Trojan Generic Downloader.h

Boujour, mon antivirus mcafee m'avertis toujours que jai un trojan qui se nomme generic downloader.h jai aussi un qui se nomme druogna et QDial-34. Il y a toujours un petit triangle jaune avec un point d exclamation a l intérieur( il apparait a coté de l heure)qui me dit que jai 4 spyware et aussi il y a toujours des page de publicité sur internet qui apparaissent meme quand jai des option pour les bloquer.Je crois que jai un bon tas de spyware et trojan dans mon pc meme apres beaucoup de nettoyage avec adaware et spybot.

Merci d avance pour votre aide.

22 réponses

  1. Contributeur sécurité
    salut
    telecharge
    http://siri.urz.free.fr/Fix/SmitfraudFix.zip
    tu le decompresse tu double clik dessus et tu choisi l option 1
    cela vas generer un rapport donne nous le

    fait ceci
    HijackThis (ici) http://www.florensac-chasse-trap.com/ section virus/logiciel de securite
    section virus/logiciel de securite demo animée sur la meme page
    tuto animée d instalation d hijackthis http://pageperso.aol.fr/balltrap34/Hijenr.gif
    telecharge le et met le dans son propre dossier ex/c :hj

    clik sur do a systeme scan et save a logfile
    et copier coller le rapport
    demo
    http://pageperso.aol.fr/balltrap34/demohijack.htm
    0
    1. Logfile of HijackThis v1.99.1
      Scan saved at 17:59:59, on 27/11/2005
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\mssearchnet.exe
      C:\Program Files\McAfee.com\VSO\mcvsshld.exe
      C:\Program Files\McAfee.com\VSO\oasclnt.exe
      C:\PROGRA~1\mcafee.com\agent\mcagent.exe
      C:\Program Files\QuickTime\qttask.exe
      C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
      C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
      C:\Program Files\Messenger\msmsgs.exe
      C:\Program Files\1-Click Answers\answers.exe
      c:\progra~1\mcafee.com\vso\mcvsescn.exe
      C:\PROGRA~1\FICHIE~1\GURUNE~1\agtserv.exe
      c:\progra~1\mcafee.com\vso\mcvsftsn.exe
      C:\Program Files\ewido\security suite\ewidoctrl.exe
      C:\Program Files\ewido\security suite\ewidoguard.exe
      c:\program files\mcafee.com\agent\mcdetect.exe
      c:\PROGRA~1\mcafee.com\vso\mcshield.exe
      c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
      C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
      C:\WINDOWS\system32\nvsvc32.exe
      C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Fichiers communs\Sony Shared\AVLib\SSScsiSV.exe
      C:\Program Files\Internet Explorer\IEXPLORE.EXE
      C:\HijackThis\HijackThis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sympatico.ca/
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
      O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
      O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
      O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
      O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
      O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
      O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
      O4 - Global Startup: 1-Click Answers.lnk = C:\Program Files\1-Click Answers\answers.exe
      O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
      O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
      O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
      O8 - Extra context menu item: Answers... - file:C:\Program Files\1-Click Answers\Html\atiemenu.htm
      O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
      O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
      O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
      O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
      O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
      O16 - DPF: {3B0EA9E6-7003-4B38-B398-9B1B6DF439C5} - http://download1.answers.com/pub/AnswersSetup.cab
      O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,99/mcinsctl.cab
      O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
      O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
      O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
      O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
      O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
      O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
      O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
      O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\MSCSPTISRV.exe
      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
      O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\PACSPTISVR.exe
      O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
      O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SPTISRV.exe
      O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SSScsiSV.exe
      0
      1. Contributeur sécurité
        tu as pas mis le rapport du premier prog que je t est mis il faut tous lire quand ont vous repond
        ont prend le temp d ecrire prenet le temp de lire
        0
        1. il faut pas trop men vouloir je suis vraiment nul en in fo alors....

          j espere que cest ce que vous parlez

          SmitFraudFix v1.98

          Rapport fait à 18:12:20,59 le 27/11/2005
          Executé à partir de C:\Documents and Settings\David\Bureau\SmitfraudFix
          OS: Microsoft Windows XP [version 5.1.2600]

          »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\

          »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS

          »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS\system

          »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS\Web

          »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS\system32

          C:\WINDOWS\system32\hp????.tmp PRESENT !
          C:\WINDOWS\system32\ld????.tmp PRESENT !
          C:\WINDOWS\system32\mscornet.exe PRESENT !
          C:\WINDOWS\system32\mssearchnet.exe PRESENT !
          C:\WINDOWS\system32\msvol.tlb PRESENT !
          C:\WINDOWS\system32\ncompat.tlb PRESENT !
          C:\WINDOWS\system32\nvctrl.exe PRESENT !

          »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\Documents and Settings\David\Application Data

          »»»»»»»»»»»»»»»»»»»»»»»» Recherche Menu Démarrer

          »»»»»»»»»»»»»»»»»»»»»»»» Recherche Bureau

          »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\Program Files

          »»»»»»»»»»»»»»»»»»»»»»»» Reboot

          »»»»»»»»»»»»»»»»»»»»»»»» Fin du rapport
          0
          1. Contributeur sécurité
            oki
            redemarre en mode sans echec
            pour cela tu tapote la touche f8
            des le debut de l allumage du pc sans t arreter
            une fenetre vas souvrir tute deplace avec les fleches du clavier sur demarreren mode sans echec
            une fois sur le bureau il ni auras pas toutes les couleurs et autres c est normal.si f8 ne marche pas utilise la touche f5

            relance le prog smitfraudfix et choisi cette fois l option 2 et repond oui a tous
            redemarre et donne le nouveau rapport
            0
            1. SmitFraudFix v1.98

              Rapport fait à 18:54:05,26 le 27/11/2005
              Executé à partir de C:\Documents and Settings\David\Bureau\SmitfraudFix
              OS: Microsoft Windows XP [version 5.1.2600]

              »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\

              »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS

              »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS\system

              »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS\Web

              »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS\system32

              »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\Documents and Settings\David\Application Data

              »»»»»»»»»»»»»»»»»»»»»»»» Recherche Menu Démarrer

              »»»»»»»»»»»»»»»»»»»»»»»» Recherche Bureau

              »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\Program Files

              »»»»»»»»»»»»»»»»»»»»»»»» Reboot

              »»»»»»»»»»»»»»»»»»»»»»»» Fin du rapport
              0
              1. C:\Program Files\ewido\security suite\ewidoctrl.exe
                C:\Program Files\ewido\security suite\ewidoguard.exe
                c:\program files\mcafee.com\agent\mcdetect.exe
                c:\PROGRA~1\mcafee.com\vso\mcshield.exe
                c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
                C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
                C:\WINDOWS\system32\nvsvc32.exe
                C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
                C:\WINDOWS\system32\svchost.exe
                C:\Program Files\Fichiers communs\Sony Shared\AVLib\SSScsiSV.exe
                c:\program files\mcafee.com\shared\mcinfo.exe
                C:\Program Files\Internet Explorer\IEXPLORE.EXE
                C:\WINDOWS\system32\wuauclt.exe
                C:\HijackThis\HijackThis.exe

                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sympatico.ca/
                O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
                O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
                O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
                O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
                O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
                O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
                O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
                O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                O4 - Global Startup: 1-Click Answers.lnk = C:\Program Files\1-Click Answers\answers.exe
                O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
                O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
                O8 - Extra context menu item: Answers... - file:C:\Program Files\1-Click Answers\Html\atiemenu.htm
                O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
                O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
                O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
                O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
                O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                O16 - DPF: {3B0EA9E6-7003-4B38-B398-9B1B6DF439C5} - http://download1.answers.com/pub/AnswersSetup.cab
                O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,99/mcinsctl.cab
                O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
                O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
                O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
                O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
                O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
                O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
                O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
                O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\MSCSPTISRV.exe
                O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\PACSPTISVR.exe
                O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
                O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SPTISRV.exe
                O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SSScsiSV.exe
                0
                1. Contributeur sécurité
                  ou en sont tes soucis et remet un hijack complet il manque le debut
                  0
                  1. Logfile of HijackThis v1.99.1
                    Scan saved at 16:40:23, on 28/11/2005
                    Platform: Windows XP SP2 (WinNT 5.01.2600)
                    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

                    Running processes:
                    C:\WINDOWS\System32\smss.exe
                    C:\WINDOWS\system32\winlogon.exe
                    C:\WINDOWS\system32\services.exe
                    C:\WINDOWS\system32\lsass.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\WINDOWS\system32\spoolsv.exe
                    C:\Program Files\ewido\security suite\ewidoctrl.exe
                    c:\program files\mcafee.com\agent\mcdetect.exe
                    c:\PROGRA~1\mcafee.com\vso\mcshield.exe
                    c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
                    C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
                    C:\WINDOWS\system32\nvsvc32.exe
                    C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\Program Files\Fichiers communs\Sony Shared\AVLib\SSScsiSV.exe
                    C:\WINDOWS\Explorer.EXE
                    C:\Program Files\McAfee.com\VSO\mcvsshld.exe
                    C:\Program Files\McAfee.com\VSO\oasclnt.exe
                    C:\PROGRA~1\mcafee.com\agent\mcagent.exe
                    C:\Program Files\QuickTime\qttask.exe
                    C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
                    C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                    C:\Program Files\Messenger\msmsgs.exe
                    C:\Program Files\1-Click Answers\answers.exe
                    c:\progra~1\mcafee.com\vso\mcvsescn.exe
                    C:\PROGRA~1\FICHIE~1\GURUNE~1\agtserv.exe
                    c:\progra~1\mcafee.com\vso\mcvsftsn.exe
                    C:\Program Files\Internet Explorer\IEXPLORE.EXE
                    C:\HijackThis\HijackThis.exe

                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sympatico.ca/
                    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
                    O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
                    O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
                    O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
                    O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
                    O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
                    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                    O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
                    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                    O4 - Global Startup: 1-Click Answers.lnk = C:\Program Files\1-Click Answers\answers.exe
                    O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                    O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
                    O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
                    O8 - Extra context menu item: Answers... - file:C:\Program Files\1-Click Answers\Html\atiemenu.htm
                    O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
                    O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
                    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                    O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
                    O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
                    O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                    O16 - DPF: {3B0EA9E6-7003-4B38-B398-9B1B6DF439C5} - http://download1.answers.com/pub/AnswersSetup.cab
                    O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,99/mcinsctl.cab
                    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
                    O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
                    O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
                    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                    O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
                    O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
                    O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
                    O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
                    O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\MSCSPTISRV.exe
                    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                    O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\PACSPTISVR.exe
                    O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
                    O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SPTISRV.exe
                    O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SSScsiSV.exe
                    0
                    1. Contributeur sécurité
                      je test demander ou en sont tes soucis
                      0
                      1. pour mes soucis jai remarquer que curieusement je n avais plus d avertissement de mes logiciels antivirus mais ce nest peut-etre qu une question de temps avant d en avoir. Si tu pouvait seulement verifier dans le rapport si tu ne trouverais pas quelque chose se serais sympa.

                        merci
                        0
                        1. Contributeur sécurité
                          ton log a l air bon
                          fait un scan ici

                          --Scan bit defender
                          http://www.bitdefender.fr
                          clik sur scan on line a gauche et suis la procedure

                          donne le rapport
                          ----------------
                          la chasse et le balltrap ma vrai passion
                          voir site perso dans profil
                          0
                          1. malheureusement un nouveau virus detecté-New Poly Win32-
                            je nai aucune nouvelle des autres mais celui je lai maintenant
                            jai bientot fini mon scan sur bitdefender
                            0
                            1. Contributeur sécurité
                              pense a me mettre le rapport
                              0
                              1. celui de bitdefender ou hijack this?
                                0
                                1. Contributeur sécurité
                                  celui de defender
                                  0
                                  1. BitDefender Online Scanner

                                    Rapport d'analyse généré à: Mon, Nov 28, 2005 - 18:21:15

                                    Voie d'analyse: A:\;C:\;D:\;E:\;F:\;

                                    Statistiques

                                    Temps
                                    00:51:13

                                    Fichiers
                                    309112

                                    Directoires
                                    3256

                                    Secteurs de boot
                                    4

                                    Archives
                                    1175

                                    Paquets programmes
                                    32558

                                    Résultats

                                    Virus identifiés
                                    1

                                    Fichiers infectés
                                    1

                                    Fichiers suspects
                                    0

                                    Avertissements
                                    0

                                    Désinfectés
                                    0

                                    Fichiers effacés
                                    1

                                    Info sur les moteurs

                                    Définition virus
                                    236422

                                    Version des moteurs
                                    AVCORE v1.0 (build 2292) (i386) (Mar 3 2005 11:57:29)

                                    Analyse des plugins
                                    13

                                    Archive des plugins
                                    39

                                    Unpack des plugins
                                    4

                                    E-mail plugins
                                    6

                                    Système plugins
                                    1

                                    Paramètres d'analyse

                                    Première action
                                    Désinfecté

                                    Seconde Action
                                    Supprimé

                                    Heuristique
                                    Oui

                                    Acceptez les avertissements
                                    Oui

                                    Extensions analysées
                                    *;

                                    Excludez les extensions

                                    Analyse d'emails
                                    Oui

                                    Analyse des Archives
                                    Oui

                                    Analyser paquets programmes
                                    Oui

                                    Analyse des fichiers
                                    Oui

                                    Analyse de boot
                                    Oui

                                    Fichier analysé
                                    Statut

                                    C:\System Volume Information\_restore{CB4A58D1-D1AC-4B34-BFED-4F74A5236CC2}\RP1\A0004003.exe
                                    Infecté par: BehavesLike:Win32.ExplorerHijack

                                    C:\System Volume Information\_restore{CB4A58D1-D1AC-4B34-BFED-4F74A5236CC2}\RP1\A0004003.exe
                                    Echec de la désinfection

                                    C:\System Volume Information\_restore{CB4A58D1-D1AC-4B34-BFED-4F74A5236CC2}\RP1\A0004003.exe
                                    Supprimé
                                    0
                                    1. Contributeur sécurité
                                      c etais un fichier dans ta restauration il la virer
                                      tu as toujours des problemes
                                      0
                                      1. comme je tai dis tantot jai eu un avertissement de New Poly Win32, je ne sais pas si cest celui la que tu parle mais a part ca les autre que j avais hier ont l airs d etres partis pour de bon.

                                        tu ma été dune tres bonne aide merci
                                        0
                                        1. Contributeur sécurité
                                          ou il la detecter stp
                                          0
                                          • 1
                                          • 2