[firefox] popup SpywareSecure.com - Page 2

Précédent
  • 1
  • 2
  1. QuelBeauPseudo Messages postés 258 Date d'inscription   Statut Membre 32
     
    Bonjour.
    Non ne formate pas lol.
    Tiens deja fixe cettte ligne (te goure pas y'en a deux avec java une seule est mauvaise):
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
    Celle la precisement pas une autre gaffe.

    "console java (sun)" => adware => remove
    0
  2. QuelBeauPseudo Messages postés 258 Date d'inscription   Statut Membre 32
     
    Relance combofix laisse le agir cette fois si (ne clique pas sur "ne rien faire").
    0
  3. QuelBeauPseudo Messages postés 258 Date d'inscription   Statut Membre 32
     
    Fixe sa:
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    puis telecharge et execute sa: Download the WindowsXP-KB914440-v12-x86-ENU.exe package now.O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    cette ligne aussi avant d'intaller le package.
    0
  4. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  5. jojo
     
    Ok j'ai tt fait comme tu m'as dis.
    Voici le raport COMBOFIX

    ComboFix 07-09-17.2 - "Maisondesb" 2007-09-18 9:40:22.2 - NTFSx86
    Microsoft Windows XP dition familiale 5.1.2600.2.1252.1.1036.18.215 [GMT 2:00]
    .

    ((((((((((((((((((((((((((((( Fichiers créés 2007-08-18 to 2007-09-18 ))))))))))))))))))))))))))))))))))))
    .

    2007-09-17 20:06 <REP> d-------- C:\WINDOWS\BDOSCAN8
    2007-09-17 16:54 51,200 --a------ C:\WINDOWS\NirCmd.exe
    2007-09-17 16:41 <REP> d-------- C:\VundoFix Backups
    2007-09-17 10:15 <REP> d-------- C:\Program Files\Hijackthis Version Fran‡aise
    2007-09-16 22:05 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
    2007-09-16 21:43 <REP> d-------- C:\Program Files\Lavalys
    2007-09-16 20:41 <REP> d-------- C:\Program Files\Panda Security
    2007-09-16 19:49 76,560 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
    2007-09-16 19:47 <REP> d-------- C:\DOCUME~1\MAISON~1\.housecall6.6
    2007-09-16 13:05 <REP> d-------- C:\Program Files\Navilog1
    2007-09-14 08:55 <REP> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy

    .
    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2007-09-18 08:28 --------- d-------- C:\Program Files\Mozilla Thunderbird
    2007-09-17 11:05 --------- d-------- C:\Program Files\SpeedFan
    2007-09-16 20:29 --------- d-------- C:\Program Files\a-squared Free
    2007-09-11 19:52 --------- d-------- C:\Program Files\Belote
    2007-09-06 12:09 801144 --a------ C:\WINDOWS\system32\aswBoot.exe
    2007-09-06 12:05 94416 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
    2007-09-06 12:05 92848 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
    2007-09-06 12:03 23152 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
    2007-09-06 12:02 42912 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
    2007-09-06 12:00 95608 --a------ C:\WINDOWS\system32\AVASTSS.scr
    2007-09-06 12:00 26624 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
    2007-07-30 19:19 92504 --a------ C:\WINDOWS\system32\cdm.dll
    2007-07-30 19:19 549720 --a------ C:\WINDOWS\system32\wuapi.dll
    2007-07-30 19:19 53080 --a------ C:\WINDOWS\system32\wuauclt.exe
    2007-07-30 19:19 43352 --a------ C:\WINDOWS\system32\wups2.dll
    2007-07-30 19:19 325976 --a------ C:\WINDOWS\system32\wucltui.dll
    2007-07-30 19:19 203096 --a------ C:\WINDOWS\system32\wuweb.dll
    2007-07-30 19:19 1712984 --a------ C:\WINDOWS\system32\wuaueng.dll
    2007-07-30 19:18 33624 --a------ C:\WINDOWS\system32\wups.dll
    2007-07-29 10:57 --------- d-------- C:\Program Files\RickDangerous
    2007-07-24 12:22 --------- d-------- C:\Program Files\a-squared Anti-Dialer
    2007-06-26 08:09 1104896 --a------ C:\WINDOWS\system32\msxml3.dll
    2007-06-19 15:32 282112 --a------ C:\WINDOWS\system32\gdi32.dll
    --------- C:\Program Files\Hijackthis Version Française
    .

    ((((((((((((((((((((((((((((( snapshot_2007-09-17_171242,09 )))))))))))))))))))))))))))))))))))))))))
    .
    ----a-w 53,248 2006-05-24 23:22:06 C:\WINDOWS\bdoscandel.exe
    ----a-w 45,056 2007-09-17 18:06:20 C:\WINDOWS\BDOSCAN8\avxdisk.dll
    ----a-w 10,240 2007-09-17 18:06:20 C:\WINDOWS\BDOSCAN8\avxs.dll
    ----a-w 27,136 2007-09-17 18:06:21 C:\WINDOWS\BDOSCAN8\avxt.dll
    ----a-w 181,248 2007-09-17 18:06:28 C:\WINDOWS\BDOSCAN8\bdcore.dll
    ----a-w 118,784 2006-05-24 23:21:00 C:\WINDOWS\BDOSCAN8\bdupd.dll
    ----a-w 53,248 2006-05-24 23:21:14 C:\WINDOWS\BDOSCAN8\ipsupd.dll
    ----a-w 142,848 2007-09-17 18:06:30 C:\WINDOWS\BDOSCAN8\libfn.dll
    ----a-w 86,016 2007-09-17 18:06:22 C:\WINDOWS\BDOSCAN8\librtvr.dll
    ----a-w 118,784 2006-05-24 23:21:00 C:\WINDOWS\Downloaded Program Files\bdupd.dll
    ----a-w 53,248 2006-05-24 23:21:14 C:\WINDOWS\Downloaded Program Files\ipsupd.dll
    ----atw 16,384 2007-09-18 06:26:05 C:\WINDOWS\Temp\Perflib_Perfdata_6e0.dat
    .
    .
    ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SoundMan"="SOUNDMAN.EXE" [2002-06-18 12:44 C:\WINDOWS\SOUNDMAN.EXE]
    "avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-09-06 12:06]
    "Cmaudio"="cmicnfg.cpl" []
    "Look 'n' Stop"="C:\Program Files\Soft4Ever\looknstop\looknstop.exe" [2007-02-17 19:12]
    "!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 11:25]

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-20 01:09]
    "ehrjbefgxa"="c:\documents and settings\maisondesb\local settings\application data\ehrjbefgxa.exe" [2007-09-10 11:50]

    R1 lnsfw1;lnsfw1;C:\WINDOWS\system32\drivers\lnsfw1.sys
    R2 a2AntiDialer;a-squared Anti-Dialer Service;C:\Program Files\a-squared Anti-Dialer\a2service.exe
    S3 fbxusb;Carte réseau virtuelle FreeBox USB;C:\WINDOWS\system32\DRIVERS\fbxusb32.sys

    .
    **************************************************************************

    catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2007-09-18 09:42:30
    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    Completion time: 2007-09-18 9:44:30
    C:\ComboFix-quarantined-files.txt ... 2007-09-18 09:44
    C:\ComboFix2.txt ... 2007-09-17 17:13
    .
    --- E O F ---

    ////////////////////////////////////////////////////////////////////////////////

    Voici le rapport d'ANTIVIR:

    AntiVir PersonalEdition Classic
    Report file date: mardi 18 septembre 2007 10:26

    Scanning for 740715 virus strains and unwanted programs.

    Licensed to: Avira AntiVir PersonalEdition Classic
    Serial number: 0000149996-ADJIE-0001
    Platform: Windows XP
    Windows version: (Service Pack 2) [5.1.2600]
    Username: Maisondesb
    Computer name: MAISON-L4YUM757

    Version information:
    BUILD.DAT : 248 14437 Bytes 31/05/2007 16:59:00
    AVSCAN.EXE : 7.0.4.15 282664 Bytes 20/04/2007 11:37:14
    AVSCAN.DLL : 7.0.4.4 33832 Bytes 27/03/2007 11:31:54
    LUKE.DLL : 7.0.4.11 143400 Bytes 27/03/2007 11:26:04
    LUKERES.DLL : 7.0.4.0 10280 Bytes 19/03/2007 11:18:59
    ANTIVIR0.VDF : 6.35.0.1 7371264 Bytes 31/05/2006 13:08:58
    ANTIVIR1.VDF : 6.37.1.151 4303360 Bytes 23/02/2007 13:09:01
    ANTIVIR2.VDF : 6.38.0.214 729600 Bytes 12/04/2007 13:09:02
    ANTIVIR3.VDF : 6.38.0.225 50688 Bytes 16/04/2007 13:09:02
    AVEWIN32.DLL : 7.4.0.12 2404864 Bytes 13/04/2007 13:04:24
    AVWINLL.DLL : 1.0.0.7 14376 Bytes 26/02/2007 09:36:26
    AVPREF.DLL : 7.0.2.1 24616 Bytes 27/03/2007 11:31:50
    AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 12:16:24
    AVPACK32.DLL : 7.3.0.8 360488 Bytes 27/03/2007 07:48:28
    AVREG.DLL : 7.0.1.2 31784 Bytes 15/03/2007 08:05:08
    AVEVTLOG.DLL : 7.0.0.18 86056 Bytes 27/03/2007 11:16:05
    AVARKT.DLL : 1.0.0.17 278568 Bytes 02/05/2007 10:32:26
    NETNT.DLL : 7.0.0.0 7720 Bytes 08/03/2007 10:09:42
    RCIMAGE.DLL : 7.0.1.15 2228264 Bytes 13/03/2007 09:46:18
    RCTEXT.DLL : 7.0.45.0 86056 Bytes 19/03/2007 11:42:42

    Configuration settings for the scan:
    Jobname..........................: Rootkit search
    Configuration file...............: C:\Program Files\AntiVir PersonalEdition Classic\rootkit.avp
    Logging..........................: high
    Primary action...................: interactive
    Secondary action.................: ignore
    Scan master boot sector..........: on
    Scan boot sector.................: on
    Scan memory......................: off
    Process scan.....................: off
    Scan registry....................: off
    Search for rootkits..............: on
    Scan all files...................: All files
    Scan archives....................: on
    Recursion depth..................: 20
    Smart extensions.................: on
    Deviating archive types..........: +BSD Mailbox, +Netscape/Mozilla Mailbox, +Eudora Mailbox, +Squid cache, +Pegasus Mailbox, +MS Outlook Mailbox,
    Macro heuristic..................: on
    File heuristic...................: high
    Deviating risk categories........: +APPL,+GAME,+JOKE,+PCK,+SPR,
    Expanded search settings.........: 0x00300922

    Start of the scan: mardi 18 septembre 2007 10:26

    Starting search for hidden objects.
    c:\documents and settings\maisondesb\local settings\application data\ehrjbefgxa.dat
    [NOTE] The file is not visible.
    [INFO] A backup was created as '47618d5a.qua' ( QUARANTINE )
    c:\documents and settings\maisondesb\local settings\application data\ehrjbefgxa.exe
    [NOTE] The file is not visible.
    [INFO] A backup was created as '452777ef.qua' ( QUARANTINE )
    [NOTE] ehrjbefgxa.exe
    [NOTE] The process is not visible.
    c:\documents and settings\maisondesb\local settings\application data\ehrjbefgxa_nav.dat
    [NOTE] The file is not visible.
    [INFO] A backup was created as '4528ad17.qua' ( QUARANTINE )
    c:\documents and settings\maisondesb\local settings\application data\ehrjbefgxa_navps.dat
    [NOTE] The file is not visible.
    [INFO] A backup was created as '452ac8bf.qua' ( QUARANTINE )
    c:\windows\prefetch\ehrjbefgxa.exe-00618453.pf
    [NOTE] The file is not visible.
    [INFO] A backup was created as '452ce627.qua' ( QUARANTINE )
    HKEY_USERS\S-1-5-21-854245398-838170752-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Runehrjbefgxa
    [NOTE] The registry entry is invisible.
    HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters\Interfaces\{62D70CF1-3CC0-4D50-861D-163A6BC10F89}ntecontextlist
    [NOTE] The registry entry is invisible.
    '281549' objects were checked, '8' hidden objects were found.

    End of the scan: mardi 18 septembre 2007 10:31
    Used time: 05:48 min

    The scan has been done completely.

    0 Scanning directories
    5 Files were scanned
    0 viruses and/or unwanted programs were found
    0 classified as suspicious:
    0 files were deleted
    0 files were repaired
    5 files were moved to quarantine
    0 files were renamed
    0 Files cannot be scanned
    5 Files not concerned
    0 Archives were scanned
    0 Warnings
    0 Notes
    8 Hidden objects were found

    /////////////////////////////////////////////////////////////////

    magré tt ca c'te putain de popup est encore présente !!
    0
  6. jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 041
     
    scan avec antivir en mode sans echec pour les virer (demarrer l'ordi en appuayant sur F8)

    ___________________
    puis

    refait navilog premiere partie
    télécharger sur le bureau
    Navilog.zip
    http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe

    = Double-Clic navilog1.zip
    = Extraire tout sur le bureau
    = Double-Clic navilog1 qui est sur le bureau
    = Appuyer sur une touche jusqu' arriver aux options
    = Choisir option 1

    un rapport : fixnavi.txt dans C : va se creer
    le copier/coller dans ton prochain message.

    ____________________

    et recolle hijackthis comme indiqué en le renommant:

    Je conseille de renomer Hijackthis, pour contrer une éventuelle infection de Vundo.

    ex:Renomme le fichier HijackThis.exe en eden.exe pour cela, fais un clic droit sur le fichier HijackThis.exe et choisis renommer dans la liste

    Ensuite avec Explorer créer un dossier c:\hijackthis
    Décompresser Hijackthis dans ce dossier.
    C'est important pour les sauvegardes."
    0
  7. jojo
     
    OK.

    Le rapport ANTIVIR en mode sans echec:

    AntiVir PersonalEdition Classic
    Report file date: vendredi 21 septembre 2007 09:36

    Scanning for 1076995 virus strains and unwanted programs.

    Licensed to: Avira AntiVir PersonalEdition Classic
    Serial number: 0000149996-ADJIE-0001
    Platform: Windows XP
    Windows version: (Service Pack 2) [5.1.2600]
    Username: Maisondesb
    Computer name: MAISON-L4YUM757

    Version information:
    BUILD.DAT : 268 15604 Bytes 31/08/2007 13:04:00
    AVSCAN.EXE : 7.0.6.1 290856 Bytes 23/08/2007 12:16:29
    AVSCAN.DLL : 7.0.6.0 49192 Bytes 16/08/2007 11:23:51
    LUKE.DLL : 7.0.5.3 147496 Bytes 14/08/2007 14:32:47
    LUKERES.DLL : 7.0.6.1 10280 Bytes 21/08/2007 11:35:20
    ANTIVIR0.VDF : 6.35.0.1 7371264 Bytes 31/05/2006 11:32:40
    ANTIVIR1.VDF : 6.39.0.129 7251968 Bytes 10/07/2007 11:32:46
    ANTIVIR2.VDF : 6.39.1.120 1918464 Bytes 12/09/2007 08:23:52
    ANTIVIR3.VDF : 6.39.1.160 197632 Bytes 21/09/2007 07:14:07
    AVEWIN32.DLL : 7.6.0.15 2806272 Bytes 20/09/2007 08:22:48
    AVWINLL.DLL : 1.0.0.7 14376 Bytes 26/02/2007 09:36:26
    AVPREF.DLL : 7.0.2.2 25640 Bytes 18/07/2007 06:39:17
    AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 12:16:24
    AVPACK32.DLL : 7.3.0.15 360488 Bytes 03/08/2007 07:46:00
    AVREG.DLL : 7.0.1.6 30760 Bytes 18/07/2007 06:17:06
    AVARKT.DLL : 1.0.0.20 278568 Bytes 28/08/2007 11:26:33
    AVEVTLOG.DLL : 7.0.0.20 86056 Bytes 18/07/2007 06:10:18
    NETNT.DLL : 7.0.0.0 7720 Bytes 08/03/2007 10:09:42
    RCIMAGE.DLL : 7.0.1.30 2342952 Bytes 07/08/2007 11:38:13
    RCTEXT.DLL : 7.0.62.0 86056 Bytes 21/08/2007 11:50:37
    SQLITE3.DLL : 3.3.17.1 339968 Bytes 23/07/2007 08:37:21

    Configuration settings for the scan:
    Jobname..........................: Complete system scan
    Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
    Logging..........................: low
    Primary action...................: interactive
    Secondary action.................: ignore
    Scan master boot sector..........: on
    Scan boot sector.................: on
    Boot sectors.....................: C:,
    Scan memory......................: on
    Process scan.....................: on
    Scan registry....................: on
    Search for rootkits..............: on
    Scan all files...................: All files
    Scan archives....................: on
    Recursion depth..................: 20
    Smart extensions.................: on
    Deviating archive types..........: +BSD Mailbox, +Netscape/Mozilla Mailbox, +Eudora Mailbox, +Squid cache, +Pegasus Mailbox, +MS Outlook Mailbox,
    Macro heuristic..................: on
    File heuristic...................: medium

    Start of the scan: vendredi 21 septembre 2007 09:36

    Starting search for hidden objects.
    The driver could not be initialized.

    The scan of running processes will be started
    Scan process 'avscan.exe' - '1' Module(s) have been scanned
    Scan process 'avscan.exe' - '1' Module(s) have been scanned
    Scan process 'avcenter.exe' - '1' Module(s) have been scanned
    Scan process 'explorer.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'guard.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'lsass.exe' - '1' Module(s) have been scanned
    Scan process 'services.exe' - '1' Module(s) have been scanned
    Scan process 'winlogon.exe' - '1' Module(s) have been scanned
    Scan process 'csrss.exe' - '1' Module(s) have been scanned
    Scan process 'smss.exe' - '1' Module(s) have been scanned
    13 processes with 13 modules were scanned

    Starting master boot sector scan:
    Master boot sector HD0
    [NOTE] No virus was found!

    Start scanning boot sectors:
    Boot sector 'C:\'
    [NOTE] No virus was found!

    Starting to scan the registry.
    The registry was scanned ( '21' files ).

    Starting the file scan:

    Begin scan in 'C:\'
    C:\pagefile.sys
    [WARNING] The file could not be opened!
    C:\Documents and Settings\Maisondesb\Bureau\ComboFix.exe
    [0] Archive type: RAR SFX (self extracting)
    --> setpath.cfexe
    [DETECTION] Contains suspicious code HEUR/Malware
    [WARNING] The file was ignored!
    C:\Program Files\Navilog1\navilog1.bat
    [DETECTION] Contains suspicious code HEUR/Exploit.HTML
    [WARNING] The file was ignored!

    End of the scan: vendredi 21 septembre 2007 10:33
    Used time: 56:33 min

    The scan has been done completely.

    2308 Scanning directories
    102926 Files were scanned
    0 viruses and/or unwanted programs were found
    2 Files were classified as suspicious:
    0 files were deleted
    0 files were repaired
    0 files were moved to quarantine
    0 files were renamed
    1 Files cannot be scanned
    102926 Files not concerned
    1749 Archives were scanned
    3 Warnings
    0 Notes

    °°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°

    le rapport Navilog

    Search Navipromo version 3.0.4 commencé le 21/09/2007 à 11:45:52,57

    !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
    !!! Poster ce rapport sur le forum pour le faire analyser !!!
    !!! Ne pas lancer la partie désinfection sans l'avis d'un spécialiste !!!

    Fix lancé depuis C:\Program Files\navilog1
    Mise a jour le 16.09.2007 a 13h00 by IL-MAFIOSO

    Microsoft Windows XP [version 5.1.2600]
    Internet Explorer : 7.0.5730.11

    *** Recherche Programmes installes ***

    *** Recherche dossiers dans C:\WINDOWS ***

    *** Recherche dossiers dans C:\Program Files ***

    *** Recherche dossiers dans C:\Documents and Settings\All Users\Application Data ***

    *** Recherche dossiers dans C:\Documents and Settings\Maisondesb\Application Data ***

    *** Recherche avec BlackLight Engine/F-secure ***
    BlackLight Engine est un produit de F-secure, pour + d'infos :
    https://www.f-secure.com/en

    Fichier(s) caché(s) dans C:\WINDOWS\system32 :

    Processus caché(s) dans C:\WINDOWS\system32 :

    *** Recherche avec GenericNaviSearch ***
    !!! Tous Ces résultats peuvent révéler des fichiers légitimes !!!
    !!! A verifier impérativement avant toute suppression manuelle !!!

    * Scan C:\WINDOWS\system32 *

    Fichiers trouvés :

    Aucun Fichier trouvé !

    Fichiers suspects :

    Aucun Fichier suspect trouvé !

    *** Recherche fichiers ***

    *** Recherche cles registre ***

    HKEY_CURRENT_USER\Software\Lanconfig trouvé !
    HKEY_USERS\S-1-5-21-854245398-838170752-725345543-1004\Software\Lanconfig trouvé !

    *** Module de Recherche complémentaire ***
    (Recherche fichiers spécifiques)

    1)Recherche fichiers connus:

    2)Recherche Heuristique :

    3)Recherche Certificats :

    Certificat Egroup trouvé !

    *** Analyse Terminé le 21/09/2007 à 11:51:07,20 ***
    °°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°

    le rapport hijackhis

    Logfile of HijackThis v1.99.1
    Scan saved at 11:56:57, on 21/09/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16512)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    C:\Program Files\a-squared Anti-Dialer\a2service.exe
    c:\program files\a-squared free\a2service.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Program Files\Soft4Ever\looknstop\looknstop.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\MSN Messenger\usnsvc.exe
    C:\Program Files\Hijackthis Version Française\eden.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
    O4 - HKLM\..\Run: [Look 'n' Stop] "C:\Program Files\Soft4Ever\looknstop\looknstop.exe" -auto
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O11 - Options group: [INTERNATIONAL] International*
    O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
    O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
    O23 - Service: a-squared Anti-Dialer Service (a2AntiDialer) - Emsi Software GmbH - C:\Program Files\a-squared Anti-Dialer\a2service.exe
    O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - c:\program files\a-squared free\a2service.exe
    O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    O23 - Service: Service d'état ASP.NET (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    0
  8. jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 041
     
    ok
    antivir n'a rien trouvé sauf deux logiciels combofix et navilog que je t'ai fait installer

    _______________

    dans démarrer puis PANNEAU DE CONFIGURATION puis AJOUT SUPPRESSION DE PROGRAMME

    cherche quelque chose comme CID et msn plus et desinstalle les
    si tu doit réinstaller msn plus fait le sans les sponsor surtout

    __________

    = Lance navilog1
    = Cette fois-ci choisi l'option 2
    = Navilog va faire le nettoyage.. patient jusqu'à ce qui soit marqué *** Nettoyage Termine le ..... ***
    = Un rapport va être génrer sur ton C:\ qui sera en option 2
    Note: le bureau disparaît

    = colle le contenu du rapport de navilog (qui est en option2)
    ----------------------

    encore des pbs?
    0
Précédent
  • 1
  • 2