[Virus] Infecté par spy sheriff - Page 2

Précédent
  • 1
  • 2
  1. aranjuez31 Messages postés 8161 Date d'inscription   Statut Contributeur 354
     
    re
    merde c est chiant ton blem
    effectivement ton logfile est à nouveau infecté
    mais par autre chose
    où vas-tu donc traîner ? warez ? p2p ? q ?
    ================
    munis-toi de :
    cleanup40 (nettoyeur de cookies+temps+tempos+prefetch+historique+etc..)
    http://pageperso.aol.fr/balltrap34/democleanup.htm
    ¤Télécharger CleanUp40 (qui élimine les fichiers temporaires) sur ce lien : http://pageperso.aol.fr/Balltrap34/CleanUp40.exe
    ==============
    mode ss échec ( imprime pour ne rien oublier ou mets sur un notpad-essaie de ne rien oublier pour ne pas avoir à recommencer)

    X / Affiche tous les fichiers et dossiers :
    Cliquer sur Démarrer/Panneau de Configuration/Options des dossiers/Affichage :
    Cocher Afficher les dossiers cachés
    Décocher la case "Masquer les fichiers protégés du système d'exploitation (recommandé)"
    Décocher Masquer les extensions dont le type est connu
    Puis fais «OK» pour valider les changements.
    Et appliquer

    ouvre hijack
    coche et fixe ceci

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
    +
    F2 - REG:system.ini: Shell=explorer.exe "C:\Program Files\Fichiers communs\Microsoft Shared\Web Folders\ibm00004.exe"
    +
    O4 - HKLM\..\Run: [ULiRaid5287] C:\Program Files\ULi5287\ULi5287.exe

    O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup

    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k

    O4 - HKLM\..\Run: [SysTray] c:\Program Files\ksjedvj.exe

    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe

    O4 - HKCU\..\Run: [0mcamcap] C:\WINDOWS\System32\0mcamcap.exe

    O4 - HKCU\..\Run: [ed95706d.exe] C:\Documents and Settings\gilou\Local Settings\Application Data\ed95706d.exe
    ==========
    va dans
    C:\WINDOWS\System32\0mcamcap.exe
    cherche et supprime '0mcamcap.exe'

    va dans
    C:\Program Files\ULi5287\ULi5287.exe
    cherche et supprime
    ULi5287

    va dans
    C:\Program Files\Fichiers communs\Microsoft Shared\Web Folders\ibm00004.exe
    cherche et supprime
    ibm00004.exe

    va dans
    C:\Documents and Settings\gilou\Local Settings\Application Data\ed95706d.exe
    cherche et supprime
    ed95706d.exe
    ======
    démarrer>'recherher>supprimer tt ce qui suit
    ed95706d.exe
    ibm00004.exe
    ULi5287.exe
    0mcamcap.exe
    secure32.html
    =========
    passe ewido en sans échec- vide quarantaine
    passe cleanup40 en sans échec
    vide poubelle
    =========
    refais X/ en sens inverse pour remasquer dossiers cachés
    ===============
    redémarre en normal
    re-ewido avec rapport collé
    re scan online de bitdef avec rapport coll'
    + scan online avec rapport collé de kasper
    http://www.kaspersky.com/kos/english/kavwebscan.html
    re rapport hijack
    ouf !
    0
  2. donguyl Messages postés 36 Statut Membre
     
    Merci de ta collaboration.

    Le scan ewido:

    ---------------------------------------------------------
    ewido anti-malware - Rapport de scan
    ---------------------------------------------------------

    + Créé le: 09:12:05, 19/05/2006
    + Somme de contrôle: A3713342

    + Résultats du scan:

    Pas de fichiers infectés trouvés!

    ::Fin du rapport
    0
  3. donguyl Messages postés 36 Statut Membre
     
    Maintenan le scan de bitdefender :

    canned File

    Status

    C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\DTLJBIAE\ehaopdu[1].txt

    Infected with: Trojan.Startpage.LG

    C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\DTLJBIAE\ehaopdu[1].txt

    Disinfection failed

    C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\DTLJBIAE\ehaopdu[1].txt

    Deleted

    C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\DTLJBIAE\gltom[1].txt

    Suspected of: BehavesLike:Win32.Backdoor

    C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\DTLJBIAE\gltom[1].txt

    Disinfection failed

    C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\DTLJBIAE\gltom[1].txt

    Deleted

    C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\DTLJBIAE\uqlwy[1].txt

    Infected with: Trojan.PWS.Sinowal.M

    C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\DTLJBIAE\uqlwy[1].txt

    Deleted

    C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\FVTUPZ9P\cbyzqvnd[1].htm

    Infected with: Trojan.ProcKill.DJ

    C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\FVTUPZ9P\cbyzqvnd[1].htm

    Deleted

    C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\FVTUPZ9P\guzdemak[1].txt

    Infected with: Trojan.Downloader.Small.AID

    C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\FVTUPZ9P\guzdemak[1].txt

    Disinfection failed

    C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\FVTUPZ9P\guzdemak[1].txt

    Deleted

    C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\K07HU1EU\ghxgzrz[1].txt

    Infected with: Trojan.Proxy.Small.BO

    C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\K07HU1EU\ghxgzrz[1].txt

    Deleted

    C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\K07HU1EU\rxlzeqh[1].htm

    Infected with: Trojan.SpySheriff.C

    C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\K07HU1EU\rxlzeqh[1].htm

    Disinfection failed

    C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\K07HU1EU\rxlzeqh[1].htm

    Deleted

    C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\OMNXMTX1\oisgkczyu[2].txt

    Infected with: Trojan.PWS.LDPinch.NG

    C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\OMNXMTX1\oisgkczyu[2].txt

    Disinfection failed

    C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\OMNXMTX1\oisgkczyu[2].txt

    Deleted

    C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\OMNXMTX1\tytrzlkz[2].txt

    Infected with: Trojan.FakeAlert.CC

    C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\OMNXMTX1\tytrzlkz[2].txt

    Disinfection failed

    C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\OMNXMTX1\tytrzlkz[2].txt

    Deleted

    C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\OMNXMTX1\ynhmanfnj[1].txt

    Infected with: Trojan.Clicker.Small.KR

    C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\OMNXMTX1\ynhmanfnj[1].txt

    Deleted

    C:\ibltyilp.exe

    Suspected of: BehavesLike:Win32.Backdoor

    C:\ibltyilp.exe

    Disinfection failed

    C:\ibltyilp.exe

    Deleted

    C:\ilyms.exe

    Infected with: Trojan.ProcKill.DJ

    C:\ilyms.exe

    Deleted

    C:\jalu.exe

    Suspected of: BehavesLike:Win32.Backdoor

    C:\jalu.exe

    Disinfection failed

    C:\jalu.exe

    Deleted

    C:\jispoi.exe

    Infected with: Trojan.ProcKill.DJ

    C:\jispoi.exe

    Deleted

    C:\Program Files\Fichiers communs\Microsoft Shared\Web Folders\ibm00003.exe

    Infected with: Trojan.PWS.Sinowal.Q

    C:\Program Files\Fichiers communs\Microsoft Shared\Web Folders\ibm00003.exe

    Disinfection failed

    C:\Program Files\Fichiers communs\Microsoft Shared\Web Folders\ibm00003.exe

    Deleted

    C:\Program Files\secure32.html

    Infected with: Trojan.SpySheriff.C

    C:\Program Files\secure32.html

    Disinfection failed

    C:\Program Files\secure32.html

    Deleted

    C:\secure32.html

    Infected with: Trojan.SpySheriff.C

    C:\secure32.html

    Disinfection failed

    C:\secure32.html

    Deleted

    C:\vxcvjle.exe

    Infected with: Trojan.ProcKill.DJ

    C:\vxcvjle.exe

    Deleted

    C:\WINDOWS\inet20026\killer.exe

    Infected with: Trojan.Killer

    C:\WINDOWS\inet20026\killer.exe

    Disinfection failed

    C:\WINDOWS\inet20026\killer.exe

    Deleted

    C:\WINDOWS\system32\0mcamcap.exe

    Infected with: Trojan.Proxy.Small.BO

    C:\WINDOWS\system32\0mcamcap.exe

    Deleted

    C:\WINDOWS\system32\dlh9jkdq1.exe

    Infected with: Trojan.Downloader.CZO

    C:\WINDOWS\system32\dlh9jkdq1.exe

    Disinfection failed

    C:\WINDOWS\system32\dlh9jkdq1.exe

    Deleted

    C:\WINDOWS\system32\dlh9jkdq2.exe

    Infected with: Backdoor.Braventry.A

    C:\WINDOWS\system32\dlh9jkdq2.exe

    Disinfection failed

    C:\WINDOWS\system32\dlh9jkdq2.exe

    Deleted

    C:\WINDOWS\system32\drivers\ntndis.exe

    Infected with: Generic.Malware.GIFMY.37A5D78A

    C:\WINDOWS\system32\drivers\ntndis.exe

    Disinfection failed

    C:\WINDOWS\system32\drivers\ntndis.exe

    Deleted

    C:\WINDOWS\system32\inetsec.exe

    Infected with: GenPack:Backdoor.SDBot.F3D4DA9D

    C:\WINDOWS\system32\inetsec.exe

    Disinfection failed

    C:\WINDOWS\system32\inetsec.exe

    Delete failed

    C:\WINDOWS\system32\taskmgn.exe

    Suspected of: BehavesLike:Win32.Backdoor

    C:\WINDOWS\system32\taskmgn.exe

    Disinfection failed

    C:\WINDOWS\system32\taskmgn.exe

    Delete failed

    C:\WINDOWS\system32\wnsec.exe

    Infected with: GenPack:Backdoor.SDBot.4E890FF4

    C:\WINDOWS\system32\wnsec.exe

    Disinfection failed

    C:\WINDOWS\system32\wnsec.exe

    Delete failed

    C:\WINDOWS\xpupdate.exe

    Infected with: Backdoor.Braventry.A

    C:\WINDOWS\xpupdate.exe

    Disinfection failed

    C:\WINDOWS\xpupdate.exe

    Deleted

    C:\wovgfs.exe

    Infected with: Trojan.ProcKill.DJ

    C:\wovgfs.exe

    Deleted
    0
  4. donguyl Messages postés 36 Statut Membre
     
    BOnjour à tous désolé de n'avoir pas pu répondre avant, boulot...Famille !

    Voila le rapport Kasperky:

    Total number of scanned objects 20319
    Number of viruses found 3
    Number of infected objects 15
    Number of suspicious objects 0
    Duration of the scan process 00:06:07

    Infected Object Name Virus Name Last Action
    C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\FVTUPZ9P\z[2].jpg/stream/data0001 Infected: Trojan-Downloader.Win32.Harnig.bq skipped

    C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\FVTUPZ9P\z[2].jpg/stream Infected: Trojan-Downloader.Win32.Harnig.bq skipped

    C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\FVTUPZ9P\z[2].jpg NSIS: infected - 2 skipped

    C:\Program Files\Fichiers communs\Microsoft Shared\Web Folders\ibm00001.exe Infected: Trojan-PSW.Win32.Sinowal.p skipped

    C:\Program Files\Fichiers communs\Microsoft Shared\Web Folders\ibm00002.dll Infected: Trojan-PSW.Win32.Sinowal.p skipped

    C:\Program Files\Fichiers communs\Microsoft Shared\Web Folders\_ibm00003.exe Infected: Trojan-PSW.Win32.Sinowal.p skipped

    C:\Program Files\Fichiers communs\Microsoft Shared\Web Folders\_ibm00013.exe Infected: Trojan-PSW.Win32.Sinowal.p skipped

    C:\Program Files\Fichiers communs\Microsoft Shared\Web Folders\_ibm00030.exe Infected: Trojan-PSW.Win32.Sinowal.p skipped

    C:\Program Files\Fichiers communs\Microsoft Shared\Web Folders\_ibm00035.exe Infected: Trojan-PSW.Win32.Sinowal.p skipped

    C:\Program Files\Fichiers communs\Microsoft Shared\Web Folders\_ibm00044.exe Infected: Trojan-PSW.Win32.Sinowal.p skipped

    C:\Program Files\Fichiers communs\Microsoft Shared\Web Folders\_ibm00047.exe Infected: Trojan-PSW.Win32.Sinowal.p skipped

    C:\WINDOWS\system32\ipod.raw.exe Infected: Packed.Win32.Tibs skipped

    C:\WINDOWS\system32\taskdir.exe Infected: Packed.Win32.Tibs skipped

    C:\WINDOWS\system32\taskdir~.exe Infected: Packed.Win32.Tibs skipped

    C:\WINDOWS\Temp\adv.exe Infected: Trojan-Downloader.Win32.Harnig.bq skipped

    Scan process completed.

    Et le dernier Hijack:

    Logfile of HijackThis v1.99.1
    Scan saved at 08:54:58, on 20/05/2006
    Platform: Windows XP (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\System32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\windows\system32\taskmgn.exe
    C:\Program Files\ewido anti-malware\ewidoctrl.exe
    C:\Program Files\ewido anti-malware\ewidoguard.exe
    C:\WINDOWS\system32\inetsec.exe
    C:\WINDOWS\system32\wnsec.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    c:\Program Files\nubnc.exe
    C:\WINDOWS\System32\wuauclt.exe
    C:\Program Files\Hijackthis Version Française\VERSION TRADUITE ORIGINALE.EXE

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    O2 - BHO: HBO Class - {5321E378-FFAD-4999-8C62-03CA8155F0B3} - C:\WINDOWS\inet20026\3.03.00.dll (file missing)
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O4 - HKLM\..\Run: [Windows Task Manager] c:\windows\system32\taskmgn.exe
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKLM\..\Run: [SysTray] c:\Program Files\nubnc.exe
    O4 - HKLM\..\Run: [ed95706d.exe] C:\WINDOWS\System32\ed95706d.exe
    O4 - HKCU\..\Run: [1803f591.exe] C:\Documents and Settings\gilou\Local Settings\Application Data\1803f591.exe
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{03386F13-C9D1-4C1D-A0B5-F4D573E3FFD9}: NameServer = 86.64.145.146 84.103.237.146
    O17 - HKLM\System\CCS\Services\Tcpip\..\{039AC7EB-12B4-40C0-8EB8-27F95CCB930D}: NameServer = 86.64.145.140,84.103.237.140
    O17 - HKLM\System\CS1\Services\Tcpip\..\{03386F13-C9D1-4C1D-A0B5-F4D573E3FFD9}: NameServer = 86.64.145.146 84.103.237.146
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
    O20 - Winlogon Notify: 20242402reg - C:\Documents and Settings\All Users\Documents\Settings\20242402.dll
    O20 - Winlogon Notify: mmxeroxk - mmxeroxk.dll (file missing)
    O20 - Winlogon Notify: SensSrv - senssrv.dll (file missing)
    O21 - SSODL: SysTray.Exbr - {6368D1FC-6F5C-4f1b-B164-E67214F678E9} - (no file)
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
    O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
    0
    1. bernie61
       
      hello
      en attendant, tu peux refaire un SmitfrauFIX optins 1 ET 2 et colles les rapports ici
      a+
      0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. donguyl Messages postés 36 Statut Membre
     
    Hello,

    Voici les deux rapports que j'ais obtenu, j'attends votre aide.

    Merci d'avance

    SmitFraudFix v2.44

    Rapport fait à 14:42:06,37, 20/05/2006
    Executé à partir de C:\Documents and Settings\gilou\Mes documents\SmitfraudFix
    OS: Microsoft Windows XP [version 5.1.2600]

    »»»»»»»»»»»»»»»»»»»»»»»» C:\

    C:\exit PRESENT !
    C:\secure32.html PRESENT !
    C:\uniq PRESENT !
    C:\winstall.exe PRESENT !

    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

    C:\WINDOWS\system32\dlh9jkdq?.exe PRESENT !
    C:\WINDOWS\system32\taskdir.exe PRESENT !
    C:\WINDOWS\system32\taskdir~.exe PRESENT !
    C:\WINDOWS\system32\vxgame?.exe PRESENT !
    C:\WINDOWS\system32\vxgame?.exe????.exe PRESENT !
    C:\WINDOWS\system32\winbrume.dll PRESENT !
    C:\WINDOWS\system32\zlbw.dll PRESENT !

    »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\gilou\Application Data

    »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

    »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\gilou\Favoris

    »»»»»»»»»»»»»»»»»»»»»»»» Bureau

    »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

    C:\Program Files\secure32.html PRESENT !

    »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

    »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

    »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

    SrchSTS.exe by S!Ri
    Search SharedTaskScheduler's .dll

    »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

    »»»»»»»»»»»»»»»»»»»»»»»» Fin

    SmitFraudFix v2.44

    Rapport fait à 14:43:36,54, 20/05/2006
    Executé à partir de C:\Documents and Settings\gilou\Mes documents\SmitfraudFix
    OS: Microsoft Windows XP [version 5.1.2600]

    »»»»»»»»»»»»»»»»»»»»»»»» Arret des processus

    »»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés

    C:\exit supprimé
    C:\secure32.html supprimé
    C:\uniq supprimé
    C:\winstall.exe supprimé
    C:\WINDOWS\system32\dlh9jkdq?.exe supprimé
    C:\WINDOWS\system32\taskdir.exe supprimé
    C:\WINDOWS\system32\taskdir~.exe supprimé
    C:\WINDOWS\system32\vxgame?.exe supprimé
    C:\WINDOWS\system32\vxgame?.exe????.exe supprimé
    C:\WINDOWS\system32\winbrume.dll supprimé
    C:\WINDOWS\system32\zlbw.dll supprimé
    C:\Program Files\secure32.html supprimé

    »»»»»»»»»»»»»»»»»»»»»»»» Suppression Fichiers Temporaires

    »»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre

    Nettoyage terminé.

    »»»»»»»»»»»»»»»»»»»»»»»» Fin
    0
  7. bernie61
     
    re
    ok c'est bien (mais on est déjà à la version 45)

    refais un hijack
    a+
    0
  8. donguyl Messages postés 36 Statut Membre
     
    Désolé de n'avoir pas pu poster avant j'étais au travail :

    Logfile of HijackThis v1.99.1
    Scan saved at 19:47:57, on 20/05/2006
    Platform: Windows XP (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\savedump.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\System32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\windows\system32\taskmgn.exe
    C:\Program Files\ewido anti-malware\ewidoctrl.exe
    C:\Program Files\ewido anti-malware\ewidoguard.exe
    C:\WINDOWS\system32\inetsec.exe
    C:\WINDOWS\system32\wnsec.exe
    C:\WINDOWS\System32\wbem\wmiprvse.exe
    C:\Program Files\Hijackthis Version Française\VERSION TRADUITE ORIGINALE.EXE

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O4 - HKLM\..\Run: [Windows Task Manager] c:\windows\system32\taskmgn.exe
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKLM\..\Run: [ed95706d.exe] C:\WINDOWS\System32\ed95706d.exe
    O4 - HKCU\..\Run: [1803f591.exe] C:\Documents and Settings\gilou\Local Settings\Application Data\1803f591.exe
    O4 - HKCU\..\Run: [ed95706d.exe] C:\Documents and Settings\gilou\Local Settings\Application Data\ed95706d.exe
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{03386F13-C9D1-4C1D-A0B5-F4D573E3FFD9}: NameServer = 84.103.237.141 86.64.145.141
    O17 - HKLM\System\CCS\Services\Tcpip\..\{039AC7EB-12B4-40C0-8EB8-27F95CCB930D}: NameServer = 86.64.145.140,84.103.237.140
    O17 - HKLM\System\CS1\Services\Tcpip\..\{03386F13-C9D1-4C1D-A0B5-F4D573E3FFD9}: NameServer = 84.103.237.141 86.64.145.141
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
    O20 - Winlogon Notify: 20242402reg - C:\Documents and Settings\All Users\Documents\Settings\20242402.dll
    O20 - Winlogon Notify: mmxeroxk - mmxeroxk.dll (file missing)
    O20 - Winlogon Notify: SensSrv - senssrv.dll (file missing)
    O20 - Winlogon Notify: xdudtt - C:\WINDOWS\SYSTEM32\xdudtt.dll
    O21 - SSODL: SysTray.Exbr - {6368D1FC-6F5C-4f1b-B164-E67214F678E9} - (no file)
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
    O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe

    Merciiiii de votre aide !
    0
Précédent
  • 1
  • 2