Fenetre furtive au démarrage - Page 2

Résolu
Précédent
  • 1
  • 2
  1. alexdarcy Messages postés 319 Date d'inscription   Statut Membre Dernière intervention   6
     
    boulepate salut
    le nv hijack après tes instructions :
    Logfile of HijackThis v1.99.1
    Scan saved at 17:13:00, on 04/10/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    D:\WINDOWS\System32\smss.exe
    D:\WINDOWS\system32\winlogon.exe
    D:\WINDOWS\system32\services.exe
    D:\WINDOWS\system32\lsass.exe
    D:\WINDOWS\system32\svchost.exe
    D:\WINDOWS\System32\svchost.exe
    D:\WINDOWS\system32\spoolsv.exe
    D:\WINDOWS\Explorer.EXE
    D:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
    D:\Program Files\ewido anti-spyware 4.0\ewido.exe
    D:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
    D:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
    D:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
    D:\Program Files\ewido anti-spyware 4.0\guard.exe
    D:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
    D:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    D:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
    D:\WINDOWS\system32\svchost.exe
    D:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
    D:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
    D:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCSRVCE.EXE
    D:\Program Files\Internet Explorer\iexplore.exe
    D:\Program Files\hijack\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.yahoo.fr/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: Norton Internet Security 2006 - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - D:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll
    O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - D:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: Norton Internet Security 2006 - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - D:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll
    O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - D:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
    O4 - HKLM\..\Run: [ccApp] "D:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [MaxtorOneTouch] D:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
    O4 - HKLM\..\Run: [!ewido] "D:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
    O4 - HKLM\..\Run: [TkBellExe] "D:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "D:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
    O20 - Winlogon Notify: WgaLogon - D:\WINDOWS\
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - D:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - D:\Program Files\Norton Internet Security\ccPwdSvc.exe
    O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - D:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - D:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
    O23 - Service: COM Host (comHost) - Symantec Corporation - D:\Program Files\Norton Internet Security\comHost.exe
    O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - D:\Program Files\ewido anti-spyware 4.0\guard.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - D:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
    O23 - Service: LiveUpdate - Symantec Corporation - D:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: Macromedia Licensing Service - Unknown owner - D:\Program Files\Fichiers communs\Macromedia Shared\Service\Macromedia Licensing.exe
    O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - D:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
    O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - D:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCSRVCE.EXE
    O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - D:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - D:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - D:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
    O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - D:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
    O23 - Service: Symantec Core LC - Symantec Corporation - D:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe

    Microsoft ASPI Manager a bien été désactivé.
    Quand à combifox fenetre furtive noire dos impossible a taper "Y"..

    Merci
    j'arrete et redemarre immédiatement tjrs en mode normale
    0
  2. alexdarcy Messages postés 319 Date d'inscription   Statut Membre Dernière intervention   6
     
    Mumm !! Boulepate après avoir effectué tes conseils, cette fichue fenetre apparaît toujours.
    En fait ce n'est pas une fenetre a proprement parler, mais un petit "éclair" très furtif juste après l'affichage du bureau. Le curseur se met en sablier.
    Il faut être très attentif pour voir cet "éclair".

    Dois je te ré-affichier le log de hijack ?
    Merci à toi.

    Alex
    0
  3. Utilisateur anonyme
     
    Salut,

    fais un clic droit sur hijackthis, clic sur propriétés, dans l'onglet "général" efface HijackThis et tu mets abcde puis lic sur ok

    ensuite, refais un rapport hijackthis en mode normal stp
    0
  4. alexdarcy Messages postés 319 Date d'inscription   Statut Membre Dernière intervention   6
     
    Cé fait boulepate.
    Voici le nv log de "abcde" alias hijack :
    Logfile of HijackThis v1.99.1
    Scan saved at 20:19:38, on 04/10/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    D:\WINDOWS\System32\smss.exe
    D:\WINDOWS\system32\winlogon.exe
    D:\WINDOWS\system32\services.exe
    D:\WINDOWS\system32\lsass.exe
    D:\WINDOWS\system32\svchost.exe
    D:\WINDOWS\System32\svchost.exe
    D:\WINDOWS\system32\spoolsv.exe
    D:\WINDOWS\Explorer.EXE
    D:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
    D:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
    D:\Program Files\ewido anti-spyware 4.0\ewido.exe
    D:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
    D:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
    D:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
    D:\Program Files\ewido anti-spyware 4.0\guard.exe
    D:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
    D:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    D:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
    D:\WINDOWS\system32\svchost.exe
    D:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
    D:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
    D:\WINDOWS\system32\wuauclt.exe
    D:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCSRVCE.EXE
    D:\Program Files\Internet Explorer\iexplore.exe
    D:\Program Files\Messenger\msmsgs.exe
    D:\Program Files\hijack\abcde.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: Norton Internet Security 2006 - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - D:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll
    O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - D:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: Norton Internet Security 2006 - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - D:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll
    O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - D:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
    O4 - HKLM\..\Run: [ccApp] "D:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [MaxtorOneTouch] D:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
    O4 - HKLM\..\Run: [!ewido] "D:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
    O4 - HKLM\..\Run: [TkBellExe] "D:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "D:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
    O20 - Winlogon Notify: WgaLogon - D:\WINDOWS\
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - D:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - D:\Program Files\Norton Internet Security\ccPwdSvc.exe
    O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - D:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - D:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
    O23 - Service: COM Host (comHost) - Symantec Corporation - D:\Program Files\Norton Internet Security\comHost.exe
    O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - D:\Program Files\ewido anti-spyware 4.0\guard.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - D:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
    O23 - Service: LiveUpdate - Symantec Corporation - D:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: Macromedia Licensing Service - Unknown owner - D:\Program Files\Fichiers communs\Macromedia Shared\Service\Macromedia Licensing.exe
    O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - D:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
    O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - D:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCSRVCE.EXE
    O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - D:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - D:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - D:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
    O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - D:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
    O23 - Service: Symantec Core LC - Symantec Corporation - D:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe

    a tout hasard voici aussi celui réalisé par Sbybot "Démarrage système :

    --- Spybot - Search & Destroy version: 1.4 (build: 20050523) ---

    2005-05-31 blindman.exe (1.0.0.1)
    2005-05-31 SpybotSD.exe (1.4.0.3)
    2005-05-31 TeaTimer.exe (1.4.0.2)
    2005-06-08 unins000.exe (51.41.0.0)
    2005-05-31 Update.exe (1.4.0.0)
    2006-02-06 advcheck.dll (1.0.2.0)
    2005-05-31 aports.dll (2.1.0.0)
    2005-05-31 borlndmm.dll (7.0.4.453)
    2005-05-31 delphimm.dll (7.0.4.453)
    2006-02-20 Tools.dll (2.0.0.2)
    2005-05-31 UnzDll.dll (1.73.1.1)
    2005-05-31 ZipDll.dll (1.73.2.0)
    2006-09-29 Includes\Cookies.sbi
    2006-09-29 Includes\Dialer.sbi
    2006-09-29 Includes\Hijackers.sbi
    2006-09-29 Includes\Keyloggers.sbi
    2004-11-29 Includes\LSP.sbi
    2006-09-29 Includes\Malware.sbi
    2006-09-29 Includes\PUPS.sbi
    2006-09-29 Includes\Revision.sbi
    2006-09-29 Includes\Security.sbi
    2006-09-29 Includes\Spybots.sbi
    2005-02-17 Includes\Tracks.uti
    2006-09-29 Includes\Trojans.sbi

    Located: HK_LM:Run, !ewido
    command: "D:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
    file: D:\Program Files\ewido anti-spyware 4.0\ewido.exe
    size: 6283264
    MD5: 10c40f37ac87a18f624143d4fe6e8dec

    Located: HK_LM:Run, ccApp
    command: "D:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
    file: D:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
    size: 53408
    MD5: 8c5d5b71e4e8a1fb8f1fa6cc57fe411e

    Located: HK_LM:Run, MaxtorOneTouch
    command: D:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
    file: D:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
    size: 45056
    MD5: acaf1704c5b2dfe4e2e26fd6fa9d5ff8

    Located: HK_LM:Run, TkBellExe
    command: "D:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
    file: D:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
    size: 180269
    MD5: 77ed13fd3196ebc7311ccd6899c7488c

    Located: System.ini, crypt32chain
    command: crypt32.dll
    file: crypt32.dll

    Located: System.ini, cryptnet
    command: cryptnet.dll
    file: cryptnet.dll

    Located: System.ini, cscdll
    command: cscdll.dll
    file: cscdll.dll

    Located: System.ini, ScCertProp
    command: wlnotify.dll
    file: wlnotify.dll

    Located: System.ini, Schedule
    command: wlnotify.dll
    file: wlnotify.dll

    Located: System.ini, sclgntfy
    command: sclgntfy.dll
    file: sclgntfy.dll

    Located: System.ini, SensLogn
    command: WlNotify.dll
    file: WlNotify.dll

    Located: System.ini, termsrv
    command: wlnotify.dll
    file: wlnotify.dll

    Located: System.ini, WgaLogon
    command:
    file:

    Located: System.ini, wlballoon
    command: wlnotify.dll
    file: wlnotify.dll

    Located: System.ini, WgaLogon (DISABLED)
    command: WgaLogon.dll
    file: WgaLogon.dll

    Ok
    Alex
    0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. alexdarcy Messages postés 319 Date d'inscription   Statut Membre Dernière intervention   6
     
    Bon pour les dernières news, apparement (peut-être n'ai-je pas été assez attentif) la fenetre furtive ne vient plus...

    Sinon g une alerte de Symantec (Norton).
    J'utilise Eremove pour filtrer mes mails avant ouverture, et depuis les changements je reçois l'alerte Symantec suivante :
    "Symantec User Session doit fermer. Veuillez nous excuser...", et à partir de là Eremove semble ne plus trouver les codes d'accès pour mes comptes mails.

    J'ai oublié de préciser : après l'alerte, l'icone Norton qui se trouve en bas dans la barre des tâches disparait...

    Voilà où j'en suis now.
    Dois je réinstaller Norton 2006 ?

    Merci boulepate pour tes renseignements et ton aide.
    Alex
    0
  7. Utilisateur anonyme
     
    Salut,

    désolé d'avoir oublier de répondre à ton dernier message, rapport hijackthis ok.

    Reinstalle Eremove pour voir, si le problème persiste, tu désactive tout Norton, puis essai avec Eremove, si ça fonctionne(réactive Norton), le problème vient de Norton et ça configuration à revoir sûrement
    0
  8. alexdarcy Messages postés 319 Date d'inscription   Statut Membre Dernière intervention   6
     
    PG boulepate je ne suis pas seul à te demander de l'aide lol

    En tout cas j'ai réinstallé Norton et apparement ça marche très bien, plus d'alerte Symantec ...

    Par contre et hélas je crois avoir toujours la fenetre furtive. Mais comme je te l'avais dit, impossible de voir même les bords de la fenetre, donc je ne sais pas si c'est une fenetre DOS !
    Bien que tout laisse penser à ça !

    Je pourrais dire que j'apperçois furtivement un cadre transparant s'ouvrir, c'est tout. Mais je dois être très attentif, cela intervient quelques secondes après l'affichage du bureau.

    Ok encore merci à toi de me consacrer du temps.
    Alex
    0
  9. Utilisateur anonyme
     
    je vois plus rien de suspect j'ai encore regardé

    Fait ce scan anti-virus en ligne avec Internet Explorer, accepte l'active X; la barre anti-popup du SP2 (en haut) va se mettre à clignoter, clic dessus et choisis "accepter l'active X" pour faire fonctionner le scan anti-virus.
    Une fois qu'il a terminé colle le rapport ici stp

    https://www.bitdefender.com/toolbox/
    0
Précédent
  • 1
  • 2