Virus et trojan aide pour les enlever
k25
Messages postés
8
Statut
Membre
-
Utilisateur anonyme -
Utilisateur anonyme -
Bonjour tout le monde,j'écrit ce message dans l'epoir que vous m'apportiez de l'aide.Je trouvais que mon ordi etait tres lent depuis un moment donc j'ai fait un scan en ligne avec Kapersky et il ma indiqué que mon PC etait infecté.Je suis donc venu sur le forum chercher des info pour essayer d'enlever ces trojans(ou virus??) et g telecharger hijackthis mais je ne possede pas les connaissance me permettant de comprendre le log.Je precise que je suis debutant et que je n'y connait rien au methodes pour enlever virus ou autre.
J'espere que kelkun pourra maider.
Configuration:Windows Xp sp2
j utilise avast v4.6, zone alarm 6.1,a-squared,Ad-aware SE,microsoft antispyware
voici le log fé avec hijackthis:
Logfile of HijackThis v1.99.1
Scan saved at 13:18:41, on 09/04/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\slrundll.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINDOWS\system32\ctfmon.exe
c:\progra~1\intern~1\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\BitTorrent\btdownloadgui.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\CARREF~1\LOCALS~1\Temp\Rar$EX02.375\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.agfqdplmpeictvhj.com/6knTq4xm/a2VWHBzzoY/Fbs2rZfQJZS06rnYYXb6HfJcif/Sm...
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - c:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.02.3000.1002\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\fr\msntb.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\fr\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [Watch] C:\PROGRA~1\Minitel\Watch.exe
O4 - HKLM\..\Run: [URLLSTCK.exe] C:\Program Files\Norton Internet Security Professional\UrlLstCk.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [emkbnxsq] C:\WINDOWS\system32\pohvrswl.exe
O4 - HKLM\..\Run: [ScanRegistry] C:\W
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKCU\..\Run: [MoneyAgent] "c:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [logo warn] C:\DOCUME~1\CARREF~1\APPLIC~1\TRUSTS~1\Globalremote.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Registry Cleaner] "C:\Program Files\Registry Cleaner Trial\regclean.exe"
O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\Xfire.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZN
O8 - Extra context menu item: Ouvrir avec GetRight - C:\Program Files\GetRight\GRbrowse.htm
O8 - Extra context menu item: Télecharger avec GetRight - C:\Program Files\GetRight\GRdownload.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {09C21411-B9A2-4DE6-8416-4E3B58577BE0} (France Telecom MDM ActiveX Control) - http://minitelweb.minitel.com/imin_data/ocx/MDM.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/downloads/kws/kavwebscan_unicode.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab
O16 - DPF: {45E83043-1F6F-4D22-A5E7-0138EA171B49} (FileSharingCtrl Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/FileSharing/fr/fileshar...
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - https://onedrive.live.com/
O16 - DPF: {54B52E52-8000-4413-BD67-FC7FE24B59F2} (EARTPatchX Class) - http://files.ea.com/downloads/rtpatch/v2/EARTPX.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) - https://www.zonealarm.com/
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://194.206.235.69:23000/activex/AxisCamControl.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab
O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} (Yahoo! Toolbar) - http://us.dl1.yimg.com/download.companion.yahoo.com/dl/toolbar/yiebio5_1_6_0.cab
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by109fd.bay109.hotmail.msn.com/activex/HMAtchmt.ocx
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: SymWMI Service (SymWSC) - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Merci
J'espere que kelkun pourra maider.
Configuration:Windows Xp sp2
j utilise avast v4.6, zone alarm 6.1,a-squared,Ad-aware SE,microsoft antispyware
voici le log fé avec hijackthis:
Logfile of HijackThis v1.99.1
Scan saved at 13:18:41, on 09/04/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\slrundll.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINDOWS\system32\ctfmon.exe
c:\progra~1\intern~1\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\BitTorrent\btdownloadgui.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\CARREF~1\LOCALS~1\Temp\Rar$EX02.375\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.agfqdplmpeictvhj.com/6knTq4xm/a2VWHBzzoY/Fbs2rZfQJZS06rnYYXb6HfJcif/Sm...
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - c:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.02.3000.1002\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\fr\msntb.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\fr\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [Watch] C:\PROGRA~1\Minitel\Watch.exe
O4 - HKLM\..\Run: [URLLSTCK.exe] C:\Program Files\Norton Internet Security Professional\UrlLstCk.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [emkbnxsq] C:\WINDOWS\system32\pohvrswl.exe
O4 - HKLM\..\Run: [ScanRegistry] C:\W
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKCU\..\Run: [MoneyAgent] "c:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [logo warn] C:\DOCUME~1\CARREF~1\APPLIC~1\TRUSTS~1\Globalremote.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Registry Cleaner] "C:\Program Files\Registry Cleaner Trial\regclean.exe"
O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\Xfire.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZN
O8 - Extra context menu item: Ouvrir avec GetRight - C:\Program Files\GetRight\GRbrowse.htm
O8 - Extra context menu item: Télecharger avec GetRight - C:\Program Files\GetRight\GRdownload.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {09C21411-B9A2-4DE6-8416-4E3B58577BE0} (France Telecom MDM ActiveX Control) - http://minitelweb.minitel.com/imin_data/ocx/MDM.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/downloads/kws/kavwebscan_unicode.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab
O16 - DPF: {45E83043-1F6F-4D22-A5E7-0138EA171B49} (FileSharingCtrl Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/FileSharing/fr/fileshar...
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - https://onedrive.live.com/
O16 - DPF: {54B52E52-8000-4413-BD67-FC7FE24B59F2} (EARTPatchX Class) - http://files.ea.com/downloads/rtpatch/v2/EARTPX.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) - https://www.zonealarm.com/
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://194.206.235.69:23000/activex/AxisCamControl.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab
O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} (Yahoo! Toolbar) - http://us.dl1.yimg.com/download.companion.yahoo.com/dl/toolbar/yiebio5_1_6_0.cab
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by109fd.bay109.hotmail.msn.com/activex/HMAtchmt.ocx
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: SymWMI Service (SymWSC) - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Merci
A voir également:
- Virus et trojan aide pour les enlever
- Enlever pub youtube - Accueil - Streaming
- Virus mcafee - Accueil - Piratage
- Enlever notification whatsapp pour une personne - Guide
- Enlever les commentaires sur word - Guide
- Trojan remover - Télécharger - Antivirus & Antimalwares
3 réponses
Salut,
Relance HijackThis, choisis " do a scan only" coche la case devant les lignes ci-dessous et clique en bas sur "fix checked"
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [Watch] C:\PROGRA~1\Minitel\Watch.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [emkbnxsq] C:\WINDOWS\system32\pohvrswl.exe
O4 - HKLM\..\Run: [ScanRegistry] C:\W
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKCU\..\Run: [MoneyAgent] "c:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [logo warn] C:\DOCUME~1\CARREF~1\APPLIC~1\TRUSTS~1\Globalremote.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Registry Cleaner] "C:\Program Files\Registry Cleaner Trial\regclean.exe"
O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
O4 - Global Startup: Adobe Gamma Loader.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZN
O8 - Extra context menu item: Ouvrir avec GetRight - C:\Program Files\GetRight\GRbrowse.htm
O8 - Extra context menu item: Télecharger avec GetRight - C:\Program Files\GetRight\GRdownload.htm
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {09C21411-B9A2-4DE6-8416-4E3B58577BE0} (France Telecom MDM ActiveX Control) - http://minitelweb.minitel.com/imin_data/ocx/MDM.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/downloads/kws/kavwebscan_unicode.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab
O16 - DPF: {45E83043-1F6F-4D22-A5E7-0138EA171B49} (FileSharingCtrl Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/FileSharing/fr/fileshar...
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - https://onedrive.live.com/
O16 - DPF: {54B52E52-8000-4413-BD67-FC7FE24B59F2} (EARTPatchX Class) - http://files.ea.com/downloads/rtpatch/v2/EARTPX.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) - https://www.zonealarm.com/
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://194.206.235.69:23000/activex/AxisCamControl.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab
O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} (Yahoo! Toolbar) - http://us.dl1.yimg.com/download.companion.yahoo.com/dl/toolbar/yiebio5_1_6_0.cab
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by109fd.bay109.hotmail.msn.com/activex/HMAtchmt.ocx
1.Fais ceci:
Affiche tous les fichiers et dossiers :
Clique sur démarrer, panneau de configuration, outils ,option des dossiers, affichage
Coche: afficher les fichiers et dossiers cachés
Appliquer, puis ok
*Cliques sur demarrer, poste de travail, C:, documents and settings, all users, application data, cherches et supprimes ce dossier:
RUSTS..< commencer par RUSTS
-si un fichier persiste lors de la suppression fais ceci:
-Redemarres ton pc, dès l'allumage de celui ci tapotes la touche f8, à l'ecran qui va apparaitre choisis "mode sans echec" attends un peu.. puis vas supprimer les fichiers/dossiers, vides ta corbeille et redemarres normalement
2.Cliques sur demarrer, rechercher, cherches et supprimes ce fichier:
pohvrswl.exe
3.Fais ce scan anti-virus en ligne et colles le rapport ici une fois qu'il a finit avec un nouveau rapport hijackthis
https://www.bitdefender.com/toolbox/
A++
Relance HijackThis, choisis " do a scan only" coche la case devant les lignes ci-dessous et clique en bas sur "fix checked"
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [Watch] C:\PROGRA~1\Minitel\Watch.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [emkbnxsq] C:\WINDOWS\system32\pohvrswl.exe
O4 - HKLM\..\Run: [ScanRegistry] C:\W
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKCU\..\Run: [MoneyAgent] "c:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [logo warn] C:\DOCUME~1\CARREF~1\APPLIC~1\TRUSTS~1\Globalremote.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Registry Cleaner] "C:\Program Files\Registry Cleaner Trial\regclean.exe"
O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
O4 - Global Startup: Adobe Gamma Loader.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZN
O8 - Extra context menu item: Ouvrir avec GetRight - C:\Program Files\GetRight\GRbrowse.htm
O8 - Extra context menu item: Télecharger avec GetRight - C:\Program Files\GetRight\GRdownload.htm
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {09C21411-B9A2-4DE6-8416-4E3B58577BE0} (France Telecom MDM ActiveX Control) - http://minitelweb.minitel.com/imin_data/ocx/MDM.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/downloads/kws/kavwebscan_unicode.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab
O16 - DPF: {45E83043-1F6F-4D22-A5E7-0138EA171B49} (FileSharingCtrl Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/FileSharing/fr/fileshar...
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - https://onedrive.live.com/
O16 - DPF: {54B52E52-8000-4413-BD67-FC7FE24B59F2} (EARTPatchX Class) - http://files.ea.com/downloads/rtpatch/v2/EARTPX.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) - https://www.zonealarm.com/
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://194.206.235.69:23000/activex/AxisCamControl.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab
O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} (Yahoo! Toolbar) - http://us.dl1.yimg.com/download.companion.yahoo.com/dl/toolbar/yiebio5_1_6_0.cab
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by109fd.bay109.hotmail.msn.com/activex/HMAtchmt.ocx
1.Fais ceci:
Affiche tous les fichiers et dossiers :
Clique sur démarrer, panneau de configuration, outils ,option des dossiers, affichage
Coche: afficher les fichiers et dossiers cachés
Appliquer, puis ok
*Cliques sur demarrer, poste de travail, C:, documents and settings, all users, application data, cherches et supprimes ce dossier:
RUSTS..< commencer par RUSTS
-si un fichier persiste lors de la suppression fais ceci:
-Redemarres ton pc, dès l'allumage de celui ci tapotes la touche f8, à l'ecran qui va apparaitre choisis "mode sans echec" attends un peu.. puis vas supprimer les fichiers/dossiers, vides ta corbeille et redemarres normalement
2.Cliques sur demarrer, rechercher, cherches et supprimes ce fichier:
pohvrswl.exe
3.Fais ce scan anti-virus en ligne et colles le rapport ici une fois qu'il a finit avec un nouveau rapport hijackthis
https://www.bitdefender.com/toolbox/
A++
Scanned File
Status
C:\Documents and Settings\All Users\Application Data\Compsurfgrimburn\Aboutinside.exe
Infected with: Trojan.Downloader.Swizzor.DE
C:\Documents and Settings\All Users\Application Data\Compsurfgrimburn\Aboutinside.exe
Disinfection failed
C:\Documents and Settings\All Users\Application Data\Compsurfgrimburn\Aboutinside.exe
Deleted
C:\Documents and Settings\All Users\Application Data\Compsurfgrimburn\anti save.exe
Infected with: Trojan.Downloader.Swizzor.DE
C:\Documents and Settings\All Users\Application Data\Compsurfgrimburn\anti save.exe
Disinfection failed
C:\Documents and Settings\All Users\Application Data\Compsurfgrimburn\anti save.exe
Deleted
C:\Documents and Settings\All Users\Application Data\Compsurfgrimburn\blueamen.exe
Infected with: Trojan.Swizzor.BA
C:\Documents and Settings\All Users\Application Data\Compsurfgrimburn\blueamen.exe
Disinfection failed
C:\Documents and Settings\All Users\Application Data\Compsurfgrimburn\blueamen.exe
Deleted
C:\Documents and Settings\All Users\Application Data\Compsurfgrimburn\copy cake.exe
Infected with: Trojan.Downloader.Swizzor.DV
C:\Documents and Settings\All Users\Application Data\Compsurfgrimburn\copy cake.exe
Deleted
C:\Documents and Settings\All Users\Application Data\Compsurfgrimburn\Dvd Jump.exe
Infected with: Trojan.Swizzor.AX
C:\Documents and Settings\All Users\Application Data\Compsurfgrimburn\Dvd Jump.exe
Disinfection failed
C:\Documents and Settings\All Users\Application Data\Compsurfgrimburn\Dvd Jump.exe
Deleted
C:\Documents and Settings\All Users\Application Data\Compsurfgrimburn\eqcake.exe
Infected with: Trojan.Swizzor.BA
C:\Documents and Settings\All Users\Application Data\Compsurfgrimburn\eqcake.exe
Disinfection failed
C:\Documents and Settings\All Users\Application Data\Compsurfgrimburn\eqcake.exe
Deleted
C:\Documents and Settings\All Users\Application Data\Compsurfgrimburn\five mapi.exe
Infected with: Trojan.Swizzor.AX
C:\Documents and Settings\All Users\Application Data\Compsurfgrimburn\five mapi.exe
Disinfection failed
C:\Documents and Settings\All Users\Application Data\Compsurfgrimburn\five mapi.exe
Deleted
C:\Documents and Settings\All Users\Application Data\Compsurfgrimburn\grid heck.exe
Infected with: Trojan.Downloader.Swizzor.DV
C:\Documents and Settings\All Users\Application Data\Compsurfgrimburn\grid heck.exe
Deleted
C:\Documents and Settings\All Users\Application Data\Compsurfgrimburn\Joysettings.exe
Infected with: Trojan.Downloader.Swizzor.DF
C:\Documents and Settings\All Users\Application Data\Compsurfgrimburn\Joysettings.exe
Disinfection failed
C:\Documents and Settings\All Users\Application Data\Compsurfgrimburn\Joysettings.exe
Deleted
C:\Documents and Settings\All Users\Application Data\Compsurfgrimburn\live trust.exe
Infected with: Trojan.Downloader.Swizzor.DE
C:\Documents and Settings\All Users\Application Data\Compsurfgrimburn\live trust.exe
Disinfection failed
C:\Documents and Settings\All Users\Application Data\Compsurfgrimburn\live trust.exe
Deleted
C:\Documents and Settings\All Users\Application Data\Compsurfgrimburn\mapishim.exe
Infected with: Trojan.Downloader.Swizzor.DV
C:\Documents and Settings\All Users\Application Data\Compsurfgrimburn\mapishim.exe
Deleted
C:\Documents and Settings\All Users\Application Data\Compsurfgrimburn\memo exit.exe
Infected with: Trojan.Swizzor.AX
C:\Documents and Settings\All Users\Application Data\Compsurfgrimburn\memo exit.exe
Disinfection failed
C:\Documents and Settings\All Users\Application Data\Compsurfgrimburn\memo exit.exe
Deleted
C:\Documents and Settings\All Users\Application Data\Compsurfgrimburn\Nurb loud.exe
Infected with: Trojan.Swizzor.AX
C:\Documents and Settings\All Users\Application Data\Compsurfgrimburn\Nurb loud.exe
Disinfection failed
C:\Documents and Settings\All Users\Application Data\Compsurfgrimburn\Nurb loud.exe
Deleted
C:\Documents and Settings\All Users\Application Data\Compsurfgrimburn\README HEART.exe
Infected with: Trojan.Swizzor.AX
C:\Documents and Settings\All Users\Application Data\Compsurfgrimburn\README HEART.exe
Disinfection failed
C:\Documents and Settings\All Users\Application Data\Compsurfgrimburn\README HEART.exe
Deleted
C:\Documents and Settings\All Users\Application Data\Compsurfgrimburn\SectByte.exe
Infected with: Trojan.Downloader.Swizzor.DE
C:\Documents and Settings\All Users\Application Data\Compsurfgrimburn\SectByte.exe
Disinfection failed
C:\Documents and Settings\All Users\Application Data\Compsurfgrimburn\SectByte.exe
Deleted
C:\Documents and Settings\All Users\Application Data\Compsurfgrimburn\Supportdash.exe
Infected with: Trojan.Downloader.Swizzor.DF
C:\Documents and Settings\All Users\Application Data\Compsurfgrimburn\Supportdash.exe
Disinfection failed
C:\Documents and Settings\All Users\Application Data\Compsurfgrimburn\Supportdash.exe
Deleted
C:\Documents and Settings\carrefour\Application Data\trust software\acjmewor.exe
Infected with: Trojan.Swizzor.AX
C:\Documents and Settings\carrefour\Application Data\trust software\acjmewor.exe
Disinfection failed
C:\Documents and Settings\carrefour\Application Data\trust software\acjmewor.exe
Deleted
C:\Documents and Settings\carrefour\Application Data\trust software\clclbtio.exe
Infected with: Trojan.Downloader.Swizzor.DF
C:\Documents and Settings\carrefour\Application Data\trust software\clclbtio.exe
Disinfection failed
C:\Documents and Settings\carrefour\Application Data\trust software\clclbtio.exe
Deleted
C:\Documents and Settings\carrefour\Application Data\trust software\Comp pop setup.exe
Infected with: Trojan.Swizzor.DH
C:\Documents and Settings\carrefour\Application Data\trust software\Comp pop setup.exe
Disinfection failed
C:\Documents and Settings\carrefour\Application Data\trust software\Comp pop setup.exe
Deleted
C:\Documents and Settings\carrefour\Application Data\trust software\dtszyvij.exe
Infected with: Trojan.Downloader.Swizzor.DI
C:\Documents and Settings\carrefour\Application Data\trust software\dtszyvij.exe
Disinfection failed
C:\Documents and Settings\carrefour\Application Data\trust software\dtszyvij.exe
Deleted
C:\Documents and Settings\carrefour\Application Data\trust software\gdkdmfom.exe
Infected with: Trojan.Swizzor.DH
C:\Documents and Settings\carrefour\Application Data\trust software\gdkdmfom.exe
Disinfection failed
C:\Documents and Settings\carrefour\Application Data\trust software\gdkdmfom.exe
Deleted
C:\Documents and Settings\carrefour\Application Data\trust software\gtklrgna.exe
Infected with: Trojan.Downloader.Swizzor.DI
C:\Documents and Settings\carrefour\Application Data\trust software\gtklrgna.exe
Disinfection failed
C:\Documents and Settings\carrefour\Application Data\trust software\gtklrgna.exe
Deleted
C:\Documents and Settings\carrefour\Application Data\trust software\juzuxpbo.exe
Infected with: Trojan.Downloader.Swizzor.DF
C:\Documents and Settings\carrefour\Application Data\trust software\juzuxpbo.exe
Disinfection failed
C:\Documents and Settings\carrefour\Application Data\trust software\juzuxpbo.exe
Deleted
C:\Documents and Settings\carrefour\Application Data\trust software\mpnszcan.exe
Infected with: Trojan.Downloader.Swizzor.DE
C:\Documents and Settings\carrefour\Application Data\trust software\mpnszcan.exe
Disinfection failed
C:\Documents and Settings\carrefour\Application Data\trust software\mpnszcan.exe
Deleted
C:\Documents and Settings\carrefour\Application Data\trust software\palmlxwb.exe
Infected with: Trojan.Downloader.Swizzor.DH
C:\Documents and Settings\carrefour\Application Data\trust software\palmlxwb.exe
Disinfection failed
C:\Documents and Settings\carrefour\Application Data\trust software\palmlxwb.exe
Deleted
C:\Documents and Settings\carrefour\Application Data\trust software\Ping Delete Itch Beep.exe
Infected with: Trojan.Swizzor.DH
C:\Documents and Settings\carrefour\Application Data\trust software\Ping Delete Itch Beep.exe
Disinfection failed
C:\Documents and Settings\carrefour\Application Data\trust software\Ping Delete Itch Beep.exe
Deleted
C:\Documents and Settings\carrefour\Application Data\trust software\qhwknugn.exe
Infected with: Trojan.Swizzor.AX
C:\Documents and Settings\carrefour\Application Data\trust software\qhwknugn.exe
Disinfection failed
C:\Documents and Settings\carrefour\Application Data\trust software\qhwknugn.exe
Deleted
C:\Documents and Settings\carrefour\Application Data\trust software\qptgmsod.exe
Infected with: Trojan.Downloader.Swizzor.DJ
C:\Documents and Settings\carrefour\Application Data\trust software\qptgmsod.exe
Disinfection failed
C:\Documents and Settings\carrefour\Application Data\trust software\qptgmsod.exe
Deleted
C:\Documents and Settings\carrefour\Application Data\trust software\vpyddcni.exe
Infected with: Trojan.Downloader.Swizzor.DE
C:\Documents and Settings\carrefour\Application Data\trust software\vpyddcni.exe
Disinfection failed
C:\Documents and Settings\carrefour\Application Data\trust software\vpyddcni.exe
Deleted
C:\Documents and Settings\carrefour\Application Data\trust software\vthmumex.exe
Infected with: Trojan.Downloader.Swizzor.DV
C:\Documents and Settings\carrefour\Application Data\trust software\vthmumex.exe
Deleted
C:\Documents and Settings\carrefour\Application Data\trust software\wdbnfqah.exe
Infected with: Trojan.Downloader.Swizzor.DV
C:\Documents and Settings\carrefour\Application Data\trust software\wdbnfqah.exe
Deleted
C:\Documents and Settings\carrefour\Application Data\trust software\wmpdmyhe.exe
Infected with: Trojan.Swizzor.BA
C:\Documents and Settings\carrefour\Application Data\trust software\wmpdmyhe.exe
Disinfection failed
C:\Documents and Settings\carrefour\Application Data\trust software\wmpdmyhe.exe
Deleted
C:\Documents and Settings\carrefour\Application Data\trust software\xtfxuaqc.exe
Infected with: Trojan.Downloader.Swizzor.DH
C:\Documents and Settings\carrefour\Application Data\trust software\xtfxuaqc.exe
Disinfection failed
C:\Documents and Settings\carrefour\Application Data\trust software\xtfxuaqc.exe
Deleted
C:\Documents and Settings\carrefour\Application Data\trust software\zowlhmjn.exe
Infected with: Trojan.Downloader.Swizzor.DE
C:\Documents and Settings\carrefour\Application Data\trust software\zowlhmjn.exe
Disinfection failed
C:\Documents and Settings\carrefour\Application Data\trust software\zowlhmjn.exe
Deleted
C:\Documents and Settings\carrefour\Application Data\trust software\zvyfryrj.exe
Infected with: Trojan.Swizzor.BA
C:\Documents and Settings\carrefour\Application Data\trust software\zvyfryrj.exe
Disinfection failed
C:\Documents and Settings\carrefour\Application Data\trust software\zvyfryrj.exe
Deleted
C:\Documents and Settings\carrefour\Bureau\Kay\Jeux video&outils\Outil\Clone cd 5.0.4.2\CRACK[1].CD-CloneCD_v5.0.2.2_by_Foulis.zip=>zmk.exe
Infected with: Trojan.Downloader.INService.I
C:\Documents and Settings\carrefour\Bureau\Kay\Jeux video&outils\Outil\Clone cd 5.0.4.2\CRACK[1].CD-CloneCD_v5.0.2.2_by_Foulis.zip=>zmk.exe
Deleted
C:\Documents and Settings\carrefour\Bureau\Kay\Jeux video&outils\Outil\Clone cd 5.0.4.2\CRACK[1].CD-CloneCD_v5.0.2.2_by_Foulis.zip
Updated
C:\Documents and Settings\carrefour\Bureau\Kay\Jeux video&outils\Outil\CRACK[1].CD-CloneCD_v4.3.1.9_by_SnD.zip=>qto.exe
Infected with: Trojan.Downloader.INService.I
C:\Documents and Settings\carrefour\Bureau\Kay\Jeux video&outils\Outil\CRACK[1].CD-CloneCD_v4.3.1.9_by_SnD.zip=>qto.exe
Deleted
C:\Documents and Settings\carrefour\Bureau\Kay\Jeux video&outils\Outil\CRACK[1].CD-CloneCD_v4.3.1.9_by_SnD.zip
Updated
C:\Documents and Settings\carrefour\Local Settings\Temp\3ce9a37b.exe
Infected with: Trojan.Downloader.Swizzor.CA
C:\Documents and Settings\carrefour\Local Settings\Temp\3ce9a37b.exe
Disinfection failed
C:\Documents and Settings\carrefour\Local Settings\Temp\3ce9a37b.exe
Deleted
C:\Documents and Settings\carrefour\Local Settings\Temp\3d8077be.exe
Infected with: Trojan.Downloader.Swizzor.DI
C:\Documents and Settings\carrefour\Local Settings\Temp\3d8077be.exe
Disinfection failed
C:\Documents and Settings\carrefour\Local Settings\Temp\3d8077be.exe
Deleted
C:\WINDOWS\Downloaded Program Files\1015423.exe
Suspected of: Generic.Malware.Y.6FEFC2C5
C:\WINDOWS\Downloaded Program Files\1015423.exe
Disinfection failed
C:\WINDOWS\Downloaded Program Files\1015423.exe
Deleted
C:\WINDOWS\Downloaded Program Files\gsa0415.exe
Infected with: Trojan.Dialer.CJ
C:\WINDOWS\Downloaded Program Files\gsa0415.exe
Disinfection failed
C:\WINDOWS\Downloaded Program Files\gsa0415.exe
Deleted
et le rapport hijackthis:
Logfile of HijackThis v1.99.1
Scan saved at 16:53:41, on 09/04/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\slrundll.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
c:\progra~1\intern~1\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\BitTorrent\btdownloadgui.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Winamp\Winamp.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\CARREF~1\LOCALS~1\Temp\Rar$EX00.797\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.agfqdplmpeictvhj.com/6knTq4xm/a2VWHBzzoY/Fbs2rZfQJZS06rnYYXb6HfJcif/Sm...
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - c:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.02.3000.1002\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\fr\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\fr\msntb.dll
O4 - HKLM\..\Run: [URLLSTCK.exe] C:\Program Files\Norton Internet Security Professional\UrlLstCk.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKCU\..\Run: [logo warn] C:\DOCUME~1\CARREF~1\APPLIC~1\TRUSTS~1\Globalremote.exe
O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\Xfire.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: SymWMI Service (SymWSC) - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
que dois-je faire maintenant?merci de ton aide
Affiche tous les fichiers et dossiers :
Clique sur démarrer, panneau de configuration, outils ,option des dossiers, affichage
Coche: afficher les fichiers et dossiers cachés
Appliquer, puis ok
*Cliques sur demarrer, poste de travail, C:, documents and settings, all users, application data, cherches et supprimes ces dossiers si encore present:
trust software
Compsurfgrimburn
-si un fichier persiste lors de la suppression fais ceci:
-Redemarres ton pc, dès l'allumage de celui ci tapotes la touche f8, à l'ecran qui va apparaitre choisis "mode sans echec" attends un peu.. puis vas supprimer les fichiers/dossiers, vides ta corbeille et redemarres normalement
2.Cliques sur demarrer, poste de travail, C:, documents and settings, "carerfour", Bureau, "Kay", jeux videos&outils, outil, Clone cdeux video&outils,Outil, puis supprime ce fichier:
CRACK[1].CD-CloneCD_v4.3.1.9_by_SnD.zip
3.Fais ce nettoyage:
¤Telecharges et installes ceci, dans la colonne de gauche cliques sur "erreurs" coches toutes les cases, puis cliques en bas sur "chercher des erreurs" une fois finit, cliques sur "reparer les erreurs" et tu aura un message pour sauvegarder ta base de registre tu dis "oui" puis tu recommences jusqu'a ce qu'il te trouve plus d'erreurs
CCleaner:
Ccleaner
¤Relance Ccleaner ,vas dans l'onglet "nettoyeur" present sur la gauche, decoches la derniere case (Avancé si elle est cochée) puis cliques sur "lancer le nettoyage"
4.Puis:
Telecharge, installe puis mets à jour ce logiciel anti-spywares, une fois que c'est fait, fais un scan complet de ton systeme et colle le rapport ici avec un nouveau rapport hijackthis
Ewido:
Ewido Security Suite
+ Résultats du scan:
C:\CA LE FAIT GRAVE !!!!\Num.exe -> Heuristic.Win32.Dialer : Nettoyer et sauvegarder
:mozilla.8:C:\Documents and Settings\carrefour\Application Data\Mozilla\Firefox\Profiles\xay2vwj4.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyer et sauvegarder
:mozilla.9:C:\Documents and Settings\carrefour\Application Data\Mozilla\Firefox\Profiles\xay2vwj4.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyer et sauvegarder
:mozilla.10:C:\Documents and Settings\carrefour\Application Data\Mozilla\Firefox\Profiles\xay2vwj4.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyer et sauvegarder
:mozilla.11:C:\Documents and Settings\carrefour\Application Data\Mozilla\Firefox\Profiles\xay2vwj4.default\cookies.txt -> TrackingCookie.Weborama : Nettoyer et sauvegarder
:mozilla.13:C:\Documents and Settings\carrefour\Application Data\Mozilla\Firefox\Profiles\xay2vwj4.default\cookies.txt -> TrackingCookie.Weborama : Nettoyer et sauvegarder
:mozilla.14:C:\Documents and Settings\carrefour\Application Data\Mozilla\Firefox\Profiles\xay2vwj4.default\cookies.txt -> TrackingCookie.Doubleclick : Nettoyer et sauvegarder
C:\Documents and Settings\carrefour\Bureau\new_uninstall.exe -> Adware.Lop : Nettoyer et sauvegarder
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq85.tmp -> TrackingCookie.Weborama : Nettoyer et sauvegarder
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq86.tmp -> TrackingCookie.Zedo : Nettoyer et sauvegarder
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq8B5.tmp -> TrackingCookie.247realmedia : Nettoyer et sauvegarder
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq8B6.tmp -> TrackingCookie.2o7 : Nettoyer et sauvegarder
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq8B7.tmp -> TrackingCookie.Adtech : Nettoyer et sauvegarder
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq8B8.tmp -> TrackingCookie.Falkag : Nettoyer et sauvegarder
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq8B9.tmp -> TrackingCookie.Bluestreak : Nettoyer et sauvegarder
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq8BA.tmp -> TrackingCookie.Casalemedia : Nettoyer et sauvegarder
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq8BB.tmp -> TrackingCookie.Comclick : Nettoyer et sauvegarder
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq8BD.tmp -> TrackingCookie.Revenue : Nettoyer et sauvegarder
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq8BE.tmp -> TrackingCookie.Serving-sys : Nettoyer et sauvegarder
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq8BF.tmp -> TrackingCookie.Tradedoubler : Nettoyer et sauvegarder
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq8C0.tmp -> TrackingCookie.Tribalfusion : Nettoyer et sauvegarder
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq8C1.tmp -> TrackingCookie.Weborama : Nettoyer et sauvegarder
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq8C2.tmp -> TrackingCookie.Adserver : Nettoyer et sauvegarder
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq8C6.tmp -> TrackingCookie.Falkag : Nettoyer et sauvegarder
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq8C7.tmp -> TrackingCookie.Bluestreak : Nettoyer et sauvegarder
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq8C8.tmp -> TrackingCookie.Casalemedia : Nettoyer et sauvegarder
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq8CA.tmp -> TrackingCookie.Comclick : Nettoyer et sauvegarder
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq8CB.tmp -> TrackingCookie.Revenue : Nettoyer et sauvegarder
:mozilla.10:C:\RECYCLER\NPROTECT\00354058.MOZ -> TrackingCookie.Estat : Nettoyer et sauvegarder
:mozilla.12:C:\RECYCLER\NPROTECT\00354058.MOZ -> TrackingCookie.Smartadserver : Nettoyer et sauvegarder
:mozilla.13:C:\RECYCLER\NPROTECT\00354058.MOZ -> TrackingCookie.Smartadserver : Nettoyer et sauvegarder
:mozilla.14:C:\RECYCLER\NPROTECT\00354058.MOZ -> TrackingCookie.Smartadserver : Nettoyer et sauvegarder
:mozilla.15:C:\RECYCLER\NPROTECT\00354058.MOZ -> TrackingCookie.Overture : Nettoyer et sauvegarder
:mozilla.16:C:\RECYCLER\NPROTECT\00354058.MOZ -> TrackingCookie.Overture : Nettoyer et sauvegarder
:mozilla.27:C:\RECYCLER\NPROTECT\00354058.MOZ -> TrackingCookie.Mediaplex : Nettoyer et sauvegarder
:mozilla.31:C:\RECYCLER\NPROTECT\00354058.MOZ -> TrackingCookie.Bluestreak : Nettoyer et sauvegarder
:mozilla.46:C:\RECYCLER\NPROTECT\00354058.MOZ -> TrackingCookie.Weborama : Nettoyer et sauvegarder
:mozilla.47:C:\RECYCLER\NPROTECT\00354058.MOZ -> TrackingCookie.Weborama : Nettoyer et sauvegarder
:mozilla.48:C:\RECYCLER\NPROTECT\00354058.MOZ -> TrackingCookie.Weborama : Nettoyer et sauvegarder
:mozilla.52:C:\RECYCLER\NPROTECT\00354058.MOZ -> TrackingCookie.Adtech : Nettoyer et sauvegarder
:mozilla.53:C:\RECYCLER\NPROTECT\00354058.MOZ -> TrackingCookie.Adtech : Nettoyer et sauvegarder
:mozilla.11:C:\RECYCLER\NPROTECT\00354061.MOZ -> TrackingCookie.Estat : Nettoyer et sauvegarder
:mozilla.12:C:\RECYCLER\NPROTECT\00354061.MOZ -> TrackingCookie.Smartadserver : Nettoyer et sauvegarder
:mozilla.13:C:\RECYCLER\NPROTECT\00354061.MOZ -> TrackingCookie.Smartadserver : Nettoyer et sauvegarder
:mozilla.14:C:\RECYCLER\NPROTECT\00354061.MOZ -> TrackingCookie.Smartadserver : Nettoyer et sauvegarder
:mozilla.15:C:\RECYCLER\NPROTECT\00354061.MOZ -> TrackingCookie.Overture : Nettoyer et sauvegarder
:mozilla.16:C:\RECYCLER\NPROTECT\00354061.MOZ -> TrackingCookie.Overture : Nettoyer et sauvegarder
:mozilla.17:C:\RECYCLER\NPROTECT\00354061.MOZ -> TrackingCookie.Mediaplex : Nettoyer et sauvegarder
:mozilla.20:C:\RECYCLER\NPROTECT\00354061.MOZ -> TrackingCookie.Bluestreak : Nettoyer et sauvegarder
:mozilla.35:C:\RECYCLER\NPROTECT\00354061.MOZ -> TrackingCookie.Weborama : Nettoyer et sauvegarder
:mozilla.36:C:\RECYCLER\NPROTECT\00354061.MOZ -> TrackingCookie.Weborama : Nettoyer et sauvegarder
:mozilla.37:C:\RECYCLER\NPROTECT\00354061.MOZ -> TrackingCookie.Weborama : Nettoyer et sauvegarder
:mozilla.41:C:\RECYCLER\NPROTECT\00354061.MOZ -> TrackingCookie.Adtech : Nettoyer et sauvegarder
:mozilla.42:C:\RECYCLER\NPROTECT\00354061.MOZ -> TrackingCookie.Adtech : Nettoyer et sauvegarder
:mozilla.7:C:\RECYCLER\NPROTECT\00354111.MOZ -> TrackingCookie.Doubleclick : Nettoyer et sauvegarder
:mozilla.12:C:\RECYCLER\NPROTECT\00354111.MOZ -> TrackingCookie.Estat : Nettoyer et sauvegarder
:mozilla.13:C:\RECYCLER\NPROTECT\00354111.MOZ -> TrackingCookie.Smartadserver : Nettoyer et sauvegarder
:mozilla.14:C:\RECYCLER\NPROTECT\00354111.MOZ -> TrackingCookie.Smartadserver : Nettoyer et sauvegarder
:mozilla.15:C:\RECYCLER\NPROTECT\00354111.MOZ -> TrackingCookie.Smartadserver : Nettoyer et sauvegarder
:mozilla.16:C:\RECYCLER\NPROTECT\00354111.MOZ -> TrackingCookie.Overture : Nettoyer et sauvegarder
:mozilla.17:C:\RECYCLER\NPROTECT\00354111.MOZ -> TrackingCookie.Overture : Nettoyer et sauvegarder
:mozilla.18:C:\RECYCLER\NPROTECT\00354111.MOZ -> TrackingCookie.Mediaplex : Nettoyer et sauvegarder
:mozilla.21:C:\RECYCLER\NPROTECT\00354111.MOZ -> TrackingCookie.Bluestreak : Nettoyer et sauvegarder
:mozilla.36:C:\RECYCLER\NPROTECT\00354111.MOZ -> TrackingCookie.Weborama : Nettoyer et sauvegarder
:mozilla.37:C:\RECYCLER\NPROTECT\00354111.MOZ -> TrackingCookie.Weborama : Nettoyer et sauvegarder
:mozilla.38:C:\RECYCLER\NPROTECT\00354111.MOZ -> TrackingCookie.Weborama : Nettoyer et sauvegarder
:mozilla.42:C:\RECYCLER\NPROTECT\00354111.MOZ -> TrackingCookie.Adtech : Nettoyer et sauvegarder
:mozilla.43:C:\RECYCLER\NPROTECT\00354111.MOZ -> TrackingCookie.Adtech : Nettoyer et sauvegarder
et celui de hijackthis :
Logfile of HijackThis v1.99.1
Scan saved at 19:25:25, on 09/04/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\CARREF~1\LOCALS~1\Temp\Rar$EX01.156\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.agfqdplmpeictvhj.com/6knTq4xm/a2VWHBzzoY/Fbs2rZfQJZS06rnYYXb6HfJcif/Sm...
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - c:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.02.3000.1002\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\fr\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\fr\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKCU\..\Run: [logo warn] C:\DOCUME~1\CARREF~1\APPLIC~1\TRUSTS~1\Globalremote.exe
O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\Xfire.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: SymWMI Service (SymWSC) - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
encore merci de ton aide
Relance HijackThis, choisis " do a scan only" coche la case devant les lignes ci-dessous et clique en bas sur "fix checked"
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.agfqdplmpeictvhj.com/6knTq4xm/a2VWHBzzoY/Fbs2rZfQJZS06rnYYXb6HfJcif/Sm...
O4 - HKCU\..\Run: [logo warn] C:\DOCUME~1\CARREF~1\APPLIC~1\TRUSTS~1\Globalremote.exe
Puis fais ceci:
Ouvre HijackThis, clique sur "Open the misc tools sections" ensuite "open Uninstall manager " clique sur "Save list" enregistre tout et colle le ici
Ad-Aware SE Personal
Adobe Acrobat 5.0
Adobe Photoshop Elements 2.0
Age of Wonders
Archiveur WinRAR
a-squared Free 1.6
Audacity 1.2.4
AV Voice Changer Software 3.0
avast! Antivirus
Barre d'outils MSN
BitTorrent 4.0.4
Bof4
BSPlayer
Camera Plus
CCleaner (remove only)
CloneCD
CM 03-04
COMMUNICATE!-32
Compel Adaptec WinASPI
Complément Microsoft Word pour Microsoft Works Suite
Correctif Windows XP - KB834707
Correctif Windows XP - KB867282
Correctif Windows XP - KB873333
Correctif Windows XP - KB873339
Correctif Windows XP - KB885250
Correctif Windows XP - KB885835
Correctif Windows XP - KB885836
Correctif Windows XP - KB885884
Correctif Windows XP - KB886185
Correctif Windows XP - KB887472
Correctif Windows XP - KB887742
Correctif Windows XP - KB887797
Correctif Windows XP - KB888113
Correctif Windows XP - KB888302
Correctif Windows XP - KB890047
Correctif Windows XP - KB890175
Correctif Windows XP - KB890859
Correctif Windows XP - KB890923
Correctif Windows XP - KB891781
Correctif Windows XP - KB893066
Correctif Windows XP - KB893086
DivX
DivX Player
Encyclopédie Microsoft Encarta 2003
EPSON Logiciel imprimante
EPSON PhotoQuicker3.4
EPSON PRINT Image Framer Tool2.0
ewido anti-malware
Extension HighMAT pour l'Assistant Graver un CD de Microsoft Windows XP
Extension Système de Microsoft Money
FileZilla (remove only)
FreeGo 2.0
glGo
GUILD WARS
Half-Life
Half-Life: Blue Shift
Half-Life: Counter-Strike
Half-Life: Opposing Force
Helix YUV Codecs (remove only)
HijackThis 1.99.1
Huffyuv AVI lossless video codec (Remove Only)
InterActual Player
J2SE Runtime Environment 5.0 Update 1
J2SE Runtime Environment 5.0 Update 4
J2SE Runtime Environment 5.0 Update 5
J2SE Runtime Environment 5.0 Update 6
Jago Version 3.67
Java 2 Runtime Environment, SE v1.4.1_02
Java Runtime Environment 1.1
Kaspersky On-line Scanner
Language pack for Ad-Aware SE
Lecteur Windows Media 10
Macromedia Flash Player 8
Macromedia Shockwave Player
Matroska Pack (remove only)
MediaShow 3.0
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 French Language Pack
Microsoft .NET Framework 1.1 Hotfix (KB886903)
Microsoft AntiSpyware
Microsoft AutoRoute 2002
Microsoft Data Access Components KB870669
Microsoft Money
Microsoft Office PowerPoint Viewer 2003
Microsoft Picture It! Photo 7.0
Microsoft Word 2002
Microsoft Works 7.0
Mise à jour de sécurité pour Lecteur Windows Media (KB911564)
Mise à jour de sécurité pour Lecteur Windows Media 10 (KB911565)
Mise à jour de sécurité pour Step by Step Interactive Training (KB898458)
Mise à jour de sécurité pour Windows XP (KB883939)
Mise à jour de sécurité pour Windows XP (KB890046)
Mise à jour de sécurité pour Windows XP (KB893756)
Mise à jour de sécurité pour Windows XP (KB896358)
Mise à jour de sécurité pour Windows XP (KB896422)
Mise à jour de sécurité pour Windows XP (KB896423)
Mise à jour de sécurité pour Windows XP (KB896424)
Mise à jour de sécurité pour Windows XP (KB896428)
Mise à jour de sécurité pour Windows XP (KB896688)
Mise à jour de sécurité pour Windows XP (KB899587)
Mise à jour de sécurité pour Windows XP (KB899588)
Mise à jour de sécurité pour Windows XP (KB899591)
Mise à jour de sécurité pour Windows XP (KB900725)
Mise à jour de sécurité pour Windows XP (KB901017)
Mise à jour de sécurité pour Windows XP (KB901190)
Mise à jour de sécurité pour Windows XP (KB901214)
Mise à jour de sécurité pour Windows XP (KB902400)
Mise à jour de sécurité pour Windows XP (KB903235)
Mise à jour de sécurité pour Windows XP (KB904706)
Mise à jour de sécurité pour Windows XP (KB905414)
Mise à jour de sécurité pour Windows XP (KB905749)
Mise à jour de sécurité pour Windows XP (KB905915)
Mise à jour de sécurité pour Windows XP (KB908519)
Mise à jour de sécurité pour Windows XP (KB911927)
Mise à jour de sécurité pour Windows XP (KB912919)
Mise à jour de sécurité pour Windows XP (KB913446)
Mise à jour pour Windows XP (KB894391)
Mise à jour pour Windows XP (KB896727)
Mise à jour pour Windows XP (KB898461)
Mise à jour pour Windows XP (KB900930)
Mise à jour pour Windows XP (KB910437)
Mozilla Firefox (1.0.7)
MSN Messenger 7.5
MSXML 4.0 SP2 Parser and SDK
Namo WebEditor 4
Nero Suite
Norton WMI Update
NVIDIA Windows 2000/XP Display Drivers
OLYMPUS CAMEDIA Master 4.1
PhotoNow! 1.0
PowerDVD
quickSkin
QuickTime
RealPlayer
RM03 - Run Time Package (RTP)
SafeCast Shared Components
ScanToWeb
Sélecteur d'installation de Microsoft Works Suite 2003
Shockwave
Skype 2.0
Smart Link 56K Voice Modem
Steam(TM)
Utilitaire de sauvegarde Windows
VideoLAN VLC media player 0.8.1
Visionneuse Journal Windows Microsoft
Winamp (remove only)
Windows Installer 3.1 (KB893803)
Windows Installer 3.1 (KB893803)
Windows Media Connect
Windows Media Connect
Windows Media Format Runtime
Windows XP Service Pack 2
winLAME rc3 (remove only)
WONswap
Xfire (remove only)
XviD codec (Neodivx Version)
Yahoo! Anti-Spy
Yahoo! Toolbar avec bloqueur de fenêtres pop-up
ZoneAlarm