A l'aide, j'ai le virus msn
Mart2inee
Messages postés
29
Statut
Membre
-
Mart2inee Messages postés 29 Statut Membre -
Mart2inee Messages postés 29 Statut Membre -
Bonjour,
Je été infecté par le virus msn, je ne sais pas comment, j'ai déjà été infecté il y a quelques mois, et j'ai du réinitialiser mon ordinateur, j'ai utilisé MSNFix et il ne trouve rien.
Voici le rapport Hisjackthis :
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:45:57, on 25/06/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\Martine\Application Data\Helpfiles\winlogon.exe
C:\Documents and Settings\Martine\Application Data\WinNT\winlogon.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\Philips\SPC220NC\Monitor.exe
C:\Program Files\Fichiers communs\Ulead Systems\AutoDetector\monitor.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Windows\LSD\LClock\lclock.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\WINDOWS\system32\imapi.exe
C:\Program Files\Philips\Philips SPC220NC Webcam\TrayMin220.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.hugedomains.com/domain_profile.cfm?d=cooxer&e=com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://melanthios-ana.com/zcvisitor/1624d318-3614-11eb-87b9-12a1ab6c324d/72092e88-2c53-401c-b988-51ef43ce1034?campaignid=47f83760-f118-11ea-9bc8-0ac2bbf4ada7
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Eazel-FR Toolbar - {a8f9752d-e2b8-4e7a-86b5-499f4330e2fe} - C:\Program Files\Eazel-FR\tbEaz1.dll
O1 - Hosts: 176.34.116.67 anubis.iseclab.org
O1 - Hosts: 82.115.191.219 www.threatexpert.com
O1 - Hosts: 207.184.189.188 threatexpert.com
O1 - Hosts: 83.127.105.183 cwsandbox.org
O1 - Hosts: 160.99.245.144 www.cwsandbox.org
O1 - Hosts: 65.43.228.126 u20.eset.com
O1 - Hosts: 151.73.244.12 u21.eset.com
O1 - Hosts: 69.151.38.25 u22.eset.com
O1 - Hosts: 103.109.81.4 u23.eset.com
O1 - Hosts: 133.4.241.195 u24.eset.com
O1 - Hosts: 68.64.170.228 u30.eset.com
O1 - Hosts: 175.198.177.201 u31.eset.com
O1 - Hosts: 53.8.12.19 u32.eset.com
O1 - Hosts: 22.154.226.141 u33.eset.com
O1 - Hosts: 119.146.212.25 u34.eset.com
O1 - Hosts: 85.184.131.91 u35.eset.com
O1 - Hosts: 240.187.62.171 u36.eset.com
O1 - Hosts: 19.204.31.25 u37.eset.com
O1 - Hosts: 177.65.100.247 u38.eset.com
O1 - Hosts: 73.40.226.62 u39.eset.com
O1 - Hosts: 8.102.230.196 u40.eset.com
O1 - Hosts: 26.212.197.23 u41.eset.com
O1 - Hosts: 161.105.22.228 u42.eset.com
O1 - Hosts: 193.237.185.222 u43.eset.com
O1 - Hosts: 62.72.52.241 u44.eset.com
O1 - Hosts: 141.81.251.45 u45.eset.com
O1 - Hosts: 114.211.67.98 u46.eset.com
O1 - Hosts: 104.21.97.41 u47.eset.com
O1 - Hosts: 252.20.221.233 u48.eset.com
O1 - Hosts: 112.216.66.21 u49.eset.com
O1 - Hosts: 161.1.48.37 f-secure.com
O1 - Hosts: 39.227.241.35 symantec.com
O1 - Hosts: 163.129.109.161 127.99.45.207
O1 - Hosts: 41.11.191.160 virusscan.jotti.org
O1 - Hosts: 216.216.16.86 acc.pdbox.co.kr
O1 - Hosts: 223.155.148.83 pcsafe.hanafos.com
O1 - Hosts: 229.189.226.40 viruschaser.com
O1 - Hosts: 196.58.211.119 www.viruschaser.com
O1 - Hosts: 190.230.38.235 v.chol.com
O1 - Hosts: 201.138.160.214 securitycenter.co.kr
O1 - Hosts: 20.157.233.212 www.securitycenter.co.kr
O1 - Hosts: 199.176.93.117 sandbox.norman.com
O1 - Hosts: 210.2.246.116 norman.com
O1 - Hosts: 194.57.48.74 sandbox.norman.no
O1 - Hosts: 254.4.17.131 norman.no
O1 - Hosts: 251.53.233.215 www.norman.no
O1 - Hosts: 76.198.111.88 kaspersky.pl
O1 - Hosts: 5.227.37.31 www.kaspersky.pl
O1 - Hosts: 232.225.82.96 www.kaspersky.telechargement.fr
O1 - Hosts: 214.205.107.197 kaspersky.telechargement.fr
O1 - Hosts: 216.104.174.107 kaspersky.de
O1 - Hosts: 111.192.222.128 www.kaspersky.de
O1 - Hosts: 93.202.90.64 kaspersky.co.nz
O1 - Hosts: 139.146.119.217 www.kaspersky.co.nz
O1 - Hosts: 240.254.221.4 kaspersky-antivirus.dk
O1 - Hosts: 225.51.87.188 www.kaspersky-antivirus.dk
O1 - Hosts: 211.2.194.249 kaspersky-me.com
O1 - Hosts: 247.19.36.216 www.kaspersky-me.com
O1 - Hosts: 164.157.254.2 kaspersky.co.uk
O1 - Hosts: 136.214.118.81 www.kaspersky.co.uk
O1 - Hosts: 139.9.230.250 kaspersky.com.au
O1 - Hosts: 237.94.93.63 www.kaspersky.com.au
O1 - Hosts: 241.89.58.100 www.kasperskyusa.com
O1 - Hosts: 45.21.98.0 kasperskyusa.com
O1 - Hosts: 209.51.51.88 agnitum.com
O1 - Hosts: 131.153.51.85 www.agnitum.com
O1 - Hosts: 13.99.177.212 smb.sygate.com
O1 - Hosts: 138.176.200.216 vic.zonelabs.com
O1 - Hosts: 217.49.114.87 download.zonelabs.com
O1 - Hosts: 105.138.169.185 zonelabs.com
O1 - Hosts: 56.17.207.189 www.zonelabs.com
O1 - Hosts: 152.88.55.78 freebyte.com
O1 - Hosts: 133.33.31.134 www.freebyte.com
O1 - Hosts: 178.46.137.244 www.bitdefender.com
O1 - Hosts: 14.113.149.84 bitdefender.com
O1 - Hosts: 218.182.101.196 www.virus-radar.com
O1 - Hosts: 60.36.184.73 virus-radar.com
O1 - Hosts: 43.63.176.139 www.nod32.com
O1 - Hosts: 82.216.110.45 nod32.com
O1 - Hosts: 184.2.9.161 avg-antivirus.net
O1 - Hosts: 180.104.10.102 www.avg-antivirus.net
O1 - Hosts: 196.243.251.70 vet.com.au
O1 - Hosts: 193.136.163.89 www.vet.com.au
O1 - Hosts: 74.188.254.27 avgbulgaria.com
O1 - Hosts: 196.85.136.142 www.avgbulgaria.com
O1 - Hosts: 238.213.232.31 windowsupdate.microsoft.com
O1 - Hosts: 135.199.81.134 update.microsoft.com
O1 - Hosts: 200.156.118.170 virusbtn.com
O1 - Hosts: 90.182.41.237 www.virusbtn.com
O1 - Hosts: 117.9.185.65 drsolomon.com
O1 - Hosts: 231.245.156.111 www.drsolomon.com
O1 - Hosts: 64.69.139.107 teamanti-virus.org
O1 - Hosts: 168.92.14.174 www.teamanti-virus.org
O1 - Hosts: 228.31.24.214 virustotal.com
O1 - Hosts: 98.22.202.158 www.virustotal.com
O1 - Hosts: 81.193.237.218 microsoft.com
O1 - Hosts: 59.71.40.31 www.microsoft.com
O1 - Hosts: 133.67.41.53 www.cert.org
O1 - Hosts: 95.132.175.239 cert.org
O1 - Hosts: 125.253.41.43 avast.com
O1 - Hosts: 49.150.94.234 www.avast.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Skyrock Toolbar - {A057A204-BACC-4D26-969A-2AB983EE729B} - C:\PROGRA~1\SKYROC~1\SKYROC~1.DLL
O2 - BHO: Eazel-FR Toolbar - {a8f9752d-e2b8-4e7a-86b5-499f4330e2fe} - C:\Program Files\Eazel-FR\tbEaz1.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Eazel-FR Toolbar - {a8f9752d-e2b8-4e7a-86b5-499f4330e2fe} - C:\Program Files\Eazel-FR\tbEaz1.dll
O3 - Toolbar: Skyrock Toolbar - {A057A204-BACC-4D26-969A-2AB983EE729B} - C:\PROGRA~1\SKYROC~1\SKYROC~1.DLL
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [Google Quick Search Box] "C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe" /autorun
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Monitor] C:\WINDOWS\Philips\SPC220NC\Monitor.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [Ulead AutoDetector v2] C:\Program Files\Fichiers communs\Ulead Systems\AutoDetector\monitor.exe
O4 - HKLM\..\Run: [systme] C:\WINDOWS\system32\supar.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [LClock] C:\Windows\LSD\LClock\lclock.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - HKLM\..\Policies\Explorer\Run: [Windows Logon Service] "C:\Documents and Settings\Martine\Application Data\Helpfiles\winlogon.exe"
O4 - HKLM\..\Policies\Explorer\Run: [Windows Logon Servicer] "C:\Documents and Settings\Martine\Application Data\WinNT\winlogon.exe"
O4 - HKCU\..\Policies\Explorer\Run: [Windows Logon Service] "C:\Documents and Settings\Martine\Application Data\Helpfiles\winlogon.exe"
O4 - HKCU\..\Policies\Explorer\Run: [Windows Logon Servicer] "C:\Documents and Settings\Martine\Application Data\WinNT\winlogon.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [WinLSD_SP3] %systemroot%\LSD\end.cmd (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-20\..\RunOnce: [WinLSD_SP3] %systemroot%\LSD\end.cmd (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [WinLSD_SP3] %systemroot%\LSD\end.cmd (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [WinLSD_SP3] %systemroot%\LSD\end.cmd (User 'Default user')
O4 - Global Startup: TrayMin220.lnk = ?
O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Service Google Update (gupdate1c9dd6aca55b53a) (gupdate1c9dd6aca55b53a) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
Je été infecté par le virus msn, je ne sais pas comment, j'ai déjà été infecté il y a quelques mois, et j'ai du réinitialiser mon ordinateur, j'ai utilisé MSNFix et il ne trouve rien.
Voici le rapport Hisjackthis :
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:45:57, on 25/06/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\Martine\Application Data\Helpfiles\winlogon.exe
C:\Documents and Settings\Martine\Application Data\WinNT\winlogon.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\Philips\SPC220NC\Monitor.exe
C:\Program Files\Fichiers communs\Ulead Systems\AutoDetector\monitor.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Windows\LSD\LClock\lclock.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\WINDOWS\system32\imapi.exe
C:\Program Files\Philips\Philips SPC220NC Webcam\TrayMin220.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.hugedomains.com/domain_profile.cfm?d=cooxer&e=com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://melanthios-ana.com/zcvisitor/1624d318-3614-11eb-87b9-12a1ab6c324d/72092e88-2c53-401c-b988-51ef43ce1034?campaignid=47f83760-f118-11ea-9bc8-0ac2bbf4ada7
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Eazel-FR Toolbar - {a8f9752d-e2b8-4e7a-86b5-499f4330e2fe} - C:\Program Files\Eazel-FR\tbEaz1.dll
O1 - Hosts: 176.34.116.67 anubis.iseclab.org
O1 - Hosts: 82.115.191.219 www.threatexpert.com
O1 - Hosts: 207.184.189.188 threatexpert.com
O1 - Hosts: 83.127.105.183 cwsandbox.org
O1 - Hosts: 160.99.245.144 www.cwsandbox.org
O1 - Hosts: 65.43.228.126 u20.eset.com
O1 - Hosts: 151.73.244.12 u21.eset.com
O1 - Hosts: 69.151.38.25 u22.eset.com
O1 - Hosts: 103.109.81.4 u23.eset.com
O1 - Hosts: 133.4.241.195 u24.eset.com
O1 - Hosts: 68.64.170.228 u30.eset.com
O1 - Hosts: 175.198.177.201 u31.eset.com
O1 - Hosts: 53.8.12.19 u32.eset.com
O1 - Hosts: 22.154.226.141 u33.eset.com
O1 - Hosts: 119.146.212.25 u34.eset.com
O1 - Hosts: 85.184.131.91 u35.eset.com
O1 - Hosts: 240.187.62.171 u36.eset.com
O1 - Hosts: 19.204.31.25 u37.eset.com
O1 - Hosts: 177.65.100.247 u38.eset.com
O1 - Hosts: 73.40.226.62 u39.eset.com
O1 - Hosts: 8.102.230.196 u40.eset.com
O1 - Hosts: 26.212.197.23 u41.eset.com
O1 - Hosts: 161.105.22.228 u42.eset.com
O1 - Hosts: 193.237.185.222 u43.eset.com
O1 - Hosts: 62.72.52.241 u44.eset.com
O1 - Hosts: 141.81.251.45 u45.eset.com
O1 - Hosts: 114.211.67.98 u46.eset.com
O1 - Hosts: 104.21.97.41 u47.eset.com
O1 - Hosts: 252.20.221.233 u48.eset.com
O1 - Hosts: 112.216.66.21 u49.eset.com
O1 - Hosts: 161.1.48.37 f-secure.com
O1 - Hosts: 39.227.241.35 symantec.com
O1 - Hosts: 163.129.109.161 127.99.45.207
O1 - Hosts: 41.11.191.160 virusscan.jotti.org
O1 - Hosts: 216.216.16.86 acc.pdbox.co.kr
O1 - Hosts: 223.155.148.83 pcsafe.hanafos.com
O1 - Hosts: 229.189.226.40 viruschaser.com
O1 - Hosts: 196.58.211.119 www.viruschaser.com
O1 - Hosts: 190.230.38.235 v.chol.com
O1 - Hosts: 201.138.160.214 securitycenter.co.kr
O1 - Hosts: 20.157.233.212 www.securitycenter.co.kr
O1 - Hosts: 199.176.93.117 sandbox.norman.com
O1 - Hosts: 210.2.246.116 norman.com
O1 - Hosts: 194.57.48.74 sandbox.norman.no
O1 - Hosts: 254.4.17.131 norman.no
O1 - Hosts: 251.53.233.215 www.norman.no
O1 - Hosts: 76.198.111.88 kaspersky.pl
O1 - Hosts: 5.227.37.31 www.kaspersky.pl
O1 - Hosts: 232.225.82.96 www.kaspersky.telechargement.fr
O1 - Hosts: 214.205.107.197 kaspersky.telechargement.fr
O1 - Hosts: 216.104.174.107 kaspersky.de
O1 - Hosts: 111.192.222.128 www.kaspersky.de
O1 - Hosts: 93.202.90.64 kaspersky.co.nz
O1 - Hosts: 139.146.119.217 www.kaspersky.co.nz
O1 - Hosts: 240.254.221.4 kaspersky-antivirus.dk
O1 - Hosts: 225.51.87.188 www.kaspersky-antivirus.dk
O1 - Hosts: 211.2.194.249 kaspersky-me.com
O1 - Hosts: 247.19.36.216 www.kaspersky-me.com
O1 - Hosts: 164.157.254.2 kaspersky.co.uk
O1 - Hosts: 136.214.118.81 www.kaspersky.co.uk
O1 - Hosts: 139.9.230.250 kaspersky.com.au
O1 - Hosts: 237.94.93.63 www.kaspersky.com.au
O1 - Hosts: 241.89.58.100 www.kasperskyusa.com
O1 - Hosts: 45.21.98.0 kasperskyusa.com
O1 - Hosts: 209.51.51.88 agnitum.com
O1 - Hosts: 131.153.51.85 www.agnitum.com
O1 - Hosts: 13.99.177.212 smb.sygate.com
O1 - Hosts: 138.176.200.216 vic.zonelabs.com
O1 - Hosts: 217.49.114.87 download.zonelabs.com
O1 - Hosts: 105.138.169.185 zonelabs.com
O1 - Hosts: 56.17.207.189 www.zonelabs.com
O1 - Hosts: 152.88.55.78 freebyte.com
O1 - Hosts: 133.33.31.134 www.freebyte.com
O1 - Hosts: 178.46.137.244 www.bitdefender.com
O1 - Hosts: 14.113.149.84 bitdefender.com
O1 - Hosts: 218.182.101.196 www.virus-radar.com
O1 - Hosts: 60.36.184.73 virus-radar.com
O1 - Hosts: 43.63.176.139 www.nod32.com
O1 - Hosts: 82.216.110.45 nod32.com
O1 - Hosts: 184.2.9.161 avg-antivirus.net
O1 - Hosts: 180.104.10.102 www.avg-antivirus.net
O1 - Hosts: 196.243.251.70 vet.com.au
O1 - Hosts: 193.136.163.89 www.vet.com.au
O1 - Hosts: 74.188.254.27 avgbulgaria.com
O1 - Hosts: 196.85.136.142 www.avgbulgaria.com
O1 - Hosts: 238.213.232.31 windowsupdate.microsoft.com
O1 - Hosts: 135.199.81.134 update.microsoft.com
O1 - Hosts: 200.156.118.170 virusbtn.com
O1 - Hosts: 90.182.41.237 www.virusbtn.com
O1 - Hosts: 117.9.185.65 drsolomon.com
O1 - Hosts: 231.245.156.111 www.drsolomon.com
O1 - Hosts: 64.69.139.107 teamanti-virus.org
O1 - Hosts: 168.92.14.174 www.teamanti-virus.org
O1 - Hosts: 228.31.24.214 virustotal.com
O1 - Hosts: 98.22.202.158 www.virustotal.com
O1 - Hosts: 81.193.237.218 microsoft.com
O1 - Hosts: 59.71.40.31 www.microsoft.com
O1 - Hosts: 133.67.41.53 www.cert.org
O1 - Hosts: 95.132.175.239 cert.org
O1 - Hosts: 125.253.41.43 avast.com
O1 - Hosts: 49.150.94.234 www.avast.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Skyrock Toolbar - {A057A204-BACC-4D26-969A-2AB983EE729B} - C:\PROGRA~1\SKYROC~1\SKYROC~1.DLL
O2 - BHO: Eazel-FR Toolbar - {a8f9752d-e2b8-4e7a-86b5-499f4330e2fe} - C:\Program Files\Eazel-FR\tbEaz1.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Eazel-FR Toolbar - {a8f9752d-e2b8-4e7a-86b5-499f4330e2fe} - C:\Program Files\Eazel-FR\tbEaz1.dll
O3 - Toolbar: Skyrock Toolbar - {A057A204-BACC-4D26-969A-2AB983EE729B} - C:\PROGRA~1\SKYROC~1\SKYROC~1.DLL
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [Google Quick Search Box] "C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe" /autorun
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Monitor] C:\WINDOWS\Philips\SPC220NC\Monitor.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [Ulead AutoDetector v2] C:\Program Files\Fichiers communs\Ulead Systems\AutoDetector\monitor.exe
O4 - HKLM\..\Run: [systme] C:\WINDOWS\system32\supar.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [LClock] C:\Windows\LSD\LClock\lclock.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - HKLM\..\Policies\Explorer\Run: [Windows Logon Service] "C:\Documents and Settings\Martine\Application Data\Helpfiles\winlogon.exe"
O4 - HKLM\..\Policies\Explorer\Run: [Windows Logon Servicer] "C:\Documents and Settings\Martine\Application Data\WinNT\winlogon.exe"
O4 - HKCU\..\Policies\Explorer\Run: [Windows Logon Service] "C:\Documents and Settings\Martine\Application Data\Helpfiles\winlogon.exe"
O4 - HKCU\..\Policies\Explorer\Run: [Windows Logon Servicer] "C:\Documents and Settings\Martine\Application Data\WinNT\winlogon.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [WinLSD_SP3] %systemroot%\LSD\end.cmd (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-20\..\RunOnce: [WinLSD_SP3] %systemroot%\LSD\end.cmd (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [WinLSD_SP3] %systemroot%\LSD\end.cmd (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [WinLSD_SP3] %systemroot%\LSD\end.cmd (User 'Default user')
O4 - Global Startup: TrayMin220.lnk = ?
O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Service Google Update (gupdate1c9dd6aca55b53a) (gupdate1c9dd6aca55b53a) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
A voir également:
- A l'aide, j'ai le virus msn
- Virus mcafee - Accueil - Piratage
- Telecharger msn - Télécharger - Messagerie
- Virus informatique - Guide
- Msn messenger - Télécharger - Messagerie
- Panda anti virus gratuit - Télécharger - Antivirus & Antimalwares
52 réponses
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
Logfile of random's system information tool 1.06 (written by random/random)
Run by Martine at 2009-06-26 17:30:18
Microsoft Windows XP Professionnel Service Pack 3
System drive C: has 22 GB (62%) free of 36 GB
Total RAM: 1014 MB (54% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:30:26, on 26/06/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\Philips\SPC220NC\Monitor.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Fichiers communs\Ulead Systems\AutoDetector\monitor.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\WINDOWS\system32\imapi.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Windows\LSD\LClock\lclock.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Philips\Philips SPC220NC Webcam\TrayMin220.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Martine\Local Settings\Temporary Internet Files\Content.IE5\L0H9CVDY\RSIT[1].exe
C:\Program Files\Trend Micro\HijackThis\Martine.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.hugedomains.com/domain_profile.cfm?d=cooxer&e=com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://melanthios-ana.com/zcvisitor/1624d318-3614-11eb-87b9-12a1ab6c324d/72092e88-2c53-401c-b988-51ef43ce1034?campaignid=47f83760-f118-11ea-9bc8-0ac2bbf4ada7
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Eazel-FR Toolbar - {a8f9752d-e2b8-4e7a-86b5-499f4330e2fe} - C:\Program Files\Eazel-FR\tbEaz1.dll
O1 - Hosts: 176.34.116.67 anubis.iseclab.org
O1 - Hosts: 82.115.191.219 www.threatexpert.com
O1 - Hosts: 207.184.189.188 threatexpert.com
O1 - Hosts: 83.127.105.183 cwsandbox.org
O1 - Hosts: 160.99.245.144 www.cwsandbox.org
O1 - Hosts: 65.43.228.126 u20.eset.com
O1 - Hosts: 151.73.244.12 u21.eset.com
O1 - Hosts: 69.151.38.25 u22.eset.com
O1 - Hosts: 103.109.81.4 u23.eset.com
O1 - Hosts: 133.4.241.195 u24.eset.com
O1 - Hosts: 68.64.170.228 u30.eset.com
O1 - Hosts: 175.198.177.201 u31.eset.com
O1 - Hosts: 53.8.12.19 u32.eset.com
O1 - Hosts: 22.154.226.141 u33.eset.com
O1 - Hosts: 119.146.212.25 u34.eset.com
O1 - Hosts: 85.184.131.91 u35.eset.com
O1 - Hosts: 240.187.62.171 u36.eset.com
O1 - Hosts: 19.204.31.25 u37.eset.com
O1 - Hosts: 177.65.100.247 u38.eset.com
O1 - Hosts: 73.40.226.62 u39.eset.com
O1 - Hosts: 8.102.230.196 u40.eset.com
O1 - Hosts: 26.212.197.23 u41.eset.com
O1 - Hosts: 161.105.22.228 u42.eset.com
O1 - Hosts: 193.237.185.222 u43.eset.com
O1 - Hosts: 62.72.52.241 u44.eset.com
O1 - Hosts: 141.81.251.45 u45.eset.com
O1 - Hosts: 114.211.67.98 u46.eset.com
O1 - Hosts: 104.21.97.41 u47.eset.com
O1 - Hosts: 252.20.221.233 u48.eset.com
O1 - Hosts: 112.216.66.21 u49.eset.com
O1 - Hosts: 161.1.48.37 f-secure.com
O1 - Hosts: 39.227.241.35 symantec.com
O1 - Hosts: 163.129.109.161 127.99.45.207
O1 - Hosts: 41.11.191.160 virusscan.jotti.org
O1 - Hosts: 216.216.16.86 acc.pdbox.co.kr
O1 - Hosts: 223.155.148.83 pcsafe.hanafos.com
O1 - Hosts: 229.189.226.40 viruschaser.com
O1 - Hosts: 196.58.211.119 www.viruschaser.com
O1 - Hosts: 190.230.38.235 v.chol.com
O1 - Hosts: 201.138.160.214 securitycenter.co.kr
O1 - Hosts: 20.157.233.212 www.securitycenter.co.kr
O1 - Hosts: 199.176.93.117 sandbox.norman.com
O1 - Hosts: 210.2.246.116 norman.com
O1 - Hosts: 194.57.48.74 sandbox.norman.no
O1 - Hosts: 254.4.17.131 norman.no
O1 - Hosts: 251.53.233.215 www.norman.no
O1 - Hosts: 76.198.111.88 kaspersky.pl
O1 - Hosts: 5.227.37.31 www.kaspersky.pl
O1 - Hosts: 232.225.82.96 www.kaspersky.telechargement.fr
O1 - Hosts: 214.205.107.197 kaspersky.telechargement.fr
O1 - Hosts: 216.104.174.107 kaspersky.de
O1 - Hosts: 111.192.222.128 www.kaspersky.de
O1 - Hosts: 93.202.90.64 kaspersky.co.nz
O1 - Hosts: 139.146.119.217 www.kaspersky.co.nz
O1 - Hosts: 240.254.221.4 kaspersky-antivirus.dk
O1 - Hosts: 225.51.87.188 www.kaspersky-antivirus.dk
O1 - Hosts: 211.2.194.249 kaspersky-me.com
O1 - Hosts: 247.19.36.216 www.kaspersky-me.com
O1 - Hosts: 164.157.254.2 kaspersky.co.uk
O1 - Hosts: 136.214.118.81 www.kaspersky.co.uk
O1 - Hosts: 139.9.230.250 kaspersky.com.au
O1 - Hosts: 237.94.93.63 www.kaspersky.com.au
O1 - Hosts: 241.89.58.100 www.kasperskyusa.com
O1 - Hosts: 45.21.98.0 kasperskyusa.com
O1 - Hosts: 209.51.51.88 agnitum.com
O1 - Hosts: 131.153.51.85 www.agnitum.com
O1 - Hosts: 13.99.177.212 smb.sygate.com
O1 - Hosts: 138.176.200.216 vic.zonelabs.com
O1 - Hosts: 217.49.114.87 download.zonelabs.com
O1 - Hosts: 105.138.169.185 zonelabs.com
O1 - Hosts: 56.17.207.189 www.zonelabs.com
O1 - Hosts: 152.88.55.78 freebyte.com
O1 - Hosts: 133.33.31.134 www.freebyte.com
O1 - Hosts: 178.46.137.244 www.bitdefender.com
O1 - Hosts: 14.113.149.84 bitdefender.com
O1 - Hosts: 218.182.101.196 www.virus-radar.com
O1 - Hosts: 60.36.184.73 virus-radar.com
O1 - Hosts: 43.63.176.139 www.nod32.com
O1 - Hosts: 82.216.110.45 nod32.com
O1 - Hosts: 184.2.9.161 avg-antivirus.net
O1 - Hosts: 180.104.10.102 www.avg-antivirus.net
O1 - Hosts: 196.243.251.70 vet.com.au
O1 - Hosts: 193.136.163.89 www.vet.com.au
O1 - Hosts: 74.188.254.27 avgbulgaria.com
O1 - Hosts: 196.85.136.142 www.avgbulgaria.com
O1 - Hosts: 238.213.232.31 windowsupdate.microsoft.com
O1 - Hosts: 135.199.81.134 update.microsoft.com
O1 - Hosts: 200.156.118.170 virusbtn.com
O1 - Hosts: 90.182.41.237 www.virusbtn.com
O1 - Hosts: 117.9.185.65 drsolomon.com
O1 - Hosts: 231.245.156.111 www.drsolomon.com
O1 - Hosts: 64.69.139.107 teamanti-virus.org
O1 - Hosts: 168.92.14.174 www.teamanti-virus.org
O1 - Hosts: 228.31.24.214 virustotal.com
O1 - Hosts: 98.22.202.158 www.virustotal.com
O1 - Hosts: 81.193.237.218 microsoft.com
O1 - Hosts: 59.71.40.31 www.microsoft.com
O1 - Hosts: 133.67.41.53 www.cert.org
O1 - Hosts: 95.132.175.239 cert.org
O1 - Hosts: 125.253.41.43 avast.com
O1 - Hosts: 49.150.94.234 www.avast.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Skyrock Toolbar - {A057A204-BACC-4D26-969A-2AB983EE729B} - C:\PROGRA~1\SKYROC~1\SKYROC~1.DLL
O2 - BHO: Eazel-FR Toolbar - {a8f9752d-e2b8-4e7a-86b5-499f4330e2fe} - C:\Program Files\Eazel-FR\tbEaz1.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Eazel-FR Toolbar - {a8f9752d-e2b8-4e7a-86b5-499f4330e2fe} - C:\Program Files\Eazel-FR\tbEaz1.dll
O3 - Toolbar: Skyrock Toolbar - {A057A204-BACC-4D26-969A-2AB983EE729B} - C:\PROGRA~1\SKYROC~1\SKYROC~1.DLL
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [Google Quick Search Box] "C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe" /autorun
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Monitor] C:\WINDOWS\Philips\SPC220NC\Monitor.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [Ulead AutoDetector v2] C:\Program Files\Fichiers communs\Ulead Systems\AutoDetector\monitor.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [LClock] C:\Windows\LSD\LClock\lclock.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - HKLM\..\Policies\Explorer\Run: [Windows Logon Servicer] "C:\Documents and Settings\Martine\Application Data\WinNT\winlogon.exe"
O4 - HKCU\..\Policies\Explorer\Run: [Windows Logon Servicer] "C:\Documents and Settings\Martine\Application Data\WinNT\winlogon.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [WinLSD_SP3] %systemroot%\LSD\end.cmd (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-20\..\RunOnce: [WinLSD_SP3] %systemroot%\LSD\end.cmd (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [WinLSD_SP3] %systemroot%\LSD\end.cmd (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [WinLSD_SP3] %systemroot%\LSD\end.cmd (User 'Default user')
O4 - Startup: OpenOffice.org 3.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Global Startup: TrayMin220.lnk = ?
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Service Google Update (gupdate1c9dd6aca55b53a) (gupdate1c9dd6aca55b53a) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
Run by Martine at 2009-06-26 17:30:18
Microsoft Windows XP Professionnel Service Pack 3
System drive C: has 22 GB (62%) free of 36 GB
Total RAM: 1014 MB (54% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:30:26, on 26/06/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\Philips\SPC220NC\Monitor.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Fichiers communs\Ulead Systems\AutoDetector\monitor.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\WINDOWS\system32\imapi.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Windows\LSD\LClock\lclock.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Philips\Philips SPC220NC Webcam\TrayMin220.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Martine\Local Settings\Temporary Internet Files\Content.IE5\L0H9CVDY\RSIT[1].exe
C:\Program Files\Trend Micro\HijackThis\Martine.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.hugedomains.com/domain_profile.cfm?d=cooxer&e=com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://melanthios-ana.com/zcvisitor/1624d318-3614-11eb-87b9-12a1ab6c324d/72092e88-2c53-401c-b988-51ef43ce1034?campaignid=47f83760-f118-11ea-9bc8-0ac2bbf4ada7
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Eazel-FR Toolbar - {a8f9752d-e2b8-4e7a-86b5-499f4330e2fe} - C:\Program Files\Eazel-FR\tbEaz1.dll
O1 - Hosts: 176.34.116.67 anubis.iseclab.org
O1 - Hosts: 82.115.191.219 www.threatexpert.com
O1 - Hosts: 207.184.189.188 threatexpert.com
O1 - Hosts: 83.127.105.183 cwsandbox.org
O1 - Hosts: 160.99.245.144 www.cwsandbox.org
O1 - Hosts: 65.43.228.126 u20.eset.com
O1 - Hosts: 151.73.244.12 u21.eset.com
O1 - Hosts: 69.151.38.25 u22.eset.com
O1 - Hosts: 103.109.81.4 u23.eset.com
O1 - Hosts: 133.4.241.195 u24.eset.com
O1 - Hosts: 68.64.170.228 u30.eset.com
O1 - Hosts: 175.198.177.201 u31.eset.com
O1 - Hosts: 53.8.12.19 u32.eset.com
O1 - Hosts: 22.154.226.141 u33.eset.com
O1 - Hosts: 119.146.212.25 u34.eset.com
O1 - Hosts: 85.184.131.91 u35.eset.com
O1 - Hosts: 240.187.62.171 u36.eset.com
O1 - Hosts: 19.204.31.25 u37.eset.com
O1 - Hosts: 177.65.100.247 u38.eset.com
O1 - Hosts: 73.40.226.62 u39.eset.com
O1 - Hosts: 8.102.230.196 u40.eset.com
O1 - Hosts: 26.212.197.23 u41.eset.com
O1 - Hosts: 161.105.22.228 u42.eset.com
O1 - Hosts: 193.237.185.222 u43.eset.com
O1 - Hosts: 62.72.52.241 u44.eset.com
O1 - Hosts: 141.81.251.45 u45.eset.com
O1 - Hosts: 114.211.67.98 u46.eset.com
O1 - Hosts: 104.21.97.41 u47.eset.com
O1 - Hosts: 252.20.221.233 u48.eset.com
O1 - Hosts: 112.216.66.21 u49.eset.com
O1 - Hosts: 161.1.48.37 f-secure.com
O1 - Hosts: 39.227.241.35 symantec.com
O1 - Hosts: 163.129.109.161 127.99.45.207
O1 - Hosts: 41.11.191.160 virusscan.jotti.org
O1 - Hosts: 216.216.16.86 acc.pdbox.co.kr
O1 - Hosts: 223.155.148.83 pcsafe.hanafos.com
O1 - Hosts: 229.189.226.40 viruschaser.com
O1 - Hosts: 196.58.211.119 www.viruschaser.com
O1 - Hosts: 190.230.38.235 v.chol.com
O1 - Hosts: 201.138.160.214 securitycenter.co.kr
O1 - Hosts: 20.157.233.212 www.securitycenter.co.kr
O1 - Hosts: 199.176.93.117 sandbox.norman.com
O1 - Hosts: 210.2.246.116 norman.com
O1 - Hosts: 194.57.48.74 sandbox.norman.no
O1 - Hosts: 254.4.17.131 norman.no
O1 - Hosts: 251.53.233.215 www.norman.no
O1 - Hosts: 76.198.111.88 kaspersky.pl
O1 - Hosts: 5.227.37.31 www.kaspersky.pl
O1 - Hosts: 232.225.82.96 www.kaspersky.telechargement.fr
O1 - Hosts: 214.205.107.197 kaspersky.telechargement.fr
O1 - Hosts: 216.104.174.107 kaspersky.de
O1 - Hosts: 111.192.222.128 www.kaspersky.de
O1 - Hosts: 93.202.90.64 kaspersky.co.nz
O1 - Hosts: 139.146.119.217 www.kaspersky.co.nz
O1 - Hosts: 240.254.221.4 kaspersky-antivirus.dk
O1 - Hosts: 225.51.87.188 www.kaspersky-antivirus.dk
O1 - Hosts: 211.2.194.249 kaspersky-me.com
O1 - Hosts: 247.19.36.216 www.kaspersky-me.com
O1 - Hosts: 164.157.254.2 kaspersky.co.uk
O1 - Hosts: 136.214.118.81 www.kaspersky.co.uk
O1 - Hosts: 139.9.230.250 kaspersky.com.au
O1 - Hosts: 237.94.93.63 www.kaspersky.com.au
O1 - Hosts: 241.89.58.100 www.kasperskyusa.com
O1 - Hosts: 45.21.98.0 kasperskyusa.com
O1 - Hosts: 209.51.51.88 agnitum.com
O1 - Hosts: 131.153.51.85 www.agnitum.com
O1 - Hosts: 13.99.177.212 smb.sygate.com
O1 - Hosts: 138.176.200.216 vic.zonelabs.com
O1 - Hosts: 217.49.114.87 download.zonelabs.com
O1 - Hosts: 105.138.169.185 zonelabs.com
O1 - Hosts: 56.17.207.189 www.zonelabs.com
O1 - Hosts: 152.88.55.78 freebyte.com
O1 - Hosts: 133.33.31.134 www.freebyte.com
O1 - Hosts: 178.46.137.244 www.bitdefender.com
O1 - Hosts: 14.113.149.84 bitdefender.com
O1 - Hosts: 218.182.101.196 www.virus-radar.com
O1 - Hosts: 60.36.184.73 virus-radar.com
O1 - Hosts: 43.63.176.139 www.nod32.com
O1 - Hosts: 82.216.110.45 nod32.com
O1 - Hosts: 184.2.9.161 avg-antivirus.net
O1 - Hosts: 180.104.10.102 www.avg-antivirus.net
O1 - Hosts: 196.243.251.70 vet.com.au
O1 - Hosts: 193.136.163.89 www.vet.com.au
O1 - Hosts: 74.188.254.27 avgbulgaria.com
O1 - Hosts: 196.85.136.142 www.avgbulgaria.com
O1 - Hosts: 238.213.232.31 windowsupdate.microsoft.com
O1 - Hosts: 135.199.81.134 update.microsoft.com
O1 - Hosts: 200.156.118.170 virusbtn.com
O1 - Hosts: 90.182.41.237 www.virusbtn.com
O1 - Hosts: 117.9.185.65 drsolomon.com
O1 - Hosts: 231.245.156.111 www.drsolomon.com
O1 - Hosts: 64.69.139.107 teamanti-virus.org
O1 - Hosts: 168.92.14.174 www.teamanti-virus.org
O1 - Hosts: 228.31.24.214 virustotal.com
O1 - Hosts: 98.22.202.158 www.virustotal.com
O1 - Hosts: 81.193.237.218 microsoft.com
O1 - Hosts: 59.71.40.31 www.microsoft.com
O1 - Hosts: 133.67.41.53 www.cert.org
O1 - Hosts: 95.132.175.239 cert.org
O1 - Hosts: 125.253.41.43 avast.com
O1 - Hosts: 49.150.94.234 www.avast.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Skyrock Toolbar - {A057A204-BACC-4D26-969A-2AB983EE729B} - C:\PROGRA~1\SKYROC~1\SKYROC~1.DLL
O2 - BHO: Eazel-FR Toolbar - {a8f9752d-e2b8-4e7a-86b5-499f4330e2fe} - C:\Program Files\Eazel-FR\tbEaz1.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Eazel-FR Toolbar - {a8f9752d-e2b8-4e7a-86b5-499f4330e2fe} - C:\Program Files\Eazel-FR\tbEaz1.dll
O3 - Toolbar: Skyrock Toolbar - {A057A204-BACC-4D26-969A-2AB983EE729B} - C:\PROGRA~1\SKYROC~1\SKYROC~1.DLL
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [Google Quick Search Box] "C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe" /autorun
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Monitor] C:\WINDOWS\Philips\SPC220NC\Monitor.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [Ulead AutoDetector v2] C:\Program Files\Fichiers communs\Ulead Systems\AutoDetector\monitor.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [LClock] C:\Windows\LSD\LClock\lclock.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - HKLM\..\Policies\Explorer\Run: [Windows Logon Servicer] "C:\Documents and Settings\Martine\Application Data\WinNT\winlogon.exe"
O4 - HKCU\..\Policies\Explorer\Run: [Windows Logon Servicer] "C:\Documents and Settings\Martine\Application Data\WinNT\winlogon.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [WinLSD_SP3] %systemroot%\LSD\end.cmd (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-20\..\RunOnce: [WinLSD_SP3] %systemroot%\LSD\end.cmd (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [WinLSD_SP3] %systemroot%\LSD\end.cmd (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [WinLSD_SP3] %systemroot%\LSD\end.cmd (User 'Default user')
O4 - Startup: OpenOffice.org 3.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Global Startup: TrayMin220.lnk = ?
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Service Google Update (gupdate1c9dd6aca55b53a) (gupdate1c9dd6aca55b53a) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
Ok, c'est mieux que tout à l'heure.
--> Télécharge UsbFix (de C_XX & Chiquitine29) sur ton Bureau.
--> Lance l'installation avec les paramètres par défaut.
--> Branche tes sources de données externes à ton PC (clé USB, disque dur externe, carte SD, etc...) sans les ouvrir.
--> Double-clique sur le raccourci UsbFix sur ton Bureau.
--> Choisis l'option 1 (Recherche).
--> Laisse travailler l'outil.
--> Poste le rapport UsbFix.txt.
Note : le rapport UsbFix.txt est sauvegardé à la racine du disque (C:\UsbFix.txt).
"Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool. Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
--> Télécharge UsbFix (de C_XX & Chiquitine29) sur ton Bureau.
--> Lance l'installation avec les paramètres par défaut.
--> Branche tes sources de données externes à ton PC (clé USB, disque dur externe, carte SD, etc...) sans les ouvrir.
--> Double-clique sur le raccourci UsbFix sur ton Bureau.
--> Choisis l'option 1 (Recherche).
--> Laisse travailler l'outil.
--> Poste le rapport UsbFix.txt.
Note : le rapport UsbFix.txt est sauvegardé à la racine du disque (C:\UsbFix.txt).
"Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool. Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
############################## [ UsbFix V3.033 ]
# User : Martine (Utilisateurs) # RIDELIGHT
# Update on 15/06/09 by C_XX
# Start at: 18:42:13 | 26/06/2009
# Website : http://pagesperso-orange.fr/NosTools/usbfix.html
# Intel(R) Pentium(R) M processor 1.73GHz
# Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 3
# Internet Explorer 7.0.5730.13
# Windows Firewall Status : Disabled
# C:\ # Disque fixe local # 35,07 Go (21,59 Go free) # NTFS
# D:\ # Disque fixe local # 35,55 Go (31,79 Go free) [ACERDATA] # FAT32
# E:\ # Disque CD-ROM # 413,72 Mo (0 Mo free) [Sims2SP5] # CDFS
# F:\ # Disque amovible # 3,79 Go (1,31 Go free) [UDISK] # FAT32
############################## [ Processus actifs ]
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\Philips\SPC220NC\Monitor.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Fichiers communs\Ulead Systems\AutoDetector\monitor.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\WINDOWS\system32\imapi.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Windows\LSD\LClock\lclock.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Philips\Philips SPC220NC Webcam\TrayMin220.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
################## [ Registre Startup ]
HKCU_Main: "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
HKCU_Main: "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
HKCU_Main: "Start Page"="https://www.google.fr/?gws_rd=ssl"
HKLM_logon: "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
HKLM_logon: "DefaultUserName"="Martine"
HKLM_logon: "AltDefaultUserName"="Martine"
HKLM_logon: "LegalNoticeCaption"=""
HKLM_logon: "LegalNoticeText"=""
HKLM_Run: igfxtray=C:\WINDOWS\system32\igfxtray.exe
HKLM_Run: igfxhkcmd=C:\WINDOWS\system32\hkcmd.exe
HKLM_Run: igfxpers=C:\WINDOWS\system32\igfxpers.exe
HKLM_Run: SynTPLpr=C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
HKLM_Run: SynTPEnh=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
HKLM_Run: RTHDCPL=RTHDCPL.EXE
HKLM_Run: Alcmtr=ALCMTR.EXE
HKLM_Run: Google Quick Search Box="C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe" /autorun
HKLM_Run: SunJavaUpdateSched="C:\Program Files\Java\jre6\bin\jusched.exe"
HKLM_Run: Monitor=C:\WINDOWS\Philips\SPC220NC\Monitor.exe
HKLM_Run: KernelFaultCheck=%systemroot%\system32\dumprep 0 -k
HKLM_Run: Ulead AutoDetector v2=C:\Program Files\Fichiers communs\Ulead Systems\AutoDetector\monitor.exe
HKLM_Run: TkBellExe="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
HKLM_Run: avgnt="C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
HKCU_Run: CTFMON.EXE=C:\WINDOWS\system32\ctfmon.exe
HKCU_Run: LClock=C:\Windows\LSD\LClock\lclock.exe
HKCU_Run: msnmsgr="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
HKCU_Run: swg=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
HKCU_Run: ares="C:\Program Files\Ares\Ares.exe" -h
HKCU_expl: "NoFolderOptions"=dword:00000001
HKCU_expl: "NoRun"=dword:00000001
################## [ Fichiers # Dossiers infectieux ]
Présent ! "C:\restore\S-1-5-21-1482476501-1644491937-682003330-1013"
Présent ! C:\restore\S-1-5-21-1482476501-1644491937-682003330-1013\Desktop.ini
Présent ! D:\autorun.inf
Présent ! E:\autorun.inf
F:\autorun.inf # -> fichier appelé : "F:\RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\wmmplayer.exe" ( Présent ! )
Présent ! F:\autorun.inf
Présent ! "F:\restore\S-1-5-21-1482476501-1644491937-682003330-1013"
Présent ! F:\restore\S-1-5-21-1482476501-1644491937-682003330-1013\Desktop.ini
Présent ! F:\restore\S-73-1235-18346-4-7346\Desktop.ini
################## [ Registre # Clés Run infectieuses ]
################## [ Registre # Mountpoints2 ]
HKCU\...\Explorer\MountPoints2\F\Shell\AutoRun\Command
HKCU\...\Explorer\MountPoints2\{04eab707-4e93-11de-8f1f-00166f55b24a}\Shell\AutoRun\Command
HKCU\...\Explorer\MountPoints2\{64d25ec0-4232-11de-8eea-00166f55b24a}\Shell\AutoRun\Command
HKCU\...\Explorer\MountPoints2\{64d25ec0-4232-11de-8eea-00166f55b24a}\Shell\open\Command
HKCU\...\Explorer\MountPoints2\{891f2686-4265-11de-8ef2-00166f55b24a}\Shell\AutoRun\Command
HKCU\...\Explorer\MountPoints2\{891f2687-4265-11de-8ef2-00166f55b24a}\Shell\AutoRun\Command
HKCU\...\Explorer\MountPoints2\{a0d35988-43d1-11de-8ef7-00166f55b24a}\Shell\AutoRun\Command
HKCU\...\Explorer\MountPoints2\{a0d35989-43d1-11de-8ef7-00166f55b24a}\Shell\AutoRun\Command
HKCU\...\Explorer\MountPoints2\{ce6dc31a-4264-11de-8ef1-00166f55b24a}\Shell\AutoRun\Command
################## [ ! Fin du rapport # UsbFix V3.033 ! ]
# User : Martine (Utilisateurs) # RIDELIGHT
# Update on 15/06/09 by C_XX
# Start at: 18:42:13 | 26/06/2009
# Website : http://pagesperso-orange.fr/NosTools/usbfix.html
# Intel(R) Pentium(R) M processor 1.73GHz
# Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 3
# Internet Explorer 7.0.5730.13
# Windows Firewall Status : Disabled
# C:\ # Disque fixe local # 35,07 Go (21,59 Go free) # NTFS
# D:\ # Disque fixe local # 35,55 Go (31,79 Go free) [ACERDATA] # FAT32
# E:\ # Disque CD-ROM # 413,72 Mo (0 Mo free) [Sims2SP5] # CDFS
# F:\ # Disque amovible # 3,79 Go (1,31 Go free) [UDISK] # FAT32
############################## [ Processus actifs ]
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\Philips\SPC220NC\Monitor.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Fichiers communs\Ulead Systems\AutoDetector\monitor.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\WINDOWS\system32\imapi.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Windows\LSD\LClock\lclock.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Philips\Philips SPC220NC Webcam\TrayMin220.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
################## [ Registre Startup ]
HKCU_Main: "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
HKCU_Main: "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
HKCU_Main: "Start Page"="https://www.google.fr/?gws_rd=ssl"
HKLM_logon: "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
HKLM_logon: "DefaultUserName"="Martine"
HKLM_logon: "AltDefaultUserName"="Martine"
HKLM_logon: "LegalNoticeCaption"=""
HKLM_logon: "LegalNoticeText"=""
HKLM_Run: igfxtray=C:\WINDOWS\system32\igfxtray.exe
HKLM_Run: igfxhkcmd=C:\WINDOWS\system32\hkcmd.exe
HKLM_Run: igfxpers=C:\WINDOWS\system32\igfxpers.exe
HKLM_Run: SynTPLpr=C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
HKLM_Run: SynTPEnh=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
HKLM_Run: RTHDCPL=RTHDCPL.EXE
HKLM_Run: Alcmtr=ALCMTR.EXE
HKLM_Run: Google Quick Search Box="C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe" /autorun
HKLM_Run: SunJavaUpdateSched="C:\Program Files\Java\jre6\bin\jusched.exe"
HKLM_Run: Monitor=C:\WINDOWS\Philips\SPC220NC\Monitor.exe
HKLM_Run: KernelFaultCheck=%systemroot%\system32\dumprep 0 -k
HKLM_Run: Ulead AutoDetector v2=C:\Program Files\Fichiers communs\Ulead Systems\AutoDetector\monitor.exe
HKLM_Run: TkBellExe="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
HKLM_Run: avgnt="C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
HKCU_Run: CTFMON.EXE=C:\WINDOWS\system32\ctfmon.exe
HKCU_Run: LClock=C:\Windows\LSD\LClock\lclock.exe
HKCU_Run: msnmsgr="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
HKCU_Run: swg=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
HKCU_Run: ares="C:\Program Files\Ares\Ares.exe" -h
HKCU_expl: "NoFolderOptions"=dword:00000001
HKCU_expl: "NoRun"=dword:00000001
################## [ Fichiers # Dossiers infectieux ]
Présent ! "C:\restore\S-1-5-21-1482476501-1644491937-682003330-1013"
Présent ! C:\restore\S-1-5-21-1482476501-1644491937-682003330-1013\Desktop.ini
Présent ! D:\autorun.inf
Présent ! E:\autorun.inf
F:\autorun.inf # -> fichier appelé : "F:\RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\wmmplayer.exe" ( Présent ! )
Présent ! F:\autorun.inf
Présent ! "F:\restore\S-1-5-21-1482476501-1644491937-682003330-1013"
Présent ! F:\restore\S-1-5-21-1482476501-1644491937-682003330-1013\Desktop.ini
Présent ! F:\restore\S-73-1235-18346-4-7346\Desktop.ini
################## [ Registre # Clés Run infectieuses ]
################## [ Registre # Mountpoints2 ]
HKCU\...\Explorer\MountPoints2\F\Shell\AutoRun\Command
HKCU\...\Explorer\MountPoints2\{04eab707-4e93-11de-8f1f-00166f55b24a}\Shell\AutoRun\Command
HKCU\...\Explorer\MountPoints2\{64d25ec0-4232-11de-8eea-00166f55b24a}\Shell\AutoRun\Command
HKCU\...\Explorer\MountPoints2\{64d25ec0-4232-11de-8eea-00166f55b24a}\Shell\open\Command
HKCU\...\Explorer\MountPoints2\{891f2686-4265-11de-8ef2-00166f55b24a}\Shell\AutoRun\Command
HKCU\...\Explorer\MountPoints2\{891f2687-4265-11de-8ef2-00166f55b24a}\Shell\AutoRun\Command
HKCU\...\Explorer\MountPoints2\{a0d35988-43d1-11de-8ef7-00166f55b24a}\Shell\AutoRun\Command
HKCU\...\Explorer\MountPoints2\{a0d35989-43d1-11de-8ef7-00166f55b24a}\Shell\AutoRun\Command
HKCU\...\Explorer\MountPoints2\{ce6dc31a-4264-11de-8ef1-00166f55b24a}\Shell\AutoRun\Command
################## [ ! Fin du rapport # UsbFix V3.033 ! ]
--> Branche tes sources de données externes à ton PC (clé USB, disque dur externe, carte SD, etc...) sans les ouvrir.
--> Double-clique sur le raccourci UsbFix présent sur ton Bureau.
--> Choisis l'option 2 (Suppression).
--> Ton Bureau disparaîtra et le PC redémarrera.
--> Au redémarrage, UsbFix scannera ton PC, laisse travailler l'outil.
--> Ensuite, poste le rapport UsbFix.txt qui apparaîtra avec le Bureau.
Note : le rapport UsbFix.txt est sauvegardé à la racine du disque (C:\UsbFix.txt).
--> Double-clique sur le raccourci UsbFix présent sur ton Bureau.
--> Choisis l'option 2 (Suppression).
--> Ton Bureau disparaîtra et le PC redémarrera.
--> Au redémarrage, UsbFix scannera ton PC, laisse travailler l'outil.
--> Ensuite, poste le rapport UsbFix.txt qui apparaîtra avec le Bureau.
Note : le rapport UsbFix.txt est sauvegardé à la racine du disque (C:\UsbFix.txt).
############################## [ UsbFix V3.033 ]
# User : Martine (Utilisateurs) # RIDELIGHT
# Update on 15/06/09 by C_XX
# Start at: 18:48:39 | 26/06/2009
# Website : http://pagesperso-orange.fr/NosTools/usbfix.html
# Intel(R) Pentium(R) M processor 1.73GHz
# Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 3
# Internet Explorer 7.0.5730.13
# Windows Firewall Status : Disabled
# C:\ # Disque fixe local # 35,07 Go (21,59 Go free) # NTFS
# D:\ # Disque fixe local # 35,55 Go (31,79 Go free) [ACERDATA] # FAT32
# E:\ # Disque CD-ROM # 413,72 Mo (0 Mo free) [Sims2SP5] # CDFS
# F:\ # Disque amovible # 3,79 Go (1,31 Go free) [UDISK] # FAT32
############################## [ Processus actifs ]
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\WINDOWS\system32\imapi.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
################## [ Fichiers # Dossiers infectieux ]
Supprimé ! C:\restore\S-1-5-21-1482476501-1644491937-682003330-1013\Desktop.ini
Supprimé ! "C:\restore\S-1-5-21-1482476501-1644491937-682003330-1013"
Supprimé ! D:\autorun.inf
(!) Non supprimé ! E:\autorun.inf
F:\autorun.inf # -> fichier appelé : "F:\RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\wmmplayer.exe" ( présent ! )
Deleted ! -> F:\RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\wmmplayer.exe
Supprimé ! F:\autorun.inf
Supprimé ! F:\restore\S-1-5-21-1482476501-1644491937-682003330-1013\Desktop.ini
Supprimé ! F:\restore\S-73-1235-18346-4-7346\Desktop.ini
Supprimé ! "F:\restore\S-1-5-21-1482476501-1644491937-682003330-1013"
################## [ Registre # Clés Run infectieuses ]
################## [ Registre # Mountpoints2 ]
Supprimé ! HKCU\...\Explorer\MountPoints2\F\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{04eab707-4e93-11de-8f1f-00166f55b24a}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{891f2686-4265-11de-8ef2-00166f55b24a}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{891f2687-4265-11de-8ef2-00166f55b24a}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{a0d35988-43d1-11de-8ef7-00166f55b24a}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{a0d35989-43d1-11de-8ef7-00166f55b24a}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{ce6dc31a-4264-11de-8ef1-00166f55b24a}\Shell\AutoRun\Command
################## [ Listing des fichiers présent ]
[13/05/2009 01:39|--a------|0] - C:\AUTOEXEC.BAT
[13/05/2009 02:31|---hs----|212] - C:\boot.ini
[28/08/2001 20:00|-rahs----|4952] - C:\Bootfont.bin
[13/05/2009 01:39|--a------|0] - C:\CONFIG.SYS
[13/05/2009 01:39|-rahs----|0] - C:\IO.SYS
[13/05/2009 01:39|-rahs----|0] - C:\MSDOS.SYS
[13/04/2008 15:43|-rahs----|47564] - C:\NTDETECT.COM
[13/04/2008 17:31|-rahs----|252240] - C:\ntldr
[29/02/2004 17:44|--a------|52576] - C:\orange.bmp
[?|?|?] - C:\pagefile.sys
[11/06/2009 21:23|--a------|304160] - C:\SPC220NC.DAT
[17/06/2009 11:54|--a------|30720] - C:\supar.MSNFix
[26/06/2009 18:49|--a------|3753] - C:\UsbFix.txt
[29/02/2004 17:44|--a------|52576] - D:\orange.bmp
[04/08/2004 00:55|--a------|28672] - D:\setupSNK.exe
[15/05/2007 05:01|-r-------|700416] - E:\AutoRun.exe
[15/05/2007 03:55|-r-------|651264] - E:\AutoRunGUI.dll
[15/05/2007 02:23|-r-------|10134] - E:\Sims2SP5.ico
[15/05/2007 03:56|-r-------|286720] - E:\Sims2SP5_Uninst.exe
[15/05/2007 05:02|-r-------|159] - E:\autorun.inf
[15/05/2007 05:02|-r-------|523] - E:\common_filelist.txt
[15/05/2007 05:02|-r-------|237330455] - E:\compressed.zip
[15/05/2007 05:01|-r-------|356352] - E:\eauninstall.exe
[15/05/2007 02:23|-r-------|10134] - E:\eauninstall.ico
[24/06/2009 19:49|--a------|16068] - F:\Offre.png
[17/06/2009 22:57|--a------|131032] - F:\Moiiiiii.png
[21/06/2009 11:24|--a------|293587] - F:\GIFTest-PhotoFiltre.gif
################## [ Vaccination ]
# C:\autorun.inf ( # Not infected ) -> Folder created by UsbFix.
# D:\autorun.inf ( # Not infected ) -> Folder created by UsbFix.
# F:\autorun.inf ( # Not infected ) -> Folder created by UsbFix.
################## [ ! Fin du rapport # UsbFix V3.033 ! ]
# User : Martine (Utilisateurs) # RIDELIGHT
# Update on 15/06/09 by C_XX
# Start at: 18:48:39 | 26/06/2009
# Website : http://pagesperso-orange.fr/NosTools/usbfix.html
# Intel(R) Pentium(R) M processor 1.73GHz
# Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 3
# Internet Explorer 7.0.5730.13
# Windows Firewall Status : Disabled
# C:\ # Disque fixe local # 35,07 Go (21,59 Go free) # NTFS
# D:\ # Disque fixe local # 35,55 Go (31,79 Go free) [ACERDATA] # FAT32
# E:\ # Disque CD-ROM # 413,72 Mo (0 Mo free) [Sims2SP5] # CDFS
# F:\ # Disque amovible # 3,79 Go (1,31 Go free) [UDISK] # FAT32
############################## [ Processus actifs ]
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\WINDOWS\system32\imapi.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
################## [ Fichiers # Dossiers infectieux ]
Supprimé ! C:\restore\S-1-5-21-1482476501-1644491937-682003330-1013\Desktop.ini
Supprimé ! "C:\restore\S-1-5-21-1482476501-1644491937-682003330-1013"
Supprimé ! D:\autorun.inf
(!) Non supprimé ! E:\autorun.inf
F:\autorun.inf # -> fichier appelé : "F:\RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\wmmplayer.exe" ( présent ! )
Deleted ! -> F:\RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\wmmplayer.exe
Supprimé ! F:\autorun.inf
Supprimé ! F:\restore\S-1-5-21-1482476501-1644491937-682003330-1013\Desktop.ini
Supprimé ! F:\restore\S-73-1235-18346-4-7346\Desktop.ini
Supprimé ! "F:\restore\S-1-5-21-1482476501-1644491937-682003330-1013"
################## [ Registre # Clés Run infectieuses ]
################## [ Registre # Mountpoints2 ]
Supprimé ! HKCU\...\Explorer\MountPoints2\F\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{04eab707-4e93-11de-8f1f-00166f55b24a}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{891f2686-4265-11de-8ef2-00166f55b24a}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{891f2687-4265-11de-8ef2-00166f55b24a}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{a0d35988-43d1-11de-8ef7-00166f55b24a}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{a0d35989-43d1-11de-8ef7-00166f55b24a}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{ce6dc31a-4264-11de-8ef1-00166f55b24a}\Shell\AutoRun\Command
################## [ Listing des fichiers présent ]
[13/05/2009 01:39|--a------|0] - C:\AUTOEXEC.BAT
[13/05/2009 02:31|---hs----|212] - C:\boot.ini
[28/08/2001 20:00|-rahs----|4952] - C:\Bootfont.bin
[13/05/2009 01:39|--a------|0] - C:\CONFIG.SYS
[13/05/2009 01:39|-rahs----|0] - C:\IO.SYS
[13/05/2009 01:39|-rahs----|0] - C:\MSDOS.SYS
[13/04/2008 15:43|-rahs----|47564] - C:\NTDETECT.COM
[13/04/2008 17:31|-rahs----|252240] - C:\ntldr
[29/02/2004 17:44|--a------|52576] - C:\orange.bmp
[?|?|?] - C:\pagefile.sys
[11/06/2009 21:23|--a------|304160] - C:\SPC220NC.DAT
[17/06/2009 11:54|--a------|30720] - C:\supar.MSNFix
[26/06/2009 18:49|--a------|3753] - C:\UsbFix.txt
[29/02/2004 17:44|--a------|52576] - D:\orange.bmp
[04/08/2004 00:55|--a------|28672] - D:\setupSNK.exe
[15/05/2007 05:01|-r-------|700416] - E:\AutoRun.exe
[15/05/2007 03:55|-r-------|651264] - E:\AutoRunGUI.dll
[15/05/2007 02:23|-r-------|10134] - E:\Sims2SP5.ico
[15/05/2007 03:56|-r-------|286720] - E:\Sims2SP5_Uninst.exe
[15/05/2007 05:02|-r-------|159] - E:\autorun.inf
[15/05/2007 05:02|-r-------|523] - E:\common_filelist.txt
[15/05/2007 05:02|-r-------|237330455] - E:\compressed.zip
[15/05/2007 05:01|-r-------|356352] - E:\eauninstall.exe
[15/05/2007 02:23|-r-------|10134] - E:\eauninstall.ico
[24/06/2009 19:49|--a------|16068] - F:\Offre.png
[17/06/2009 22:57|--a------|131032] - F:\Moiiiiii.png
[21/06/2009 11:24|--a------|293587] - F:\GIFTest-PhotoFiltre.gif
################## [ Vaccination ]
# C:\autorun.inf ( # Not infected ) -> Folder created by UsbFix.
# D:\autorun.inf ( # Not infected ) -> Folder created by UsbFix.
# F:\autorun.inf ( # Not infected ) -> Folder created by UsbFix.
################## [ ! Fin du rapport # UsbFix V3.033 ! ]
--> Désinstalle UsbFix et Java 6 Update 13.
--> Mets à jour Java.
--> Mets à jour Adobe Reader.
Ton PC va mieux ?
--> Mets à jour Java.
--> Mets à jour Adobe Reader.
Ton PC va mieux ?