»»»»»»»»»»»»»»» 404Fix

    404Fix
    Credits: Malware Analysis & Diagnostic
    Code: S!Ri

    »»»»»»»»»»»»»»»»»»»»»»»» DNS

    Description: Carte réseau Fast Ethernet PCI Realtek RTL8139 Family
    DNS Server Search Order: 192.168.1.1

    HKLM\SYSTEM\CCS\Services\Tcpip\..\{485DB833-EEEC-4201-9FBA-0C38320A2205}: DhcpNameServer=192.168.1.1
    HKLM\SYSTEM\CS1\Services\Tcpip\..\{485DB833-EEEC-4201-9FBA-0C38320A2205}: DhcpNameServer=192.168.1.1
    HKLM\SYSTEM\CS2\Services\Tcpip\..\{485DB833-EEEC-4201-9FBA-0C38320A2205}: DhcpNameServer=192.168.1.1
    HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
    HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
    HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1

    »»»»»»»»»»»»»»»»»»»»»»»» Suppression Fichiers Temporaires

    »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
    "System"=""

    »»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre

    Nettoyage terminé.

    »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Après SmitFraudFix
    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

    SrchSTS.exe by S!Ri
    Search SharedTaskScheduler's .dll

    »»»»»»»»»»»»»»»»»»»»»»»» Fin

    Merci d'avance pour la suite car j'ai toujours le même méssage c'est à dire :
    You have a sécurity probleme, do you want scan.....
    0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. pimprenelle27 Messages postés 22182 Statut Contributeur sécurité 2 503
     
    Telecharge malwarebytes

    NB : S'il te manque COMCTL32.OCX alors télécharge le ici

    Tu l´instale; le programme va se mettre automatiquement a jour.

    Une fois a jour, le programme va se lancer; click sur l´onglet parametre, et coche la case : "Arreter internet explorer pendant la suppression".

    Click maintenant sur l´onglet recherche et coche la case : "executer un examen complet".

    Puis click sur "rechercher".

    Laisse le scanner le pc...

    Si des elements on ete trouvés > click sur supprimer la selection.

    si il t´es demandé de redemarrer > click sur "yes".

    A la fin un rapport va s´ouvrir; sauvegarde le de maniere a le retrouver en vu de le poster sur le forum.
    Copie et colle le rapport stp.

    PS : les rapport sont aussi rangé dans l onglet rapport/log

    Tutoriaux
    0
  7. clubtissier
     
    Voici le rapport apres avoir scanné avec malwarebytes:
    Malwarebytes' Anti-Malware 1.34
    Version de la base de données: 1829
    Windows 5.1.2600 Service Pack 3

    13/03/2009 22:35:43
    mbam-log-2009-03-13 (22-35-43).txt

    Type de recherche: Examen rapide
    Eléments examinés: 63947
    Temps écoulé: 4 minute(s), 50 second(s)

    Processus mémoire infecté(s): 0
    Module(s) mémoire infecté(s): 0
    Clé(s) du Registre infectée(s): 0
    Valeur(s) du Registre infectée(s): 0
    Elément(s) de données du Registre infecté(s): 2
    Dossier(s) infecté(s): 0
    Fichier(s) infecté(s): 0

    Processus mémoire infecté(s):
    (Aucun élément nuisible détecté)

    Module(s) mémoire infecté(s):
    (Aucun élément nuisible détecté)

    Clé(s) du Registre infectée(s):
    (Aucun élément nuisible détecté)

    Valeur(s) du Registre infectée(s):
    (Aucun élément nuisible détecté)

    Elément(s) de données du Registre infecté(s):
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.Dropper) -> Data: c:\windows\system32\userinit.exe -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.Dropper) -> Data: system32\userinit.exe -> Quarantined and deleted successfully.

    Dossier(s) infecté(s):
    (Aucun élément nuisible détecté)

    Fichier(s) infecté(s):
    (Aucun élément nuisible détecté)
    0
  8. pimprenelle27 Messages postés 22182 Statut Contributeur sécurité 2 503
     
    ok c'est bien tu va me vider la quarantaine de malwre, me faire un nouvel hijackthis, puis ceci :

    Pour commencer : faire un petit nettoyage de l'ordi et du registre avec Ccleaner, regarde bien le Tuto CCleaner

    Télécharge Superantispyware (SAS)

    Choisis "enregistrer" et enregistre-le sur ton bureau.

    Double-clique sur l'icône d'installation qui vient de se créer et suis les instructions.

    Créé une icône sur le bureau.

    Double-clique sur l'icône de SAS (une tête dans un cercle rouge barré) pour le lancer.

    - Si l'outil te demande de mettre à jour le programme ("update the program definitions", clique sur yes.
    - Sous Configuration and Preferences, clique sur le bouton "Preferences"
    - Clique sur l'onglet "Scanning Control "
    - Dans "Scanner Options ", assure toi que la case devant lles lignes suivantes est cochée :

    Close browsers before scanning
    Scan for tracking cookies
    Terminate memory threats before quarantining
    - Laisse les autres lignes décochées.

    - Clique sur le bouton "Close" pour quitter l'écran du centre de contrôle.

    - Dans la fenêtre principale, clique, dans "Scan for Harmful Software", sur "Scan your computer".

    Dans la colonne de gauche, coche C:\Fixed Drive.

    Dans la colonne de droite, sous "Complete scan", clique sur "Perform Complete Scan"

    Clique sur "next" pour lancer le scan. Patiente pendant la durée du scan.

    A la fin du scan, une fenêtre de résultats s'ouvre . Clique sur OK.

    Assure toi que toutes les lignes de la fenêtre blanche sont cochées et clique sur "Next".

    Tout ce qui a été trouvé sera mis en quarantaine. S'il t'es demandé de redémarrer l'ordi ("reboot"), clique sur Yes.

    Pour recopier les informations sur le forum, fais ceci :

    - après le redémarrage de l'ordi, double-clique sur l'icône pour lancer SAS.
    - Clique sur "Preferences" puis sur l'onglet "Statistics/Logs ".
    - Dans "scanners logs", double-clique sur SUPERAntiSpyware Scan Log.

    - Le rapport va s'ouvrir dans ton éditeur de texte par défaut.

    - Copie son contenu dans ta réponse.

    Regarde bien le tuto SUPERAntiSpyware il est très bien expliqué.

    0
  9. clubtissier
     
    Bonjour,
    Apres avoir scanné mon pc aves superantispyware des objets ont été mis en quarantaine mais mon méssage d'alerte est toujours là;
    Comme convenu voici le rapport de super machin truc:
    SUPERAntiSpyware Scan Log
    https://www.superantispyware.com/

    Generated 03/14/2009 at 01:17 PM

    Application Version : 4.25.1014

    Core Rules Database Version : 3795
    Trace Rules Database Version: 1751

    Scan type : Complete Scan
    Total Scan Time : 00:30:02

    Memory items scanned : 449
    Memory threats detected : 0
    Registry items scanned : 5146
    Registry threats detected : 2
    File items scanned : 17117
    File threats detected : 19

    Adware.Tracking Cookie
    C:\Documents and Settings\tissier\Cookies\tissier@atdmt[1].txt
    C:\Documents and Settings\tissier\Cookies\tissier@fr.sitestat[2].txt
    C:\Documents and Settings\tissier\Cookies\tissier@xiti[1].txt
    C:\Documents and Settings\tissier\Cookies\tissier@weborama[3].txt
    C:\Documents and Settings\tissier\Cookies\tissier@mediaplex[2].txt
    C:\Documents and Settings\tissier\Cookies\tissier@www.etracker[2].txt
    C:\Documents and Settings\tissier\Cookies\tissier@youporn[2].txt
    C:\Documents and Settings\tissier\Cookies\tissier@paypal.112.2o7[1].txt
    C:\Documents and Settings\tissier\Cookies\tissier@stats.paypal[2].txt
    C:\Documents and Settings\tissier\Cookies\tissier@fr.sitestat[1].txt
    C:\Documents and Settings\tissier\Cookies\tissier@aimfar.solution.weborama[2].txt
    C:\Documents and Settings\tissier\Cookies\tissier@estat[1].txt
    C:\Documents and Settings\tissier\Cookies\tissier@fl01.ct2.comclick[2].txt
    C:\Documents and Settings\tissier\Cookies\tissier@2o7[2].txt
    C:\Documents and Settings\tissier\Cookies\tissier@msnportal.112.2o7[1].txt
    C:\Documents and Settings\LocalService\Cookies\system@2o7[1].txt
    C:\Documents and Settings\tissier\Cookies\tissier@weborama[2].txt
    C:\Documents and Settings\tissier\Cookies\tissier@fl01.ct2.comclick[1].txt

    Adware.MyWebSearch/FunWebProducts
    HKCR\CLSID\{9AFB8248-617F-460d-9366-D71CDEDA3179}
    HKCR\CLSID\{9AFB8248-617F-460d-9366-D71CDEDA3179}\TreatAs

    Trojan.Unknown Origin
    C:\WINDOWS\SYSTEM32\VGHD.SCR

    Voilà merci et à bientôt.
    0
  10. pimprenelle27 Messages postés 22182 Statut Contributeur sécurité 2 503
     
    ok maintenant supprime tout ce que SAS à trouvé, ensuite fait ceci :

    Télécharger RemoveIT Pro

    Fais un scan et poste moi le rapport.

    0
  11. clubtissier
     
    voici le rapport de remove machin chose
    RemoveIT Pro v4 - SE (Build date: 6.6.2008) full information log file.
    Generated at: 15/03/2009 on 00:07:59
    Microsoft Windows XP Home Edition Service Pack 3 (Build 2600)
    Author: Damjan Irgolic
    https://www.incodesolutions.com/
    support@incodesolutions.com

    Running processes: (27)
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Windows Live\Family Safety\fsssvc.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\Program Files\Windows Live\Family Safety\fsui.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
    C:\Program Files\Windows Live\Contacts\wlcomm.exe
    C:\Program Files\InCode Solutions\RemoveIT Pro v4 - SE\removeit.exe

    Running processes: (27)
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Windows Live\Family Safety\fsssvc.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\Program Files\Windows Live\Family Safety\fsui.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
    C:\Program Files\Windows Live\Contacts\wlcomm.exe
    C:\Program Files\InCode Solutions\RemoveIT Pro v4 - SE\removeit.exe

    Startup files:
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\CTFMON.EXE
    [C:\WINDOWS\system32\ctfmon.exe]
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\swg
    [C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe]
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\msnmsgr
    ["C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background]
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\SUPERAntiSpyware
    [C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe]
    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\SoundMan
    [SOUNDMAN.EXE]
    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\HP Software Update
    [C:\Program Files\HP\HP Software Update\HPWuSchd2.exe]
    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\TkBellExe
    ["C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot]
    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\Adobe Reader Speed Launcher
    ["C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"]
    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\NvCplDaemon
    [RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup]
    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\nwiz
    [nwiz.exe /install]
    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\NvMediaCenter
    [RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit]
    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\fssui
    ["C:\Program Files\Windows Live\Family Safety\fsui.exe" -autorun]
    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\AVP
    ["C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe"]

    Detail report: (83)
    Clsid c:\progra~1\kasper~1\kasper~1\mzvkbd.dll[42d13f21ac4dc7f5674d18697ccfc8ab][79112]
    Clsid c:\program files\superantispyware\saswinlo.dll[972edede23ac8d59aac0c09799c6f18a][356352]
    Clsid C:\WINDOWS\system32\crypt32.dll[39976dad9564b336b153184268db032f][606208]
    Clsid C:\WINDOWS\system32\cryptnet.dll[938488d25648d26e6bfe3e47dc2ec5e8][64512]
    Clsid C:\WINDOWS\system32\cscdll.dll[6b646a601aec823032af4dc19273cfda][102912]
    Clsid c:\windows\system32\klogon.dll[a09ef6a4793948a74060c70ad423f067][218376]
    Clsid C:\WINDOWS\system32\sclgntfy.dll[c01c7266e73b199101651a7508364df7][22016]
    Clsid c:\windows\system32\stobject.dll[9689fcc8c26c3d6afac892a6c5d1b81a][122368]
    Clsid c:\windows\system32\webcheck.dll[a163a85a0834b85faf918caadec55687][233472]
    Clsid C:\WINDOWS\system32\wlnotify.dll[c664757f8243499ba6e45102af459de6][94208]
    Clsid c:\windows\system32\wpdshserviceobj.dll[045e228f71c31901084b64be59093499][133632]
    Proc C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe[89d583fc41d48328128a974c25afaeb7][185896]
    Proc C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[5d61be7db55b026a5d61a3eed09d0ead][39408]
    Proc C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[feddd3579fee51a9873d856df3933c68][151552]
    Proc C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[f14219fc767f1383526ab423f278a8e3][210520]
    Proc C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[7af5a466cf4aeca28e3dcbcf5b6fd220][49152]
    Proc C:\Program Files\InCode Solutions\RemoveIT Pro v4 - SE\removeit.exe[1ec5a876a537b62f07c92e5bc8103149][550912]
    Proc C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[d358e077a0a05d9b12da22d137ee8464][226656]
    Proc C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe[11afbca9eac51cf988918bffe935e6ee][1830128]
    Proc C:\Program Files\Windows Live\Contacts\wlcomm.exe[654480ea67078c7b4c6c8ba871b07d5d][27512]
    Proc C:\Program Files\Windows Live\Family Safety\fsssvc.exe[9b1622ebeb31b3411b13382ffcb8737d][533360]
    Proc C:\Program Files\Windows Live\Family Safety\fsui.exe[f0ae48a813a3371eba17ca8bd58c7e48][454000]
    Proc C:\Program Files\Windows Live\Messenger\msnmsgr.exe[35b9fa77b73358d9063cd61aa3d83ee8][3885408]
    Proc C:\WINDOWS\Explorer.EXE[f2317622d29f9ff0f88aeecd5f60f0dd][1037824]
    Proc C:\WINDOWS\SOUNDMAN.EXE[fb1bc9a15a3df6cfd446e1b3bd0b5099][577536]
    Proc C:\WINDOWS\system32\ctfmon.exe[59dc5bb82e4c8e0b3eadcfdbc44ba6e4][15360]
    Proc C:\WINDOWS\system32\lsass.exe[91e6024d6d4dcdecdb36c43ecf9bbecb][13312]
    Proc C:\WINDOWS\system32\nvsvc32.exe[934833b3cd462a6f8a96f64d024c8b20][159812]
    Proc C:\WINDOWS\system32\RUNDLL32.EXE[93ad0b78c7357a05f50e594ec7c22300][33792]
    Proc C:\WINDOWS\system32\services.exe[54cb50058851d95e56ec70d09f70857f][109056]
    Proc C:\WINDOWS\system32\spoolsv.exe[460e4ce148bd07218da0b6a3d31885a9][57856]
    Proc C:\WINDOWS\system32\svchost.exe[e4bdf223cd75478bf44567b4d5c2634d][14336]
    RegRun c:\program files\adobe\reader 9.0\reader\reader_sl.exe[69b16c7b7746ba5c642fc05b3561fc73][34672]
    RegRun c:\program files\fichiers communs\real\update_ob\realsched.exe [89d583fc41d48328128a974c25afaeb7][185896]
    RegRun c:\program files\google\googletoolbarnotifier\googletoolbarnotifier.exe[5d61be7db55b026a5d61a3eed09d0ead][39408]
    RegRun c:\program files\hp\hp software update\hpwuschd2.exe[7af5a466cf4aeca28e3dcbcf5b6fd220][49152]
    RegRun c:\program files\kaspersky lab\kaspersky internet security 2009\avp.exe[b66d20e5ee3082c5d9ca008e412572d2][206088]
    RegRun c:\program files\superantispyware\superantispyware.exe[11afbca9eac51cf988918bffe935e6ee][1830128]
    RegRun c:\program files\windows live\family safety\fsui.exe [f0ae48a813a3371eba17ca8bd58c7e48][454000]
    RegRun c:\program files\windows live\messenger\msnmsgr.exe [35b9fa77b73358d9063cd61aa3d83ee8][3885408]
    RegRun C:\WINDOWS\soundman.exe[fb1bc9a15a3df6cfd446e1b3bd0b5099][577536]
    RegRun c:\windows\system32\ctfmon.exe[59dc5bb82e4c8e0b3eadcfdbc44ba6e4][15360]
    RegRun c:\windows\system32\nvcpl.dll[519a35fd7e1bf9a6f5e698c907897c91][13529088]
    RegRun c:\windows\system32\nvmctray.dll[b40f60442c3ed9add0a4e743535b5f6b][86016]
    Service c:\program files\google\common\google updater\googleupdaterservice.exe[34b56a3c195aee6ae11001d277acc83e][168432]
    Service c:\program files\kaspersky lab\kaspersky internet security 2009\avp.exe [b66d20e5ee3082c5d9ca008e412572d2][206088]
    Service c:\program files\microsoft\search enhancement pack\seaport\seaport.exe[d358e077a0a05d9b12da22d137ee8464][226656]
    Service c:\program files\pc connectivity solution\servicelayer.exe[277d0890e10584c216bccfa4ef6b9b3d][575488]
    Service c:\program files\windows live\family safety\fsssvc.exe[9b1622ebeb31b3411b13382ffcb8737d][533360]
    Service c:\program files\windows media player\wmpnetwk.exe[c9bea742ce225cc993c9465fddae4656][918016]
    Service c:\windows\microsoft.net\framework\v2.0.50727\aspnet_state.exe[d33c507942299753868204cc7642fa27][29896]
    Service c:\windows\microsoft.net\framework\v2.0.50727\mscorsvw.exe[3c4d595e7f9b747325aef28b4adcaae5][66240]
    Service c:\windows\microsoft.net\framework\v3.0\windows communication foundation\infocard.exe[ea7267505149b3a10df32506a4e4e412][741376]
    Service c:\windows\microsoft.net\framework\v3.0\windows communication foundation\smsvchost.exe[8070bb07fe06de8b9acb29b07016a273][122880]
    Service c:\windows\microsoft.net\framework\v3.0\wpf\presentationfontcache.exe[facecf3f75baf3775a879d1168402270][36864]
    Service c:\windows\system32\alg.exe[5e9a6658a2a69ae7eb195113b7a2e7a9][44544]
    Service c:\windows\system32\cisvc.exe[793ef38a5fd086c3c8e48a8a861562ed][5632]
    Service c:\windows\system32\clipsrv.exe[8b30cbb0c07d49b2658fb190946b0e7e][33280]
    Service c:\windows\system32\dllhost.exe [0dad93bb0fecf5016ae3c06cbb0a873b][5120]
    Service c:\windows\system32\dmadmin.exe [ead2b8aaeb16e538106d295cd7bd7a48][225280]
    Service c:\windows\system32\imapi.exe[c4221678bbaa55239c23632875759961][150528]
    Service c:\windows\system32\locator.exe[499c59a2584f6d4ea41e944da571d993][75264]
    Service c:\windows\system32\lsass.exe[91e6024d6d4dcdecdb36c43ecf9bbecb][13312]
    Service c:\windows\system32\mnmsrvc.exe[d3a2870cd96cda7bcff3dc54f64087ad][32768]
    Service c:\windows\system32\msdtc.exe[8648d670ae0d95c95e7bbb5b80661796][6144]
    Service c:\windows\system32\msiexec.exe [0411f7ee63ae48d2918ab4f2c79ab6c4][78848]
    Service c:\windows\system32\netdde.exe[5c9b1d83755b36237b70f95df3d46a52][114176]
    Service c:\windows\system32\nvsvc32.exe[934833b3cd462a6f8a96f64d024c8b20][159812]
    Service c:\windows\system32\rsvp.exe[414964844f4793acb868d057e8ed997e][132608]
    Service c:\windows\system32\scardsvr.exe[67949cc8a865296c1333c96a4e1a2d66][100352]
    Service c:\windows\system32\services.exe[54cb50058851d95e56ec70d09f70857f][109056]
    Service c:\windows\system32\sessmgr.exe[9f63d9c5b238ed1c375d417eff3d5be7][142848]
    Service c:\windows\system32\smlogsvc.exe[0899061318a6b1d9596aabfc77f45e44][93184]
    Service c:\windows\system32\spoolsv.exe[460e4ce148bd07218da0b6a3d31885a9][57856]
    Service c:\windows\system32\svchost.exe [e4bdf223cd75478bf44567b4d5c2634d][14336]
    Service c:\windows\system32\ups.exe[1edc93d7bd731b5ca6248ae245099b60][18432]
    Service c:\windows\system32\vssvc.exe[5a4da252b2c0550ab83d129c02cf6c19][295424]
    Service c:\windows\system32\wbem\wmiapsrv.exe[4e8e8a58f56b25d0795f484e5eb7f898][126464]
    Startup c:\documents and settings\all users\menu démarrer\programmes\démarrage\desktop.ini[d6a6856702e3f0953e7246a9b4a9fe35][84]
    Startup c:\documents and settings\tissier\menu démarrer\programmes\démarrage\desktop.ini[d6a6856702e3f0953e7246a9b4a9fe35][84]
    Startup c:\program files\hp\digital imaging\bin\hpqtra08.exe[f14219fc767f1383526ab423f278a8e3][210520]
    Startup c:\program files\microsoft office\office10\osa.exe[5bc65464354a9fd3beaa28e18839734a][83360]
    System.ini c:\windows\microsoft.net\framework\v3.0\wpf\presentationfontcache.exe[facecf3f75baf3775a879d1168402270][36864]

    Startup folder: (4)
    Startup name: desktop.ini
    Command: C:\Documents and Settings\tissier\Menu Démarrer\Programmes\Démarrage\desktop.ini
    Startup name: desktop.ini
    Command: C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\desktop.ini
    Startup name: HP Digital Imaging Monitor.lnk
    Command: C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    Startup name: Microsoft Office.lnk
    Command: C:\Program Files\Microsoft Office\Office10\OSA.EXE

    Win.ini Startup: (1)
    Path: No additional driver found!

    Win.ini Startup: (1)
    Path: No additional driver found!

    Keyboard drivers: (1)
    Name: No Keyboard Filter driver found!

    Services: (97)
    Service Name: .NET Runtime Optimization Service v2.0.50727_X86 [Stopped],
    Path: C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
    Service Name: Accès du périphérique d'interface utilisateur [Stopped],
    Path: C:\WINDOWS\System32\svchost.exe -k netsvcs
    Service Name: Acquisition d'image Windows (WIA) [Running],
    Path: C:\WINDOWS\System32\svchost.exe -k imgsvc
    Service Name: Affichage des messages [Stopped],
    Path: C:\WINDOWS\System32\svchost.exe -k netsvcs
    Service Name: Agent de protection d'accès réseau [Stopped],
    Path: C:\WINDOWS\System32\svchost.exe -k netsvcs
    Service Name: Aide et support [Running],
    Path: C:\WINDOWS\System32\svchost.exe -k netsvcs
    Service Name: Appel de procédure distante (RPC) [Running],
    Path: C:\WINDOWS\system32\svchost -k rpcss
    Service Name: Application système COM+ [Stopped],
    Path: C:\WINDOWS\System32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}
    Service Name: ASP.NET State Service [Stopped],
    Path: C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
    Service Name: Assistance TCP/IP NetBIOS [Running],
    Path: C:\WINDOWS\System32\svchost.exe -k LocalService
    Service Name: Audio Windows [Running],
    Path: C:\WINDOWS\System32\svchost.exe -k netsvcs
    Service Name: Avertissement [Stopped],
    Path: C:\WINDOWS\System32\svchost.exe -k LocalService
    Service Name: Carte à puce [Stopped],
    Path: C:\WINDOWS\System32\SCardSvr.exe
    Service Name: Carte de performance WMI [Stopped],
    Path: C:\WINDOWS\System32\wbem\wmiapsrv.exe
    Service Name: Centre de sécurité [Running],
    Path: C:\WINDOWS\System32\svchost.exe -k netsvcs
    Service Name: Cliché instantané de volume [Stopped],
    Path: C:\WINDOWS\System32\vssvc.exe
    Service Name: Client de suivi de lien distribué [Running],
    Path: C:\WINDOWS\system32\svchost.exe -k netsvcs
    Service Name: Client DHCP [Running],
    Path: C:\WINDOWS\System32\svchost.exe -k netsvcs
    Service Name: Client DNS [Stopped],
    Path: C:\WINDOWS\System32\svchost.exe -k NetworkService
    Service Name: Compatibilité avec le Changement rapide d'utilisateur [Running],
    Path: C:\WINDOWS\System32\svchost.exe -k netsvcs
    Service Name: Configuration automatique de réseau câblé [Stopped],
    Path: C:\WINDOWS\System32\svchost.exe -k dot3svc
    Service Name: Configuration automatique sans fil [Running],
    Path: C:\WINDOWS\System32\svchost.exe -k netsvcs
    Service Name: Connexion secondaire [Running],
    Path: C:\WINDOWS\System32\svchost.exe -k netsvcs
    Service Name: Connexions réseau [Running],
    Path: C:\WINDOWS\System32\svchost.exe -k netsvcs
    Service Name: DDE réseau [Stopped],
    Path: C:\WINDOWS\system32\netdde.exe
    Service Name: Détection matériel noyau [Running],
    Path: C:\WINDOWS\System32\svchost.exe -k netsvcs
    Service Name: Distributed Transaction Coordinator [Stopped],
    Path: C:\WINDOWS\System32\msdtc.exe
    Service Name: DSDM DDE réseau [Stopped],
    Path: C:\WINDOWS\system32\netdde.exe
    Service Name: Emplacement protégé [Running],
    Path: C:\WINDOWS\system32\lsass.exe
    Service Name: Explorateur d'ordinateur [Stopped],
    Path: C:\WINDOWS\System32\svchost.exe -k netsvcs
    Service Name: Fournisseur de la prise en charge de sécurité LM NT [Stopped],
    Path: C:\WINDOWS\System32\lsass.exe
    Service Name: Gestion d'applications [Stopped],
    Path: C:\WINDOWS\system32\svchost.exe -k netsvcs
    Service Name: Gestionnaire de comptes de sécurité [Running],
    Path: C:\WINDOWS\system32\lsass.exe
    Service Name: Gestionnaire de connexion automatique d'accès distant [Stopped],
    Path: C:\WINDOWS\System32\svchost.exe -k netsvcs
    Service Name: Gestionnaire de connexions d'accès distant [Running],
    Path: C:\WINDOWS\System32\svchost.exe -k netsvcs
    Service Name: Gestionnaire de disque logique [Stopped],
    Path: C:\WINDOWS\System32\svchost.exe -k netsvcs
    Service Name: Gestionnaire de l'Album [Stopped],
    Path: C:\WINDOWS\system32\clipsrv.exe
    Service Name: Gestionnaire de session d'aide sur le Bureau à distance [Stopped],
    Path: C:\WINDOWS\system32\sessmgr.exe
    Service Name: Google Updater Service [Stopped],
    Path: "C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe"
    Service Name: Horloge Windows [Running],
    Path: C:\WINDOWS\System32\svchost.exe -k netsvcs
    Service Name: Hôte de périphérique universel Plug-and-Play [Running],
    Path: C:\WINDOWS\System32\svchost.exe -k LocalService
    Service Name: hpqcxs08 [Running],
    Path: C:\WINDOWS\system32\svchost.exe -k hpdevmgmt
    Service Name: HTTP SSL [Stopped],
    Path: C:\WINDOWS\System32\svchost.exe -k HTTPFilter
    Service Name: Infrastructure de gestion Windows [Running],
    Path: C:\WINDOWS\system32\svchost.exe -k netsvcs
    Service Name: Journal des événements [Running],
    Path: C:\WINDOWS\system32\services.exe
    Service Name: Journaux et alertes de performance [Stopped],
    Path: C:\WINDOWS\system32\smlogsvc.exe
    Service Name: Kaspersky Internet Security [Running],
    Path: "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" -r
    Service Name: Lanceur de processus serveur DCOM [Running],
    Path: C:\WINDOWS\system32\svchost -k DcomLaunch
    Service Name: Localisateur d'appels de procédure distante (RPC) [Stopped],
    Path: C:\WINDOWS\System32\locator.exe
    Service Name: Mises à jour automatiques [Running],
    Path: C:\WINDOWS\System32\svchost.exe -k netsvcs
    Service Name: MS Software Shadow Copy Provider [Stopped],
    Path: C:\WINDOWS\System32\dllhost.exe /Processid:{DF521080-EEC1-4B14-8C44-E76324D22D7D}
    Service Name: Net Driver HPZ12 [Running],
    Path: C:\WINDOWS\System32\svchost.exe -k HPZ12
    Service Name: Net.Tcp Port Sharing Service [Stopped],
    Path: "C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe"
    Service Name: NLA (Network Location Awareness) [Running],
    Path: C:\WINDOWS\System32\svchost.exe -k netsvcs
    Service Name: Notification d'événement système [Running],
    Path: C:\WINDOWS\system32\svchost.exe -k netsvcs
    Service Name: NVIDIA Display Driver Service [Running],
    Path: C:\WINDOWS\system32\nvsvc32.exe
    Service Name: Onduleur [Stopped],
    Path: C:\WINDOWS\System32\ups.exe
    Service Name: Ouverture de session réseau [Stopped],
    Path: C:\WINDOWS\System32\lsass.exe
    Service Name: Pare-feu Windows / Partage de connexion Internet [Running],
    Path: C:\WINDOWS\System32\svchost.exe -k netsvcs
    Service Name: Partage de Bureau à distance NetMeeting [Stopped],
    Path: C:\WINDOWS\System32\mnmsrvc.exe
    Service Name: Planificateur de tâches [Running],
    Path: C:\WINDOWS\System32\svchost.exe -k netsvcs
    Service Name: Plug-and-Play [Running],
    Path: C:\WINDOWS\system32\services.exe
    Service Name: Pml Driver HPZ12 [Running],
    Path: C:\WINDOWS\System32\svchost.exe -k HPZ12
    Service Name: QoS RSVP [Stopped],
    Path: C:\WINDOWS\System32\rsvp.exe
    Service Name: Routage et accès distant [Stopped],
    Path: C:\WINDOWS\System32\svchost.exe -k netsvcs
    Service Name: SeaPort [Running],
    Path: "C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe"
    Service Name: Serveur [Running],
    Path: C:\WINDOWS\System32\svchost.exe -k netsvcs
    Service Name: Service COM de gravage de CD IMAPI [Stopped],
    Path: C:\WINDOWS\System32\imapi.exe
    Service Name: Service d'administration du Gestionnaire de disque logique [Stopped],
    Path: C:\WINDOWS\System32\dmadmin.exe /com
    Service Name: Service d'approvisionnement réseau [Stopped],
    Path: C:\WINDOWS\System32\svchost.exe -k netsvcs
    Service Name: Service de découvertes SSDP [Running],
    Path: C:\WINDOWS\System32\svchost.exe -k LocalService
    Service Name: Service de la passerelle de la couche Application [Running],
    Path: C:\WINDOWS\System32\alg.exe
    Service Name: Service de numéro de série du lecteur multimédia portable [Stopped],
    Path: C:\WINDOWS\System32\svchost.exe -k netsvcs
    Service Name: Service de rapport d'erreurs [Running],
    Path: C:\WINDOWS\System32\svchost.exe -k netsvcs
    Service Name: Service de restauration système [Running],
    Path: C:\WINDOWS\System32\svchost.exe -k netsvcs
    Service Name: Service de transfert intelligent en arrière-plan [Stopped],
    Path: C:\WINDOWS\System32\svchost.exe -k netsvcs
    Service Name: Service d'indexation [Stopped],
    Path: C:\WINDOWS\system32\cisvc.exe
    Service Name: Service Gestion des clés et des certificats d'intégrité [Stopped],
    Path: C:\WINDOWS\System32\svchost.exe -k netsvcs
    Service Name: Service HP CUE DeviceDiscovery [Running],
    Path: C:\WINDOWS\system32\svchost.exe -k hpdevmgmt
    Service Name: Service Partage réseau du Lecteur Windows Media [Stopped],
    Path: "C:\Program Files\Windows Media Player\WMPNetwk.exe"
    Service Name: Service Protocole EAP (Extensible Authentication Protocol) [Stopped],
    Path: C:\WINDOWS\System32\svchost.exe -k eapsvcs
    Service Name: ServiceLayer [Stopped],
    Path: "C:\Program Files\PC Connectivity Solution\ServiceLayer.exe"
    Service Name: Services de cryptographie [Running],
    Path: C:\WINDOWS\system32\svchost.exe -k netsvcs
    Service Name: Services IPSEC [Running],
    Path: C:\WINDOWS\System32\lsass.exe
    Service Name: Services Terminal Server [Running],
    Path: C:\WINDOWS\System32\svchost -k DComLaunch
    Service Name: Spouleur d'impression [Running],
    Path: C:\WINDOWS\system32\spoolsv.exe
    Service Name: Station de travail [Running],
    Path: C:\WINDOWS\System32\svchost.exe -k netsvcs
    Service Name: Stockage amovible [Stopped],
    Path: C:\WINDOWS\system32\svchost.exe -k netsvcs
    Service Name: Système d'événements de COM+ [Running],
    Path: C:\WINDOWS\System32\svchost.exe -k netsvcs
    Service Name: Téléphonie [Running],
    Path: C:\WINDOWS\System32\svchost.exe -k netsvcs
    Service Name: Thèmes [Running],
    Path: C:\WINDOWS\System32\svchost.exe -k netsvcs
    Service Name: WebClient [Running],
    Path: C:\WINDOWS\System32\svchost.exe -k LocalService
    Service Name: Windows CardSpace [Stopped],
    Path: "C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe"
    Service Name: Windows Driver Foundation - User-mode Driver Framework [Running],
    Path: C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
    Service Name: Windows Installer [Stopped],
    Path: C:\WINDOWS\System32\msiexec.exe /V
    Service Name: Windows Live Contrôle parental [Running],
    Path: "C:\Program Files\Windows Live\Family Safety\fsssvc.exe"
    Service Name: Windows Presentation Foundation Font Cache 3.0.0.0 [Stopped],
    Path: C:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
    Finished...

    Merci.
    0
  12. pimprenelle27 Messages postés 22182 Statut Contributeur sécurité 2 503
     
    il n'a détecté aucun virus?
    0