Lspvt32.exe au démarrage.

Fermé
gregkz7 Messages postés 29 Date d'inscription dimanche 20 septembre 2009 Statut Membre Dernière intervention 5 octobre 2009 - 20 sept. 2009 à 11:16
benurrr Messages postés 9643 Date d'inscription samedi 24 mai 2008 Statut Contributeur sécurité Dernière intervention 11 janvier 2012 - 7 oct. 2009 à 20:55
Bonjour,
Aprés plusieurs recherches sur le net pour me séparer de ce foutu message au démarrage de Windows pourriez me donner un coup de main pour me débarrasser de lspvt.exe qui serait d'après mes recherches un malware.Ayant tout essayé avec certains logiciels je me tourne vers vous pour trouver une solution.
Merci d'avance Greg.
A voir également:

47 réponses

gregkz7 Messages postés 29 Date d'inscription dimanche 20 septembre 2009 Statut Membre Dernière intervention 5 octobre 2009
30 sept. 2009 à 17:23
bonjour benurr,voici le rapport combofix

ComboFix 09-09-29.04 - greg 30/09/2009 17:04.3.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.767.335 [GMT 2:00]
Lancé depuis: c:\documents and settings\greg\Bureau\ComboFix.exe
Commutateurs utilisés :: c:\documents and settings\greg\Bureau\CFscript.txt
AV: avast! antivirus 4.8.1335 [VPS 090929-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
* Un nouveau point de restauration a été créé

FILE ::
"c:\windows\system32\lspvt32.exe"
"c:\windows\system32\perfc00C.dat"
"c:\windows\system32\perfh00C.dat"
.

(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\AskSearch
c:\windows\system32\lspvt32.exe
c:\windows\system32\perfc00C.dat
c:\windows\system32\perfh00C.dat

.
((((((((((((((((((((((((((((( Fichiers créés du 2009-08-28 au 2009-09-30 ))))))))))))))))))))))))))))))))))))
.

2009-09-29 19:34 . 2009-09-29 19:34 -------- d-----w- c:\program files\Lavalys
2009-09-29 15:56 . 2009-09-29 15:56 -------- d-----w- C:\rsit
2009-09-28 19:46 . 2009-09-28 19:46 -------- d-----w- c:\program files\sisagp
2009-09-28 19:45 . 2002-09-26 12:41 29312 ----a-w- c:\windows\system32\drivers\SISAGPX.SYS
2009-09-28 19:45 . 2002-10-17 13:14 49024 ----a-w- c:\windows\system32\drivers\sisidex.sys
2009-09-28 19:45 . 2002-08-20 12:58 139264 ----a-w- c:\windows\system32\IDEproperty.dll
2009-09-28 19:45 . 2002-08-20 15:19 9472 ----a-w- c:\windows\system32\drivers\sisperf.sys
2009-09-28 19:44 . 1998-01-23 10:20 305664 ----a-w- c:\windows\IsUn040c.exe
2009-09-28 19:44 . 2003-03-25 15:50 4096 ----a-w- c:\windows\system32\drivers\siside.sys
2009-09-26 16:10 . 2009-09-26 16:10 -------- d-----w- c:\program files\Xi
2009-09-26 15:32 . 2009-09-26 15:32 -------- d-----w- C:\My Videos
2009-09-26 15:32 . 2009-09-26 15:32 -------- d-----w- c:\documents and settings\greg\Application Data\aHisoft
2009-09-26 15:32 . 2009-09-26 15:32 -------- d-----w- c:\program files\aHisoft
2009-09-26 15:24 . 2009-09-26 15:24 -------- d-----w- c:\program files\FreeTime
2009-09-26 10:02 . 2009-09-26 10:02 -------- d-----w- c:\documents and settings\greg\Application Data\Apowersoft
2009-09-26 10:02 . 2009-09-26 10:02 -------- d-----w- c:\program files\Apowersoft
2009-09-23 20:08 . 2009-09-24 18:17 -------- d-----w- c:\documents and settings\greg\.housecall6.6
2009-09-22 20:33 . 2009-09-22 20:33 579584 -c--a-w- c:\windows\system32\dllcache\user32.dll
2009-09-22 20:32 . 2009-09-23 18:33 -------- d-----w- c:\windows\ERUNT
2009-09-22 20:32 . 2009-09-23 18:31 -------- d-----w- C:\Backups
2009-09-22 19:40 . 2009-09-23 18:31 -------- d-----w- C:\RAPPORT
2009-09-20 09:30 . 2009-09-29 15:56 -------- d-----w- c:\program files\trend micro
2009-09-18 14:31 . 2009-09-18 14:31 -------- d-----w- c:\program files\Java
2009-09-18 13:49 . 2009-09-18 13:49 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-09-18 13:49 . 2009-09-18 13:49 -------- d-----w- c:\program files\SUPERAntiSpyware
2009-09-18 13:49 . 2009-09-18 13:49 -------- d-----w- c:\documents and settings\greg\Application Data\SUPERAntiSpyware.com
2009-09-18 13:49 . 2009-09-18 13:49 -------- d-----w- c:\program files\Fichiers communs\Wise Installation Wizard
2009-09-18 13:29 . 2009-09-18 13:29 -------- d-----w- c:\windows\system32\wbem\Repository
2009-09-18 12:12 . 2009-09-18 12:12 -------- d-----w- C:\fuqid
2009-09-18 12:08 . 2009-09-18 13:28 -------- d-----w- C:\frost
2009-09-18 08:59 . 2009-09-18 08:59 -------- d-----w- c:\program files\Netscape
2009-09-17 20:55 . 2009-09-17 20:55 -------- d-----w- c:\program files\Godlike Developers
2009-09-17 19:37 . 2009-09-17 19:37 -------- d-----w- c:\program files\xp-AntiSpy
2009-09-15 19:47 . 2009-09-15 19:47 -------- d-----w- c:\program files\CCleaner
2009-09-13 15:42 . 2009-09-13 15:42 -------- d-----w- c:\program files\Sony
2009-09-09 18:02 . 2009-06-21 21:47 153088 -c----w- c:\windows\system32\dllcache\triedit.dll
2009-09-08 16:25 . 2009-09-08 16:25 -------- d-----w- c:\program files\uTorrent
2009-09-02 18:09 . 2009-09-02 18:10 -------- d-----w- c:\documents and settings\All Users\Application Data\Bluetooth
2009-09-02 18:06 . 2009-09-02 18:06 -------- d-----w- c:\program files\IVT Corporation
2009-09-02 17:53 . 2008-04-14 01:34 153088 -c--a-w- c:\windows\system32\dllcache\irftp.exe
2009-09-02 17:53 . 2008-04-14 01:34 153088 ----a-w- c:\windows\system32\irftp.exe
2009-09-02 17:53 . 2008-04-14 01:33 8192 -c--a-w- c:\windows\system32\dllcache\wshirda.dll
2009-09-02 17:53 . 2008-04-14 01:33 8192 ----a-w- c:\windows\system32\wshirda.dll
2009-09-02 17:53 . 2008-04-14 01:33 29184 -c--a-w- c:\windows\system32\dllcache\irmon.dll
2009-09-02 17:53 . 2008-04-14 01:33 29184 ----a-w- c:\windows\system32\irmon.dll

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-30 15:03 . 2009-03-26 17:24 -------- d-----w- c:\documents and settings\greg\Application Data\c1
2009-09-30 15:03 . 2009-03-26 17:22 -------- d-----w- c:\documents and settings\greg\Application Data\c2
2009-09-30 15:03 . 2009-04-20 18:58 -------- d-----w- c:\documents and settings\greg\Application Data\uTorrent
2009-09-28 19:46 . 2008-12-30 20:30 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-09-28 19:37 . 2008-12-31 10:27 -------- d-----w- c:\program files\ma-config.com
2009-09-28 19:37 . 2008-12-31 10:27 -------- d-----w- c:\documents and settings\All Users\Application Data\ma-config.com
2009-09-23 14:44 . 2009-04-25 09:39 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-09-18 14:31 . 2009-04-24 16:09 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-09-18 08:09 . 2008-12-30 20:59 42944 ----a-w- c:\documents and settings\greg\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-18 07:55 . 2008-12-31 09:20 -------- d-----w- c:\documents and settings\greg\Application Data\BitTorrent
2009-09-17 20:59 . 2009-01-02 10:38 -------- d-----w- c:\program files\emule
2009-09-15 18:26 . 2009-01-31 15:30 -------- d-----w- c:\program files\a-squared Free
2009-09-14 19:21 . 2009-01-03 14:07 -------- d-----w- c:\program files\K-Lite Codec Pack
2009-09-10 12:54 . 2009-04-25 09:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 12:53 . 2009-04-25 09:39 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-08-22 19:53 . 2009-08-22 19:53 -------- d-----w- c:\program files\MSBuild
2009-08-22 19:53 . 2009-08-22 19:53 -------- d-----w- c:\program files\Reference Assemblies
2009-08-16 15:08 . 2009-01-03 14:07 178176 ----a-w- c:\windows\system32\unrar.dll
2009-08-05 09:00 . 2002-08-30 12:00 205312 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-17 19:03 . 2002-08-30 12:00 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-12 10:21 . 2004-08-19 23:09 233472 ------w- c:\windows\system32\wmpdxm.dll
.

((((((((((((((((((((((((((((( SnapShot@2009-09-29_18.01.24 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-09-30 14:51 . 2009-09-30 14:51 16384 c:\windows\Temp\Perflib_Perfdata_650.dat
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LogitechSoftwareUpdate"="c:\program files\Logitech\Video\ManifestEngine.exe" [2005-06-08 196608]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2009-09-08 288048]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-09-15 1998576]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Lexmark X74-X75"="c:\program files\Lexmark X74-X75\lxbbbmgr.exe" [2002-07-31 57344]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-16 13529088]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-16 86016]
"LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2005-07-19 221184]
"LogitechVideoRepair"="c:\program files\Logitech\Video\ISStart.exe" [2005-06-08 458752]
"LogitechVideoTray"="c:\program files\Logitech\Video\LogiTray.exe" [2005-06-08 217088]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"QuickTime Task"="c:\windows\system32\qttask.exe" [2009-04-23 28672]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-09-18 149280]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2008-05-16 1630208]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\soundman.exe [2007-04-16 577536]
"BluetoothAuthenticationAgent"="bthprops.cpl" - c:\windows\system32\bthprops.cpl [2008-04-14 110592]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoStartMenuSubFolders"= 0 (0x0)
"NoCommonGroups"= 0 (0x0)
"NoPrinters"= 0 (0x0)
"NoRecentDocsNetHood"= 0 (0x0)
"NoChangeAnimation"= 0 (0x0)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 13:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\emule\\eMule.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
"c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"c:\\Program Files\\SopCast\\SopCast.exe"=
"c:\\Program Files\\TVAnts\\Tvants.exe"=
"c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [30/12/2008 22:38 114768]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [15/09/2009 11:42 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [15/09/2009 11:42 74480]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [30/12/2008 22:59 20560]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [15/09/2009 11:42 7408]
S2 freenet-darknet-8888-8888-8888-8888;Freenet 0.7 darknet-8888-8888-8888-8888;"c:\program files\Freenet\bin\wrapper-windows-x86-32.exe" -s "c:\program files\Freenet\wrapper.conf" --> c:\program files\Freenet\bin\wrapper-windows-x86-32.exe [?]
S2 freenet-darknet-8888-8888-8888;Freenet 0.7 darknet-8888-8888-8888;"c:\program files\Freenet\bin\wrapper-windows-x86-32.exe" -s "c:\program files\Freenet\wrapper.conf" --> c:\program files\Freenet\bin\wrapper-windows-x86-32.exe [?]
S2 freenet-darknet-8888-8888;Freenet 0.7 darknet-8888-8888;"c:\program files\Freenet\bin\wrapper-windows-x86-32.exe" -s "c:\program files\Freenet\wrapper.conf" --> c:\program files\Freenet\bin\wrapper-windows-x86-32.exe [?]
S2 freenet-darknet-8888;Freenet 0.7 darknet-8888;"c:\program files\Freenet\bin\wrapper-windows-x86-32.exe" -s "c:\program files\Freenet\wrapper.conf" --> c:\program files\Freenet\bin\wrapper-windows-x86-32.exe [?]
S2 freenet-darknet-8889;Freenet 0.7 darknet-8889;"c:\program files\Freenet\bin\wrapper-windows-x86-32.exe" -s "c:\program files\Freenet\wrapper.conf" --> c:\program files\Freenet\bin\wrapper-windows-x86-32.exe [?]
S2 freenet;Freenet background service;"c:\program files\Freenet\bin\wrapper-windows-x86-32.exe" -s "c:\program files\Freenet\wrapper.conf" --> c:\program files\Freenet\bin\wrapper-windows-x86-32.exe [?]
S2 freenet_2;Freenet background service_2;"c:\program files\Freenet\bin\wrapper-windows-x86-32.exe" -s "c:\program files\Freenet\wrapper.conf" --> c:\program files\Freenet\bin\wrapper-windows-x86-32.exe [?]
S2 freenet_3;Freenet background service_3;"c:\program files\Freenet\bin\wrapper-windows-x86-32.exe" -s "c:\program files\Freenet\wrapper.conf" --> c:\program files\Freenet\bin\wrapper-windows-x86-32.exe [?]
S3 maconfservice;Ma-Config Service;c:\program files\ma-config.com\maconfservice.exe [23/09/2009 14:50 238960]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.ask.com/?o=13928&l=dis
mWindow Title =
uSearchURL,(Default) = hxxp://toolbar.ask.com/toolbarv/askRedirect?o=13925&gct=&gc=1&q=%s
IE: &Télécharger avec NetTransport - c:\program files\Xi\NetTransport 2\NTAddLink.html
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Tout t&élécharger avec NetTransport - c:\program files\Xi\NetTransport 2\NTAddList.html
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\greg\Application Data\Mozilla\Firefox\Profiles\824jt3ad.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Ask
FF - prefs.js: browser.startup.homepage - hxxp://www.neufportail.fr/
FF - prefs.js: keyword.URL - hxxp://toolbar.ask.com/toolbarv/askRedirect?o=13925&gct=&gc=1&q=
FF - plugin: c:\program files\ma-config.com\nphardwaredetection.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHELINS SUPPRIMES - - - -

HKLM-Run-Microsoft ALU manager - c:\windows\system32\lspvt32.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-09-30 17:11
Windows 5.1.2600 Service Pack 3 NTFS

Recherche de processus cachés ...

Recherche d'éléments en démarrage automatique cachés ...

Recherche de fichiers cachés ...

Scan terminé avec succès
Fichiers cachés: 0

**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------

[HKEY_USERS\S-1-5-21-1214440339-1078081533-839522115-1004\Software\SecuROM\License information*]
"datasecu"=hex:43,6f,79,31,64,e3,07,bb,1d,5f,c9,8c,ec,b9,68,80,b3,c8,b3,a2,4e,
85,a4,4e,f8,f2,f1,b7,4e,db,f1,f3,63,c8,69,d9,16,f0,1d,4c,e3,31,4a,c8,e8,2d,\
"rkeysecu"=hex:6c,e8,1a,7f,93,fd,7d,b2,24,0d,42,c1,1d,ef,78,cd
.
--------------------- DLLs chargées dans les processus actifs ---------------------

- - - - - - - > 'winlogon.exe'(744)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\documents and settings\greg\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
.
Heure de fin: 2009-09-30 17:13
ComboFix-quarantined-files.txt 2009-09-30 15:13
ComboFix2.txt 2009-09-29 18:03

Avant-CF: 56 387 489 792 octets libres
Après-CF: 56 030 314 496 octets libres

205 --- E O F --- 2009-09-10 17:00

voici l'hijackthis

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:21:04, on 30/09/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\a-squared Free\a2service.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Lexmark X74-X75\lxbbbmon.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\PROGRA~1\PANICW~1\POP-UP~1\POPUPS~1.EXE
C:\Program Files\uTorrent\uTorrent.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.ask.com/?o=13928&l=dis
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://toolbar.ask.com/toolbarv/askRedirect?o=13925&gct=&gc=1&q=
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://toolbar.ask.com/toolbarv/askRedirect?o=13925&gct=&gc=1&q=%s
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: NTIECatcher Class - {C56CB6B0-0D96-11D6-8C65-B2868B609932} - C:\Program Files\Xi\NetTransport 2\NTIEHelper.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [Lexmark X74-X75] "C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] C:\WINDOWS\system32\qttask.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [PopUpStopperProfessional] "C:\PROGRA~1\PANICW~1\POP-UP~1\POPUPS~1.EXE"
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: &Télécharger avec NetTransport - C:\Program Files\Xi\NetTransport 2\NTAddLink.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Tout t&élécharger avec NetTransport - C:\Program Files\Xi\NetTransport 2\NTAddList.html
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - https://www.pierron.fr/ressources/evaluation/cd2i3d_demo/utilitaires/Qtime/qtplugin.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Freenet background service (freenet) - Unknown owner - C:\Program Files\Freenet\bin\wrapper-windows-x86-32.exe (file missing)
O23 - Service: Freenet 0.7 darknet-8888 (freenet-darknet-8888) - Unknown owner - C:\Program Files\Freenet\bin\wrapper-windows-x86-32.exe (file missing)
O23 - Service: Freenet 0.7 darknet-8888-8888 (freenet-darknet-8888-8888) - Unknown owner - C:\Program Files\Freenet\bin\wrapper-windows-x86-32.exe (file missing)
O23 - Service: Freenet 0.7 darknet-8888-8888-8888 (freenet-darknet-8888-8888-8888) - Unknown owner - C:\Program Files\Freenet\bin\wrapper-windows-x86-32.exe (file missing)
O23 - Service: Freenet 0.7 darknet-8888-8888-8888-8888 (freenet-darknet-8888-8888-8888-8888) - Unknown owner - C:\Program Files\Freenet\bin\wrapper-windows-x86-32.exe (file missing)
O23 - Service: Freenet 0.7 darknet-8889 (freenet-darknet-8889) - Unknown owner - C:\Program Files\Freenet\bin\wrapper-windows-x86-32.exe (file missing)
O23 - Service: Freenet background service_2 (freenet_2) - Unknown owner - C:\Program Files\Freenet\bin\wrapper-windows-x86-32.exe (file missing)
O23 - Service: Freenet background service_3 (freenet_3) - Unknown owner - C:\Program Files\Freenet\bin\wrapper-windows-x86-32.exe (file missing)
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
0
benurrr Messages postés 9643 Date d'inscription samedi 24 mai 2008 Statut Contributeur sécurité Dernière intervention 11 janvier 2012 107
30 sept. 2009 à 19:53
salut

---) Relance HijackThis et choisis Do a system scan only

---) Coche les cases qui sont devant les lignes suivantes :

R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://toolbar.ask.com/toolbarv/askRedirect?o=13925&gct=&gc=1&q=

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://toolbar.ask.com/toolbarv/askRedirect?o=13925&gct=&gc=1&q=%s


---) Fais ensuite "fix checked"

0
gregkz7 Messages postés 29 Date d'inscription dimanche 20 septembre 2009 Statut Membre Dernière intervention 5 octobre 2009
30 sept. 2009 à 20:07
voila c'est fait
0
gregkz7 Messages postés 29 Date d'inscription dimanche 20 septembre 2009 Statut Membre Dernière intervention 5 octobre 2009
1 oct. 2009 à 18:09
bonjour benurr

j'ai récupéré le gestionnaire de tache et l'invité de commande

greg
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
benurrr Messages postés 9643 Date d'inscription samedi 24 mai 2008 Statut Contributeur sécurité Dernière intervention 11 janvier 2012 107
2 oct. 2009 à 15:17
salut

vire avast et installe antivir et fait un scan

http://download.softpedia.com/dl/2bea5269e0ed1e7f6f1b62ff4105852e/4a7bcc0d/100006527/software/antivirus/avira_antivir_personal_en.exe

içi un tuto pour le configurer au taquet

https://www.commentcamarche.net/faq/16831-tutoriel-configuration-optimale-d-antivir-personal
0
gregkz7 Messages postés 29 Date d'inscription dimanche 20 septembre 2009 Statut Membre Dernière intervention 5 octobre 2009
5 oct. 2009 à 17:44
salut benurr

avast viré antivir installé et au scan 2 alarmes résolues
0
benurrr Messages postés 9643 Date d'inscription samedi 24 mai 2008 Statut Contributeur sécurité Dernière intervention 11 janvier 2012 107
7 oct. 2009 à 20:55
salut

ok
0