[virus] infecté par GaelicumA

bigbabou -  
Kristopher Messages postés 3752 Statut Contributeur -
bonjour,

voilà je suis infecté depuis quelques semaine par le virus Gaelicum A dont je n'arrive pas à me débarraser. j'utilise AVG mais même avec leur utilitaire de désinfection, quand tout est nettoyé (apparement) le virus revient sans cesse.

j'ai essayé les antivirus en ligne (secuser, bitdefender, ...) mais ils ne veulent pas se lancer seul Panda Antivirus a réussi ... mais je ne suis pas sur du resultat

j'ai vu sur d'autres forum qu'un log hijackthis pouvais aider mais je ne sais pas l'interpreter. si quelqu'un pouvait m'aider merci d'avance

voilà mon log hijack apres panda

Logfile of HijackThis v1.99.1
Scan saved at 20:20:49, on 04/02/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Launch Manager\LaunchAp.exe
C:\Program Files\Launch Manager\PowerKey.exe
C:\Program Files\Launch Manager\HotkeyApp.exe
C:\Program Files\Launch Manager\CtrlVol.exe
C:\Program Files\Launch Manager\OSDCtrl.exe
C:\Program Files\Launch Manager\Wbutton.exe
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Java\jre1.5.0\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9EE.EXE
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Documents and Settings\Bigabou\Application Data\Verbatim Software\V-Key.exe
C:\Program Files\SuperCopier2\SuperCopier2.exe
C:\Acer\eManager\anbmServ.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\oodag.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\System32\alg.exe
C:\DOCUME~1\Bigabou\LOCALS~1\Temp\modulhac.exe
C:\Program Files\eMule\emule.exe
C:\Program Files\Mozilla Firefox\firefox.exe
D:\temp\logiciel\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.neuf.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://home.neuf.fr
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = 
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = 
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://global.acer.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {206E52E0-D52E-11D4-AD54-0000E86C26F6} - C:\PROGRA~1\FRESHD~1\FRESHD~1\fdcatch.dll
O2 - BHO: Trellian BHO Impl - {24180B00-2EB6-11d7-BD6F-004854603DCE} - C:\Program Files\TRELLIAN\Toolbar\toolbar.dll
O2 - BHO: (no name) - {45574C30-4C30-4486-BB18-75F5CE01F5BC} - C:\WINDOWS\system32\msihnd32.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: ToolbarBrowser - {71AAABE5-1F0F-11d7-BD6F-004854603DCE} - C:\Program Files\TRELLIAN\Toolbar\toolbar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [LaunchAp] C:\Program Files\Launch Manager\LaunchAp.exe
O4 - HKLM\..\Run: [PowerKey] "C:\Program Files\Launch Manager\PowerKey.exe"
O4 - HKLM\..\Run: [LManager] C:\Program Files\Launch Manager\HotkeyApp.exe
O4 - HKLM\..\Run: [CtrlVol] C:\Program Files\Launch Manager\CtrlVol.exe
O4 - HKLM\..\Run: [LMgrOSD] C:\Program Files\Launch Manager\OSDCtrl.exe
O4 - HKLM\..\Run: [Wbutton] "C:\Program Files\Launch Manager\Wbutton.exe"
O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0\bin\jusched.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [EPSON Stylus CX6600 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9EE.EXE /P26 "EPSON Stylus CX6600 Series" /O6 "USB001" /M "Stylus CX6600"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe"  -osboot
O4 - HKCU\..\Run: [Store 'n' Go] C:\Documents and Settings\Bigabou\Application Data\Verbatim Software\V-Key.exe
O4 - HKCU\..\Run: [SuperCopier2.exe] C:\Program Files\SuperCopier2\SuperCopier2.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.5.0) - 
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://www.msnjeux.com/online2/MSN_INTL_FRANCE/insaniquarium/zylomgamesplayer.cab
O16 - DPF: {CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA} (Environnement d'exécution Java 1.4.1_02) - 
O16 - DPF: {CE69F98F-2AF3-4306-BAC6-A79070EDA1B4} (Zylom Loader Object) - http://eu.download.games.yahoo.com/zylom/activex/zylomloader.cab
O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} (SproutLauncherCtrl Class) - http://www.msnjeux.com/online2/MSN_INTL_FRANCE/feeding_frenzy/SproutLauncher.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{4D22EABD-2355-4762-895B-6FBF90FA5293}: NameServer = 86.64.145.154 86.64.145.144
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Fichiers communs\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe



merci

7 réponses

  1. Kristopher Messages postés 3752 Statut Contributeur 106
     
    Salut,

    1/ Coche et fixe ces lignes :

    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.5.0) -
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
    O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://www.msnjeux.com/online2/MSN_INTL_FRANCE/insaniquarium/zylomgamesplayer.cab
    O16 - DPF: {CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA} (Environnement d'exécution Java 1.4.1_02) -
    O16 - DPF: {CE69F98F-2AF3-4306-BAC6-A79070EDA1B4} (Zylom Loader Object) - http://eu.download.games.yahoo.com/zylom/activex/zylomloader.cab
    O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} (SproutLauncherCtrl Class) - http://www.msnjeux.com/online2/MSN_INTL_FRANCE/feeding_frenzy/SproutLauncher.cab

    2/
    - Télécharge CCLEANER et nettoie ton PC avec : http://www.01net.com/telecharger/windows/Utilitaire/nettoyeurs_et_installeurs/fiches/32599.html
    Tutorial là : http://www.vulgarisation-informatique.com/nettoyer-windows-ccleaner.php

    3/ Télécharge et scanne ton PC avec Ewido Security Suite : http://www.01net.com/telecharger/windows/Utilitaire/antivirus/fiches/31851.html
    Copie/colle le rapport sur le forum.

    ++
    0
    1. bigbabou
       
      bonjour et merci pour ton aide

      alors j'ai nettoyer avec CCleaner et voilà le résultat avec ewido. J'ai fait plusieurs scan avec car il ne me nettoyait pas tout. voilà le rapport
      ---------------------------------------------------------
       ewido anti-malware - Rapport de scan
      ---------------------------------------------------------
      
       + Créé le:		17:25:50, 05/02/2006
       + Somme de contrôle:	F103B24B
      
       + Résultats du scan:
      
      	[2016] C:\WINDOWS\system32\acwav.dll -> Spyware.Look2Me : Erreur durant le nettoyage
      	[588] C:\WINDOWS\system32\acwav.dll -> Spyware.Look2Me : Erreur durant le nettoyage
      
      
      ::Fin du rapport


      j'ai essayé d'effacer la dll mentionnée mais windows m'en empeche. si tu pouvais m'aiguiller vers la solution merci.
      En tout cas avec ces histoires je sais pas si mon histoire de virus est reglée ou pas.

      au cas ou je remet mon log highjack this effectué apres le scan ewido

      Logfile of HijackThis v1.99.1
      Scan saved at 17:34:17, on 05/02/2006
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
      
      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
      C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      C:\Program Files\Launch Manager\LaunchAp.exe
      C:\Program Files\Launch Manager\PowerKey.exe
      C:\Program Files\Launch Manager\HotkeyApp.exe
      C:\Program Files\Launch Manager\CtrlVol.exe
      C:\Program Files\Launch Manager\OSDCtrl.exe
      C:\Program Files\Launch Manager\Wbutton.exe
      C:\WINDOWS\system32\VTTimer.exe
      C:\WINDOWS\AGRSMMSG.exe
      C:\Program Files\Java\jre1.5.0\bin\jusched.exe
      C:\Program Files\QuickTime\qttask.exe
      C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
      G:\SYSTEM~2\NORTON~1\navapw32.exe
      C:\Acer\eManager\anbmServ.exe
      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
      C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
      C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
      C:\Program Files\ewido anti-malware\ewidoctrl.exe
      C:\Program Files\ewido anti-malware\ewidoguard.exe
      C:\WINDOWS\system32\nvsvc32.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
      C:\Program Files\ewido anti-malware\securitysuite.exe
      C:\Program Files\Windows NT\Accessoires\WORDPAD.EXE
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\Program Files\Symantec\LiveUpdate\AUpdate.exe
      C:\DOCUME~1\Bigabou\LOCALS~1\Temp\Rar$EX00.375\HijackThis.exe
      
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
      R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://global.acer.com/
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
      O3 - Toolbar: ToolbarBrowser - {71AAABE5-1F0F-11d7-BD6F-004854603DCE} - C:\Program Files\TRELLIAN\Toolbar\toolbar.dll
      O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
      O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - G:\system_works_2002\Norton AntiVirus\NavShExt.dll
      O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
      O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      O4 - HKLM\..\Run: [LaunchAp] C:\Program Files\Launch Manager\LaunchAp.exe
      O4 - HKLM\..\Run: [PowerKey] "C:\Program Files\Launch Manager\PowerKey.exe"
      O4 - HKLM\..\Run: [LManager] C:\Program Files\Launch Manager\HotkeyApp.exe
      O4 - HKLM\..\Run: [CtrlVol] C:\Program Files\Launch Manager\CtrlVol.exe
      O4 - HKLM\..\Run: [LMgrOSD] C:\Program Files\Launch Manager\OSDCtrl.exe
      O4 - HKLM\..\Run: [Wbutton] "C:\Program Files\Launch Manager\Wbutton.exe"
      O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
      O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
      O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0\bin\jusched.exe
      O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [EPSON Stylus CX6600 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9EE.EXE /P26 "EPSON Stylus CX6600 Series" /O6 "USB001" /M "Stylus CX6600"
      O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      O4 - HKLM\..\Run: [winsysupd] C:\windows\winsysupd5.exe
      O4 - HKLM\..\Run: [NAV Agent] G:\SYSTEM~2\NORTON~1\navapw32.exe
      O4 - HKCU\..\Run: [SuperCopier2.exe] C:\Program Files\SuperCopier2\SuperCopier2.exe
      O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
      O17 - HKLM\System\CCS\Services\Tcpip\..\{4D22EABD-2355-4762-895B-6FBF90FA5293}: NameServer = 86.64.145.140 86.64.145.150
      O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
      O20 - Winlogon Notify: ShellScrap - C:\WINDOWS\system32\mvp8l97u1.dll
      O21 - SSODL: DCOM Server - {2C1CD3D7-86AC-4068-93BC-A02304BB8C34} - (no file)
      O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
      O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
      O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
      O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
      O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
      O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
      O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
      O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
      O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Fichiers communs\Macromedia Shared\Service\Macromedia Licensing.exe
      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
      O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
      


      merci encore
      0
    2. Kristopher Messages postés 3752 Statut Contributeur 106
       
      Salut Bigabou,

      Comment cela se fait-il que les rapports de HijackThis et celui de Ewido soient d'une autre couleur que le reste du texte ?

      1/ Télécharge l2mfix :

      http://www.downloads.subratam.org/l2mfix.exe

      Double clic sur l2mfix.exe pour lancer l'extraction.
      Dans le dossier l2mfix, double clic sur l2mfix.bat, appuie sur n'importe quelle touche puis choisis l'option #1 (et pas autre chose) et valide avec la touche "Entrée".
      Le bloc note va s'ouvrir avec le résultat du scan.
      Copie/colle le rapport sur le forum stp.
      0
      1. bigbabou > Kristopher Messages postés 3752 Statut Contributeur
         
        re

        pour le texte en couleur je sais pas c'est juste le copier coller de notepad...

        voilà le log l2mfix

        L2MFIX find log 010406
        These are the registry keys present
        **********************************************************************************
        Winlogon/notify:
        Windows Registry Editor Version 5.00
        
        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]
        
        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
        "Asynchronous"=dword:00000000
        "Impersonate"=dword:00000000
        "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
          6c,00,00,00
        "Logoff"="ChainWlxLogoffEvent"
        
        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
        "Asynchronous"=dword:00000000
        "Impersonate"=dword:00000000
        "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
          6c,00,6c,00,00,00
        "Logoff"="CryptnetWlxLogoffEvent"
        
        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
        "DLLName"="cscdll.dll"
        "Logon"="WinlogonLogonEvent"
        "Logoff"="WinlogonLogoffEvent"
        "ScreenSaver"="WinlogonScreenSaverEvent"
        "Startup"="WinlogonStartupEvent"
        "Shutdown"="WinlogonShutdownEvent"
        "StartShell"="WinlogonStartShellEvent"
        "Impersonate"=dword:00000000
        "Asynchronous"=dword:00000001
        
        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
        "DLLName"="wlnotify.dll"
        "Logon"="SCardStartCertProp"
        "Logoff"="SCardStopCertProp"
        "Lock"="SCardSuspendCertProp"
        "Unlock"="SCardResumeCertProp"
        "Enabled"=dword:00000001
        "Impersonate"=dword:00000001
        "Asynchronous"=dword:00000001
        
        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
        "Asynchronous"=dword:00000000
        "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
          6c,00,6c,00,00,00
        "Impersonate"=dword:00000000
        "StartShell"="SchedStartShell"
        "Logoff"="SchedEventLogOff"
        
        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
        "Logoff"="WLEventLogoff"
        "Impersonate"=dword:00000000
        "Asynchronous"=dword:00000001
        "DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
          6c,00,6c,00,00,00
        
        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
        "DLLName"="WlNotify.dll"
        "Lock"="SensLockEvent"
        "Logon"="SensLogonEvent"
        "Logoff"="SensLogoffEvent"
        "Safe"=dword:00000001
        "MaxWait"=dword:00000258
        "StartScreenSaver"="SensStartScreenSaverEvent"
        "StopScreenSaver"="SensStopScreenSaverEvent"
        "Startup"="SensStartupEvent"
        "Shutdown"="SensShutdownEvent"
        "StartShell"="SensStartShellEvent"
        "PostShell"="SensPostShellEvent"
        "Disconnect"="SensDisconnectEvent"
        "Reconnect"="SensReconnectEvent"
        "Unlock"="SensUnlockEvent"
        "Impersonate"=dword:00000001
        "Asynchronous"=dword:00000001
        
        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ShellScrap]
        "Asynchronous"=dword:00000000
        "DllName"="C:\\WINDOWS\\system32\\mvp8l97u1.dll"
        "Impersonate"=dword:00000000
        "Logon"="WinLogon"
        "Logoff"="WinLogoff"
        "Shutdown"="WinShutdown"
        
        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
        "Asynchronous"=dword:00000000
        "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
          6c,00,6c,00,00,00
        "Impersonate"=dword:00000000
        "Logoff"="TSEventLogoff"
        "Logon"="TSEventLogon"
        "PostShell"="TSEventPostShell"
        "Shutdown"="TSEventShutdown"
        "StartShell"="TSEventStartShell"
        "Startup"="TSEventStartup"
        "MaxWait"=dword:00000258
        "Reconnect"="TSEventReconnect"
        "Disconnect"="TSEventDisconnect"
        
        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
        "DLLName"="wlnotify.dll"
        "Logon"="RegisterTicketExpiredNotificationEvent"
        "Logoff"="UnregisterTicketExpiredNotificationEvent"
        "Impersonate"=dword:00000001
        "Asynchronous"=dword:00000001
        
        **********************************************************************************
        useragent:
        Windows Registry Editor Version 5.00
        
        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
        "{7EFCA0EF-7564-106B-362A-609B4C65CCBF}"=""
        
        **********************************************************************************
        Shell Extension key:
        Windows Registry Editor Version 5.00
        
        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
        "{00022613-0000-0000-C000-000000000046}"="Feuille de propri‚t‚s du fichier multim‚dia"
        "{176d6597-26d3-11d1-b350-080036a75b03}"="Gestion de scanneur ICM"
        "{1F2E5C40-9550-11CE-99D2-00AA006E086C}"="Page de s‚curit‚ NTFS"
        "{3EA48300-8CF6-101B-84FB-666CCB9BCD32}"="Page des propri‚t‚s de OLE DocFile"
        "{40dd6e20-7c17-11ce-a804-00aa003ca9f6}"="Extensions de l'environnement pour le partage"
        "{41E300E0-78B6-11ce-849B-444553540000}"="PlusPack CPL Extension"
        "{42071712-76d4-11d1-8b24-00a0c9068ff3}"="Extension Affichage Carte du Panneau de configuration"
        "{42071713-76d4-11d1-8b24-00a0c9068ff3}"="Extension Affichage cran du Panneau de configuration"
        "{42071714-76d4-11d1-8b24-00a0c9068ff3}"="Extension Affichage Panorama du Panneau de configuration"
        "{4E40F770-369C-11d0-8922-00A024AB2DBB}"="Page de s‚curit‚ DS"
        "{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}"="Page de compatibilit‚"
        "{56117100-C0CD-101B-81E2-00AA004AE837}"="Gestionnaire de donn‚es endommag‚es de l'environnement"
        "{59099400-57FF-11CE-BD94-0020AF85B590}"="Extension copie de disquette"
        "{59be4990-f85c-11ce-aff7-00aa003ca9f6}"="Extensions de l'environnement pour les objets r‚seau de Microsoft Windows"
        "{5DB2625A-54DF-11D0-B6C4-0800091AA605}"="Gestion d'‚cran ICM"
        "{675F097E-4C4D-11D0-B6C1-0800091AA605}"="Gestion d'imprimante ICM"
        "{764BF0E1-F219-11ce-972D-00AA00A14F56}"="Extensions de l'environnement de compression de fichiers"
        "{77597368-7b15-11d0-a0c2-080036af3f03}"="Extension de l'environnement d'imprimante Web"
        "{7988B573-EC89-11cf-9C00-00AA00A14F56}"="Disk Quota UI"
        "{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}"="Menu contextuel de cryptage"
        "{85BBD920-42A0-1069-A2E4-08002B30309D}"="Porte-documents"
        "{88895560-9AA2-1069-930E-00AA0030EBC8}"="Extension ic“ne HyperTerminal"
        "{BD84B380-8CA2-1069-AB1D-08000948F534}"="Fonts"
        "{DBCE2480-C732-101B-BE72-BA78E9AD5B27}"="Profil ICC"
        "{F37C5810-4D3F-11d0-B4BF-00AA00BBB723}"="Page de s‚curit‚ des imprimantes"
        "{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}"="Extensions de l'environnement pour le partage"
        "{f92e8c40-3d33-11d2-b1aa-080036a75b03}"="Display TroubleShoot CPL Extension"
        "{7444C717-39BF-11D1-8CD9-00C04FC29D45}"="Extension de cryptographie PKO"
        "{7444C719-39BF-11D1-8CD9-00C04FC29D45}"="Extension de cryptographie Sign"
        "{7007ACC7-3202-11D1-AAD2-00805FC1270E}"="Connexions r‚seau"
        "{992CFFA0-F557-101A-88EC-00DD010CCC48}"="Connexions r‚seau"
        "{E211B736-43FD-11D1-9EFB-0000F8757FCD}"="&Scanneurs et appareils photo"
        "{FB0C9C8A-6C50-11D1-9F1D-0000F8757FCD}"="&Scanneurs et appareils photo"
        "{905667aa-acd6-11d2-8080-00805f6596d2}"="&Scanneurs et appareils photo"
        "{3F953603-1008-4f6e-A73A-04AAC7A992F1}"="&Scanneurs et appareils photo"
        "{83bbcbf3-b28a-4919-a5aa-73027445d672}"="&Scanneurs et appareils photo"
        "{F0152790-D56E-4445-850E-4F3117DB740C}"="Remote Sessions CPL Extension"
        "{60254CA5-953B-11CF-8C96-00AA00B8708C}"="Extensions de l'interpr‚teur de commandes pour l'environnement d'ex‚cution de scripts Windows"
        "{2206CDB2-19C1-11D1-89E0-00C04FD7A829}"="Liaison de donn‚es Microsoft"
        "{DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Icon Handler"
        "{797F1E90-9EDD-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Shell Extension"
        "{D6277990-4C6A-11CF-8D87-00AA0060F5BF}"="Tƒches planifi‚es"
        "{2559a1f7-21d7-11d4-bdaf-00c04f60b9f0}"="Set Program Access and Defaults"
        "{5F327514-6C5E-4d60-8F16-D07FA08A78ED}"="Auto Update Property Sheet Extension"
        "{0DF44EAA-FF21-4412-828E-260A8728E7F1}"="Barre des tƒches et menu D‚marrer"
        "{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}"="Rechercher"
        "{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}"="Aide et support"
        "{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}"="Aide et support"
        "{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}"="Ex‚cuter..."
        "{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}"="Internet"
        "{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}"="Courrier ‚lectronique"
        "{D20EA4E1-3957-11d2-A40B-0C5020524152}"="Polices"
        "{D20EA4E1-3957-11d2-A40B-0C5020524153}"="Outils d'administration"
        "{596AB062-B4D2-4215-9F74-E9109B0A8153}"="Page de propri‚t‚s des versions pr‚c‚dentes"
        "{9DB7A13C-F208-4981-8353-73CC61AE2783}"="Versions pr‚c‚dentes"
        "{875CB1A1-0F29-45de-A1AE-CFB4950D0B78}"="Audio Media Properties Handler"
        "{40C3D757-D6E4-4b49-BB41-0E5BBEA28817}"="Video Media Properties Handler"
        "{E4B29F9D-D390-480b-92FD-7DDB47101D71}"="Wav Properties Handler"
        "{87D62D94-71B3-4b9a-9489-5FE6850DC73E}"="Avi Properties Handler"
        "{A6FD9E45-6E44-43f9-8644-08598F5A74D9}"="Midi Properties Handler"
        "{c5a40261-cd64-4ccf-84cb-c394da41d590}"="Video Thumbnail Extractor"
        "{5E6AB780-7743-11CF-A12B-00AA004AE837}"="Barre d'outils Internet Microsoft"
        "{22BF0C20-6DA7-11D0-B373-00A0C9034938}"="tat du t‚l‚chargement"
        "{91EA3F8B-C99B-11d0-9815-00C04FD91972}"="Dossier Bureau ‚tendu"
        "{6413BA2C-B461-11d1-A18A-080036B11A03}"="Dossier du shell augment‚"
        "{F61FFEC1-754F-11d0-80CA-00AA005B4383}"="BandProxy"
        "{7BA4C742-9E81-11CF-99D3-00AA004AE837}"="Bande du navigateur Microsoft"
        "{30D02401-6A81-11d0-8274-00C04FD5AE38}"="Bande de recherche"
        "{169A0691-8DF9-11d1-A1C4-00C04FD75D13}"="Volet int‚gr‚ de recherche"
        "{07798131-AF23-11d1-9111-00A0C98BA67D}"="Recherche Web"
        "{AF4F6510-F982-11d0-8595-00AA004CD6D8}"="Utilitaire des options de l'arborescence du Registre"
        "{01E04581-4EEE-11d0-BFE9-00AA005B4383}"="&Adresse"
        "{A08C11D2-A228-11d0-825B-00AA005B4383}"="BoŒte d'entr‚e de l'adresse"
        "{00BB2763-6A77-11D0-A535-00C04FD7D062}"="Saisie semi-automatique Microsoft"
        "{7376D660-C583-11d0-A3A5-00C04FD706EC}"="TridentImageExtractor"
        "{6756A641-DE71-11d0-831B-00AA005B4383}"="Liste de saisie semi-automatique MRU"
        "{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}"="Liste de saisie semi-automatique personnalis‚e MRU"
        "{7e653215-fa25-46bd-a339-34a2790f3cb7}"="Accessible"
        "{acf35015-526e-4230-9596-becbe19f0ac9}"="Barre de progrŠs auto-ouvrante"
        "{00BB2764-6A77-11D0-A535-00C04FD7D062}"="Liste de saisie semi-automatique de l'historique Microsoft"
        "{03C036F1-A186-11D0-824A-00AA005B4383}"="Liste de saisie semi-automatique du dossier Shell Microsoft"
        "{00BB2765-6A77-11D0-A535-00C04FD7D062}"="Conteneur de la liste de saisie semi-automatique multiple Microsoft"
        "{ECD4FC4E-521C-11D0-B792-00A0C90312E1}"="Menu Site de bandes"
        "{3CCF8A41-5C85-11d0-9796-00AA00B90ADF}"="Shell DeskBarApp"
        "{ECD4FC4C-521C-11D0-B792-00A0C90312E1}"="Barre du Bureau"
        "{ECD4FC4D-521C-11D0-B792-00A0C90312E1}"="Shell Rebar BandSite"
        "{DD313E04-FEFF-11d1-8ECD-0000F87A470C}"="Assistance utilisateur"
        "{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}"="ParamŠtres du dossier global"
        "{EFA24E61-B078-11d0-89E4-00C04FC9E26E}"="Favorites Band"
        "{0A89A860-D7B1-11CE-8350-444553540000}"="Shell Automation Inproc Service"
        "{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}"="Shell DocObject Viewer"
        "{A5E46E3A-8849-11D1-9D8C-00C04FC99D61}"="Microsoft Browser Architecture"
        "{FBF23B40-E3F0-101B-8488-00AA003E56F8}"="InternetShortcut"
        "{3C374A40-BAE4-11CF-BF7D-00AA006946EE}"="Microsoft Url History Service"
        "{FF393560-C2A7-11CF-BFF4-444553540000}"="Historique"
        "{7BD29E00-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
        "{7BD29E01-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
        "{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"="Microsoft Url Search Hook"
        "{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC}"="Image de d‚marrage de la Suite IE4"
        "{67EA19A0-CCEF-11d0-8024-00C04FD75D13}"="CDF Extension Copy Hook"
        "{131A6951-7F78-11D0-A979-00C04FD705A2}"="ISFBand OC"
        "{9461b922-3c5a-11d2-bf8b-00c04fb93661}"="Search Assistant OC"
        "{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}"="Internet"
        "{871C5380-42A0-1069-A2EA-08002B30309D}"="Internet Name Space"
        "{EFA24E64-B078-11d0-89E4-00C04FC9E26E}"="Explorer Band"
        "{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
        "{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
        "{88C6C381-2E85-11D0-94DE-444553540000}"="Dossier ActiveX Cache"
        "{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"="WebCheck"
        "{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}"="Subscription Mgr"
        "{F5175861-2688-11d0-9C5E-00AA00A45957}"="Dossier Inscription"
        "{08165EA0-E946-11CF-9C87-00AA005127ED}"="WebCheckWebCrawler"
        "{E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB}"="WebCheckChannelAgent"
        "{E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7}"="TrayAgent"
        "{7D559C10-9FE9-11d0-93F7-00AA0059CE02}"="Code Download Agent"
        "{E6CC6978-6B6E-11D0-BECA-00C04FD940BE}"="ConnectionAgent"
        "{D8BD2030-6FC9-11D0-864F-00AA006809D9}"="PostAgent"
        "{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}"="WebCheck SyncMgr Handler"
        "{352EC2B7-8B9A-11D1-B8AE-006008059382}"="Gestionnaire d'applications d'environnement"
        "{0B124F8F-91F0-11D1-B8B5-006008059382}"="num‚rateur d'applications install‚es"
        "{CFCCC7A0-A282-11D1-9082-006008059382}"="Publication d'application Darwin"
        "{e84fda7c-1d6a-45f6-b725-cb260c236066}"="Shell Image Verbs"
        "{66e4e4fb-f385-4dd0-8d74-a2efd1bc6178}"="Shell Image Data Factory"
        "{00E7B358-F65B-4dcf-83DF-CD026B94BFD4}"="Autoplay for SlideShow"
        "{3F30C968-480A-4C6C-862D-EFC0897BB84B}"="Extracteur de miniatures de fichier + GDI"
        "{9DBD2C50-62AD-11d0-B806-00C04FD706EC}"="Gestionnaire de miniatures - Informations de r‚sum‚ (DOCFILES)"
        "{EAB841A0-9550-11cf-8C16-00805F1408F3}"="Extracteur de miniatures HTML"
        "{eb9b1153-3b57-4e68-959a-a3266bc3d7fe}"="Shell Image Property Handler"
        "{CC6EEFFB-43F6-46c5-9619-51D571967F7D}"="Assistant Publication de sites Web"
        "{add36aa8-751a-4579-a266-d66f5202ccbb}"="Commande d'impressions via le Web"
        "{6b33163c-76a5-4b6c-bf21-45de9cd503a1}"="Objet Assistant de publication Shell"
        "{58f1f272-9240-4f51-b6d4-fd63d1618591}"="Assistant Obtenir une identit‚ Passport"
        "{7A9D77BD-5403-11d2-8785-2E0420524153}"="Comptes d'utilisateurs"
        "{BD472F60-27FA-11cf-B8B4-444553540000}"="Compressed (zipped) Folder Right Drag Handler"
        "{888DCA60-FC0A-11CF-8F0F-00C04FD7D062}"="Compressed (zipped) Folder SendTo Target"
        "{f39a0dc0-9cc8-11d0-a599-00c04fd64433}"="Fichier de chaŒne"
        "{f3aa0dc0-9cc8-11d0-a599-00c04fd64434}"="Raccourci de chaŒne"
        "{f3ba0dc0-9cc8-11d0-a599-00c04fd64435}"="Channel Handler Object"
        "{f3da0dc0-9cc8-11d0-a599-00c04fd64437}"="Channel Menu"
        "{f3ea0dc0-9cc8-11d0-a599-00c04fd64438}"="Channel Properties"
        "{692F0339-CBAA-47e6-B5B5-3B84DB604E87}"="Extensions Manager Folder"
        "{63da6ec0-2e98-11cf-8d82-444553540000}"="FTP Folders Webview"
        "{883373C3-BF89-11D1-BE35-080036B11A03}"="Microsoft DocProp Shell Ext"
        "{A9CF0EAE-901A-4739-A481-E35B73E47F6D}"="Microsoft DocProp Inplace Edit Box Control"
        "{8EE97210-FD1F-4B19-91DA-67914005F020}"="Microsoft DocProp Inplace ML Edit Box Control"
        "{0EEA25CC-4362-4A12-850B-86EE61B0D3EB}"="Microsoft DocProp Inplace Droplist Combo Control"
        "{6A205B57-2567-4A2C-B881-F787FAB579A3}"="Microsoft DocProp Inplace Calendar Control"
        "{28F8A4AC-BBB3-4D9B-B177-82BFC914FA33}"="Microsoft DocProp Inplace Time Control"
        "{8A23E65E-31C2-11d0-891C-00A024AB2DBB}"="Directory Query UI"
        "{9E51E0D0-6E0F-11d2-9601-00C04FA31A86}"="Shell properties for a DS object"
        "{163FDC20-2ABC-11d0-88F0-00A024AB2DBB}"="Directory Object Find"
        "{F020E586-5264-11d1-A532-0000F8757D7E}"="Directory Start/Search Find"
        "{0D45D530-764B-11d0-A1CA-00AA00C16E65}"="Directory Property UI"
        "{62AE1F9A-126A-11D0-A14B-0800361B1103}"="Directory Context Menu Verbs"
        "{ECF03A33-103D-11d2-854D-006008059367}"="MyDocs Copy Hook"
        "{ECF03A32-103D-11d2-854D-006008059367}"="MyDocs Drop Target"
        "{4a7ded0a-ad25-11d0-98a8-0800361b1103}"="MyDocs Properties"
        "{750fdf0e-2a26-11d1-a3ea-080036587f03}"="Offline Files Menu"
        "{10CFC467-4392-11d2-8DB4-00C04FA31A66}"="Offline Files Folder Options"
        "{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E}"="Dossier Fichiers hors connexion"
        "{143A62C8-C33B-11D1-84FE-00C04FA34A14}"="Microsoft Agent Character Property Sheet Handler"
        "{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6}"="DfsShell"
        "{60fd46de-f830-4894-a628-6fa81bc0190d}"="%DESC_PublishDropTarget%"
        "{7A80E4A8-8005-11D2-BCF8-00C04F72C717}"="MMC Icon Handler"
        "{0CD7A5C0-9F37-11CE-AE65-08002B2E1262}"=".CAB file viewer"
        "{32714800-2E5F-11d0-8B85-00AA0044F941}"="Des &personnes..."
        "{8DD448E6-C188-4aed-AF92-44956194EB1F}"="Windows Media Player Play as Playlist Context Menu Handler"
        "{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}"="Windows Media Player Burn Audio CD Context Menu Handler"
        "{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}"="Windows Media Player Add to Playlist Context Menu Handler"
        "{2F603045-309F-11CF-9774-0020AFD0CFF6}"="Synaptics Control Panel"
        "{A70C977A-BF00-412C-90B7-034C51DA2439}"="NvCpl DesktopContext Class"
        "{FFB699E0-306A-11d3-8BD1-00104B6F7516}"="Play on my TV helper"
        "{1CDB2949-8F65-4355-8456-263E7C208A5D}"="Desktop Explorer"
        "{1E9B04FB-F9E5-4718-997B-B8DA88302A47}"="Desktop Explorer Menu"
        "{1E9B04FB-F9E5-4718-997B-B8DA88302A48}"="nView Desktop Context Menu"
        "{0006F045-0000-0000-C000-000000000046}"="Microsoft Outlook Custom Icon Handler"
        "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"="WinRAR shell extension"
        "{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}"="Shell Extensions for RealOne Player"
        "{0E6C58A9-F592-4862-B35F-CA45E24003B3}"="CloneCD"
        "{32020A01-506E-484D-A2A8-BE3CF17601C3}"="AlcoholShellEx"
        "{0AC6C6C5-F7A8-11D2-BEF4-00C04F990001}"="Macromedia FTP & RDS"
        "{6B19FEC2-A45B-11CF-9045-00A0C9039735}"="Registered ActiveX Controls"
        "{D545EBD1-BD92-11CF-8772-00A0C9039735}"="Developer Studio Components"
        "{0873D142-79EF-49fa-81B5-211AAC0B0A7F}"="Target Finder Shell Extension"
        "{A5110426-177D-4e08-AB3F-785F10B4439C}"="Mes t‚l‚phones"
        "{9F97547E-4609-42C5-AE0C-81C61FFAEBC3}"="AVG7 Shell Extension"
        "{9F97547E-460A-42C5-AE0C-81C61FFAEBC3}"="AVG7 Find Extension"
        "{472083B0-C522-11CF-8763-00608CC02F24}"="avast"
        "{640167b4-59b0-47a6-b335-a6b3c0695aea}"="Portable Media Devices"
        "{cc86590a-b60a-48e6-996b-41d25ed39a1e}"="Portable Media Devices Menu"
        "{E3EC3DC5-C3CC-46E6-985A-F5BF5DB95C24}"=""
        "{47E85213-3FD6-4F96-8485-D24DE7DE832D}"=""
        
        **********************************************************************************
        HKEY ROOT CLASSIDS:
        Windows Registry Editor Version 5.00
        
        [HKEY_CLASSES_ROOT\CLSID\{47E85213-3FD6-4F96-8485-D24DE7DE832D}]
        @=""
        
        [HKEY_CLASSES_ROOT\CLSID\{47E85213-3FD6-4F96-8485-D24DE7DE832D}\Implemented Categories]
        @=""
        
        [HKEY_CLASSES_ROOT\CLSID\{47E85213-3FD6-4F96-8485-D24DE7DE832D}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
        @=""
        
        [HKEY_CLASSES_ROOT\CLSID\{47E85213-3FD6-4F96-8485-D24DE7DE832D}\InprocServer32]
        @="C:\\WINDOWS\\system32\\acwav.dll"
        "ThreadingModel"="Apartment"
        
        **********************************************************************************
        Files Found are not all bad files:
        
        C:\WINDOWS\SYSTEM32\
           pndx5032.dll   Sun 27 Nov 2005  20:09:40   A....          5 632     5,50 K
           pndx5016.dll   Sun 27 Nov 2005  20:09:40   A....          6 656     6,50 K
           pncrt.dll      Sun 27 Nov 2005  20:09:36   A....        278 528   272,00 K
           rmoc3260.dll   Sun 27 Nov 2005  20:10:02   A....        176 167   172,04 K
           acwav.dll      Sun  5 Feb 2006  17:10:32   ..S.R        234 261   228,77 K
           cmdlin~1.dll   Tue 17 Jan 2006   2:19:48   A....         43 520    42,50 K
           mvp8l9~1.dll   Sun  5 Feb 2006   4:27:24   ..S.R        234 261   228,77 K
           q4680e~1.dll   Sun  5 Feb 2006  17:08:00   ..S.R        234 517   229,02 K
        
        8 items found:  8 files (3 H/S), 0 directories.
           Total of file sizes:  1 213 542 bytes      1,16 M
        Locate .tmp files:
        
        No matches found.
        **********************************************************************************
        Directory Listing of system files:
         Le volume dans le lecteur C s'appelle ACER
         Le num‚ro de s‚rie du volume est 0A2A-1AD4
        
         R‚pertoire de C:\WINDOWS\System32
        
        05/02/2006  17:10           234ÿ261 acwav.dll
        05/02/2006  17:08           234ÿ517 q4680ejueho80.dll
        05/02/2006  04:27           234ÿ261 mvp8l97u1.dll
        13/09/2004  19:30    <REP>          Microsoft
        13/09/2004  19:13    <REP>          dllcache
                       3 fichier(s)          703ÿ039 octets
                       2 R‚p(s)   9ÿ218ÿ703ÿ360 octets libres
        


        le deuxieme rapport arrive ....
        0
  2. Utilisateur anonyme
     
    Salut bigbabou, kristofer

    bigbabou, est ce que tu peux envoyer ce fichier pour analyse ici:
    http://siri.urz.free.fr/upload/
    clic sur parcourir, recherche le fichier et valide.
    C:\windows\winsysupd5.exe

    merci, a+
    0
    1. Kristopher Messages postés 3752 Statut Contributeur 106
       
      Salut mouai31 :)

      Tu penses qu'il s'agit d'une nouvelle infection ?
      C'est oui, S!RI pourra mettre SmitfraudFix à jour :)

      Bonne après midi.

      ++
      0
    2. bigbabou
       
      ayez c'est fait mais à quoi celà sert il ?

      merci qd eme pour l'aide
      0
    3. Kristopher Messages postés 3752 Statut Contributeur 106 > bigbabou
       
      Envoie le 2ème rapport.

      On va pas y passer toute la nuit...
      0
    4. bigbabou > Kristopher Messages postés 3752 Statut Contributeur
       
      désolé pour le temps de réponse mais j'ai la charge dédiée qui augmente toute seul jusqu'à 1Go ce qui bloque tout mon PC j'ai du redémarré ....
      0
    5. bigbabou > Kristopher Messages postés 3752 Statut Contributeur
       
      voilà le second log, merci encore ;)



      L2mfix 010406
      Creating Account.
      Le compte existe d‚j….

      Vous obtiendrez une aide suppl‚mentaire en entrant NET HELPMSG 2224.

      Adding Administrative privleges.
      Checking for L2MFix account(0=no 1=yes):
      1
      Granting SeDebugPrivilege to L2MFIX ... successful

      Running From:
      C:\WINDOWS\system32

      Killing Processes!

      Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
      Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org
      Killing PID 824 'smss.exe'

      Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
      Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org
      Killing PID 1096 'winlogon.exe'
      Killing PID 1096 'winlogon.exe'

      Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
      Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org
      Killing PID 680 'explorer.exe'

      Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
      Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org
      Killing PID 3972 'rundll32.exe'
      Restoring Sedebugprivilege:
      Granting SeDebugPrivilege to Administrateurs ... successful

      Scanning First Pass. Please Wait!

      First Pass Completed

      Second Pass Scanning

      Second pass Completed!
      1 fichier(s) copi‚(s).
      1 fichier(s) copi‚(s).
      1 fichier(s) copi‚(s).
      1 fichier(s) copi‚(s).
      1 fichier(s) copi‚(s).
      Deleting: C:\WINDOWS\system32\jtn2075oe.dll
      Successfully Deleted: C:\WINDOWS\system32\jtn2075oe.dll
      Deleting: C:\WINDOWS\system32\mtdex.dll
      Successfully Deleted: C:\WINDOWS\system32\mtdex.dll
      Deleting: C:\WINDOWS\system32\mvp8l97u1.dll
      Successfully Deleted: C:\WINDOWS\system32\mvp8l97u1.dll
      Deleting: C:\WINDOWS\system32\q4680ejueho80.dll
      Successfully Deleted: C:\WINDOWS\system32\q4680ejueho80.dll
      Deleting: C:\WINDOWS\system32\__delete_on_reboot__guard.tmp
      Successfully Deleted: C:\WINDOWS\system32\__delete_on_reboot__guard.tmp

      msg11?.dll
      0 fichier(s) copi‚(s).
      Desktop.ini sucessfully removed




      Restoring Windows Update Certificates.:

      The following Is the Current Export of the Winlogon notify key:
      ****************************************************************************
      Windows Registry Editor Version 5.00

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\App Management]
      "Asynchronous"=dword:00000000
      "DllName"="C:\\WINDOWS\\system32\\mvp8l97u1.dll"
      "Impersonate"=dword:00000000
      "Logon"="WinLogon"
      "Logoff"="WinLogoff"
      "Shutdown"="WinShutdown"

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
      "Asynchronous"=dword:00000000
      "Impersonate"=dword:00000000
      "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
      6c,00,00,00
      "Logoff"="ChainWlxLogoffEvent"

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
      "Asynchronous"=dword:00000000
      "Impersonate"=dword:00000000
      "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
      6c,00,6c,00,00,00
      "Logoff"="CryptnetWlxLogoffEvent"

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
      "DLLName"="cscdll.dll"
      "Logon"="WinlogonLogonEvent"
      "Logoff"="WinlogonLogoffEvent"
      "ScreenSaver"="WinlogonScreenSaverEvent"
      "Startup"="WinlogonStartupEvent"
      "Shutdown"="WinlogonShutdownEvent"
      "StartShell"="WinlogonStartShellEvent"
      "Impersonate"=dword:00000000
      "Asynchronous"=dword:00000001

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
      "DLLName"="wlnotify.dll"
      "Logon"="SCardStartCertProp"
      "Logoff"="SCardStopCertProp"
      "Lock"="SCardSuspendCertProp"
      "Unlock"="SCardResumeCertProp"
      "Enabled"=dword:00000001
      "Impersonate"=dword:00000001
      "Asynchronous"=dword:00000001

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
      "Asynchronous"=dword:00000000
      "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
      6c,00,6c,00,00,00
      "Impersonate"=dword:00000000
      "StartShell"="SchedStartShell"
      "Logoff"="SchedEventLogOff"

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
      "Logoff"="WLEventLogoff"
      "Impersonate"=dword:00000000
      "Asynchronous"=dword:00000001
      "DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
      6c,00,6c,00,00,00

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
      "DLLName"="WlNotify.dll"
      "Lock"="SensLockEvent"
      "Logon"="SensLogonEvent"
      "Logoff"="SensLogoffEvent"
      "Safe"=dword:00000001
      "MaxWait"=dword:00000258
      "StartScreenSaver"="SensStartScreenSaverEvent"
      "StopScreenSaver"="SensStopScreenSaverEvent"
      "Startup"="SensStartupEvent"
      "Shutdown"="SensShutdownEvent"
      "StartShell"="SensStartShellEvent"
      "PostShell"="SensPostShellEvent"
      "Disconnect"="SensDisconnectEvent"
      "Reconnect"="SensReconnectEvent"
      "Unlock"="SensUnlockEvent"
      "Impersonate"=dword:00000001
      "Asynchronous"=dword:00000001

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
      "Asynchronous"=dword:00000000
      "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
      6c,00,6c,00,00,00
      "Impersonate"=dword:00000000
      "Logoff"="TSEventLogoff"
      "Logon"="TSEventLogon"
      "PostShell"="TSEventPostShell"
      "Shutdown"="TSEventShutdown"
      "StartShell"="TSEventStartShell"
      "Startup"="TSEventStartup"
      "MaxWait"=dword:00000258
      "Reconnect"="TSEventReconnect"
      "Disconnect"="TSEventDisconnect"

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
      "DLLName"="wlnotify.dll"
      "Logon"="RegisterTicketExpiredNotificationEvent"
      "Logoff"="UnregisterTicketExpiredNotificationEvent"
      "Impersonate"=dword:00000001
      "Asynchronous"=dword:00000001


      The following are the files found:
      ****************************************************************************
      C:\WINDOWS\system32\jtn2075oe.dll
      C:\WINDOWS\system32\mtdex.dll
      C:\WINDOWS\system32\mvp8l97u1.dll
      C:\WINDOWS\system32\q4680ejueho80.dll
      C:\WINDOWS\system32\__delete_on_reboot__guard.tmp

      Registry Entries that were Deleted:
      Please verify that the listing looks ok.
      If there was something deleted wrongly there are backups in the backreg folder.
      ****************************************************************************
      Windows Registry Editor Version 5.00

      [HKEY_CLASSES_ROOT\CLSID\{47E85213-3FD6-4F96-8485-D24DE7DE832D}]
      @=""

      [HKEY_CLASSES_ROOT\CLSID\{47E85213-3FD6-4F96-8485-D24DE7DE832D}\Implemented Categories]
      @=""

      [HKEY_CLASSES_ROOT\CLSID\{47E85213-3FD6-4F96-8485-D24DE7DE832D}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
      @=""

      [HKEY_CLASSES_ROOT\CLSID\{47E85213-3FD6-4F96-8485-D24DE7DE832D}\InprocServer32]
      @="C:\\WINDOWS\\system32\\mtdex.dll"
      "ThreadingModel"="Apartment"

      REGEDIT4

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
      "{E3EC3DC5-C3CC-46E6-985A-F5BF5DB95C24}"=-
      "{47E85213-3FD6-4F96-8485-D24DE7DE832D}"=-
      [-HKEY_CLASSES_ROOT\CLSID\{E3EC3DC5-C3CC-46E6-985A-F5BF5DB95C24}]
      [-HKEY_CLASSES_ROOT\CLSID\{47E85213-3FD6-4F96-8485-D24DE7DE832D}]
      REGEDIT4

      [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
      "SV1"=""
      ****************************************************************************
      Desktop.ini Contents:
      ****************************************************************************
      [.ShellClassInfo]
      CLSID={645FF040-5081-101B-9F08-00AA002F954E}
      ****************************************************************************
      Checking for L2MFix account(0=no 1=yes):
      0
      Zipping up files for submission:
      adding: dlls/jtn2075oe.dll (deflated 4%)
      adding: dlls/mtdex.dll (deflated 4%)
      adding: dlls/mvp8l97u1.dll (deflated 4%)
      adding: dlls/q4680ejueho80.dll (deflated 4%)
      adding: dlls/__delete_on_reboot__guard.tmp (deflated 4%)
      adding: backregs/notibac.reg (deflated 87%)
      adding: backregs/shell.reg (deflated 73%)
      adding: backregs/47E85213-3FD6-4F96-8485-D24DE7DE832D.reg (deflated 70%)
      0
  3. Utilisateur anonyme
     
    lol, dsl Kristopher

    C'est fort possible, je sais que S!ri recherche ce type de fichiers pour analyse, on verra à la nouvelle update du fix s'il s'agissait bien de cela.

    a++
    0
  4. Kristopher Messages postés 3752 Statut Contributeur 106
     
    Re,

    T'es toujours infecté :(

    Coche et fixe ces 2 lignes avec HijackThis :

    O20 - Winlogon Notify: App Management - C:\WINDOWS\system32\mvp8l97u1.dll (file missing)
    O21 - SSODL: DCOM Server - {2C1CD3D7-86AC-4068-93BC-A02304BB8C34} - (no file)

    Puis,

    - Télécharger le logiciel SmitfraudFix :
    http://siri.urz.free.fr/Fix/SmitfraudFix.zip et décompresse le.

    - Exécute le, Double clic sur "Smitfraudfix.cmd", choisit l’option 1, il va générer un rapport.

    Copie et colle le sur le forum.

    Ensuite

    Fais cette manipulation :

    - Redémarre le PC en mode sans échec : tu tapotes sur la touche F8 de ton clavier (ou bien F5 selon la version de Windows) et tu choisis le mode sans échec)

    - Tu relances SmitfraudFix cette fois-ci en choisissant l'option 2 et tu réponds oui à tout.

    Colle le nouveau rapport ensuite.

    ++
    0
    1. bigbabou Messages postés 8 Statut Membre
       
      re et merci beaucoup pour le temps que tu consacre a mon probleme...

      donc voilà le rapport de smitFraudFix

      SmitFraudFix v2.16

      Rapport fait à 18:50:14,85 le 05/02/2006
      Executé à partir de G:\program Files\smitfraud\SmitfraudFix
      OS: Microsoft Windows XP [version 5.1.2600]

      »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\


      »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS

      C:\WINDOWS\secure32.html PRESENT !

      »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS\system


      »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS\Web


      »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS\system32


      »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\Documents and Settings\Bigabou\Application Data

      C:\Documents and Settings\Bigabou\Application Data\Install.dat PRESENT !

      »»»»»»»»»»»»»»»»»»»»»»»» Recherche Menu Démarrer


      »»»»»»»»»»»»»»»»»»»»»»»» Recherche Bureau


      »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\Program Files

      C:\Program Files\SpySheriff\ PRESENT!

      »»»»»»»»»»»»»»»»»»»»»»»» Recherche présence de clés corrompues


      »»»»»»»»»»»»»»»»»»»»»»»» Recherche éléments du bureau

      [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
      "Source"="About:Home"
      "SubscribedURL"="About:Home"
      "FriendlyName"="Ma page d'accueil"


      »»»»»»»»»»»»»»»»»»»»»»»» Recherche Sharedtaskscheduler

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
      "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Pr‚-chargeur Browseui"
      "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="D‚mon de cache des cat‚gories de composant"
      "{2C1CD3D7-86AC-4068-93BC-A02304BB8C34}"="DCOM Server"

      »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll


      »»»»»»»»»»»»»»»»»»»»»»»» Fin du rapport


      merci encore
      0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. bigbabou Messages postés 8 Statut Membre
     
    voilà le rapport en mode sans echec, merci

    SmitFraudFix v2.16

    Rapport fait à 19:00:36,15 le 05/02/2006
    Executé à partir de D:\#download\logiciel\SmitfraudFix
    OS: Microsoft Windows XP [version 5.1.2600]

    »»»»»»»»»»»»»»»»»»»»»»»» Arret des processus

    »»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés

    C:\WINDOWS\secure32.html supprimé
    C:\Documents and Settings\Bigabou\Application Data\Install.dat supprimé
    C:\Program Files\SpySheriff\ supprimé

    »»»»»»»»»»»»»»»»»»»»»»»» Nettoyage Fichiers Temporaires

    »»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre

    Nettoyage terminé.

    »»»»»»»»»»»»»»»»»»»»»»»» Fin du rapport
    0
  7. bigbabou Messages postés 8 Statut Membre
     
    re bonjour

    bah ça réglé tout ce qui est spyware et page qui s'affichait dans mon navigateur.

    mais j'ai encore eu une infection signalé par AVG de gaelicum.A .... :(
    existe t-il encore une solution pour résoudre mon probleme ??

    merci encore pour ton aide.
    0
    1. Kristopher Messages postés 3752 Statut Contributeur 106
       
      Salut bigbabou,

      Soit plus explicite stp.

      mais j'ai encore eu une infection signalé par AVG de gaelicum.A .... :(

      -> Quel fichier est contaminé ?
      -> Reposte un nouveau log HijackThis stp.

      ++
      0
  8. bigbabou Messages postés 8 Statut Membre
     
    désolé j'aipas noté le fichier infecté je crois que c'était un truc du genre E_FATI mais je sais plus l'extension...
    je noterai les noms la prochaine fois

    Sinon j'ai un probleme qui est apparut c'est que au bout de 20 min d'utilisation lapres un reboot la charge dédiée augmente et passe à 1Go ce qui fait tout ramer et je suis bon pour un reboot

    sinon voilà le rapport hijack this :

    Logfile of HijackThis v1.99.1
    Scan saved at 20:14:57, on 05/02/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\Launch Manager\LaunchAp.exe
    C:\Program Files\Launch Manager\PowerKey.exe
    C:\Program Files\Launch Manager\HotkeyApp.exe
    C:\Program Files\Launch Manager\CtrlVol.exe
    C:\Program Files\Launch Manager\OSDCtrl.exe
    C:\Program Files\Launch Manager\Wbutton.exe
    C:\WINDOWS\system32\VTTimer.exe
    C:\WINDOWS\AGRSMMSG.exe
    C:\Program Files\Java\jre1.5.0\bin\jusched.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9EE.EXE
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
    C:\Program Files\SuperCopier2\SuperCopier2.exe
    C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    C:\Acer\eManager\anbmServ.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
    C:\Program Files\ewido anti-malware\ewidoctrl.exe
    C:\Program Files\ewido anti-malware\ewidoguard.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\wdfmgr.exe
    C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
    C:\WINDOWS\system32\msiexec.exe
    C:\WINDOWS\System32\alg.exe
    C:\DOCUME~1\Bigabou\LOCALS~1\Temp\Rar$EX00.547\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://global.acer.com/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    O2 - BHO: (no name) - {206E52E0-D52E-11D4-AD54-0000E86C26F6} - C:\PROGRA~1\FRESHD~1\FRESHD~1\fdcatch.dll
    O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
    O3 - Toolbar: ToolbarBrowser - {71AAABE5-1F0F-11d7-BD6F-004854603DCE} - C:\Program Files\TRELLIAN\Toolbar\toolbar.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - G:\system_works_2002\Norton AntiVirus\NavShExt.dll (file missing)
    O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [LaunchAp] C:\Program Files\Launch Manager\LaunchAp.exe
    O4 - HKLM\..\Run: [PowerKey] "C:\Program Files\Launch Manager\PowerKey.exe"
    O4 - HKLM\..\Run: [LManager] C:\Program Files\Launch Manager\HotkeyApp.exe
    O4 - HKLM\..\Run: [CtrlVol] C:\Program Files\Launch Manager\CtrlVol.exe
    O4 - HKLM\..\Run: [LMgrOSD] C:\Program Files\Launch Manager\OSDCtrl.exe
    O4 - HKLM\..\Run: [Wbutton] "C:\Program Files\Launch Manager\Wbutton.exe"
    O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
    O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0\bin\jusched.exe
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [EPSON Stylus CX6600 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9EE.EXE /P26 "EPSON Stylus CX6600 Series" /O6 "USB001" /M "Stylus CX6600"
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [NAV Agent] G:\SYSTEM~2\NORTON~1\navapw32.exe
    O4 - HKCU\..\Run: [SuperCopier2.exe] C:\Program Files\SuperCopier2\SuperCopier2.exe
    O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O17 - HKLM\System\CCS\Services\Tcpip\..\{4D22EABD-2355-4762-895B-6FBF90FA5293}: NameServer = 80.118.196.41 80.118.192.111
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
    O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
    O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
    O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
    O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
    O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Fichiers communs\Macromedia Shared\Service\Macromedia Licensing.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
    0
    1. Kristopher Messages postés 3752 Statut Contributeur 106
       
      Re,

      Je te conseille de changer d'antivirus parce que AVG est loin d'être performant...

      - Télécharge Avast! : http://www.avast.com/
      Tutorial là : http://www.pcentraide.com/index.php?showtopic=120

      /!\ Important /!\

      D'abord télécharge Avast, ensuite attend de recevoir ta clé d'activation.
      Une fois cela, désinstalle AVG et scanne ton PC avec Avast.
      Puis copie/colle le rapport si tu veux, je vais essayer de te donner un coup de main :)

      ++
      0
    2. bigbabou Messages postés 8 Statut Membre > Kristopher Messages postés 3752 Statut Contributeur
       
      ouais c'est ce que je commençais à me dire aussi...

      merci en tout cas pour le coup de main j'installe tout ça et je mettrai le rapport d'avast quand ça sera fini

      merci encore
      0
    3. Kristopher Messages postés 3752 Statut Contributeur 106 > Kristopher Messages postés 3752 Statut Contributeur
       
      Ok ça marche :)

      Reviens dès que tu auars fait tes devoirs :D

      Bon courage :)

      ++
      0
    4. bigbabou Messages postés 8 Statut Membre > Kristopher Messages postés 3752 Statut Contributeur
       
      ayez !!

      bon il m'a trouvé 16 virus j'ai Ignorés les fichiers dans le repertoire windows et les autres je les ai mis en quarantaine....

      donc voilà le rapport avast


      05/02/2006 20:39
      Analyse de tous les lecteurs locaux
      Fichier C:\WINDOWS\system32\ActiveScan\pskavs.dll est infecté par Win32:CTX, Réparer: Erreur 42060 {Le fichier n'a pas été réparé.}, Réparer: Erreur 42060 {Le fichier n'a pas été réparé.}
      Fichier C:\System Volume Information\_restore{A65CAB81-8F87-4280-8ABC-C81056D754CC}\RP218\A0064475.EXE\[Yoda] est infecté par Win32:Ircbot-LH [Trj], Supprimé
      Fichier C:\System Volume Information\_restore{A65CAB81-8F87-4280-8ABC-C81056D754CC}\RP220\A0065463.dll est infecté par Win32:Adware-gen. [Adw], Réparer: Erreur 42060 {Le fichier n'a pas été réparé.}, Supprimé
      Fichier C:\System Volume Information\_restore{A65CAB81-8F87-4280-8ABC-C81056D754CC}\RP223\A0065517.dll est infecté par Win32:Adware-gen. [Adw], Supprimé
      Fichier C:\System Volume Information\_restore{A65CAB81-8F87-4280-8ABC-C81056D754CC}\RP225\A0065659.dll est infecté par Win32:Adware-gen. [Adw], Mis en quarantaine
      Fichier C:\System Volume Information\_restore{A65CAB81-8F87-4280-8ABC-C81056D754CC}\RP230\A0067702.dll est infecté par Win32:Adware-gen. [Adw], Mis en quarantaine
      Fichier C:\System Volume Information\_restore{A65CAB81-8F87-4280-8ABC-C81056D754CC}\RP230\A0067703.dll est infecté par Win32:Adware-gen. [Adw], Mis en quarantaine
      Fichier C:\System Volume Information\_restore{A65CAB81-8F87-4280-8ABC-C81056D754CC}\RP230\A0067704.dll est infecté par Win32:Adware-gen. [Adw], Mis en quarantaine
      Fichier C:\System Volume Information\_restore{A65CAB81-8F87-4280-8ABC-C81056D754CC}\RP235\A0068782.dll est infecté par Win32:Adware-gen. [Adw], Mis en quarantaine
      Fichier C:\System Volume Information\_restore{A65CAB81-8F87-4280-8ABC-C81056D754CC}\RP235\A0068913.DLL est infecté par Win32:Adware-gen. [Adw], Mis en quarantaine
      Fichier C:\System Volume Information\_restore{A65CAB81-8F87-4280-8ABC-C81056D754CC}\RP235\A0068914.dll est infecté par Win32:Trojano-3384 [Trj], Mis en quarantaine
      Fichier C:\System Volume Information\_restore{A65CAB81-8F87-4280-8ABC-C81056D754CC}\RP235\A0068927.EXE est infecté par Win32:Adware-gen. [Adw], Mis en quarantaine
      Fichier C:\System Volume Information\_restore{A65CAB81-8F87-4280-8ABC-C81056D754CC}\RP235\A0068931.dll est infecté par Win32:Adware-gen. [Adw], Mis en quarantaine
      Fichier C:\System Volume Information\_restore{A65CAB81-8F87-4280-8ABC-C81056D754CC}\RP235\A0069943.dll est infecté par Win32:Adware-gen. [Adw], Mis en quarantaine
      Fichier C:\System Volume Information\_restore{A65CAB81-8F87-4280-8ABC-C81056D754CC}\RP235\A0069952.dll est infecté par Win32:Adware-gen. [Adw], Mis en quarantaine
      Fichier C:\System Volume Information\_restore{A65CAB81-8F87-4280-8ABC-C81056D754CC}\RP235\A0070034.EXE est infecté par Win32:Tenga, Mis en quarantaine
      Fichier C:\hiberfil.sys Erreur 0xC0000022 {Accès refusé}
      Fichier C:\Sysinfo\WORKS70\COMMON\APERþu.WSB Erreur 0xC0000034 {Nom d'objet introuvable.}

      Nombre de dossiers parcourus : 12762
      Nombre de fichiers analysés : 142357
      Nombre de fichiers infectés : 16


      merci pour ta patience
      0
    5. Kristopher Messages postés 3752 Statut Contributeur 106 > bigbabou Messages postés 8 Statut Membre
       
      ok tu peux tranquillement vider la quarantaine

      Après crée juste un nouveau point de restauration

      ++
      0