Smitfraud-C.CoreService - Page 2

Résolu
  1. ouf ça y est, java ok, acrobate aussi

    ensuite j'ai fait le scan en mode sans echec et j'ai eu un petit probleme: quand il a trouvé des trucs j'ai coché mettre en quarantaine mais comme l'écran est réduit je n'ai pas pu voir si je confirmais ou si j'annulais, j'ai juste pu faire entrer...

    voici le rapport

    AntiVir PersonalEdition Classic
    Report file date: mardi 11 décembre 2007 18:18

    Scanning for 970579 virus strains and unwanted programs.

    Licensed to: Avira AntiVir PersonalEdition Classic
    Serial number: 0000149996-ADJIE-0001
    Platform: Windows XP
    Windows version: (Service Pack 2) [5.1.2600]
    Username: Administrateur
    Computer name: MON_PAYCAY

    Version information:
    BUILD.DAT : 270 15603 Bytes 19/09/2007 13:32:00
    AVSCAN.EXE : 7.0.6.1 290856 Bytes 23/08/2007 13:16:29
    AVSCAN.DLL : 7.0.6.0 49192 Bytes 16/08/2007 12:23:51
    LUKE.DLL : 7.0.5.3 147496 Bytes 14/08/2007 15:32:47
    LUKERES.DLL : 7.0.6.1 10280 Bytes 21/08/2007 12:35:20
    ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 14:27:15
    ANTIVIR1.VDF : 7.0.0.0 1640448 Bytes 13/09/2007 14:26:55
    ANTIVIR2.VDF : 7.0.1.30 1575424 Bytes 30/11/2007 17:01:31
    ANTIVIR3.VDF : 7.0.1.75 203264 Bytes 11/12/2007 17:01:31
    AVEWIN32.DLL : 7.6.0.40 3064320 Bytes 11/12/2007 17:01:32
    AVWINLL.DLL : 1.0.0.7 14376 Bytes 26/02/2007 10:36:26
    AVPREF.DLL : 7.0.2.2 25640 Bytes 18/07/2007 07:39:17
    AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 13:16:24
    AVPACK32.DLL : 7.3.0.15 360488 Bytes 03/08/2007 08:46:00
    AVREG.DLL : 7.0.1.6 30760 Bytes 18/07/2007 07:17:06
    AVARKT.DLL : 1.0.0.20 278568 Bytes 28/08/2007 12:26:33
    AVEVTLOG.DLL : 7.0.0.20 86056 Bytes 18/07/2007 07:10:18
    NETNT.DLL : 7.0.0.0 7720 Bytes 08/03/2007 11:09:42
    RCIMAGE.DLL : 7.0.1.30 2342952 Bytes 07/08/2007 12:38:13
    RCTEXT.DLL : 7.0.62.0 86056 Bytes 21/08/2007 12:50:37
    SQLITE3.DLL : 3.3.17.1 339968 Bytes 23/07/2007 09:37:21

    Configuration settings for the scan:
    Jobname..........................: Complete system scan
    Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
    Logging..........................: low
    Primary action...................: interactive
    Secondary action.................: ignore
    Scan master boot sector..........: off
    Scan boot sector.................: on
    Boot sectors.....................: E:,
    Scan memory......................: on
    Process scan.....................: on
    Scan registry....................: on
    Search for rootkits..............: off
    Scan all files...................: All files
    Scan archives....................: on
    Recursion depth..................: 20
    Smart extensions.................: on
    Macro heuristic..................: on
    File heuristic...................: high

    Start of the scan: mardi 11 décembre 2007 18:18

    The scan of running processes will be started
    Scan process 'avscan.exe' - '1' Module(s) have been scanned
    Scan process 'avcenter.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'explorer.exe' - '1' Module(s) have been scanned
    Scan process 'aawservice.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'lsass.exe' - '1' Module(s) have been scanned
    Scan process 'services.exe' - '1' Module(s) have been scanned
    Scan process 'winlogon.exe' - '1' Module(s) have been scanned
    Scan process 'csrss.exe' - '1' Module(s) have been scanned
    Scan process 'smss.exe' - '1' Module(s) have been scanned
    12 processes with 12 modules were scanned

    Start scanning boot sectors:
    Boot sector 'C:\'
    [NOTE] No virus was found!
    Boot sector 'E:\'
    [NOTE] No virus was found!

    Starting to scan the registry.
    The registry was scanned ( '36' files ).

    Starting the file scan:

    Begin scan in 'C:\' <Windows>
    C:\qoobox\Quarantine\catchme2007-12-11_143116.42.zip
    [0] Archive type: ZIP
    --> core.sys
    [DETECTION] Is the Trojan horse TR/Rootkit.Gen
    --> cbxxutu.dll
    [DETECTION] Is the Trojan horse TR/Spy.Agent.AOS
    --> pmkjh.dll
    [DETECTION] Is the Trojan horse TR/Vundo.Gen
    [INFO] The file was moved to '47d2cce1.qua'!
    C:\qoobox\Quarantine\C\WINDOWS\system32\cbxxutu.dll.vir
    [DETECTION] Is the Trojan horse TR/Spy.Agent.AOS
    [INFO] The file was moved to '47d6ccea.qua'!
    C:\qoobox\Quarantine\C\WINDOWS\system32\dypacpim.dll.vir
    [DETECTION] Is the Trojan horse TR/Vundo.DRT
    [INFO] The file was moved to '47cecd02.qua'!
    C:\qoobox\Quarantine\C\WINDOWS\system32\pmkjh.dll.vir
    [DETECTION] Is the Trojan horse TR/Trash.Gen
    [INFO] The file was moved to '47c9ccf7.qua'!
    C:\qoobox\Quarantine\C\WINDOWS\system32\urqroli.dll.vir
    [DETECTION] Is the Trojan horse TR/Spy.Agent.AOS
    [INFO] The file was moved to '47cfccfc.qua'!
    C:\WINDOWS\system32\drivers\dtscsi.sys
    [WARNING] The file could not be opened!
    C:\WINDOWS\system32\drivers\sptd.sys
    [WARNING] The file could not be opened!
    C:\WINDOWS\system32\drivers\sptd8845.sys
    [WARNING] The file could not be opened!
    Begin scan in 'E:\' <Mes données>
    E:\pagefile.sys
    [WARNING] The file could not be opened!
    E:\Logiciels\emotionicones\26000_émoticones_MSN_Messenger_par_WARSEZ.rar
    [0] Archive type: RAR
    --> 26000_‚moticones_MSN_Messenger_par_WARSEZ\EMOTICON\msn messenger 6.2 + generatore di disegni\MsgPlus-301.exe
    [DETECTION] Is the Trojan horse TR/Dldr.Swizzor.AG.2
    [INFO] The file was moved to '478ed339.qua'!

    End of the scan: mardi 11 décembre 2007 19:33
    Used time: 1:14:49 min

    The scan has been done completely.

    4582 Scanning directories
    236738 Files were scanned
    8 viruses and/or unwanted programs were found
    0 Files were classified as suspicious:
    0 files were deleted
    0 files were repaired
    6 files were moved to quarantine
    0 files were renamed
    4 Files cannot be scanned
    236730 Files not concerned
    1476 Archives were scanned
    4 Warnings
    0 Notes
    0
    1. Contributeur
      ok

      tout ce que antivir a detecté en plus grande partie (sauf le pack d´emoicones) etait contenue dans les quarantaines des differents outils que nous avons utilisés

      comment va ton pc maintenant?

      @+
      0
      1. antivir s'est relancé au démarage donc je le laisse tourner et ça ralenti mais il avait déja l'air mieux!

        j'ai un disque dur externe, que j'utilise de façon irrégulière. je le passe avec antivir?

        avec quoi dois je proteger mon pc a l'avenir, antivir en permanence j'imagine, dois je mettre autre chose?

        1000 mercis pour tout ce temps passé sur mes problèmes!!!!!
        0
        1. Contributeur
          remets un hijack this stp

          je te donnerais qeuleques conseils pour finir.

          et oui passe antivir sur ton dd externe aussi

          @+
          0
          1. je m'occuperais du disque dur externe plus tard, et si je m'en sort pas je te dirais, c'est pas urgent du tout...

            je vais déja suivre tes instructions pour finir...

            voila le rapport

            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 20:40, on 11/12/2007
            Platform: Windows XP SP2 (WinNT 5.01.2600)
            MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
            Boot mode: Normal

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            E:\Logiciels\aawservice.exe
            E:\Logiciels\avast\aswUpdSv.exe
            E:\Logiciels\avast\ashServ.exe
            C:\WINDOWS\Explorer.EXE
            E:\Logiciels\DAEMON Tools\daemon.exe
            E:\LOGICI~1\avast\ashDisp.exe
            E:\Logiciels\3.0\Apps\apdproxy.exe
            C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
            C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
            C:\Program Files\SuperCopier\SuperCopier.exe
            C:\Program Files\Cegetel\C-BOX\Wizard\QuickAccess.exe
            C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
            C:\Program Files\Google\Web Accelerator\GoogleWebAccWarden.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
            C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
            C:\WINDOWS\system32\drivers\CDAC11BA.EXE
            C:\WINDOWS\system32\nvsvc32.exe
            C:\Program Files\ADSL Autoconnect\ADSL Autoconnect.exe
            C:\Program Files\Google\Web Accelerator\googlewebaccclient.exe
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\Internet Explorer\IEXPLORE.EXE
            C:\WINDOWS\system32\wscntfy.exe
            C:\WINDOWS\system32\wuauclt.exe
            E:\Logiciels\HijackThis.exe

            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.f270.mail.yahoo.com/dc/launch?sysreq=ignore
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.google.fr/?gws_rd=ssl
            R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://localhost:9100/proxy.pac
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
            O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
            O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - E:\Logiciels\BitComet\tools\BitCometBHO_1.1.7.4.dll
            O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - E:\LOGICI~1\SPYBOT~1\SDHelper.dll
            O2 - BHO: Google Web Accelerator Helper - {69A87B7D-DE56-4136-9655-716BA50C19C7} - C:\Program Files\Google\Web Accelerator\GoogleWebAccToolbar.dll
            O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
            O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
            O3 - Toolbar: Google Web Accelerator - {DB87BFA2-A2E3-451E-8E5A-C89982D87CBF} - C:\Program Files\Google\Web Accelerator\GoogleWebAccToolbar.dll
            O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
            O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
            O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
            O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
            O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
            O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
            O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
            O4 - HKLM\..\Run: [adiras] adiras.exe
            O4 - HKLM\..\Run: [DAEMON Tools] "E:\Logiciels\DAEMON Tools\daemon.exe" -lang 1033
            O4 - HKLM\..\Run: [avast!] E:\LOGICI~1\avast\ashDisp.exe
            O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
            O4 - HKLM\..\Run: [Adobe Photo Downloader] "E:\Logiciels\3.0\Apps\apdproxy.exe"
            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
            O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
            O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
            O4 - HKCU\..\Run: [SuperCopier.exe] C:\Program Files\SuperCopier\SuperCopier.exe
            O4 - HKCU\..\Run: [Configuration de la C-BOX] C:\Program Files\Cegetel\C-BOX\Wizard\QuickAccess.exe
            O4 - HKCU\..\Run: [updateMgr] E:\Logiciels\Reader\AdobeUpdateManager.exe AcRdB7_0_9
            O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
            O4 - Global Startup: Run Google Web Accelerator.lnk = C:\Program Files\Google\Web Accelerator\GoogleWebAccWarden.exe
            O8 - Extra context menu item: &D&ownload &with BitComet - res://E:\Logiciels\BitComet\BitComet.exe/AddLink.htm
            O8 - Extra context menu item: &D&ownload all video with BitComet - res://E:\Logiciels\BitComet\BitComet.exe/AddVideo.htm
            O8 - Extra context menu item: &D&ownload all with BitComet - res://E:\Logiciels\BitComet\BitComet.exe/AddAllLink.htm
            O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
            O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
            O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
            O9 - Extra button: BitComet Search - {461CC20B-FB6E-4f16-8FE8-C29359DB100E} - E:\Logiciels\BitComet\tools\BitCometBHO_1.1.7.4.dll
            O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
            O14 - IERESET.INF: START_PAGE_URL=https://www.google.fr/?gws_rd=ssl
            O16 - DPF: {3DA5D23B-EFE1-4181-ADB7-7D457567AACA} (TGOnlineCtrl Class) - http://www.msnjeux.com/online2/MSN_INTL_FRANCE/panda_craze/pandaonline.cab
            O16 - DPF: {49E67060-2C0D-415E-94C7-52A49F73B2F1} (CPlayFirstPiratePoppersControl Object) - http://www.msnjeux.com/online2/MSN_INTL_FRANCE/pirate_poppers/PiratePoppers.1.0.0.32.cab
            O16 - DPF: {639658F3-B141-4D6B-B936-226F75A5EAC3} (CPlayFirstDinerDash2Control Object) - http://msnfr.oberon-media.com/online2/MSN_INTL_FRANCE/diner_dash_2/DinerDash2.1.0.0.53.cab
            O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
            O16 - DPF: {7CCAD6DD-DD0B-440B-91FF-7670F5AADC21} (SpinTop Games Launcher) - http://www.msnjeux.com/online2/MSN_INTL_FRANCE/mystery_solitaire/SpinTopGamesLauncher.cab
            O16 - DPF: {BAE1D8DF-0B35-47E3-A1E7-EEB3FF2ECD19} (CPlayFirstddfotgControl Object) - http://msnfr.oberon-media.com/online2/MSN_INTL_FRANCE/diner_dash_flo_on_the_go/ddfotg.1.0.0.33.cab
            O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game07.zylom.com/activex/zylomgamesplayer.cab
            O16 - DPF: {CE69F98F-2AF3-4306-BAC6-A79070EDA1B4} (Zylom Loader Object) - http://eu.download.games.yahoo.com/zylom/activex/zylomloader.cab
            O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://www.msnjeux.com/online2/MSN_INTL_FRANCE/shapo/shapo.cab
            O16 - DPF: {E1342154-4889-42B5-BEF6-19237577048F} (OberongamesLoader Object) - http://msnfr.oberon-media.com/online2/MSN_INTL_FRANCE/bejeweled2/Oberongamesloader.cab
            O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - E:\Logiciels\aawservice.exe
            O23 - Service: ADSLAutoconnect - Unknown owner - C:\Program Files\ADSL Autoconnect\ADSL Autoconnect.exe
            O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
            O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
            O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - E:\Logiciels\avast\aswUpdSv.exe
            O23 - Service: avast! Antivirus - ALWIL Software - E:\Logiciels\avast\ashServ.exe
            O23 - Service: avast! Mail Scanner - ALWIL Software - E:\Logiciels\avast\ashMaiSv.exe
            O23 - Service: avast! Web Scanner - ALWIL Software - E:\Logiciels\avast\ashWebSv.exe
            O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
            O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
            O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
            O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
            0
            1. ça marche super, merci beaucoup!!!!!
              0
              1. Contributeur
                pimousse29,

                desinstale avast et garde antivir

                Désinstalleur Avast:
                https://www.avast.com/fr-fr/uninstall-utility

                puis :

                tu surf avec internet explorer 6.0 = failles de securitées importantes

                alors fais les mises a jour windows : tu veux la version 7.0

                et pourquoi ne pas surfer avec firefox? = plus sur, tout en gardant ie 7.0 pour les mises a jour windows car impossible a effectuer sous firefox

                ta version de acrobat reader n´est pas a jour, tu veux la version 8.1 derniere en date alors desinstale ta version par le panneau de configuration / ajoue et suppression de programme

                et instale la derniere :

                https://get2.adobe.com/reader/otherversions/

                ou foxit plus léger :

                https://www.clubic.com/telecharger-fiche13808-foxit-reader.html

                Ccleaner:

                -> Télécharge Ccleaner (n'installe pas la barre d'outil Yahoo):

                http://www.commentcamarche.net/telecharger/telechargement 168 ccleaner

                -> L´installer.

                -> Une fois installé et lancé :

                Dans la colonne de gauche, click sur :

                ->"erreurs" :

                Coches toutes les cases dans les propriétés du nettoyeur de l´onglet "windows" et "applications", puis click en bas sur "chercher des erreurs" une fois terminé, clic sur "reparer les erreurs", tu auras un message pour sauvegarder ta base de registre, tu click "oui" puis tu recommence jusqu'à ce qu'il ne trouve plus rien.

                ps : les sauvegardes que tu auras faites, pourront etre supprimées ulterieurement si tout va bien.

                ->"nettoyeur"

                quitte ton navigateur avant de le lancer, décoche la derniere case (Avancé si elle est cochée) puis click sur "lancer le nettoyage" qunand il aura terminé le scan click en bas a droite sur "lancer le nettoyage" et accepte par oui.

                -> Tutoriel en image :

                https://www.vulgarisation-informatique.com/nettoyer-windows-ccleaner.php

                -> Pour ceux qui voudraient aller plus loin en compagnie de jesses (fonctions avancés) :

                et

                telecharge et instal regcleaner:

                http://www.01net.com/windows/Utilitaire/nettoyeurs_et_installeurs/fiches/4894.html

                tutorial :

                http://www.softastuces.com/tuto/maint/regcleaner/

                puis tu peux installer ces antispyware residents pour plus de securité si tu le desir en complement au tea timer de spybot :

                spywareblaster :

                http://www.brightfort.com/spywareblaster.html

                c´est un resident, il suffit de le mettre a jour de temps en temps car la version gratuite ne le fait pas toute seul , une fois installé et mis a jour tu mets toutes les protections sur "enable"

                telecharge aussi cet anti spyware il a aussi un resident le teatimer :

                spyware gard :

                https://www.zebulon.fr/dossiers/securite/47-spywareguard.html

                voila

                Bye`
                0
                Précédent
                • 1
                • 2