Multiple infection

Fermé
cathar6 - 31 déc. 2006 à 12:47
 Utilisateur anonyme - 5 janv. 2007 à 11:42
bonjour a tous ! j'ai fait un scan avec spyware nuker XT et j'ai été etonnée de voir tout ce qu'il ma trouvé , pouvez vous m'aidez a m'en débarrassez !!

merci infiniment

Spyware Nuker XT Detection Report
Scan Started:
12/31/2006 11:23
Software Version:
4.8.77.1815
Database Version:
12/11/2006 09:41:36 AM
Operating System:
Windows XP 5.1.2600 [Service Pack 1]
Web Browser(s):
IE:6.0.2800.1106;FF:1.5.0.9 (fr);
24/7 RealMedia
960-55877
A cookie that is shared among websites to track your web surfing habits.
Cookie

Mozilla Firefox | .247realmedia.com/ | 548595 | 20
Cookie

Mozilla Firefox | .247realmedia.com/ | itcanban | 1
Cookie

Mozilla Firefox | .247realmedia.com/ | RMFD | 011H0lmaO1...
Cookie

Mozilla Firefox | .247realmedia.com/ | RMID | 56cac73145...
Cookie

Mozilla Firefox | .247realmedia.com/ | wub1206 | 4
Cookie

Mozilla Firefox | .247realmedia.com/ | wumb1206 | 4
2o7
669-33236
A cookie that is shared among websites to track your web surfing habits.
Cookie

Mozilla Firefox | .msnportal.112.2o7.net/ | s_vi | [CS]v1|459...
Cookie

Mozilla Firefox | .sfr.122.2o7.net/ | s_vi | [CS]v1|459...
Advertising.com
679-1710
A cookie that is shared among websites to track your web surfing habits.
Cookie

Mozilla Firefox | .advertising.com/ | ACID | cc50001167...
Cookie

Mozilla Firefox | .advertising.com/ | BASE | 66gkFfd9ym...
Cookie

Mozilla Firefox | .advertising.com/ | F1 | B88zWWEBAA...
Cookie

Mozilla Firefox | .advertising.com/ | ROLL | Z+vdvb/ua7...
Adware.MediaTickets
646-22651
Silently connects to its controlling servers where it downloads files. May display pop-up advertisements.
Registry Key

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/CONFLICT.1/MediaTicketsInstaller.ocx
Registry Value

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/CONFLICT.1/MediaTicketsInstaller.ocx:.Owner
Registry Value

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/CONFLICT.1/MediaTicketsInstaller.ocx:{9EB320CE-BE1D-4304-A081-4B4665414BEF}
File

C:\WINDOWS\System32\oi-uninstaller.ico
Bluestreak
819-49880
A cookie that is shared among websites to track your web surfing habits.
Cookie

Mozilla Firefox | .bluestreak.com/ | id | 4373208768...
CashEngines
968-55887
A cookie that is shared among websites to track your web surfing habits.
Cookie

Mozilla Firefox | click.cashengines.com/ | Click | 7e69bf63-f...
CoolWebSearch
539-53077
Hijacks browser settings and redirects traffic to a search portal site.
File

C:\tmp.txt
DoubleClick
446-2378
A cookie that is shared among websites to track your web surfing habits.
Cookie

Mozilla Firefox | .doubleclick.net/ | id | 800000b3f9...
EyeBlaster
979-55898
A cookie that is shared among websites to track your web surfing habits.
Cookie

Mozilla Firefox | .serving-sys.com/ | A1 | 1gNk2bPO03...
Cookie

Mozilla Firefox | .serving-sys.com/ | B1 | 0FWV08885Q
Cookie

Mozilla Firefox | .serving-sys.com/ | C1 | 07Rh8885Q%...
Cookie

Mozilla Firefox | .serving-sys.com/ | D1 | 07Rh018y88...
Cookie

Mozilla Firefox | .serving-sys.com/ | E1 | 03c08885Q
Fast Click
438-2102
A cookie that is shared among websites to track your web surfing habits.
Cookie

Mozilla Firefox | .fastclick.net/ | m1 | d101289:1:...
Cookie

Mozilla Firefox | .fastclick.net/ | m3 | d101291:1:...
Cookie

Mozilla Firefox | .fastclick.net/ | m6 | 66745:1:13...
Cookie

Mozilla Firefox | .fastclick.net/ | pluto | 22020772-e...
HitBox
447-2382
A cookie that is shared among websites to track your web surfing habits.
Cookie

Mozilla Firefox | .hitbox.com/ | CTG | 1167511160
Cookie

Mozilla Firefox | .ehg-logantod.hitbox.com/ | DM56031688NVV6 | V1eB(#X"rz...
Cookie

Mozilla Firefox | .hitbox.com/ | WSS_GW | V1z%%e@Q%%...
Keylogger.Msconfg
1168-62254
Logs all keystrokes and sends them to its server. Silently attempts to infect other computers on the network.
Registry Value

HKEY_CURRENT_USER\Software\Microsoft\OLE:Microsoft Update 32
Registry Value

HKEY_USERS\.DEFAULT\Software\Microsoft\OLE:Microsoft Update 32
Registry Value

HKEY_USERS\S-1-5-18\Software\Microsoft\OLE:Microsoft Update 32
Malware.win32ssr
1210-62631
Lowers system security settings. Makes connections to the internet and downloads other bad files. Attempts to infect other computers on a local network by scanning local IP addresses.
File

C:\WINDOWS\System32\SVKP.sys
MediaPlex
448-2383
A cookie that is shared among websites to track your web surfing habits.
Cookie

Mozilla Firefox | .mediaplex.com/ | svid | 5259884295
SpyAnytime
1107
Spy software which silently logs keystrokes and monitors computer activity.
File

C:\Program Files\Fichiers communs\Logitech\QCDriver\ijl11.dll
TradeDoubler
1009-56791
A cookie that is shared among websites to track your web surfing habits.
Cookie

Mozilla Firefox | .tradedoubler.com/ | TD_PIC | 988046*5Z1...
Cookie

Mozilla Firefox | .tradedoubler.com/ | TD_UNIQUE_IMP | 463a368121...
Trojan.Lsass
1156-61522
Silently connects to a remote location where it downloads other files. Opens certain ports and attempts to disable certain security features on an infected computer. May cause your system to shutdown.
Registry Value

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks:{00DBDAC8-4691-4797-8E6A-7C6AB89BC441}
Registry Key

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\lsass
Registry Value

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\lsass:Description
Registry Value

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\lsass:DisplayName
Registry Value

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\lsass:ErrorControl
Registry Value

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\lsass:FailureActions
Registry Value

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\lsass:ObjectName
Registry Value

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\lsass:Start
Registry Value

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\lsass:Type
Registry Key

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\lsass\Security
Registry Value

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\lsass\Security:Security
Registry Key

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lsass
Registry Value

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lsass:Description
Registry Value

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lsass:DisplayName
Registry Value

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lsass:ErrorControl
Registry Value

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lsass:FailureActions
Registry Value

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lsass:ObjectName
Registry Value

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lsass:Start
Registry Value

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lsass:Type
Registry Key

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lsass\Enum
Registry Value

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lsass\Enum:0
Registry Value

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lsass\Enum:Count
Registry Value

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lsass\Enum:NextInstance
Registry Key

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lsass\Security
Registry Value

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lsass\Security:Security
Registry Key

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\rdriv
Registry Value

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\rdriv:DisplayName
Registry Value

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\rdriv:ErrorControl
Registry Value

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\rdriv:Start
Registry Value

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\rdriv:Type
Registry Key

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\rdriv\Security
Registry Value

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\rdriv\Security:Security
Registry Key

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rdriv
Registry Value

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rdriv:DisplayName
Registry Value

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rdriv:ErrorControl
Registry Value

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rdriv:Start
Registry Value

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rdriv:Type
Registry Key

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rdriv\Security
Registry Value

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rdriv\Security:Security
Trojan.msmsgs
1123-60562
Silently connects to it's controlling server where it transmits information, recieves instructions, and downloads other files. Hijacks IE's homepage as well as Windows desktop and changes IE's Security and ZoneMap settings.
Registry Value

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\Range10::Range:85.255.117.243
aQuantive
978-2354
A cookie that is shared among websites to track your web surfing habits.
Cookie

Mozilla Firefox | .atdmt.com/ | AA002 | 1167420813...

49 réponses

Utilisateur anonyme
31 déc. 2006 à 13:33
Hum...
d'abord une chose à chaque fois que tu surf sur le Net, prend l'habitude de nettoyer ton pc quand tu rentres chez toi (bureau XP) ....un peu comme quand tu t'essuyes les pieds quand tu rentres à la maison !
Je te conseille ATF cleaner:
Il fait partie du kit de téléchargement que dois downloader pour nettoyer ton pc:
https://leblogdeclaude.blogspot.com/2006/10/informatique-procdure-de-nettoyage.html
Et je te conseille de nettoyer ton pc en faisant cette procédure calmement et dans l'ordre.
Ensuite tu feras cei:
https://leblogdeclaude.blogspot.com/2006/10/informatique-section-hijackthis.html
0
Logfile of HijackThis v1.99.1
Scan saved at 15:38:25, on 31/12/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Executive Software\DiskeeperWorkstation\DKService.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\Ontrack\SYSTEM~1\mxtask.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\PROGRA~1\Softwin\BITDEF~1\bdnagent.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Documents and Settings\sabrina\Bureau\Nouveau dossier (2)\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: Humour Toolbar - {B7D3E479-CC68-42B5-A338-938ECE35F419} - (no file)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\karim\SPYBOT~1\SDHelper.dll
O2 - BHO: XBTP03387 - {70F76008-A8D9-4d5f-ABB7-3395612738F8} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [SpyCatcher Reminder] "C:\Program Files\SpyCatcher 2006\SpyCatcher.exe" reminder
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [BDNewsAgent] "C:\PROGRA~1\Softwin\BITDEF~1\bdnagent.exe"
O4 - HKLM\..\Run: [BDMCon] C:\PROGRA~1\Softwin\BITDEF~1\bdmcon.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.6962\GoogleToolbarNotifier.exe
O4 - Global Startup: SpyCatcher Protector.lnk = C:\Program Files\SpyCatcher 2006\Protector.exe
O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: Easy-WebPrint Ajouter à la liste d'impressions - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint Impression rapide - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Imprimer - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O8 - Extra context menu item: Easy-WebPrint Prévisualiser - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Humour Toolbar - {B7D3E479-CC68-42B5-A338-938ECE35F419} - (no file)
O9 - Extra 'Tools' menuitem: Humour Toolbar - {B7D3E479-CC68-42B5-A338-938ECE35F419} - (no file)
O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - www.wanadoo.fr (file missing) (HKCU)
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
O17 - HKLM\System\CCS\Services\Tcpip\..\{2A8FAC4D-E9F0-408B-90AE-476BD8306011}: NameServer = 80.10.246.130 80.10.246.3
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: interceptor.dll C:\PROGRA~1\Google\GOOGLE~4\GOEC62~1.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe" /service (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\DiskeeperWorkstation\DKService.exe
O23 - Service: ewido anti-spyware 4.0 guard - Unknown owner - (no file)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
O23 - Service: LicCtrl Service (LicCtrlService) - Unknown owner - rundll32.exe (file missing)
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
O23 - Service: SystemSuite Task Manager - Ontrack Data International - C:\PROGRA~1\Ontrack\SYSTEM~1\mxtask.exe
O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\Program Files\TuneUp Utilities 2006\WinStylerThemeSvc.exe
0
Utilisateur anonyme
31 déc. 2006 à 15:45
Si je ne m'abuse je demande de renommer Hijackthis...
C:\Documents and Settings\sabrina\Bureau\Nouveau dossier (2)\HijackThis.exe
Je te remercie.
Certains virus détectent Hijackthis.....
https://leblogdeclaude.blogspot.com/2006/10/informatique-section-hijackthis.html
Refaits un log Hijackthis.
-------------------------------------------------------------------------
Ne jamais mettre deux anti-virus sur un pc.
Désinstalles Avast, garde Bitdefender.
Ne démarres pas ewido en prime, s'en servir juste pour un scan éventuel.
Probablement une case à décocher dans les paramètres.
O23 - Service: ewido anti-spyware 4.0 guard - Unknown owner - (no file)

0
ok voici le nouveau alors :

Logfile of HijackThis v1.99.1
Scan saved at 16:14:59, on 31/12/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Executive Software\DiskeeperWorkstation\DKService.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\Ontrack\SYSTEM~1\mxtask.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\PROGRA~1\Softwin\BITDEF~1\bdnagent.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Documents and Settings\sabrina\Bureau\Nouveau dossier (2)\metin !!.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: Humour Toolbar - {B7D3E479-CC68-42B5-A338-938ECE35F419} - (no file)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\karim\SPYBOT~1\SDHelper.dll
O2 - BHO: XBTP03387 - {70F76008-A8D9-4d5f-ABB7-3395612738F8} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [SpyCatcher Reminder] "C:\Program Files\SpyCatcher 2006\SpyCatcher.exe" reminder
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [BDNewsAgent] "C:\PROGRA~1\Softwin\BITDEF~1\bdnagent.exe"
O4 - HKLM\..\Run: [BDMCon] C:\PROGRA~1\Softwin\BITDEF~1\bdmcon.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.6962\GoogleToolbarNotifier.exe
O4 - Global Startup: SpyCatcher Protector.lnk = C:\Program Files\SpyCatcher 2006\Protector.exe
O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: Easy-WebPrint Ajouter à la liste d'impressions - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint Impression rapide - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Imprimer - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O8 - Extra context menu item: Easy-WebPrint Prévisualiser - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Humour Toolbar - {B7D3E479-CC68-42B5-A338-938ECE35F419} - (no file)
O9 - Extra 'Tools' menuitem: Humour Toolbar - {B7D3E479-CC68-42B5-A338-938ECE35F419} - (no file)
O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - www.wanadoo.fr (file missing) (HKCU)
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
O17 - HKLM\System\CCS\Services\Tcpip\..\{2A8FAC4D-E9F0-408B-90AE-476BD8306011}: NameServer = 80.10.246.130 80.10.246.3
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: interceptor.dll C:\PROGRA~1\Google\GOOGLE~4\GOEC62~1.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe" /service (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\DiskeeperWorkstation\DKService.exe
O23 - Service: ewido anti-spyware 4.0 guard - Unknown owner - (no file)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
O23 - Service: LicCtrl Service (LicCtrlService) - Unknown owner - rundll32.exe (file missing)
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
O23 - Service: SystemSuite Task Manager - Ontrack Data International - C:\PROGRA~1\Ontrack\SYSTEM~1\mxtask.exe
O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\Program Files\TuneUp Utilities 2006\WinStylerThemeSvc.exe
0
iceman6259 Messages postés 301 Date d'inscription lundi 21 mars 2005 Statut Membre Dernière intervention 13 avril 2007 11
31 déc. 2006 à 19:28
puis, clique dans les carrés a cote de ceci:

R3 - URLSearchHook: Humour Toolbar - {B7D3E479-CC68-42B5-A338-938ECE35F419} - (no file)

O2 - BHO: XBTP03387 - {70F76008-A8D9-4d5f-ABB7-3395612738F8} - (no file)

O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)

O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)

O9 - Extra button: Humour Toolbar - {B7D3E479-CC68-42B5-A338-938ECE35F419} - (no file)

O9 - Extra 'Tools' menuitem: Humour Toolbar - {B7D3E479-CC68-42B5-A338-938ECE35F419} - (no file)

O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - www.wanadoo.fr (file missing) (HKCU)



puis clique sur Fix cheked

y'a encore des trucs je pense, mais je peux pas trop m'avancer sur ses points... Si quelqu'un peut vérifier ensuite, j'préfère pas prendre d'autres initiatives moi...

ps: refais un scan et colle le new log ici

Bon réveillon !!
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
Utilisateur anonyme
31 déc. 2006 à 18:33
Je vois que tu as gardé Avast.
C'est ton choix.
Si tu savais ce que les trucs et bidules de thèmes apportent comme salo....es sur un PC.
Je te conseille de désinstaller ce machin...
TuneUp WinStyler Theme Service
Quittes à ce que tu le remettes après, mais perso j'y suis allergique.
ça prend de la ressource, et ça sert à pas grand chose...ah, si , souvent des bestioles en tous genres!
--------------------------------------------------------------------------
Refaits un log Hjt après....euhh, là ce sera pour demain !
A +
0
iceman6259 Messages postés 301 Date d'inscription lundi 21 mars 2005 Statut Membre Dernière intervention 13 avril 2007 11
31 déc. 2006 à 19:18
pour l'antivirus, je comprend pas non plus. J'utilise AVG moi, parce que c'est gratuit. Mais avast à de très bonne critique. bref...

en ce qui conserne TuneUp, je l'utilise beaucoup moi, et j'ai jamais eu de saloprie!!

je le trouve même plutot très simpa pour réparer et optimiser XP, et l'améliorer à son gout... mais ca reste mon avis...
0
salut philo2100

merci d'avoir repondu
"Je vois que tu as gardé Avast."
pourquoi tu me dis cela ? je n'aurais pas du le garder ? j'aurais du installer un autre antivirus ? lequel ? pourquoi ?

Si tu savais ce que les trucs et bidules de thèmes apportent comme salo....es sur un PC.
Je te conseille de désinstaller ce machin...

je ne vois pas de quoi tu parles ?

TuneUp WinStyler Theme Service
la non plus...

merci de m'éclairer car ce que tu dis m'interesse vraiment
0
iceman6259 Messages postés 301 Date d'inscription lundi 21 mars 2005 Statut Membre Dernière intervention 13 avril 2007 11
31 déc. 2006 à 19:36
relance HijackThis, et fait un scan seul.

puis coche les case suivante:

R3 - URLSearchHook: Humour Toolbar - {B7D3E479-CC68-42B5-A338-938ECE35F419} - (no file)

O2 - BHO: XBTP03387 - {70F76008-A8D9-4d5f-ABB7-3395612738F8} - (no file)

O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)

O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)

O9 - Extra button: Humour Toolbar - {B7D3E479-CC68-42B5-A338-938ECE35F419} - (no file)

O9 - Extra 'Tools' menuitem: Humour Toolbar - {B7D3E479-CC68-42B5-A338-938ECE35F419} - (no file)

O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - www.wanadoo.fr (file missing) (HKCU)



puis clique sur Fix cheked

y'a encore des trucs je pense, mais je peux pas trop m'avancer sur ses points... Si quelqu'un peut vérifier ensuite, j'préfère pas prendre d'autres initiatives moi...

ps: refais un scan et colle le new log ici

Bon réveillon !!
0
merci beaucoup !!

c'est fait
0
iceman6259 Messages postés 301 Date d'inscription lundi 21 mars 2005 Statut Membre Dernière intervention 13 avril 2007 11
31 déc. 2006 à 19:41
j't'en pris ;)

mais y'a d'autres trucs à faire, mais je peux pas prendre la responsabilité de t'aider plus, vu que je suis trop novice ;)

ce que tu as fait, c'est fixé des trucs sans effet en fait, mais qui encombre ton registre.

ps: fait attention en telechargemnt des barre d'outils ou autre truc, c'est blinder de spyware...

Perso, j'ai Firefox2 avec google intégrer, et c tout !! lol
0
Utilisateur anonyme
1 janv. 2007 à 11:04
, ,    ,      ,    ,     ,     ,   ,      ,     ,     ,      ,      ,     
,       ,     ,    ,       ,   .____. ,   ,     ,      ,       ,      ,     
 ,    ,   ,    ,     ,   ,   , |   :|         ,   , ,   ,   ,       , 
   ,        ,    ,     ,     __|====|__ ||||||  ,        ,      ,      ,    
 ,   ,    ,   ,     ,    , *  / o  o \  ||||||,   ,  ,        ,    ,
,   ,   ,         ,   ,     * | -=   |  \====/ ,       ,   ,    ,     ,    
   ,  ,    ,   ,           , U==\__//__. \\//    ,  ,        ,    , 
,   ,  ,    ,    ,    ,  ,   / \\==// \ \ ||  ,   ,      ,          ,  
 ,  ,    ,    ,     ,      ,|    o ||  | \||   ,      ,     ,   ,     ,     
,      ,    ,    ,      ,   |    o ""  |\_|B),    ,  ,    ,       , 
  ,  ,    ,   ,     ,      , \__  --__/   ||  ,        ,      ,     ,   
,  ,   ,       ,     ,   ,  /          \  ||,   ,   ,      ,    ,    ,
 ,      ,   ,     ,        |            | ||      ,  ,   ,    ,   ,  
,    ,    ,   ,  ,    ,   ,|            | || ,  ,  ,   ,   ,     ,  ,   
 ------_____---------____---\__ --_  __/__LJ__---------________-----___
0
LOL !

on pourrait revenir a mes problemes ?

TRES BONNE ANNEE A TOI PHILO2100 ET A TOUT LE MONDE
0
Utilisateur anonyme
1 janv. 2007 à 11:33
Moi je veux, bien mais vois-tu Mr iceman6259
a juger bon de prendre "le relai" sans aucune forme de politesse élémentaire...donc, tu attends qu'il dégèle !
Bonne année à toi et à iceman6259
, ,    ,      ,    ,     ,     ,   ,      ,     ,     ,      ,      ,     
,       ,     ,    ,       ,   .____. ,   ,     ,      ,       ,      ,     
 ,    ,   ,    ,     ,   ,   , |   :|         ,   , ,   ,   ,       , 
   ,        ,    ,     ,     __|====|__ ||||||  ,        ,      ,      ,    
 ,   ,    ,   ,     ,    , *  / o  o \  ||||||,   ,  ,        ,    ,
,   ,   ,         ,   ,     * | -=   |  \====/ ,       ,   ,    ,     ,    
   ,  ,    ,   ,           , U==\__//__. \\//    ,  ,        ,    , 
,   ,  ,    ,    ,    ,  ,   / \\==// \ \ ||  ,   ,      ,          ,  
 ,  ,    ,    ,     ,      ,|    o ||  | \||   ,      ,     ,   ,     ,     
,      ,    ,    ,      ,   |    o ""  |\_|B),    ,  ,    ,       , 
  ,  ,    ,   ,     ,      , \__  --__/   ||  ,        ,      ,     ,   
,  ,   ,       ,     ,   ,  /          \  ||,   ,   ,      ,    ,    ,
 ,      ,   ,     ,        |            | ||      ,  ,   ,    ,   ,  
,    ,    ,   ,  ,    ,   ,|            | || ,  ,  ,   ,   ,     ,  ,   
 ------_____---------____---\__ --_  __/__LJ__---------________-----___
0
re philo ! moi je veux que ce soit toi qui m'aide et iceman a stipuler plus haut qu'il passait le relais
0
philo tu es la ?
0
iceman6259 Messages postés 301 Date d'inscription lundi 21 mars 2005 Statut Membre Dernière intervention 13 avril 2007 11
1 janv. 2007 à 12:12
je suis désolé d'être intervenu sans politesse. Je voulais juste l'aider un peu, sans vouloir t'embéter. Milles excuses.

Et en effet, je laisse le relais à d'autres. J'ai fais ce qu'il m'a paru bon. Maintenant, p'tetre que je me suis trompé ...

Désolé cathar6, j'voulais pas te plomber ton problème, juste l'avancer le temps qu'il revienne...

Et désolé encore philou2100...

Bonne année à vous.

Iceman6259
0
^^Marie^^ Messages postés 113901 Date d'inscription mardi 6 septembre 2005 Statut Membre Dernière intervention 28 août 2020 3 275
1 janv. 2007 à 12:28
Salut à tous et Meilleurs Voeux

Pour avancer

Cartha refais un Hitjakthis
stp
merci

0
Utilisateur anonyme
1 janv. 2007 à 12:53
ok, message reçu....tous !

ça va y aller...
tu faits ce que t'as demandé Marie...c-à-d un log Hijackthis, pour que l'on reprenne le post ....
Je te remercie
0
ok c'est parti !!

Logfile of HijackThis v1.99.1
Scan saved at 14:39:38, on 01/01/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Executive Software\DiskeeperWorkstation\DKService.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\Ontrack\SYSTEM~1\mxtask.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\PROGRA~1\Softwin\BITDEF~1\bdnagent.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\karim\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\sabrina\Bureau\Nouveau dossier (2)\metin !!.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\karim\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {70F76008-A8D9-4d5f-ABB7-3395612738F8} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [SpyCatcher Reminder] "C:\Program Files\SpyCatcher 2006\SpyCatcher.exe" reminder
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [BDNewsAgent] "C:\PROGRA~1\Softwin\BITDEF~1\bdnagent.exe"
O4 - HKLM\..\Run: [BDMCon] C:\PROGRA~1\Softwin\BITDEF~1\bdmcon.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
O4 - HKLM\..\Run: [Easy-PrintToolBox] C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon
O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.6962\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\karim\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: SpyCatcher Protector.lnk = C:\Program Files\SpyCatcher 2006\Protector.exe
O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Easy-WebPrint Ajouter à la liste d'impressions - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint Impression rapide - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Imprimer - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O8 - Extra context menu item: Easy-WebPrint Prévisualiser - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} -
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} -
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
O17 - HKLM\System\CCS\Services\Tcpip\..\{2A8FAC4D-E9F0-408B-90AE-476BD8306011}: NameServer = 80.10.246.130 80.10.246.3
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: interceptor.dll C:\PROGRA~1\Google\GOOGLE~4\GOEC62~1.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe" /service (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\DiskeeperWorkstation\DKService.exe
O23 - Service: ewido anti-spyware 4.0 guard - Unknown owner - (no file)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
O23 - Service: LicCtrl Service (LicCtrlService) - Unknown owner - rundll32.exe (file missing)
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
O23 - Service: SystemSuite Task Manager - Ontrack Data International - C:\PROGRA~1\Ontrack\SYSTEM~1\mxtask.exe
O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\Program Files\TuneUp Utilities 2006\WinStylerThemeSvc.exe
0
Utilisateur anonyme
1 janv. 2007 à 15:12
Faits une sauvegarde de ta BDR:
https://leblogdeclaude.blogspot.com/2006/10/informatique-sauvegarde-de-la-base-de.html
---------------------------------------------------------------------------------
Désinstalles spycatcher:
----------------------------------------------------------------------
SpyCatcher 2006, an easy to use antispyware utility from Tenebril, does a good job of blocking and removing spyware under Microsoft Windows 2000 or XP, although its blocking technique can be slightly nerve-wracking: It allows most spyware to install, then quarantines programs that attempt malicious action.
----------------------------------------------------------------------------


Essayes de finir ce programme au démarrage avec Msconfig:
mxtask.exe
-----------------------------------------------------------------------------------
mxtask.exe is associated with V Communications Fix-It utilities and is an essential background process for this application. This program is a non-essential system process, but should not be terminated unless suspected to be causing problems.
-------------------------------------------------------------------
ça aussi:
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
------------------------------------------------------------------------
--------------------------------------------------------------------------
Tu as encore du Bitdefender dans ton ordi ?
Il ya ça qui démarre:
C:\PROGRA~1\Softwin\BITDEF~1\bdnagent.exe
--------------------------------------------------------------------
O4 - HKLM\..\Run: [BDNewsAgent] "C:\PROGRA~1\Softwin\BITDEF~1\bdnagent.exe"
O4 - HKLM\..\Run: [BDMCon] C:\PROGRA~1\Softwin\BITDEF~1\bdmcon.exe
----------------------------------------------------------------------------
----------------------------------------------------------------------------

ici il y a les deux qui se marchent dessus:
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\karim\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: SpyCatcher Protector.lnk = C:\Program Files\SpyCatcher 2006\Protector.exe
Après le désinstall ça devrait aller, mais désactive Teatimer.exe dans Spyboot
---------------------------------------------------------------
Refaits un log HJT
0
salut philo !

***je suis pas tres bon en anglais mais j'ai cru comprendre que spycatcher n'était pas assez efficace ? pourtant je lis beaucoup d'avis positif sur ce logiciel. si je le désinstalle je mets quoi a la place ?

***Essayes de finir ce programme au démarrage avec Msconfig:
comment fait-on pour finir un prog avec msconfig

***mxtask.exe
je n'ai pas compris ce qu'était ce prog

***O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\karim\Spybot - Search & Destroy\TeaTimer.exe
pourquoi enlever la protection residente de spybot ?

merci vraiment pour tes reponses, et tes conseils ! j'attends ta reponse !

a+ philo2100
0