Demande d'aide...log HijackThis joint - Page 2

Résolu
  1. et voila Bit defender...Zonz alarm et avast n'avaient rien détecté avant

    BitDefender Online Scanner - Real Time Virus Report

    Generated at: Sat, Feb 24, 2007 - 08:48:13

    Scan Info

    Scanned Files

    629748

    Infected Files

    7

    Virus Detected

    MemScan:Win32.Worm.P2P.Puce.B
    3

    MemScan:Trojan.Downloader.Agent.NC

    2

    Trojan.Horse.BFO

    2

    This summary of the scan process will be used by the BitDefender Antivirus Lab to create agregate statistics about virus activity around the world.

    J'espère qu'avec tout ça, tu vas pouvoir analyser...
    au fait ça veut dire quoi la dernière ligne de ton message??
    "C:\WINDOWS\Temp\kdqao.ren "

    merci
    @+
    0
    1. Et voila le nouveau HijackThis apres ces manips....
      Le ventilo tourne toujours autant..

      Sinon, le code apparait dans le cadre noir pour valider le message alors qu'hier j'étais obligé de couper ZA pour qu'il apparaisse..

      Logfile of HijackThis v1.99.0
      Scan saved at 09:09:16, on 24/02/2007
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16414)

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\Program Files\Alwil Software\Avast4\ashServ.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
      C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
      C:\WINDOWS\system32\oodag.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\ZoneLabs\vsmon.exe
      C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
      C:\WINDOWS\vsnpstd3.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      C:\WINDOWS\system32\ZoneLabs\isafe.exe
      C:\Archives de programme\HijackThis\HijackThis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.f1live.com/
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
      O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
      O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
      O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
      O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
      O3 - Toolbar: Steganos Internet Anonyme - {00000000-5736-4205-0008-f7ed0776fb27} - c:\program files\steganos internet anonym 2006\sia2006iep.dll
      O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
      O4 - HKLM\..\Run: [snpstd3] C:\WINDOWS\vsnpstd3.exe
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
      O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
      O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
      O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
      O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
      O18 - Protocol: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll
      O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
      O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
      O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
      O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
      O23 - Service: avast! iAVS4 Control Service - Unknown - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
      O23 - Service: AutoComplete Service - Acesoft - C:\Program Files\Acesoft\Tracks Eraser Pro\delautocomp.exe
      O23 - Service: avast! Antivirus - Unknown - C:\Program Files\Alwil Software\Avast4\ashServ.exe
      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
      O23 - Service: CA ISafe - Computer Associates International, Inc. - C:\WINDOWS\system32\ZoneLabs\isafe.exe
      O23 - Service: Service d'administration du Gestionnaire de disque logique - Unknown - C:\WINDOWS\System32\dmadmin.exe
      O23 - Service: Journal des événements - Unknown - C:\WINDOWS\system32\services.exe
      O23 - Service: Fax - Unknown - C:\WINDOWS\system32\fxssvc.exe
      O23 - Service: Groove Installer Service - Groove Networks, Inc. - c:\Program Files\Groove Networks\Groove\Bin\GrooveInstallerService.exe
      O23 - Service: Service COM de gravage de CD IMAPI - Unknown - C:\WINDOWS\system32\imapi.exe
      O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
      O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
      O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe
      O23 - Service: Plug-and-Play - Unknown - C:\WINDOWS\system32\services.exe
      O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
      O23 - Service: Gestionnaire de session d'aide sur le Bureau à distance - Unknown - C:\WINDOWS\system32\sessmgr.exe
      O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Fichiers communs\PCSuite\Services\ServiceLayer.exe
      O23 - Service: Journaux et alertes de performance - Unknown - C:\WINDOWS\system32\smlogsvc.exe
      O23 - Service: TrueVector Internet Monitor - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
      O23 - Service: Cliché instantané de volume - Unknown - C:\WINDOWS\System32\vssvc.exe
      O23 - Service: Carte de performance WMI - Unknown - C:\WINDOWS\system32\wbem\wmiapsrv.exe
      O23 - Service: Service Partage réseau du Lecteur Windows Media - Unknown - C:\Program Files\Windows Media Player\WMPNetwk.exe
      0
      1. Contributeur sécurité
        Bonjour,

        le rapport de bitdefender, ne me dit pas où est logé le problème, il en manque un morceau.

        pour la dernière ligne de mon message, c'était un pense bête que je m'étais mis et que j'ai oublié d'enlever. Ne t'en occupe pas.

        0
        1. Bonjour,

          C'est tout ce qu'il y avait apparemment.
          sinon comment faire??
          je refais un scan??
          @+
          0
          1. Contributeur sécurité
            c'est étrange, ils ont tout changé chez bitdefender....qu'elle galère. Désolée on va faire un scan ailleurs alors. parce qu'avec ça, je ne vais pas loin.

            pour l'histoire de la température de tes ventilos, as tu vérifié si il n'y avait pas de la poussière dessus. Ceci occasionne souvent ce genre de problème.

            * Fait un scan antivirus en ligne Panda et copie colle le résultat ici
            https://www.pandasecurity.com/?ref=www.pandasoftware.com/activescan/fr/activescan_principal.htm

            * tuto en image
            https://forum.pcastuces.com/default.asp#haut

            à la lettre T
            0
            1. Merci pour tes conseils...

              Impossible de lancer panda (installation activeX refusée, même ZA coupé) avec IE

              Désolé
              0
              1. Contributeur sécurité
                essaye ici

                * fait un scan antivirus en ligne avec SYMANTEC
                http://security.symantec.com/sscv6/default.asp?langid=ie&venid=sym

                A effectuer avec IE
                Clique sur Virus Detection --->" Start "
                Clique sur " I accept ", puis " Next "
                Clique sur " I consent ", puis " Next "
                Un control active X, va se charger
                Dans la nouvelle fenetre qui s'ouvre, valide en bas à gauche " Toujours faire confiance .... ", puis clique sur OK
                Le scan débute donc par le dernier HDD

                0
                1. enfin, ça roule...obligé de supprimer le filtre anti-hameçonage...

                  Ceci dit , juste apres l'installation de l'active X le scan a démare et ZA m'a demandé d'autoriser "Confidence Online EE v5.0 NT5 Build (5,0,1,7)"

                  tu connais???

                  j'ai refusé et ça n'a rien changé au scan
                  0
                  1. Contributeur sécurité
                    non je ne connais pas du tout.
                    si le fait de refuser te permet quand même de faire le scan, c'est le mieux à faire.
                    0
                    1. voila le résultat VIRUSAFE mais je ne comprends rien

                      53176 files scanned, 0 file(s) infected on your disk drives.

                      No viruses were detected in memory.

                      Your computer is free of known threats. Virus Detection does not check compressed files.

                      Your computer appears safe for now. For real-time protection from viruses, hackers and privacy threats, upgrade to Norton Internet Security™.

                      No viruses were detected in memory.

                      The scan was cancelled before finishing. To restart the scan, click here.

                      Your computer is free of known threats. Virus Detection does not check compressed files.

                      Your computer appears safe for now. For real-time protection from viruses, hackers and privacy threats, upgrade to Norton Internet Security™.

                      Search for the name of the threat(s) listed below on the Symantec Security Response site for removal information.

                      Warning! The scan detected a virus that is active in your computer's memory.
                      The scan ended to prevent further infection.

                      You should shut down your computer immediately and restart it with an antivirus rescue disk or similar tool.

                      No viruses were detected in memory.

                      Your computer is infected with at least one known virus or Trojan horse.

                      Search for the name of the threat(s) listed below on the Symantec Security Response site for removal information.

                      No viruses were detected in memory.

                      Your computer is infected with at least one known virus or Trojan horse.

                      Note: The scan was cancelled before finishing. There may be more infected files on this computer.

                      Search for the name of the threat(s) listed below on the Symantec Security Response site for removal information.

                      A scan has not been run. To start Virus Detection, click here.
                      0
                      1. Contributeur sécurité
                        bon tout parait ok maintenant. As tu encore des problèmes ?

                        0
                        1. J'ai viré Avast ( le traitre),MSN, et d'autre mer***, maintenant , le ventilo semble souffler moins chaud

                          Merci donc pour tout ce temps que tu m'as accordé ...
                          Je repasserai plus tard dans la soirée pour te donner le résultat final, mais disons "GAGNE"
                          merci encore super le forum

                          Ceci dit j'ai un pb sur un autre sujet (réseaux) et personne ne vient parler avec moi.....snif...
                          0
                          1. Contributeur sécurité
                            si tu as viré avast, ok, mais j'espère que tu en as mis un autre....

                            pour ton sujet sur réseaux, désolée, mais c'est pas ma partie.
                            0
                            1. lequel??
                              J'ai Zone Alarm sécurity suite...firewall, antispy,antivirus et aussi AVG.. CCleaner,spybot

                              Je peux aller régulièrement chez bit defender??scan online.

                              si tu as un conseil, je suis preneur..merci encore
                              0
                              1. Contributeur sécurité
                                tu me dis que tu as supprimé avast, qu'est-ce que tu as comme antivirus alors ?
                                0
                                1. l'antivirus de ZoneAlarm?
                                  c'est grave docteur???
                                  0
                                  1. Contributeur sécurité
                                    non c'est ok, je ne me souvenais plus que dans la suite il y avait l'antivirus d'inclus. Donc tu n'as pas besoin d'autre antivirus bien évidemment

                                    0
                                    1. merci à toi Philae et peut être à un de ces jours car je ne suis pas un phoenix en informatique
                                      0
                                      1. Contributeur sécurité
                                        bon we et bonne fin de soirée
                                        0
                                        Précédent
                                        • 1
                                        • 2