Désinfecter un ordi

Ti-Pat Messages postés 2 Statut Membre -  
 Utilisateur anonyme -
Bonjour,

mon oncle ma confier son ordi pour faire le menage des nombreux virus spyware et autre.

J'ai fait un scan avec hyjack this et j'aimerais votre assistance pour désinfecter l'ordi.

Merci

Voici le rapport

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:51:32, on 2011-01-15
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Safe mode

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\Administrateur\Application Data\dwm.exe
C:\WINDOWS\system32\svchost.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\csrss.exe
C:\Documents and Settings\Administrateur\Application Data\Microsoft\conhost.exe
C:\Documents and Settings\Administrateur\Bureau\HiJackThis.exe
C:\Documents and Settings\Administrateur\Application Data\Microsoft\conhost.exe
C:\Documents and Settings\Administrateur\Application Data\Microsoft\conhost.exe
C:\Documents and Settings\Administrateur\Application Data\Microsoft\conhost.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\csrss.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:50505
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll
F3 - REG:win.ini: load=C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\csrss.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
O1 - Hosts: 74.125.45.100 4-open-davinci.com
O1 - Hosts: 74.125.45.100 securitysoftwarepayments.com
O1 - Hosts: 74.125.45.100 privatesecuredpayments.com
O1 - Hosts: 74.125.45.100 secure.privatesecuredpayments.com
O1 - Hosts: 74.125.45.100 getantivirusplusnow.com
O1 - Hosts: 74.125.45.100 secure-plus-payments.com
O1 - Hosts: 74.125.45.100 www.getantivirusplusnow.com
O1 - Hosts: 74.125.45.100 www.secure-plus-payments.com
O1 - Hosts: 74.125.45.100 www.getavplusnow.com
O1 - Hosts: 74.125.45.100 safebrowsing-cache.google.com
O1 - Hosts: 74.125.45.100 urs.microsoft.com
O1 - Hosts: 74.125.45.100 www.securesoftwarebill.com
O1 - Hosts: 74.125.45.100 secure.paysecuresystem.com
O1 - Hosts: 74.125.45.100 paysoftbillsolution.com
O1 - Hosts: 74.125.45.100 protected.maxisoftwaremart.com
O1 - Hosts: 217.23.15.139 www.google.com
O1 - Hosts: 217.23.15.139 google.com
O1 - Hosts: 217.23.15.139 google.com.au
O1 - Hosts: 217.23.15.139 www.google.com.au
O1 - Hosts: 217.23.15.139 google.be
O1 - Hosts: 217.23.15.139 www.google.be
O1 - Hosts: 217.23.15.139 google.com.br
O1 - Hosts: 217.23.15.139 www.google.com.br
O1 - Hosts: 217.23.15.139 google.ca
O1 - Hosts: 217.23.15.139 www.google.ca
O1 - Hosts: 217.23.15.139 google.ch
O1 - Hosts: 217.23.15.139 www.google.ch
O1 - Hosts: 217.23.15.139 google.de
O1 - Hosts: 217.23.15.139 www.google.de
O1 - Hosts: 217.23.15.139 google.dk
O1 - Hosts: 217.23.15.139 www.google.dk
O1 - Hosts: 217.23.15.139 google.fr
O1 - Hosts: 217.23.15.139 www.google.fr
O1 - Hosts: 217.23.15.139 google.ie
O1 - Hosts: 217.23.15.139 www.google.ie
O1 - Hosts: 217.23.15.139 google.it
O1 - Hosts: 217.23.15.139 www.google.it
O1 - Hosts: 217.23.15.139 google.co.jp
O1 - Hosts: 217.23.15.139 www.google.co.jp
O1 - Hosts: 217.23.15.139 google.nl
O1 - Hosts: 217.23.15.139 www.google.nl
O1 - Hosts: 217.23.15.139 google.no
O1 - Hosts: 217.23.15.139 www.google.no
O1 - Hosts: 217.23.15.139 google.co.nz
O1 - Hosts: 217.23.15.139 www.google.co.nz
O1 - Hosts: 217.23.15.139 google.pl
O1 - Hosts: 217.23.15.139 www.google.pl
O1 - Hosts: 217.23.15.139 google.se
O1 - Hosts: 217.23.15.139 www.google.se
O1 - Hosts: 217.23.15.139 google.co.uk
O1 - Hosts: 217.23.15.139 www.google.co.uk
O1 - Hosts: 217.23.15.139 google.co.za
O1 - Hosts: 217.23.15.139 www.google.co.za
O1 - Hosts: 217.23.15.139 www.google-analytics.com
O1 - Hosts: 217.23.15.139 www.bing.com
O1 - Hosts: 217.23.15.139 search.yahoo.com
O1 - Hosts: 217.23.15.139 www.search.yahoo.com
O1 - Hosts: 217.23.15.139 uk.search.yahoo.com
O1 - Hosts: 217.23.15.139 ca.search.yahoo.com
O1 - Hosts: 217.23.15.139 de.search.yahoo.com
O1 - Hosts: 217.23.15.139 fr.search.yahoo.com
O1 - Hosts: 217.23.15.139 au.search.yahoo.com
O3 - Toolbar: LimeWire Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /r
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Fichiers communs\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe"
O4 - HKLM\..\RunOnce: [*upd_debug.exe] "C:\Documents and Settings\Administrateur\Application Data\4CA2625C03E1F39F57B9AC42B402D87E\upd_debug.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Administrateur\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr .exe" /background
O4 - HKCU\..\Run: [My Security Engine] "C:\Documents and Settings\All Users\Application Data\0decd66\MS0dec.exe" /s /d
O4 - HKCU\..\Run: [mediafix70700en02.exe] C:\Documents and Settings\Administrateur\Application Data\4CA2625C03E1F39F57B9AC42B402D87E\mediafix70700en02.exe
O4 - HKCU\..\Run: [{B3A69D7B-AF58-024D-79B8-B0C2B2EA899C}] "C:\Documents and Settings\Administrateur\Application Data\Ivde\tibym.exe"
O4 - HKCU\..\Run: [mediafix70700en02 .exe] C:\Documents and Settings\Administrateur\Application Data\4CA2625C03E1F39F57B9AC42B402D87E\mediafix70700en02 .exe
O4 - HKCU\..\Run: [mediafix70700en02 .exe] C:\Documents and Settings\Administrateur\Application Data\4CA2625C03E1F39F57B9AC42B402D87E\mediafix70700en02 .exe
O4 - HKCU\..\Run: [mediafix70700en02 .exe] C:\Documents and Settings\Administrateur\Application Data\4CA2625C03E1F39F57B9AC42B402D87E\mediafix70700en02 .exe
O4 - HKCU\..\Run: [WeatherEye] C:\Documents and Settings\Administrateur\Local Settings\Application Data\MétéoMédia\MétéoÉclair\WeatherEye .exe
O4 - HKCU\..\Run: [msclr] C:\Documents and Settings\All Users\Application Data\mswd\mswd.exe
O4 - HKCU\..\Run: [mediafix70700en02 .exe] C:\Documents and Settings\Administrateur\Application Data\4CA2625C03E1F39F57B9AC42B402D87E\mediafix70700en02 .exe
O4 - HKCU\..\Run: [mediafix70700en02 .exe] C:\Documents and Settings\Administrateur\Application Data\4CA2625C03E1F39F57B9AC42B402D87E\mediafix70700en02 .exe
O4 - HKCU\..\Run: [mediafix70700en02 .exe] C:\Documents and Settings\Administrateur\Application Data\4CA2625C03E1F39F57B9AC42B402D87E\mediafix70700en02 .exe
O4 - HKCU\..\Run: [mediafix70700en02 .exe] C:\Documents and Settings\Administrateur\Application Data\4CA2625C03E1F39F57B9AC42B402D87E\mediafix70700en02 .exe
O4 - HKCU\..\Run: [mediafix70700en02 .exe] C:\Documents and Settings\Administrateur\Application Data\4CA2625C03E1F39F57B9AC42B402D87E\mediafix70700en02 .exe
O4 - HKCU\..\Run: [mediafix70700en02 .exe] C:\Documents and Settings\Administrateur\Application Data\4CA2625C03E1F39F57B9AC42B402D87E\mediafix70700en02 .exe
O4 - HKCU\..\Run: [mediafix70700en02 .exe] C:\Documents and Settings\Administrateur\Application Data\4CA2625C03E1F39F57B9AC42B402D87E\mediafix70700en02 .exe
O4 - HKCU\..\Run: [mediafix70700en02 .exe] C:\Documents and Settings\Administrateur\Application Data\4CA2625C03E1F39F57B9AC42B402D87E\mediafix70700en02 .exe
O4 - HKCU\..\Run: [mediafix70700en02 .exe] C:\Documents and Settings\Administrateur\Application Data\4CA2625C03E1F39F57B9AC42B402D87E\mediafix70700en02 .exe
O4 - HKCU\..\Run: [mediafix70700en02 .exe] C:\Documents and Settings\Administrateur\Application Data\4CA2625C03E1F39F57B9AC42B402D87E\mediafix70700en02 .exe
O4 - HKCU\..\Run: [mediafix70700en02 .exe] C:\Documents and Settings\Administrateur\Application Data\4CA2625C03E1F39F57B9AC42B402D87E\mediafix70700en02 .exe
O4 - HKCU\..\Run: [mediafix70700en02 .exe] C:\Documents and Settings\Administrateur\Application Data\4CA2625C03E1F39F57B9AC42B402D87E\mediafix70700en02 .exe
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-20\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-20\..\RunOnce: [*upd_debug.exe] "C:\Documents and Settings\Administrateur\Application Data\4CA2625C03E1F39F57B9AC42B402D87E\upd_debug.exe" (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O4 - .DEFAULT User Startup: caxi.exe (User 'Default user')
O4 - .DEFAULT User Startup: celyg.exe (User 'Default user')
O4 - .DEFAULT User Startup: ramean.exe (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: &Virtual Keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files\Kaspersky Lab\Kaspersky PURE\klwtbbho.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: URLs c&heck - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files\Kaspersky Lab\Kaspersky PURE\klwtbbho.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} (get_atlcom Class) - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{3BED26DF-767A-46EE-B865-6F52AF1B1F87}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CCS\Services\Tcpip\..\{9A93A9BC-945F-4B0C-9250-4801A6346444}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS1\Services\Tcpip\..\{3BED26DF-767A-46EE-B865-6F52AF1B1F87}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS2\Services\Tcpip\..\{3BED26DF-767A-46EE-B865-6F52AF1B1F87}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll,C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Kaspersky PURE (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky PURE\avp.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: CryptoStorage control service (CSObjectsSrv) - Infowatch - C:\Program Files\Fichiers communs\InfoWatch\CryptoStorage\ProtectedObjectsSrv.exe
O23 - Service: Service Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
A voir également:

1 réponse

Utilisateur anonyme
 
Bonsoir

Ton oncle dispose d'une version illégitime de Windows.

@+

---------Contributeur Sécurité---------
On a tous été un jour débutant dans quelque chose.
Mais le savoir est la récompense de l'assiduité.
0