Une étoile rouge inahbituel

Bonjour, J'ai un genre de petit symbole comme cela * rouge dans ma barre d'icône (heure, messenger, l'état de ma connexion) quand je clique dessus elle me demande un mot de passe alors je me demande ce que ses et j'aurais bien besoin d'aide merci de me répondre bientôt.
Configuration: Windows Vista
Firefox 3.0.11

26 réponses

Résumé de la discussion

Un utilisateur signale l'apparition d'un symbole rouge dans la barre d'état système, qui demande un mot de passe lors du clic. Des éléments de diagnostic ont été présentés, notamment un rapport détaillé des processus en cours et des paramètres du système sur Windows Vista et Firefox 3.0.11, afin d'identifier une infection. Le contenu montre des outils et fichiers liés à des logiciels de sécurité, de messagerie et de navigation, avec des éléments de registre et des chemins d'installation susceptibles d'indiquer des composants indésirables. D'autres détails mentionnent des programmes Toshiba et Google Toolbar, ainsi que des éléments de pare-feu et des entrées Run, fournissant une vue d'ensemble des modifications récentes sur le système.

Bobot (l’IA à votre service)
  1. bonsoir

    si il est la c'est qu'il est dans ton de menu de démarrage

    donc regarde
    panneau configuration
    programmes
    modifier menu démarrage et tu verras ce que t'as installe

    0
    1. j'ai regardé je mi connais un peut asse pour savoir que ce n'est pas supposer être la il me demande un mot de passe si je porte mais souris dessus sans cliquer il est marquer (record)=(enregistrement).
      0
      1. oui ok tu t'y connais

        donc si tu t'y connais a partir de ce menu tu peux savoir ce que c'est le logiciel et le supprimer s'il te plait pas

        0
        1. Salut,

          Il est situé apparemment dans la barre de notification ...

          Clique droit dessus, puis sur Propriétés pour voir ce que cela donne.
          0
          1. le probleme s'est qui n'apparait pas comme un virus (dans les scan) ni dans dans le le disque c: et pas dans le dossier windos et ni dans supression de programme ^^ =/
            0
            1. il est marquer exit quand je clique sur exit sa me demande un mot de pass
              0
              1. comme je t'ai dis si tu vas dans le menu demarrage et tu defile ce qui tourne sur ton menu démarrage
                il te dis tous les infos sur la droite
                regarde la et t'en sauras un peu plus

                0
                1. Salut !

                  Pour vérifier :

                  Télécharge Random's System Information Tool (RSIT) (par random/random) sur ton Bureau.

                  http://images.malwareremoval.com/random/RSIT.exe

                  Double-clique sur RSIT.exe.

                  Clique sur Continue à l'écran Disclaimer.

                  Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.

                  Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront. Poste le contenu de log.txt (c'est celui qui apparaît à l'écran) ainsi que de info.txt (que tu verras dans la barre des tâches).

                  A noter: Les rapports se trouvent également ici: C:\rsit.

                  ++
                  0
                  1. j'ai essayer un hijak vlas 2 jour rien danormale
                    0
                    1. RSIT est plus parlant. Tu l'as analysé tout seul ton rapport ?

                      +
                      0
                  2. la dans ce menu sur la droite il te donne les details regarde ce qu'il te dit
                    http://img1.imagilive.com/affiche/0609/Capturera3c.JPG.htm

                    0
                    1. il n'as rien qui s'apparente au logiciel expliquer
                      0
                      1. a peut pres tout saule j'ai eu un peut d'aide mais bon
                        0
                        1. Tu veux pas faire RSIT ? On sera fixé sur une éventuelle infection.

                          +
                          0
                          1. oui jveut bien la faire sras pas long ^^ jetais occup
                            0
                            1. Logfile of random's system information tool 1.06 (written by random/random)
                              Run by mikael at 2009-06-25 19:15:27
                              Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 1
                              System drive C: has 151 GB (66%) free of 230 GB
                              Total RAM: 3963 MB (48% free)

                              Logfile of Trend Micro HijackThis v2.0.2
                              Scan saved at 19:15:46, on 2009-06-25
                              Platform: Windows Vista SP1 (WinNT 6.00.1905)
                              MSIE: Internet Explorer v8.00 (8.00.6001.18702)
                              Boot mode: Normal

                              Running processes:
                              C:\Program Files\ltmoh\ltmoh.exe
                              C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
                              C:\Program Files (x86)\Internet Download Manager\IDMan.exe
                              C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe
                              C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe
                              C:\Program Files (x86)\rkfree\rkfree.exe
                              C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe
                              C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSwMgr.exe
                              C:\Program Files (x86)\Dofus\Dofus.exe
                              C:\Program Files (x86)\Dofus\dofus.dll
                              C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe
                              C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
                              C:\Program Files (x86)\Mozilla Firefox\firefox.exe
                              C:\Program Files (x86)\Windows Media Player\wmplayer.exe
                              C:\Users\mikael\Downloads\RSIT.exe
                              C:\Program Files (x86)\trend micro\mikael.exe

                              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.shoptoshiba.ca/welcome
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
                              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                              F2 - REG:system.ini: UserInit=userinit.exe
                              O1 - Hosts: ::1 localhost
                              O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll
                              O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                              O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                              O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar.dll
                              O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll
                              O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files (x86)\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
                              O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
                              O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar.dll
                              O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
                              O4 - HKLM\..\Run: [cfFncEnabler.exe] cfFncEnabler.exe
                              O4 - HKLM\..\Run: [Camera Assistant Software] "C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe" /start
                              O4 - HKLM\..\Run: [jswtrayutil] "C:\Program Files (x86)\Jumpstart\jswtrayutil.exe"
                              O4 - HKLM\..\Run: [rkfree] "C:\Program Files (x86)\rkfree\rkfree.exe" /b
                              O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre6\bin\jusched.exe"
                              O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                              O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
                              O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
                              O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
                              O4 - HKCU\..\Run: [swg] C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                              O4 - HKCU\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
                              O4 - HKCU\..\Run: [VoipBuster] "C:\Program Files (x86)\VoipBuster.com\VoipBuster\VoipBuster.exe" -nosplash -minimized
                              O4 - HKCU\..\Run: [Speech Recognition] "C:\Windows\Speech\Common\sapisvr.exe" -SpeechUX -Startup
                              O4 - HKCU\..\Run: [IDMan] C:\Program Files (x86)\Internet Download Manager\IDMan.exe /onboot
                              O4 - HKCU\..\Run: [Hide IP Platinum] C:\Program Files (x86)\Hide IP Platinum\hideippla.exe
                              O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe
                              O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                              O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                              O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                              O4 - Global Startup: TOSHIBA Face Recognition Watcher.lnk = C:\Program Files\Toshiba\SmartFaceV\SmartFaceVWatcher.exe
                              O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
                              O8 - Extra context menu item: Télécharger avec IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm
                              O8 - Extra context menu item: Télécharger le contenu de video FLV avec IDM - C:\Program Files (x86)\Internet Download Manager\IEGetVL.htm
                              O8 - Extra context menu item: Télécharger tous les liens avec IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm
                              O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
                              O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
                              O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files (x86)\PokerStars\PokerStarsUpdate.exe
                              O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
                              O13 - Gopher Prefix:
                              O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
                              O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-CA/a-UNO1/GAME_UNO1.cab
                              O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                              O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
                              O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files (x86)\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
                              O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Unknown owner - C:\Windows\system32\agr64svc.exe (file missing)
                              O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
                              O23 - Service: ConfigFree Gadget Service - TOSHIBA Corporation. - C:\Program Files (x86)\TOSHIBA\ConfigFree\CFProcSRVC.exe
                              O23 - Service: ConfigFree Service - TOSHIBA CORPORATION - C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe
                              O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
                              O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
                              O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
                              O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files (x86)\TOSHIBA Games\TOSHIBA Game Console\GameConsoleService.exe
                              O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
                              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                              O23 - Service: Jumpstart Wifi Protected Setup (jswpsapi) - Atheros Communications, Inc. - C:\Program Files (x86)\Jumpstart\jswpsapi.exe
                              O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
                              O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
                              O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
                              O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
                              O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
                              O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
                              O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
                              O23 - Service: SmartFaceVWatchSrv - Toshiba - C:\Program Files\TOSHIBA\SmartFaceV\SmartFaceVWatchSrv.exe
                              O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
                              O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
                              O23 - Service: TeamViewer 4 (TeamViewer4) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version4\TeamViewer_Service.exe
                              O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files (x86)\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
                              O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - Unknown owner - C:\Windows\system32\TODDSrv.exe (file missing)
                              O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
                              O23 - Service: TOSHIBA SMART Log Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe
                              O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
                              O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
                              O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
                              O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
                              O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
                              O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
                              0
                              1. je sais rkfree (sest un key logger mais bon jlai installer moi meme) jrecuper pas malle de moot de pass de a peut pret tlm
                                0
                                1. ce serait pas pour un jeu a la quelle t'es entrain de jouer
                                  j'ai vu que tu jouais a dofus par ex

                                  0
                                  1. oui je joue a dofus j'aime bien mais bon c'est pas la le probleme pourtant je le voit pas comme un probleme actif mais pourtant il est la
                                    0
                                    1. je crois j'ai trouve ce serait pas ton jeux poker star
                                      star = etoile en anglais tu as besoin d'un mot de passe pour acceder

                                      0
                                      1. non pokerstar regarder sur internet est un jeu de poker avec argent virtuele (ou payant (mais faut payer))
                                        0
                                        • 1
                                        • 2