Outerinfo est-il bien désinstallé?
Alex91150
Messages postés
12
Statut
Membre
-
Séb08 Messages postés 18169 Date d'inscription Statut Contributeur Dernière intervention -
Séb08 Messages postés 18169 Date d'inscription Statut Contributeur Dernière intervention -
Bonjour à tous, je me présente, Alex91150, mais vous pouvez m'appeler Alex ou Alexandre, c'est plus court ;).
Voila mon problème: en fouinant dans la partie Ajout/Suppression de programmes, j'ai remarqué un logiciel appelé Outerinfo. Après recherche chez Google, j'ai découvert qu'il s'agissait d'un spyware, sans doute responsable de mon problème (fenêtres pub pour WinANtiVirus 2006 ou Ultimate Defender). Je l'ai donc désinstallé par Ajout/Suppression de programmes. Mais j'ai l'impression que ça n'a pas suffi car j'ai encore les pop-up Ultimate Defender. Que faire?
Voila mon log HijackThis:
Logfile of HijackThis v1.99.1
Scan saved at 20:00:35, on 05/06/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16441)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Documents and Settings\All Users\Application Data\hspuvety.exe
C:\WINDOWS\system32\atiptaxx.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Internet Explorer\iexplore.exe
D:\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [hspuvety.exe] C:\Documents and Settings\All Users\Application Data\hspuvety.exe
O4 - HKLM\..\Run: [FileZilla Server Interface] "C:\Program Files\FileZilla Server\FileZilla Server Interface.exe"
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [ApachInc] rundll32.exe "C:\WINDOWS\system32\ghsgcumg.dll",realset
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [CTSyncU.exe] "C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"
O4 - HKCU\..\RunOnce: [SWHelper] "C:\WINDOWS\system32\Macromed\Shockwave 10\PostUpdate.exe" 1014020
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/20061205/qtinstall.info.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {45B69029-F3AB-4204-92DE-D5140C3E8E74} (F5 Networks Auto Update) - https://extranet.mousquetaires.com/dana-na/auth/url_1/welcome.cgi
O16 - DPF: {6C275925-A1ED-4DD2-9CEE-9823F5FDAA10} (F5 Networks SSLTunnel) - https://extranet.mousquetaires.com/dana-na/auth/url_1/welcome.cgi#version=5600,0,61228,0055
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
O16 - DPF: {7584c670-2274-4efb-b00b-d6aaba6d3850} (Microsoft RDP Client Control (redist)) - https://extranet.mousquetaires.com/dana-na/auth/url_1/welcome.cgi#version=5,2,3790,0
O16 - DPF: {BE833F39-1E0C-468C-BA70-25AAEE55775E} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab.cab
O16 - DPF: {CC85ACDF-B277-486F-8C70-2C9B2ED2A4E7} (F5 Networks SuperHost Class) - https://extranet.mousquetaires.com/dana-na/auth/url_1/welcome.cgi#version=5600,0,61017,0703
O16 - DPF: {E0FF21FA-B857-45C5-8621-F120A0C17FF2} (F5 Networks Host Control) - https://extranet.mousquetaires.com/dana-na/auth/url_1/welcome.cgi#version=5600,0,61228,0050
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: FileZilla Server FTP server (FileZilla Server) - FileZilla Project - C:\Program Files\FileZilla Server\FileZilla Server.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
Vous en pensez quoi?
Merci!
Voila mon problème: en fouinant dans la partie Ajout/Suppression de programmes, j'ai remarqué un logiciel appelé Outerinfo. Après recherche chez Google, j'ai découvert qu'il s'agissait d'un spyware, sans doute responsable de mon problème (fenêtres pub pour WinANtiVirus 2006 ou Ultimate Defender). Je l'ai donc désinstallé par Ajout/Suppression de programmes. Mais j'ai l'impression que ça n'a pas suffi car j'ai encore les pop-up Ultimate Defender. Que faire?
Voila mon log HijackThis:
Logfile of HijackThis v1.99.1
Scan saved at 20:00:35, on 05/06/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16441)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Documents and Settings\All Users\Application Data\hspuvety.exe
C:\WINDOWS\system32\atiptaxx.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Internet Explorer\iexplore.exe
D:\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [hspuvety.exe] C:\Documents and Settings\All Users\Application Data\hspuvety.exe
O4 - HKLM\..\Run: [FileZilla Server Interface] "C:\Program Files\FileZilla Server\FileZilla Server Interface.exe"
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [ApachInc] rundll32.exe "C:\WINDOWS\system32\ghsgcumg.dll",realset
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [CTSyncU.exe] "C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"
O4 - HKCU\..\RunOnce: [SWHelper] "C:\WINDOWS\system32\Macromed\Shockwave 10\PostUpdate.exe" 1014020
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/20061205/qtinstall.info.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {45B69029-F3AB-4204-92DE-D5140C3E8E74} (F5 Networks Auto Update) - https://extranet.mousquetaires.com/dana-na/auth/url_1/welcome.cgi
O16 - DPF: {6C275925-A1ED-4DD2-9CEE-9823F5FDAA10} (F5 Networks SSLTunnel) - https://extranet.mousquetaires.com/dana-na/auth/url_1/welcome.cgi#version=5600,0,61228,0055
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
O16 - DPF: {7584c670-2274-4efb-b00b-d6aaba6d3850} (Microsoft RDP Client Control (redist)) - https://extranet.mousquetaires.com/dana-na/auth/url_1/welcome.cgi#version=5,2,3790,0
O16 - DPF: {BE833F39-1E0C-468C-BA70-25AAEE55775E} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab.cab
O16 - DPF: {CC85ACDF-B277-486F-8C70-2C9B2ED2A4E7} (F5 Networks SuperHost Class) - https://extranet.mousquetaires.com/dana-na/auth/url_1/welcome.cgi#version=5600,0,61017,0703
O16 - DPF: {E0FF21FA-B857-45C5-8621-F120A0C17FF2} (F5 Networks Host Control) - https://extranet.mousquetaires.com/dana-na/auth/url_1/welcome.cgi#version=5600,0,61228,0050
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: FileZilla Server FTP server (FileZilla Server) - FileZilla Project - C:\Program Files\FileZilla Server\FileZilla Server.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
Vous en pensez quoi?
Merci!
A voir également:
- Outerinfo est-il bien désinstallé?
- Confirmez qu'il s'agit bien de vous - Forum Gmail
- Vérifier que le serveur freebox est bien connecté à internet - Forum Freebox
- Si je désinstalle messenger est ce que je perd tout - Forum Facebook
- Messenger désinstallation - Forum Facebook Messenger
- Message automatique le bon coin votre bien est toujours disponible ✓ - Forum Vos droits sur internet
23 réponses
Salut,
Voila le rapport SmitFraudFix:
EDIT: Récemment, j'ai découvert à la racine du disque système, 3 fichiers: hcojjefh1.exe, hcojjefh2.exe, hcojjefh3.exe. J'ai fait un rapport Virus Total sur le premier fichier. Le voilà:
EDIT2: Le rapport VT du 2e fichier, hcojjefh2.exe:
Voila le rapport SmitFraudFix:
SmitFraudFix v2.195
Rapport fait à 7:41:08,90, 22/06/2007
Executé à partir de D:\SmitfraudFix
OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
Le type du système de fichiers est NTFS
Fix executé en mode normal
»»»»»»»»»»»»»»»»»»»»»»»» Process
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Documents and Settings\All Users\Application Data\hspuvety.exe
C:\WINDOWS\system32\atiptaxx.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\cmd.exe
»»»»»»»»»»»»»»»»»»»»»»»» hosts
»»»»»»»»»»»»»»»»»»»»»»»» C:\
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\papa
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\papa\Application Data
»»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer
»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\papa\Favoris
»»»»»»»»»»»»»»»»»»»»»»»» Bureau
»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files
»»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues
»»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="Ma page d'accueil"
»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""
»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""
»»»»»»»»»»»»»»»»»»»»»»»» Rustock
»»»»»»»»»»»»»»»»»»»»»»»» DNS
Description: Carte réseau 3Com EtherLink XL 10/100 PCI TX (3C905B-TX) - Miniport d'ordonnancement de paquets
DNS Server Search Order: 212.27.53.252
DNS Server Search Order: 212.27.54.252
HKLM\SYSTEM\CCS\Services\Tcpip\..\{E7E94806-205E-4367-9CD0-9F916B1A6FFC}: DhcpNameServer=212.27.53.252 212.27.54.252
HKLM\SYSTEM\CS1\Services\Tcpip\..\{E7E94806-205E-4367-9CD0-9F916B1A6FFC}: DhcpNameServer=212.27.53.252 212.27.54.252
HKLM\SYSTEM\CS2\Services\Tcpip\..\{E7E94806-205E-4367-9CD0-9F916B1A6FFC}: DhcpNameServer=212.27.53.252 212.27.54.252
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=212.27.53.252 212.27.54.252
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=212.27.53.252 212.27.54.252
HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=212.27.53.252 212.27.54.252
»»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll
»»»»»»»»»»»»»»»»»»»»»»»» Fin
EDIT: Récemment, j'ai découvert à la racine du disque système, 3 fichiers: hcojjefh1.exe, hcojjefh2.exe, hcojjefh3.exe. J'ai fait un rapport Virus Total sur le premier fichier. Le voilà:
Antivirus Version Update Result AhnLab-V3 2007.6.21.1 06.22.2007 no virus found AntiVir 7.4.0.34 06.21.2007 no virus found Authentium 4.93.8 06.22.2007 Possibly a new variant of W32/SelfStarterInternetTrojan!Maximus Avast 4.7.997.0 06.21.2007 no virus found AVG 7.5.0.467 06.20.2007 no virus found BitDefender 7.2 06.22.2007 no virus found CAT-QuickHeal 9.00 06.21.2007 no virus found ClamAV devel-20070416 06.22.2007 no virus found DrWeb 4.33 06.21.2007 no virus found eSafe 7.0.15.0 06.21.2007 Downloader.MisleadAp eTrust-Vet 30.8.3733 06.22.2007 no virus found Ewido 4.0 06.21.2007 no virus found FileAdvisor 1 06.22.2007 No threat detected Fortinet 2.91.0.0 06.22.2007 Misc/Ultimate F-Prot 4.3.2.48 06.21.2007 W32/SelfStarterInternetTrojan!Maximus F-Secure 6.70.13030.0 06.22.2007 no virus found Ikarus T3.1.1.8 06.22.2007 not-a-virus:.FraudTool.Win32.UltimateDefender.a Kaspersky 4.0.2.24 06.22.2007 no virus found McAfee 5058 06.21.2007 New Malware.ca Microsoft 1.2701 06.22.2007 no virus found NOD32v2 2343 06.21.2007 probably a variant of Win32/Adware.UltimateDefender Norman 5.80.02 06.21.2007 no virus found Panda 9.0.0.4 06.22.2007 Application/UltimateCleaner Sophos 4.18.0 06.21.2007 no virus found Sunbelt 2.2.907.0 06.21.2007 Trojan-Downloader.MisleadApp Symantec 10 06.22.2007 Downloader.MisleadApp TheHacker 6.1.6.136 06.20.2007 no virus found VBA32 3.12.0.2 06.21.2007 no virus found VirusBuster 4.3.23:9 06.21.2007 no virus found Webwasher-Gateway 6.0.1 06.21.2007 Worm.Win32.ModifiedUPX.gen!90 (suspicious) Aditional Information File size: 99072 bytes MD5: 711d6a7b5bb4a9ee0ec162a948f76b2f SHA1: 9ec63ea5dc46aca749f48bc0fd296fcf17be6c41 packers: UPX packers: UPX Bit9 info: http://fileadvisor.bit9.com/services/extinfo.aspx?md5=711d6a7b5bb4a9ee0ec162a948f76b2f packers: UPX
EDIT2: Le rapport VT du 2e fichier, hcojjefh2.exe:
AhnLab-V3 2007.6.21.1 06.22.2007 no virus found AntiVir 7.4.0.34 06.21.2007 ADSPY/Udefender.1 Authentium 4.93.8 06.22.2007 Possibly a new variant of W32/SelfStarterInternetTrojan!Maximus Avast 4.7.997.0 06.21.2007 Win32:Adware-gen. AVG 7.5.0.467 06.20.2007 no virus found BitDefender 7.2 06.22.2007 no virus found CAT-QuickHeal 9.00 06.21.2007 no virus found ClamAV devel-20070416 06.22.2007 no virus found DrWeb 4.33 06.21.2007 no virus found eSafe 7.0.15.0 06.21.2007 Downloader.MisleadAp eTrust-Vet 30.8.3733 06.22.2007 no virus found Ewido 4.0 06.21.2007 no virus found FileAdvisor 1 06.22.2007 no virus found Fortinet 2.91.0.0 06.22.2007 Misc/Ultimate F-Prot 4.3.2.48 06.21.2007 W32/SelfStarterInternetTrojan!Maximus F-Secure 6.70.13030.0 06.22.2007 no virus found Ikarus T3.1.1.8 06.22.2007 not-a-virus:.FraudTool.Win32.UltimateDefender.a Kaspersky 4.0.2.24 06.22.2007 no virus found McAfee 5058 06.21.2007 New Malware.ca Microsoft 1.2701 06.22.2007 no virus found NOD32v2 2343 06.21.2007 a variant of Win32/Adware.UltimateDefender Norman 5.80.02 06.21.2007 no virus found Panda 9.0.0.4 06.22.2007 Application/UltimateCleaner Prevx1 V2 06.22.2007 Spyware.UltimateDefender Sophos 4.18.0 06.21.2007 no virus found Sunbelt 2.2.907.0 06.21.2007 Trojan-Downloader.MisleadApp Symantec 10 06.22.2007 Downloader.MisleadApp TheHacker 6.1.6.136 06.20.2007 no virus found VBA32 3.12.0.2 06.21.2007 no virus found VirusBuster 4.3.23:9 06.21.2007 no virus found Webwasher-Gateway 6.0.1 06.21.2007 Ad-Spyware.Udefender.1 Aditional Information File size: 100096 bytes MD5: d591294599c8e4c8ae5eaef45ee2075f SHA1: 873566084ffab23aeb547f33e63d60b4bb0e3442 packers: UPX packers: UPX packers: UPX Prevx info: http://fileinfo.prevx.com/...</code>
EDIT3: Et pour le dernier hcojjefh3.exe:
AhnLab-V3 2007.6.21.1 06.22.2007 no virus found AntiVir 7.4.0.34 06.21.2007 ADSPY/Udefender.1 Authentium 4.93.8 06.22.2007 Possibly a new variant of W32/SelfStarterInternetTrojan!Maximus Avast 4.7.997.0 06.21.2007 Win32:Adware-gen. AVG 7.5.0.467 06.20.2007 no virus found BitDefender 7.2 06.22.2007 no virus found CAT-QuickHeal 9.00 06.21.2007 no virus found ClamAV devel-20070416 06.22.2007 no virus found DrWeb 4.33 06.21.2007 no virus found eSafe 7.0.15.0 06.21.2007 Downloader.MisleadAp eTrust-Vet 30.8.3733 06.22.2007 no virus found Ewido 4.0 06.21.2007 no virus found FileAdvisor 1 06.22.2007 no virus found Fortinet 2.91.0.0 06.22.2007 Misc/Ultimate F-Prot 4.3.2.48 06.21.2007 W32/SelfStarterInternetTrojan!Maximus F-Secure 6.70.13030.0 06.22.2007 no virus found Ikarus T3.1.1.8 06.22.2007 not-a-virus:.FraudTool.Win32.UltimateDefender.a Kaspersky 4.0.2.24 06.22.2007 no virus found McAfee 5058 06.21.2007 New Malware.ca Microsoft 1.2701 06.22.2007 no virus found NOD32v2 2343 06.21.2007 a variant of Win32/Adware.UltimateDefender Norman 5.80.02 06.21.2007 no virus found Panda 9.0.0.4 06.22.2007 Application/UltimateCleaner Prevx1 V2 06.22.2007 Spyware.UltimateDefender Sophos 4.18.0 06.21.2007 no virus found Sunbelt 2.2.907.0 06.21.2007 Trojan-Downloader.MisleadApp Symantec 10 06.22.2007 Downloader.MisleadApp TheHacker 6.1.6.136 06.20.2007 no virus found VBA32 3.12.0.2 06.21.2007 no virus found VirusBuster 4.3.23:9 06.21.2007 no virus found Webwasher-Gateway 6.0.1 06.21.2007 Ad-Spyware.Udefender.1 Aditional Information File size: 100096 bytes MD5: d591294599c8e4c8ae5eaef45ee2075f SHA1: 873566084ffab23aeb547f33e63d60b4bb0e3442 packers: UPX packers: UPX packers: UPX Prevx info: http://fileinfo.prevx.com/...</pre>
fait un scan ici
https://www.bitdefender.fr/
et copie colle le résultat ici
* En bas, à gauche de la fenêtre, clique sur BitDefender SCAN ONLINE
* Dans la nouvelle fenêtre, clique sur I agree
* La fenêtre change encore, clique sur Click here to scan
* Les signatures se chargent, etc.
tuto en image
http://pageperso.aol.fr/rginformatique/mapage/defender.htm
https://www.bitdefender.fr/
et copie colle le résultat ici
* En bas, à gauche de la fenêtre, clique sur BitDefender SCAN ONLINE
* Dans la nouvelle fenêtre, clique sur I agree
* La fenêtre change encore, clique sur Click here to scan
* Les signatures se chargent, etc.
tuto en image
http://pageperso.aol.fr/rginformatique/mapage/defender.htm