[Virus] Infecté par spy sheriff
donguyl
Messages postés
36
Statut
Membre
-
bernie61 -
bernie61 -
Bonjour à tous me revoilà dans le monde de la misère ! Voila j'ai acheté un nouveau pc ! j'installe ma connexion et je dl 2 ou 3 trucs et le fameux Spysheriff s'immisce sournoisement. Je crois que j'ai un Backoor - haxdoor un truc comme ça que je n'ai pas vraiment pu identifier !
Vous aviez été ultra performant la dernière fois ! Merci de bien vouloir m'aider a nouveau !
Vous aviez été ultra performant la dernière fois ! Merci de bien vouloir m'aider a nouveau !
A voir également:
- [Virus] Infecté par spy sheriff
- Virus mcafee - Accueil - Piratage
- Spy bot - Télécharger - Antivirus & Antimalwares
- Spy sweeper - Télécharger - Antivirus & Antimalwares
- Virus informatique - Guide
- Virus facebook demande d'amis - Accueil - Facebook
28 réponses
re
merde c est chiant ton blem
effectivement ton logfile est à nouveau infecté
mais par autre chose
où vas-tu donc traîner ? warez ? p2p ? q ?
================
munis-toi de :
cleanup40 (nettoyeur de cookies+temps+tempos+prefetch+historique+etc..)
http://pageperso.aol.fr/balltrap34/democleanup.htm
¤Télécharger CleanUp40 (qui élimine les fichiers temporaires) sur ce lien : http://pageperso.aol.fr/Balltrap34/CleanUp40.exe
==============
mode ss échec ( imprime pour ne rien oublier ou mets sur un notpad-essaie de ne rien oublier pour ne pas avoir à recommencer)
X / Affiche tous les fichiers et dossiers :
Cliquer sur Démarrer/Panneau de Configuration/Options des dossiers/Affichage :
Cocher Afficher les dossiers cachés
Décocher la case "Masquer les fichiers protégés du système d'exploitation (recommandé)"
Décocher Masquer les extensions dont le type est connu
Puis fais «OK» pour valider les changements.
Et appliquer
ouvre hijack
coche et fixe ceci
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
+
F2 - REG:system.ini: Shell=explorer.exe "C:\Program Files\Fichiers communs\Microsoft Shared\Web Folders\ibm00004.exe"
+
O4 - HKLM\..\Run: [ULiRaid5287] C:\Program Files\ULi5287\ULi5287.exe
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SysTray] c:\Program Files\ksjedvj.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [0mcamcap] C:\WINDOWS\System32\0mcamcap.exe
O4 - HKCU\..\Run: [ed95706d.exe] C:\Documents and Settings\gilou\Local Settings\Application Data\ed95706d.exe
==========
va dans
C:\WINDOWS\System32\0mcamcap.exe
cherche et supprime '0mcamcap.exe'
va dans
C:\Program Files\ULi5287\ULi5287.exe
cherche et supprime
ULi5287
va dans
C:\Program Files\Fichiers communs\Microsoft Shared\Web Folders\ibm00004.exe
cherche et supprime
ibm00004.exe
va dans
C:\Documents and Settings\gilou\Local Settings\Application Data\ed95706d.exe
cherche et supprime
ed95706d.exe
======
démarrer>'recherher>supprimer tt ce qui suit
ed95706d.exe
ibm00004.exe
ULi5287.exe
0mcamcap.exe
secure32.html
=========
passe ewido en sans échec- vide quarantaine
passe cleanup40 en sans échec
vide poubelle
=========
refais X/ en sens inverse pour remasquer dossiers cachés
===============
redémarre en normal
re-ewido avec rapport collé
re scan online de bitdef avec rapport coll'
+ scan online avec rapport collé de kasper
http://www.kaspersky.com/kos/english/kavwebscan.html
re rapport hijack
ouf !
merde c est chiant ton blem
effectivement ton logfile est à nouveau infecté
mais par autre chose
où vas-tu donc traîner ? warez ? p2p ? q ?
================
munis-toi de :
cleanup40 (nettoyeur de cookies+temps+tempos+prefetch+historique+etc..)
http://pageperso.aol.fr/balltrap34/democleanup.htm
¤Télécharger CleanUp40 (qui élimine les fichiers temporaires) sur ce lien : http://pageperso.aol.fr/Balltrap34/CleanUp40.exe
==============
mode ss échec ( imprime pour ne rien oublier ou mets sur un notpad-essaie de ne rien oublier pour ne pas avoir à recommencer)
X / Affiche tous les fichiers et dossiers :
Cliquer sur Démarrer/Panneau de Configuration/Options des dossiers/Affichage :
Cocher Afficher les dossiers cachés
Décocher la case "Masquer les fichiers protégés du système d'exploitation (recommandé)"
Décocher Masquer les extensions dont le type est connu
Puis fais «OK» pour valider les changements.
Et appliquer
ouvre hijack
coche et fixe ceci
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
+
F2 - REG:system.ini: Shell=explorer.exe "C:\Program Files\Fichiers communs\Microsoft Shared\Web Folders\ibm00004.exe"
+
O4 - HKLM\..\Run: [ULiRaid5287] C:\Program Files\ULi5287\ULi5287.exe
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SysTray] c:\Program Files\ksjedvj.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [0mcamcap] C:\WINDOWS\System32\0mcamcap.exe
O4 - HKCU\..\Run: [ed95706d.exe] C:\Documents and Settings\gilou\Local Settings\Application Data\ed95706d.exe
==========
va dans
C:\WINDOWS\System32\0mcamcap.exe
cherche et supprime '0mcamcap.exe'
va dans
C:\Program Files\ULi5287\ULi5287.exe
cherche et supprime
ULi5287
va dans
C:\Program Files\Fichiers communs\Microsoft Shared\Web Folders\ibm00004.exe
cherche et supprime
ibm00004.exe
va dans
C:\Documents and Settings\gilou\Local Settings\Application Data\ed95706d.exe
cherche et supprime
ed95706d.exe
======
démarrer>'recherher>supprimer tt ce qui suit
ed95706d.exe
ibm00004.exe
ULi5287.exe
0mcamcap.exe
secure32.html
=========
passe ewido en sans échec- vide quarantaine
passe cleanup40 en sans échec
vide poubelle
=========
refais X/ en sens inverse pour remasquer dossiers cachés
===============
redémarre en normal
re-ewido avec rapport collé
re scan online de bitdef avec rapport coll'
+ scan online avec rapport collé de kasper
http://www.kaspersky.com/kos/english/kavwebscan.html
re rapport hijack
ouf !
Merci de ta collaboration.
Le scan ewido:
---------------------------------------------------------
ewido anti-malware - Rapport de scan
---------------------------------------------------------
+ Créé le: 09:12:05, 19/05/2006
+ Somme de contrôle: A3713342
+ Résultats du scan:
Pas de fichiers infectés trouvés!
::Fin du rapport
Le scan ewido:
---------------------------------------------------------
ewido anti-malware - Rapport de scan
---------------------------------------------------------
+ Créé le: 09:12:05, 19/05/2006
+ Somme de contrôle: A3713342
+ Résultats du scan:
Pas de fichiers infectés trouvés!
::Fin du rapport
Maintenan le scan de bitdefender :
canned File
Status
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\DTLJBIAE\ehaopdu[1].txt
Infected with: Trojan.Startpage.LG
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\DTLJBIAE\ehaopdu[1].txt
Disinfection failed
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\DTLJBIAE\ehaopdu[1].txt
Deleted
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\DTLJBIAE\gltom[1].txt
Suspected of: BehavesLike:Win32.Backdoor
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\DTLJBIAE\gltom[1].txt
Disinfection failed
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\DTLJBIAE\gltom[1].txt
Deleted
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\DTLJBIAE\uqlwy[1].txt
Infected with: Trojan.PWS.Sinowal.M
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\DTLJBIAE\uqlwy[1].txt
Deleted
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\FVTUPZ9P\cbyzqvnd[1].htm
Infected with: Trojan.ProcKill.DJ
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\FVTUPZ9P\cbyzqvnd[1].htm
Deleted
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\FVTUPZ9P\guzdemak[1].txt
Infected with: Trojan.Downloader.Small.AID
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\FVTUPZ9P\guzdemak[1].txt
Disinfection failed
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\FVTUPZ9P\guzdemak[1].txt
Deleted
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\K07HU1EU\ghxgzrz[1].txt
Infected with: Trojan.Proxy.Small.BO
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\K07HU1EU\ghxgzrz[1].txt
Deleted
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\K07HU1EU\rxlzeqh[1].htm
Infected with: Trojan.SpySheriff.C
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\K07HU1EU\rxlzeqh[1].htm
Disinfection failed
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\K07HU1EU\rxlzeqh[1].htm
Deleted
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\OMNXMTX1\oisgkczyu[2].txt
Infected with: Trojan.PWS.LDPinch.NG
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\OMNXMTX1\oisgkczyu[2].txt
Disinfection failed
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\OMNXMTX1\oisgkczyu[2].txt
Deleted
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\OMNXMTX1\tytrzlkz[2].txt
Infected with: Trojan.FakeAlert.CC
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\OMNXMTX1\tytrzlkz[2].txt
Disinfection failed
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\OMNXMTX1\tytrzlkz[2].txt
Deleted
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\OMNXMTX1\ynhmanfnj[1].txt
Infected with: Trojan.Clicker.Small.KR
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\OMNXMTX1\ynhmanfnj[1].txt
Deleted
C:\ibltyilp.exe
Suspected of: BehavesLike:Win32.Backdoor
C:\ibltyilp.exe
Disinfection failed
C:\ibltyilp.exe
Deleted
C:\ilyms.exe
Infected with: Trojan.ProcKill.DJ
C:\ilyms.exe
Deleted
C:\jalu.exe
Suspected of: BehavesLike:Win32.Backdoor
C:\jalu.exe
Disinfection failed
C:\jalu.exe
Deleted
C:\jispoi.exe
Infected with: Trojan.ProcKill.DJ
C:\jispoi.exe
Deleted
C:\Program Files\Fichiers communs\Microsoft Shared\Web Folders\ibm00003.exe
Infected with: Trojan.PWS.Sinowal.Q
C:\Program Files\Fichiers communs\Microsoft Shared\Web Folders\ibm00003.exe
Disinfection failed
C:\Program Files\Fichiers communs\Microsoft Shared\Web Folders\ibm00003.exe
Deleted
C:\Program Files\secure32.html
Infected with: Trojan.SpySheriff.C
C:\Program Files\secure32.html
Disinfection failed
C:\Program Files\secure32.html
Deleted
C:\secure32.html
Infected with: Trojan.SpySheriff.C
C:\secure32.html
Disinfection failed
C:\secure32.html
Deleted
C:\vxcvjle.exe
Infected with: Trojan.ProcKill.DJ
C:\vxcvjle.exe
Deleted
C:\WINDOWS\inet20026\killer.exe
Infected with: Trojan.Killer
C:\WINDOWS\inet20026\killer.exe
Disinfection failed
C:\WINDOWS\inet20026\killer.exe
Deleted
C:\WINDOWS\system32\0mcamcap.exe
Infected with: Trojan.Proxy.Small.BO
C:\WINDOWS\system32\0mcamcap.exe
Deleted
C:\WINDOWS\system32\dlh9jkdq1.exe
Infected with: Trojan.Downloader.CZO
C:\WINDOWS\system32\dlh9jkdq1.exe
Disinfection failed
C:\WINDOWS\system32\dlh9jkdq1.exe
Deleted
C:\WINDOWS\system32\dlh9jkdq2.exe
Infected with: Backdoor.Braventry.A
C:\WINDOWS\system32\dlh9jkdq2.exe
Disinfection failed
C:\WINDOWS\system32\dlh9jkdq2.exe
Deleted
C:\WINDOWS\system32\drivers\ntndis.exe
Infected with: Generic.Malware.GIFMY.37A5D78A
C:\WINDOWS\system32\drivers\ntndis.exe
Disinfection failed
C:\WINDOWS\system32\drivers\ntndis.exe
Deleted
C:\WINDOWS\system32\inetsec.exe
Infected with: GenPack:Backdoor.SDBot.F3D4DA9D
C:\WINDOWS\system32\inetsec.exe
Disinfection failed
C:\WINDOWS\system32\inetsec.exe
Delete failed
C:\WINDOWS\system32\taskmgn.exe
Suspected of: BehavesLike:Win32.Backdoor
C:\WINDOWS\system32\taskmgn.exe
Disinfection failed
C:\WINDOWS\system32\taskmgn.exe
Delete failed
C:\WINDOWS\system32\wnsec.exe
Infected with: GenPack:Backdoor.SDBot.4E890FF4
C:\WINDOWS\system32\wnsec.exe
Disinfection failed
C:\WINDOWS\system32\wnsec.exe
Delete failed
C:\WINDOWS\xpupdate.exe
Infected with: Backdoor.Braventry.A
C:\WINDOWS\xpupdate.exe
Disinfection failed
C:\WINDOWS\xpupdate.exe
Deleted
C:\wovgfs.exe
Infected with: Trojan.ProcKill.DJ
C:\wovgfs.exe
Deleted
canned File
Status
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\DTLJBIAE\ehaopdu[1].txt
Infected with: Trojan.Startpage.LG
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\DTLJBIAE\ehaopdu[1].txt
Disinfection failed
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\DTLJBIAE\ehaopdu[1].txt
Deleted
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\DTLJBIAE\gltom[1].txt
Suspected of: BehavesLike:Win32.Backdoor
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\DTLJBIAE\gltom[1].txt
Disinfection failed
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\DTLJBIAE\gltom[1].txt
Deleted
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\DTLJBIAE\uqlwy[1].txt
Infected with: Trojan.PWS.Sinowal.M
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\DTLJBIAE\uqlwy[1].txt
Deleted
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\FVTUPZ9P\cbyzqvnd[1].htm
Infected with: Trojan.ProcKill.DJ
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\FVTUPZ9P\cbyzqvnd[1].htm
Deleted
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\FVTUPZ9P\guzdemak[1].txt
Infected with: Trojan.Downloader.Small.AID
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\FVTUPZ9P\guzdemak[1].txt
Disinfection failed
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\FVTUPZ9P\guzdemak[1].txt
Deleted
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\K07HU1EU\ghxgzrz[1].txt
Infected with: Trojan.Proxy.Small.BO
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\K07HU1EU\ghxgzrz[1].txt
Deleted
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\K07HU1EU\rxlzeqh[1].htm
Infected with: Trojan.SpySheriff.C
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\K07HU1EU\rxlzeqh[1].htm
Disinfection failed
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\K07HU1EU\rxlzeqh[1].htm
Deleted
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\OMNXMTX1\oisgkczyu[2].txt
Infected with: Trojan.PWS.LDPinch.NG
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\OMNXMTX1\oisgkczyu[2].txt
Disinfection failed
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\OMNXMTX1\oisgkczyu[2].txt
Deleted
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\OMNXMTX1\tytrzlkz[2].txt
Infected with: Trojan.FakeAlert.CC
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\OMNXMTX1\tytrzlkz[2].txt
Disinfection failed
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\OMNXMTX1\tytrzlkz[2].txt
Deleted
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\OMNXMTX1\ynhmanfnj[1].txt
Infected with: Trojan.Clicker.Small.KR
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\OMNXMTX1\ynhmanfnj[1].txt
Deleted
C:\ibltyilp.exe
Suspected of: BehavesLike:Win32.Backdoor
C:\ibltyilp.exe
Disinfection failed
C:\ibltyilp.exe
Deleted
C:\ilyms.exe
Infected with: Trojan.ProcKill.DJ
C:\ilyms.exe
Deleted
C:\jalu.exe
Suspected of: BehavesLike:Win32.Backdoor
C:\jalu.exe
Disinfection failed
C:\jalu.exe
Deleted
C:\jispoi.exe
Infected with: Trojan.ProcKill.DJ
C:\jispoi.exe
Deleted
C:\Program Files\Fichiers communs\Microsoft Shared\Web Folders\ibm00003.exe
Infected with: Trojan.PWS.Sinowal.Q
C:\Program Files\Fichiers communs\Microsoft Shared\Web Folders\ibm00003.exe
Disinfection failed
C:\Program Files\Fichiers communs\Microsoft Shared\Web Folders\ibm00003.exe
Deleted
C:\Program Files\secure32.html
Infected with: Trojan.SpySheriff.C
C:\Program Files\secure32.html
Disinfection failed
C:\Program Files\secure32.html
Deleted
C:\secure32.html
Infected with: Trojan.SpySheriff.C
C:\secure32.html
Disinfection failed
C:\secure32.html
Deleted
C:\vxcvjle.exe
Infected with: Trojan.ProcKill.DJ
C:\vxcvjle.exe
Deleted
C:\WINDOWS\inet20026\killer.exe
Infected with: Trojan.Killer
C:\WINDOWS\inet20026\killer.exe
Disinfection failed
C:\WINDOWS\inet20026\killer.exe
Deleted
C:\WINDOWS\system32\0mcamcap.exe
Infected with: Trojan.Proxy.Small.BO
C:\WINDOWS\system32\0mcamcap.exe
Deleted
C:\WINDOWS\system32\dlh9jkdq1.exe
Infected with: Trojan.Downloader.CZO
C:\WINDOWS\system32\dlh9jkdq1.exe
Disinfection failed
C:\WINDOWS\system32\dlh9jkdq1.exe
Deleted
C:\WINDOWS\system32\dlh9jkdq2.exe
Infected with: Backdoor.Braventry.A
C:\WINDOWS\system32\dlh9jkdq2.exe
Disinfection failed
C:\WINDOWS\system32\dlh9jkdq2.exe
Deleted
C:\WINDOWS\system32\drivers\ntndis.exe
Infected with: Generic.Malware.GIFMY.37A5D78A
C:\WINDOWS\system32\drivers\ntndis.exe
Disinfection failed
C:\WINDOWS\system32\drivers\ntndis.exe
Deleted
C:\WINDOWS\system32\inetsec.exe
Infected with: GenPack:Backdoor.SDBot.F3D4DA9D
C:\WINDOWS\system32\inetsec.exe
Disinfection failed
C:\WINDOWS\system32\inetsec.exe
Delete failed
C:\WINDOWS\system32\taskmgn.exe
Suspected of: BehavesLike:Win32.Backdoor
C:\WINDOWS\system32\taskmgn.exe
Disinfection failed
C:\WINDOWS\system32\taskmgn.exe
Delete failed
C:\WINDOWS\system32\wnsec.exe
Infected with: GenPack:Backdoor.SDBot.4E890FF4
C:\WINDOWS\system32\wnsec.exe
Disinfection failed
C:\WINDOWS\system32\wnsec.exe
Delete failed
C:\WINDOWS\xpupdate.exe
Infected with: Backdoor.Braventry.A
C:\WINDOWS\xpupdate.exe
Disinfection failed
C:\WINDOWS\xpupdate.exe
Deleted
C:\wovgfs.exe
Infected with: Trojan.ProcKill.DJ
C:\wovgfs.exe
Deleted
BOnjour à tous désolé de n'avoir pas pu répondre avant, boulot...Famille !
Voila le rapport Kasperky:
Total number of scanned objects 20319
Number of viruses found 3
Number of infected objects 15
Number of suspicious objects 0
Duration of the scan process 00:06:07
Infected Object Name Virus Name Last Action
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\FVTUPZ9P\z[2].jpg/stream/data0001 Infected: Trojan-Downloader.Win32.Harnig.bq skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\FVTUPZ9P\z[2].jpg/stream Infected: Trojan-Downloader.Win32.Harnig.bq skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\FVTUPZ9P\z[2].jpg NSIS: infected - 2 skipped
C:\Program Files\Fichiers communs\Microsoft Shared\Web Folders\ibm00001.exe Infected: Trojan-PSW.Win32.Sinowal.p skipped
C:\Program Files\Fichiers communs\Microsoft Shared\Web Folders\ibm00002.dll Infected: Trojan-PSW.Win32.Sinowal.p skipped
C:\Program Files\Fichiers communs\Microsoft Shared\Web Folders\_ibm00003.exe Infected: Trojan-PSW.Win32.Sinowal.p skipped
C:\Program Files\Fichiers communs\Microsoft Shared\Web Folders\_ibm00013.exe Infected: Trojan-PSW.Win32.Sinowal.p skipped
C:\Program Files\Fichiers communs\Microsoft Shared\Web Folders\_ibm00030.exe Infected: Trojan-PSW.Win32.Sinowal.p skipped
C:\Program Files\Fichiers communs\Microsoft Shared\Web Folders\_ibm00035.exe Infected: Trojan-PSW.Win32.Sinowal.p skipped
C:\Program Files\Fichiers communs\Microsoft Shared\Web Folders\_ibm00044.exe Infected: Trojan-PSW.Win32.Sinowal.p skipped
C:\Program Files\Fichiers communs\Microsoft Shared\Web Folders\_ibm00047.exe Infected: Trojan-PSW.Win32.Sinowal.p skipped
C:\WINDOWS\system32\ipod.raw.exe Infected: Packed.Win32.Tibs skipped
C:\WINDOWS\system32\taskdir.exe Infected: Packed.Win32.Tibs skipped
C:\WINDOWS\system32\taskdir~.exe Infected: Packed.Win32.Tibs skipped
C:\WINDOWS\Temp\adv.exe Infected: Trojan-Downloader.Win32.Harnig.bq skipped
Scan process completed.
Et le dernier Hijack:
Logfile of HijackThis v1.99.1
Scan saved at 08:54:58, on 20/05/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\windows\system32\taskmgn.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\WINDOWS\system32\inetsec.exe
C:\WINDOWS\system32\wnsec.exe
C:\Program Files\Mozilla Firefox\firefox.exe
c:\Program Files\nubnc.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Hijackthis Version Française\VERSION TRADUITE ORIGINALE.EXE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: HBO Class - {5321E378-FFAD-4999-8C62-03CA8155F0B3} - C:\WINDOWS\inet20026\3.03.00.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [Windows Task Manager] c:\windows\system32\taskmgn.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SysTray] c:\Program Files\nubnc.exe
O4 - HKLM\..\Run: [ed95706d.exe] C:\WINDOWS\System32\ed95706d.exe
O4 - HKCU\..\Run: [1803f591.exe] C:\Documents and Settings\gilou\Local Settings\Application Data\1803f591.exe
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{03386F13-C9D1-4C1D-A0B5-F4D573E3FFD9}: NameServer = 86.64.145.146 84.103.237.146
O17 - HKLM\System\CCS\Services\Tcpip\..\{039AC7EB-12B4-40C0-8EB8-27F95CCB930D}: NameServer = 86.64.145.140,84.103.237.140
O17 - HKLM\System\CS1\Services\Tcpip\..\{03386F13-C9D1-4C1D-A0B5-F4D573E3FFD9}: NameServer = 86.64.145.146 84.103.237.146
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: 20242402reg - C:\Documents and Settings\All Users\Documents\Settings\20242402.dll
O20 - Winlogon Notify: mmxeroxk - mmxeroxk.dll (file missing)
O20 - Winlogon Notify: SensSrv - senssrv.dll (file missing)
O21 - SSODL: SysTray.Exbr - {6368D1FC-6F5C-4f1b-B164-E67214F678E9} - (no file)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
Voila le rapport Kasperky:
Total number of scanned objects 20319
Number of viruses found 3
Number of infected objects 15
Number of suspicious objects 0
Duration of the scan process 00:06:07
Infected Object Name Virus Name Last Action
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\FVTUPZ9P\z[2].jpg/stream/data0001 Infected: Trojan-Downloader.Win32.Harnig.bq skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\FVTUPZ9P\z[2].jpg/stream Infected: Trojan-Downloader.Win32.Harnig.bq skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\FVTUPZ9P\z[2].jpg NSIS: infected - 2 skipped
C:\Program Files\Fichiers communs\Microsoft Shared\Web Folders\ibm00001.exe Infected: Trojan-PSW.Win32.Sinowal.p skipped
C:\Program Files\Fichiers communs\Microsoft Shared\Web Folders\ibm00002.dll Infected: Trojan-PSW.Win32.Sinowal.p skipped
C:\Program Files\Fichiers communs\Microsoft Shared\Web Folders\_ibm00003.exe Infected: Trojan-PSW.Win32.Sinowal.p skipped
C:\Program Files\Fichiers communs\Microsoft Shared\Web Folders\_ibm00013.exe Infected: Trojan-PSW.Win32.Sinowal.p skipped
C:\Program Files\Fichiers communs\Microsoft Shared\Web Folders\_ibm00030.exe Infected: Trojan-PSW.Win32.Sinowal.p skipped
C:\Program Files\Fichiers communs\Microsoft Shared\Web Folders\_ibm00035.exe Infected: Trojan-PSW.Win32.Sinowal.p skipped
C:\Program Files\Fichiers communs\Microsoft Shared\Web Folders\_ibm00044.exe Infected: Trojan-PSW.Win32.Sinowal.p skipped
C:\Program Files\Fichiers communs\Microsoft Shared\Web Folders\_ibm00047.exe Infected: Trojan-PSW.Win32.Sinowal.p skipped
C:\WINDOWS\system32\ipod.raw.exe Infected: Packed.Win32.Tibs skipped
C:\WINDOWS\system32\taskdir.exe Infected: Packed.Win32.Tibs skipped
C:\WINDOWS\system32\taskdir~.exe Infected: Packed.Win32.Tibs skipped
C:\WINDOWS\Temp\adv.exe Infected: Trojan-Downloader.Win32.Harnig.bq skipped
Scan process completed.
Et le dernier Hijack:
Logfile of HijackThis v1.99.1
Scan saved at 08:54:58, on 20/05/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\windows\system32\taskmgn.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\WINDOWS\system32\inetsec.exe
C:\WINDOWS\system32\wnsec.exe
C:\Program Files\Mozilla Firefox\firefox.exe
c:\Program Files\nubnc.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Hijackthis Version Française\VERSION TRADUITE ORIGINALE.EXE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: HBO Class - {5321E378-FFAD-4999-8C62-03CA8155F0B3} - C:\WINDOWS\inet20026\3.03.00.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [Windows Task Manager] c:\windows\system32\taskmgn.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SysTray] c:\Program Files\nubnc.exe
O4 - HKLM\..\Run: [ed95706d.exe] C:\WINDOWS\System32\ed95706d.exe
O4 - HKCU\..\Run: [1803f591.exe] C:\Documents and Settings\gilou\Local Settings\Application Data\1803f591.exe
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{03386F13-C9D1-4C1D-A0B5-F4D573E3FFD9}: NameServer = 86.64.145.146 84.103.237.146
O17 - HKLM\System\CCS\Services\Tcpip\..\{039AC7EB-12B4-40C0-8EB8-27F95CCB930D}: NameServer = 86.64.145.140,84.103.237.140
O17 - HKLM\System\CS1\Services\Tcpip\..\{03386F13-C9D1-4C1D-A0B5-F4D573E3FFD9}: NameServer = 86.64.145.146 84.103.237.146
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: 20242402reg - C:\Documents and Settings\All Users\Documents\Settings\20242402.dll
O20 - Winlogon Notify: mmxeroxk - mmxeroxk.dll (file missing)
O20 - Winlogon Notify: SensSrv - senssrv.dll (file missing)
O21 - SSODL: SysTray.Exbr - {6368D1FC-6F5C-4f1b-B164-E67214F678E9} - (no file)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
Hello,
Voici les deux rapports que j'ais obtenu, j'attends votre aide.
Merci d'avance
SmitFraudFix v2.44
Rapport fait à 14:42:06,37, 20/05/2006
Executé à partir de C:\Documents and Settings\gilou\Mes documents\SmitfraudFix
OS: Microsoft Windows XP [version 5.1.2600]
»»»»»»»»»»»»»»»»»»»»»»»» C:\
C:\exit PRESENT !
C:\secure32.html PRESENT !
C:\uniq PRESENT !
C:\winstall.exe PRESENT !
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32
C:\WINDOWS\system32\dlh9jkdq?.exe PRESENT !
C:\WINDOWS\system32\taskdir.exe PRESENT !
C:\WINDOWS\system32\taskdir~.exe PRESENT !
C:\WINDOWS\system32\vxgame?.exe PRESENT !
C:\WINDOWS\system32\vxgame?.exe????.exe PRESENT !
C:\WINDOWS\system32\winbrume.dll PRESENT !
C:\WINDOWS\system32\zlbw.dll PRESENT !
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\gilou\Application Data
»»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer
»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\gilou\Favoris
»»»»»»»»»»»»»»»»»»»»»»»» Bureau
»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files
C:\Program Files\secure32.html PRESENT !
»»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues
»»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau
»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll
»»»»»»»»»»»»»»»»»»»»»»»» Fin
SmitFraudFix v2.44
Rapport fait à 14:43:36,54, 20/05/2006
Executé à partir de C:\Documents and Settings\gilou\Mes documents\SmitfraudFix
OS: Microsoft Windows XP [version 5.1.2600]
»»»»»»»»»»»»»»»»»»»»»»»» Arret des processus
»»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés
C:\exit supprimé
C:\secure32.html supprimé
C:\uniq supprimé
C:\winstall.exe supprimé
C:\WINDOWS\system32\dlh9jkdq?.exe supprimé
C:\WINDOWS\system32\taskdir.exe supprimé
C:\WINDOWS\system32\taskdir~.exe supprimé
C:\WINDOWS\system32\vxgame?.exe supprimé
C:\WINDOWS\system32\vxgame?.exe????.exe supprimé
C:\WINDOWS\system32\winbrume.dll supprimé
C:\WINDOWS\system32\zlbw.dll supprimé
C:\Program Files\secure32.html supprimé
»»»»»»»»»»»»»»»»»»»»»»»» Suppression Fichiers Temporaires
»»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre
Nettoyage terminé.
»»»»»»»»»»»»»»»»»»»»»»»» Fin
Voici les deux rapports que j'ais obtenu, j'attends votre aide.
Merci d'avance
SmitFraudFix v2.44
Rapport fait à 14:42:06,37, 20/05/2006
Executé à partir de C:\Documents and Settings\gilou\Mes documents\SmitfraudFix
OS: Microsoft Windows XP [version 5.1.2600]
»»»»»»»»»»»»»»»»»»»»»»»» C:\
C:\exit PRESENT !
C:\secure32.html PRESENT !
C:\uniq PRESENT !
C:\winstall.exe PRESENT !
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32
C:\WINDOWS\system32\dlh9jkdq?.exe PRESENT !
C:\WINDOWS\system32\taskdir.exe PRESENT !
C:\WINDOWS\system32\taskdir~.exe PRESENT !
C:\WINDOWS\system32\vxgame?.exe PRESENT !
C:\WINDOWS\system32\vxgame?.exe????.exe PRESENT !
C:\WINDOWS\system32\winbrume.dll PRESENT !
C:\WINDOWS\system32\zlbw.dll PRESENT !
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\gilou\Application Data
»»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer
»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\gilou\Favoris
»»»»»»»»»»»»»»»»»»»»»»»» Bureau
»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files
C:\Program Files\secure32.html PRESENT !
»»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues
»»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau
»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll
»»»»»»»»»»»»»»»»»»»»»»»» Fin
SmitFraudFix v2.44
Rapport fait à 14:43:36,54, 20/05/2006
Executé à partir de C:\Documents and Settings\gilou\Mes documents\SmitfraudFix
OS: Microsoft Windows XP [version 5.1.2600]
»»»»»»»»»»»»»»»»»»»»»»»» Arret des processus
»»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés
C:\exit supprimé
C:\secure32.html supprimé
C:\uniq supprimé
C:\winstall.exe supprimé
C:\WINDOWS\system32\dlh9jkdq?.exe supprimé
C:\WINDOWS\system32\taskdir.exe supprimé
C:\WINDOWS\system32\taskdir~.exe supprimé
C:\WINDOWS\system32\vxgame?.exe supprimé
C:\WINDOWS\system32\vxgame?.exe????.exe supprimé
C:\WINDOWS\system32\winbrume.dll supprimé
C:\WINDOWS\system32\zlbw.dll supprimé
C:\Program Files\secure32.html supprimé
»»»»»»»»»»»»»»»»»»»»»»»» Suppression Fichiers Temporaires
»»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre
Nettoyage terminé.
»»»»»»»»»»»»»»»»»»»»»»»» Fin
Désolé de n'avoir pas pu poster avant j'étais au travail :
Logfile of HijackThis v1.99.1
Scan saved at 19:47:57, on 20/05/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\savedump.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\windows\system32\taskmgn.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\WINDOWS\system32\inetsec.exe
C:\WINDOWS\system32\wnsec.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\Program Files\Hijackthis Version Française\VERSION TRADUITE ORIGINALE.EXE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [Windows Task Manager] c:\windows\system32\taskmgn.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [ed95706d.exe] C:\WINDOWS\System32\ed95706d.exe
O4 - HKCU\..\Run: [1803f591.exe] C:\Documents and Settings\gilou\Local Settings\Application Data\1803f591.exe
O4 - HKCU\..\Run: [ed95706d.exe] C:\Documents and Settings\gilou\Local Settings\Application Data\ed95706d.exe
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{03386F13-C9D1-4C1D-A0B5-F4D573E3FFD9}: NameServer = 84.103.237.141 86.64.145.141
O17 - HKLM\System\CCS\Services\Tcpip\..\{039AC7EB-12B4-40C0-8EB8-27F95CCB930D}: NameServer = 86.64.145.140,84.103.237.140
O17 - HKLM\System\CS1\Services\Tcpip\..\{03386F13-C9D1-4C1D-A0B5-F4D573E3FFD9}: NameServer = 84.103.237.141 86.64.145.141
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: 20242402reg - C:\Documents and Settings\All Users\Documents\Settings\20242402.dll
O20 - Winlogon Notify: mmxeroxk - mmxeroxk.dll (file missing)
O20 - Winlogon Notify: SensSrv - senssrv.dll (file missing)
O20 - Winlogon Notify: xdudtt - C:\WINDOWS\SYSTEM32\xdudtt.dll
O21 - SSODL: SysTray.Exbr - {6368D1FC-6F5C-4f1b-B164-E67214F678E9} - (no file)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
Merciiiii de votre aide !
Logfile of HijackThis v1.99.1
Scan saved at 19:47:57, on 20/05/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\savedump.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\windows\system32\taskmgn.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\WINDOWS\system32\inetsec.exe
C:\WINDOWS\system32\wnsec.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\Program Files\Hijackthis Version Française\VERSION TRADUITE ORIGINALE.EXE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [Windows Task Manager] c:\windows\system32\taskmgn.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [ed95706d.exe] C:\WINDOWS\System32\ed95706d.exe
O4 - HKCU\..\Run: [1803f591.exe] C:\Documents and Settings\gilou\Local Settings\Application Data\1803f591.exe
O4 - HKCU\..\Run: [ed95706d.exe] C:\Documents and Settings\gilou\Local Settings\Application Data\ed95706d.exe
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{03386F13-C9D1-4C1D-A0B5-F4D573E3FFD9}: NameServer = 84.103.237.141 86.64.145.141
O17 - HKLM\System\CCS\Services\Tcpip\..\{039AC7EB-12B4-40C0-8EB8-27F95CCB930D}: NameServer = 86.64.145.140,84.103.237.140
O17 - HKLM\System\CS1\Services\Tcpip\..\{03386F13-C9D1-4C1D-A0B5-F4D573E3FFD9}: NameServer = 84.103.237.141 86.64.145.141
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: 20242402reg - C:\Documents and Settings\All Users\Documents\Settings\20242402.dll
O20 - Winlogon Notify: mmxeroxk - mmxeroxk.dll (file missing)
O20 - Winlogon Notify: SensSrv - senssrv.dll (file missing)
O20 - Winlogon Notify: xdudtt - C:\WINDOWS\SYSTEM32\xdudtt.dll
O21 - SSODL: SysTray.Exbr - {6368D1FC-6F5C-4f1b-B164-E67214F678E9} - (no file)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
Merciiiii de votre aide !
re
bon là on s'en sort pas parce que tu n'as NI parefeu NI mise à jour de windows
http://users.skynet.be/BernieClub/index.html#tutor
installe ZoneAlarm ou Outpost ou Kério
et stp met à jour windows SP1 si peu de RAM ou SP2 si 512 MB
a+
bon là on s'en sort pas parce que tu n'as NI parefeu NI mise à jour de windows
http://users.skynet.be/BernieClub/index.html#tutor
installe ZoneAlarm ou Outpost ou Kério
et stp met à jour windows SP1 si peu de RAM ou SP2 si 512 MB
a+