Processus inconnu

Résolu
Bonjour,

mon ordi portable rame à la suite de la détection et du nettoyage d'un spyware par spybot. Maintenant, je trouve au demarrage un processus dans mon fichier application data\gghhhhhhhz.exe gghhhhhhhz. Qu'est ce que c'est?
Merci.

52 réponses

Résumé de la discussion

La détection et le nettoyage d'un spyware par Spybot font apparaître au démarrage un fichier gghhhhhhhz.exe dans le dossier Application Data, suscitant des doutes sur son identité. Selon l’analyse, gghhhhhhz.exe peut ne plus exister physiquement mais laisser des traces dans la base de registre; CCleaner est recommandé pour nettoyer ces entrées. D'autres observations indiquent que TBMon.exe peut être un élément légitime selon le contexte, tandis que fzekaee.exe est perçu comme infectieux et à éviter. En cas de doute persistant, les rapports montrent des listes d’éléments d’auto-démarrage et des modules externes, ce qui appelle à une vérification croisée des clés Run et des composants de sécurité.

Bobot (l’IA à votre service)
  1. c'est un fichier executable au nom totalement aléatoire et il ya 99% de chances que ce soit la preuve d'une infection.

    Met un log hijackthis pour vérification
    0
    1. merci pour l'info,
      je suis completement novice, je ne sais pas comment faire
      si tu as le temps de me guider...
      0
      1. autres processus "bizarres":
        sistray.EXE
        TBMon.exe
        fzekaee.exe fzekaee
        merci si vous avez d'autres infos.
        0
        1. voila ce que ca donne

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 22:45:07, on 06/11/2007
          Platform: Windows XP SP2 (WinNT 5.01.2600)
          MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
          Boot mode: Normal

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
          C:\Program Files\Network Associates\VirusScan\Mcshield.exe
          C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
          C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
          C:\WINDOWS\Explorer.EXE
          C:\Program Files\Apoint2K\Apoint.exe
          C:\WINDOWS\System32\sistray.EXE
          C:\WINDOWS\System32\khooker.exe
          C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
          C:\WINDOWS\AGRSMMSG.exe
          C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
          C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
          C:\Program Files\Fichiers communs\Network Associates\TalkBack\TBMon.exe
          C:\Program Files\TechCity Solutions\AliceSAV\AliceAgent.exe
          C:\WINDOWS\system32\rundll32.exe
          C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
          C:\Program Files\Apoint2K\HidFind.exe
          C:\Program Files\Apoint2K\Apntex.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\Internet Explorer\iexplore.exe
          C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
          C:\Program Files\Internet Explorer\iexplore.exe
          C:\logiciels\Trend Micro\HijackThis\HijackThis.exe

          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://portail.free.fr/
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://fr.yahoo.com/?p=us
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ustart.org
          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Alice ADSL
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
          O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
          O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
          O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
          O4 - HKLM\..\Run: [SiS Tray] C:\WINDOWS\System32\sistray.EXE
          O4 - HKLM\..\Run: [SiS KHooker] C:\WINDOWS\System32\khooker.exe
          O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
          O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
          O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
          O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
          O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Fichiers communs\Network Associates\TalkBack\TBMon.exe"
          O4 - HKLM\..\Run: [AliceSAV] C:\Program Files\TechCity Solutions\AliceSAV\AliceAgent.exe
          O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
          O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
          O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
          O4 - HKCU\..\Run: [gghhhhhhhz] c:\documents and settings\caroline\local settings\application data\gghhhhhhhz.exe gghhhhhhhz
          O4 - HKCU\..\Run: [fzekaee] c:\windows\system32\fzekaee.exe fzekaee
          O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
          O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
          O4 - HKUS\S-1-5-18\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'SYSTEM')
          O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
          O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
          O4 - Global Startup: Microsoft Office.lnk = C:\logiciels\MSOffice\Office\OSA9.EXE
          O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
          O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
          O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O15 - Trusted Zone: http://www.secuser.com
          O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) - http://s.tf1.fr/mmdia/static/rawflow/clients/5.3.1.0/Rawflow.cab
          O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www3.snapfish.fr/SnapfishActivia.cab
          O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
          O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/webplayer/stage6/windows/AutoDLDivXWebPlayerInstaller.cab
          O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
          O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://cbn971.spaces.live.com/PhotoUpload/MsnPUpld.cab
          O16 - DPF: {B49C4597-8721-4789-9250-315DFBD9F525} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/radio/ampx/ampx2.6.1.11_en_dl.cab
          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          O23 - Service: Service Framework McAfee (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
          O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
          O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
          O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
          0
          1. Télécharge navilog sur le bureau
            Site officiel >> http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe
            tu le lances set tu choisis l'option 1
            puis tu reviens avec le rapport dans ta réponse
            0
            1. Voici le resuslat

              Search Navipromo version 3.3.4 commencé le 06/11/2007 à 22:58:00,19

              !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
              !!! Postez ce rapport sur le forum pour le faire analyser !!!
              !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

              Outil exécuté depuis C:\Program Files\navilog1
              Mise à jour le 02.11.2007 à 12h00 par IL-MAFIOSO

              Microsoft Windows XP [version 5.1.2600]
              Internet Explorer : 6.0.2900.2180

              *** Recherche Programmes installés ***

              *** Recherche dossiers dans C:\WINDOWS ***

              *** Recherche dossiers dans C:\Program Files ***

              *** Recherche dossiers dans C:\Documents and Settings\All Users\Application Data ***

              *** Recherche dossiers dans C:\Documents and Settings\caroline\Application Data ***

              *** Recherche dossiers dans C:\DOCUME~1\ALLUSE~1\MENUDÉ~1\PROGRA~1 ***

              *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
              pour + d'infos : http://www.gmer.net

              Aucun fichier trouvé dans :

              - C:\WINDOWS\system32
              - C:\DOCUME~1\CAROLINE\LOCALS~1\APPLIC~1

              *** Recherche avec GenericNaviSearch ***
              !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
              !!! A vérifier impérativement avant toute suppression manuelle !!!

              * Recherche dans C:\WINDOWS\system32 *

              * Recherche dans C:\DOCUME~1\CAROLINE\LOCALS~1\APPLIC~1 *

              *** Recherche fichiers ***

              C:\WINDOWS\pack.epk trouvé !

              *** Recherche clés spécifiques dans le Registre ***

              HKEY_CURRENT_USER\Software\Lanconfig trouvé !

              *** Module de Recherche complémentaire ***
              (Recherche fichiers spécifiques)

              1)Recherche fichiers connus:

              2)Recherche Heuristique :

              C:\DOCUME~1\CAROLINE\LOCALS~1\APPLIC~1\gghhhhhhhz.dat trouvé !
              C:\DOCUME~1\CAROLINE\LOCALS~1\APPLIC~1\gghhhhhhhz_nav.dat trouvé !

              3)Recherche Certificats :

              Certificat Egroup trouvé !

              *** Analyse terminée le 06/11/2007 à 22:59:00,80 ***
              0
              1. pour info, systray est un process de windows

                Tbmon, voilà ce que j'ai trouvé à son sujet

                The process TalkBack Monitor belongs to the software TalkBack Monitor or McAfee VirusScan Enterprise or Employer eServices or Yazzle by OIN or Windows Media Encoder 9 Series or TBMon.exe or rgc:audio Triangle II by Network Associates, Inc (nai.com).

                File TBMon.exe is located in a subfolder of "C:\Program Files\Common Files" (usually C:\Program Files\Common Files\Network Associates\TalkBack\). Known file sizes on Windows XP are 147514 bytes (99% of all occurrence), 69632 bytes.
                TBMon.exe is not a Windows core file. The program has no visible window. Program is loaded during the Windows boot process (see Registry key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run). The application can be removed using the control panel Add\Remove programs applet. Therefore the technical security rating is 38% dangerous, however also read the users reviews.


                chez toi il est situé dans C:\Program Files\Fichiers communs\Network Associates\TalkBack\TBMon.exe

                C'est très probablement un processus parfaitement normal

                Je n'en dirai pas autant de fzekaee.exe qui lui est infectieux à 100%

                0
                1. passe à l'option 2 de navilog
                  0
                  1. il semblerait que ça ait marché, voila ce que ça donne

                    Clean Navipromo version 3.3.4 commencé le 06/11/2007 à 23:05:20,53

                    Outil exécuté depuis C:\Program Files\navilog1
                    Mise à jour le 02.11.2007 à 12h00 par IL-MAFIOSO

                    Microsoft Windows XP [version 5.1.2600]
                    Internet Explorer : 6.0.2900.2180

                    Mode suppression automatique

                    *** fsbl1.txt non trouvé ***
                    (Assurez-vous que Catchme n'avait rien trouvé lors de la recherche)

                    *** Suppression avec sauvegardes résultats GenericNaviSearch ***

                    * Suppression dans C:\WINDOWS\System32 *

                    * Suppression dans C:\DOCUME~1\CAROLINE\LOCALS~1\APPLIC~1 *

                    *** Suppression dossiers dans C:\WINDOWS ***

                    *** Suppression dossiers dans C:\Program Files ***

                    *** Suppression dossiers dans C:\Documents and Settings\All Users\Application Data ***

                    *** Suppression dossiers dans C:\Documents and Settings\caroline\Application Data ***

                    *** Suppression dossiers dans C:\DOCUME~1\ALLUSE~1\MENUDÉ~1\PROGRA~1 ***

                    *** Suppression fichiers ***

                    C:\WINDOWS\pack.epk supprimé !

                    *** Suppression fichiers temporaires ***

                    Nettoyage contenu C:\WINDOWS\Temp effectué !
                    Nettoyage contenu C:\Documents and Settings\caroline\Local Settings\Temp effectué !

                    *** Traitement Recherche complémentaire ***
                    (Recherche fichiers spécifiques)

                    1)Recherche fichiers connus:

                    2)Recherche, création sauvegardes et suppression Heuristique :

                    C:\DOCUME~1\CAROLINE\LOCALS~1\APPLIC~1\gghhhhhhhz.dat trouvé !
                    Copie C:\DOCUME~1\CAROLINE\LOCALS~1\APPLIC~1\gghhhhhhhz.dat réalisé avec succès !
                    C:\DOCUME~1\CAROLINE\LOCALS~1\APPLIC~1\gghhhhhhhz.dat supprimé !

                    C:\DOCUME~1\CAROLINE\LOCALS~1\APPLIC~1\gghhhhhhhz_nav.dat trouvé !
                    Copie C:\DOCUME~1\CAROLINE\LOCALS~1\APPLIC~1\gghhhhhhhz_nav.dat réalisé avec succès !
                    C:\DOCUME~1\CAROLINE\LOCALS~1\APPLIC~1\gghhhhhhhz_nav.dat supprimé !

                    *** Sauvegarde du Registre vers dossier Backupnavi ***

                    sauvegarde du Registre réalisé avec succès !

                    *** Nettoyage Registre ***

                    Nettoyage Registre Ok

                    *** Certificats ***

                    Certificat Egroup supprimé !

                    *** Nettoyage terminé le 06/11/2007 à 23:10:33,85 ***

                    Pourtant quand je regarde dans lemenu demarrer, les 2 processus suspects y sont encore
                    0
                    1. oui ça a marché mais refais un log hijackthis pour voir s'il n'y a pas autre chose
                      0
                      1. Logfile of Trend Micro HijackThis v2.0.2
                        Scan saved at 23:32:33, on 06/11/2007
                        Platform: Windows XP SP2 (WinNT 5.01.2600)
                        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                        Boot mode: Normal

                        Running processes:
                        C:\WINDOWS\System32\smss.exe
                        C:\WINDOWS\system32\winlogon.exe
                        C:\WINDOWS\system32\services.exe
                        C:\WINDOWS\system32\lsass.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\WINDOWS\system32\spoolsv.exe
                        C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
                        C:\Program Files\Network Associates\VirusScan\Mcshield.exe
                        C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
                        C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
                        C:\WINDOWS\Explorer.EXE
                        C:\Program Files\Apoint2K\Apoint.exe
                        C:\WINDOWS\System32\sistray.EXE
                        C:\WINDOWS\System32\khooker.exe
                        C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
                        C:\WINDOWS\AGRSMMSG.exe
                        C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
                        C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
                        C:\Program Files\Fichiers communs\Network Associates\TalkBack\TBMon.exe
                        C:\Program Files\TechCity Solutions\AliceSAV\AliceAgent.exe
                        C:\WINDOWS\system32\rundll32.exe
                        C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                        C:\WINDOWS\system32\ctfmon.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\Program Files\Apoint2K\HidFind.exe
                        C:\Program Files\Apoint2K\Apntex.exe
                        C:\Program Files\Internet Explorer\iexplore.exe
                        C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
                        C:\WINDOWS\system32\wuauclt.exe
                        C:\logiciels\Trend Micro\HijackThis\HijackThis.exe

                        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://portail.free.fr/
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://fr.yahoo.com/?p=us
                        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ustart.org
                        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Alice ADSL
                        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                        O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
                        O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                        O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                        O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
                        O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
                        O4 - HKLM\..\Run: [SiS Tray] C:\WINDOWS\System32\sistray.EXE
                        O4 - HKLM\..\Run: [SiS KHooker] C:\WINDOWS\System32\khooker.exe
                        O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
                        O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
                        O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
                        O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
                        O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Fichiers communs\Network Associates\TalkBack\TBMon.exe"
                        O4 - HKLM\..\Run: [AliceSAV] C:\Program Files\TechCity Solutions\AliceSAV\AliceAgent.exe
                        O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
                        O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                        O4 - HKCU\..\Run: [gghhhhhhhz] c:\documents and settings\caroline\local settings\application data\gghhhhhhhz.exe gghhhhhhhz
                        O4 - HKCU\..\Run: [fzekaee] c:\windows\system32\fzekaee.exe fzekaee
                        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
                        O4 - HKUS\S-1-5-18\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'SYSTEM')
                        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
                        O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
                        O4 - Global Startup: Microsoft Office.lnk = C:\logiciels\MSOffice\Office\OSA9.EXE
                        O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                        O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                        O15 - Trusted Zone: http://www.secuser.com
                        O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) - http://s.tf1.fr/mmdia/static/rawflow/clients/5.3.1.0/Rawflow.cab
                        O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www3.snapfish.fr/SnapfishActivia.cab
                        O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
                        O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/webplayer/stage6/windows/AutoDLDivXWebPlayerInstaller.cab
                        O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
                        O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://cbn971.spaces.live.com/PhotoUpload/MsnPUpld.cab
                        O16 - DPF: {B49C4597-8721-4789-9250-315DFBD9F525} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/radio/ampx/ampx2.6.1.11_en_dl.cab
                        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                        O23 - Service: Service Framework McAfee (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
                        O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
                        O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
                        O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
                        0
                        1. rafais la procedure navilog mais en mode sans echec.

                          Pour cela tu redemarres ton ordi et lors du redemarrage tu pianotes sasn interruption sur F8

                          avec les fleches du clavier, tu choisiras "mode sans echec"

                          Puis, dans ta session, tu relanceras navilog option 2
                          0
                          1. me revoila, (en espérant ke kris6943, ou une ame charitable soit là)
                            je n'ai pas pu terminer la manip hier soir.
                            En voulant terminer à l'instant, il m'a fallut désinstaller et réinstaller Naivilog à sa demande, puis relancer une recherche. Voila le new result:

                            Search Navipromo version 3.3.4 commencé le 07/11/2007 à 20:40:20,53

                            !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
                            !!! Postez ce rapport sur le forum pour le faire analyser !!!
                            !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

                            Outil exécuté depuis C:\Program Files\navilog1
                            Mise à jour le 02.11.2007 à 12h00 par IL-MAFIOSO

                            Microsoft Windows XP [version 5.1.2600]
                            Internet Explorer : 6.0.2900.2180

                            *** Recherche Programmes installés ***

                            *** Recherche dossiers dans C:\WINDOWS ***

                            *** Recherche dossiers dans C:\Program Files ***

                            *** Recherche dossiers dans C:\Documents and Settings\All Users\Application Data ***

                            *** Recherche dossiers dans C:\Documents and Settings\caroline\Application Data ***

                            *** Recherche dossiers dans C:\DOCUME~1\ALLUSE~1\MENUDÉ~1\PROGRA~1 ***

                            *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
                            pour + d'infos : http://www.gmer.net

                            Aucun fichier trouvé dans :

                            - C:\WINDOWS\system32
                            - C:\DOCUME~1\CAROLINE\LOCALS~1\APPLIC~1

                            *** Recherche avec GenericNaviSearch ***
                            !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
                            !!! A vérifier impérativement avant toute suppression manuelle !!!

                            * Recherche dans C:\WINDOWS\system32 *

                            * Recherche dans C:\DOCUME~1\CAROLINE\LOCALS~1\APPLIC~1 *

                            *** Recherche fichiers ***

                            *** Recherche clés spécifiques dans le Registre ***

                            *** Module de Recherche complémentaire ***
                            (Recherche fichiers spécifiques)

                            1)Recherche fichiers connus:

                            2)Recherche Heuristique :

                            3)Recherche Certificats :

                            Certificat Egroup absent !

                            *** Analyse terminée le 07/11/2007 à 20:41:16,49 ***
                            0
                            1. navilog ne trouve plus rien
                              pourtant il y a encore une infection visible dans ces deux lignes:i

                              O4 - HKCU\..\Run: [gghhhhhhhz] c:\documents and settings\caroline\local settings\application data\gghhhhhhhz.exe gghhhhhhhz
                              O4 - HKCU\..\Run: [fzekaee] c:\windows\system32\fzekaee.exe fzekaee

                              je me renseigne et je reviens avec, j'espère, la solution.
                              0
                              1. j'ai également lancé AVG antirookit qui n'a rien trouvé non plus
                                0
                                1. par contre, je vois les fichiers fzekaee dans le repertoire systeme32, il y en a 4, avec des extention différentes, si ca peut t'aider
                                  0
                                  1. Si tu les vois, renomme les en ajoutant .VIR à leur nom

                                    exemple: fzekaee.exe va devenir fzekaee.exe .vir
                                    0
                                    1. c'est fait.
                                      Mais je voulais aussi te signaler ke g lancer McAfee qui a détecté 2 prog "potentiellement indésirable" (comme il dit),
                                      reboo.exe qui était dans le repertoire de navilog et A0016391.exe qui se trouvait a c:\System Volume Information\_restore....
                                      il semblerait qu'il les ai supprimé.
                                      Est ce grave, docteur?
                                      Deplus, j'ai en repertoire quarantine qui n'est plus vide: il contient A0015901.exe.vir et infected.doc
                                      0
                                      1. A0016391.exe qui se trouvait a c:\System Volume Information\_restore....

                                        celui là, il est (ou était) dans la restauration système de windows
                                        Pour être certain qu'il est supprimé, tu vas désactiver la restauration systeme, puis redémarrer, et la réactiver ensuite.Pour cela, fais ceci:

                                        clic droit sur le poste de travail,
                                        propriétés
                                        restauration du systeme
                                        tu coches desactiver la restauration puis OK
                                        tu redemarres
                                        et tu retournes enlever la coche que tu viens de faire

                                        Tu peux vider ton dossier quarantaine. A quoi bon sauvegarder des choses indésirables....
                                        0
                                        • 1
                                        • 2
                                        • 3