Pubs intempestives

pato59 Messages postés 7 Statut Membre -  
jfkpresident Messages postés 13877 Statut Contributeur sécurité -
Bonjour,

J'ai un problême de pub intempestive lorsque je suis sur le net.

* On m'a dit qu'il s'agit surement d'un spyware. J'ai donc installé spybot mais le résultat d'analyse ne donne rien.
On m'a demander de le configurer, et qu'il y aurait surement des choses à retirer en ce qui concerne le démarrage du systême.
J'ai lancé une analyse, et je posterai le rapport dans le prochain message pour plus de clarté.

* On m'a aussi conseillé de changer d'anti virus, car j'utilisai avast (il deviendrai aveugle).
On m'a parlé de avira antivir, que j'ai installé. J'ai suivi un tutorial pour la configuration. Le scan est en cours à l'heure actuelle.

* On m'a aussi conseillé de changer mon pare-feu car celui de windows ne serai pas fiable.
J'ai donc installé sunbelt Kerio (selon conseils) puis je l'ai configuré.
Depuis, j'ai une tentative d'untrusion bloqué par ce dernier (ça tombe bien, il a l'air de fonctionner ^^).
Mais il s'agit de system 32.

==> c:\windows\system32\hjfzkv.exe

Ce message apparaît sans cesse, ce qui est assez gênant...

Au final, je me retrouve avec :

* des fenêtres intempestives sur le net.
* des programmes qui s'éxécute (selon spybot) au démarrage du systême (je poste le rapport au prochain message.
* un pare-feu qui me bloque quelque chose en rapport avec le system 32.

Merci de l'aide que vous pourriez m'apporter.
Configuration: Windows XP
Firefox 2.0.0.7

11 réponses

  1. pato59 Messages postés 7 Statut Membre
     
    comme promi, voici le rapport de spybot concernant le systême de démarrage (je ne sais pas lesquels supprimer) :

    --- Spybot - Search & Destroy version: 1.5 (build: 20070830) ---

    2007-08-31 blindman.exe (1.0.0.6)
    2007-08-31 SDMain.exe (1.0.0.4)
    2007-08-31 SDUpdate.exe (1.0.6.4)
    2007-08-31 SDWinSec.exe (1.0.0.8)
    2007-08-31 SpybotSD.exe (1.5.1.15)
    2007-08-31 TeaTimer.exe (1.5.0.9)
    2006-03-05 unins000.exe (51.41.0.0)
    2008-01-07 unins001.exe (51.46.0.0)
    2007-08-31 Update.exe (1.4.0.5)
    2007-08-31 advcheck.dll (1.5.3.0)
    2007-04-02 aports.dll (2.1.0.0)
    2005-05-31 borlndmm.dll (7.0.4.453)
    2005-05-31 delphimm.dll (7.0.4.453)
    2007-04-02 DelZip179.dll (1.79.5.3)
    2007-08-31 SDHelper.dll (1.5.0.8)
    2007-08-31 Tools.dll (2.1.2.0)
    2005-05-31 UnzDll.dll (1.73.1.1)
    2005-05-31 ZipDll.dll (1.73.2.0)
    2008-01-02 Includes\Cookies.sbi
    2007-12-26 Includes\Dialer.sbi
    2008-01-02 Includes\DialerC.sbi
    2007-12-26 Includes\Hijackers.sbi
    2008-01-02 Includes\HijackersC.sbi
    2007-10-04 Includes\Keyloggers.sbi
    2008-01-02 Includes\KeyloggersC.sbi
    2004-11-29 Includes\LSP.sbi
    2007-11-07 Includes\Malware.sbi
    2008-01-02 Includes\MalwareC.sbi
    2007-10-24 Includes\PUPS.sbi
    2008-01-02 Includes\PUPSC.sbi
    2008-01-02 Includes\Revision.sbi
    2007-05-30 Includes\Security.sbi
    2008-01-02 Includes\SecurityC.sbi
    2007-11-07 Includes\Spybots.sbi
    2008-01-02 Includes\SpybotsC.sbi
    2007-11-06 Includes\Tracks.uti
    2007-12-12 Includes\Trojans.sbi
    2008-01-02 Includes\TrojansC.sbi
    2008-12-24 Plugins\TCPIPAddress.dll

    Located: HK_LM:Run, Adobe Reader Speed Launcher
    command: "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    file: C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
    size: 39792
    MD5: E28D00EC675F5F5A5A0555E7A4523A6E

    Located: HK_LM:Run, ATIPTA
    command: C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    file: C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    size: 344064
    MD5: 8016FE187A0FEC6FEC628DDC21E8A248

    Located: HK_LM:Run, avgnt
    command: "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
    file: C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
    size: 249896
    MD5: 6E898F5959E7195D64594C30E9251938

    Located: HK_LM:Run, CTDVDDET
    command: C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDet.EXE
    file: C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDet.EXE
    size: 45056
    MD5: DB20FCE248D269E1C396E70A91E587C8

    Located: HK_LM:Run, CTHelper
    command: CTHELPER.EXE
    file: C:\WINDOWS\system32\CTHELPER.EXE
    size: 24576
    MD5: 439231898C6FDC13996AE3D733D00FBA

    Located: HK_LM:Run, ehTray
    command: C:\WINDOWS\ehome\ehtray.exe
    file: C:\WINDOWS\ehome\ehtray.exe
    size: 64512
    MD5: 9C69E6A25F5500501B14AF43311F8D8B

    Located: HK_LM:Run, EoEngine
    command:
    file:
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: HK_LM:Run, EoWeather
    command:
    file:
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: HK_LM:Run, HPHmon06
    command: C:\WINDOWS\system32\hphmon06.exe
    file: C:\WINDOWS\system32\hphmon06.exe
    size: 659456
    MD5: A6FD829F428F6445B8F72FF725438590

    Located: HK_LM:Run, HPHUPD06
    command: c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
    file: c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
    size: 49152
    MD5: FE08C1FF4466AD41F6AA113678F5020D

    Located: HK_LM:Run, hpsysdrv
    command: c:\windows\system\hpsysdrv.exe
    file: c:\windows\system\hpsysdrv.exe
    size: 52736
    MD5: 06A1ECB63DF139EC639E084D4AB3C9D7

    Located: HK_LM:Run, IgfxTray
    command: C:\WINDOWS\system32\igfxtray.exe
    file: C:\WINDOWS\system32\igfxtray.exe
    size: 155648
    MD5: 8BBBADA96FFE1449EDD39256EDA99CD8

    Located: HK_LM:Run, IMEKRMIG6.1
    command: C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
    file: C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
    size: 44032
    MD5: E6BB63BBE1BED01769CA87F4DAC286C8

    Located: HK_LM:Run, IMJPMIG8.1
    command: "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
    file: C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE
    size: 208952
    MD5: 7BBE4CF421AECC7F0226EDD75F12079F

    Located: HK_LM:Run, ISUSPM Startup
    command: C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
    file: C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe
    size: 196608
    MD5: 81061E94950A18093E0FFD0841896F22

    Located: HK_LM:Run, LogitechVideoRepair
    command: C:\Program Files\Logitech\Video\ISStart.exe
    file: C:\Program Files\Logitech\Video\ISStart.exe
    size: 458752
    MD5: 3C0EE706CEB7E9A154BF8E7749CA5A91

    Located: HK_LM:Run, LogitechVideoTray
    command: C:\Program Files\Logitech\Video\LogiTray.exe
    file: C:\Program Files\Logitech\Video\LogiTray.exe
    size: 217088
    MD5: 2D3BCCA5C7CA55FEDD60E3336D3A92AF

    Located: HK_LM:Run, LSBWatcher
    command: c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
    file: c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
    size: 253952
    MD5: 9819C4F68686E9FE1D62DD0D4767DDD5

    Located: HK_LM:Run, LVCOMSX
    command: C:\WINDOWS\system32\LVCOMSX.EXE
    file: C:\WINDOWS\system32\LVCOMSX.EXE
    size: 221184
    MD5: 5BA8A7DA5D0573F7923E02B260AAD2F1

    Located: HK_LM:Run, MsmqIntCert
    command: regsvr32 /s mqrt.dll
    file: C:\WINDOWS\system32\reg.exe
    size: 53248
    MD5: 53771CA046C6606A1FC807E077131224

    Located: HK_LM:Run, MSPY2002
    command: C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
    file: C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe
    size: 59392
    MD5: 1B17E09C1223F6D17336D2DD7A1AF4F4

    Located: HK_LM:Run, NeroFilterCheck
    command: C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
    file: C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
    size: 155648
    MD5: C93AB037A8C792D5F8A1A9FC88A7C7C5

    Located: HK_LM:Run, PHIME2002A
    command: C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
    file: C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE
    size: 455168
    MD5: 024DC0F68DF5FD6AE9DD82DFBAF479D6

    Located: HK_LM:Run, PHIME2002ASync
    command: C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
    file: C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE
    size: 455168
    MD5: 024DC0F68DF5FD6AE9DD82DFBAF479D6

    Located: HK_LM:Run, PS2
    command: C:\WINDOWS\system32\ps2.exe
    file: C:\WINDOWS\system32\ps2.exe
    size: 81920
    MD5: C4C523E78774E05D06EFE3E10017CF6D

    Located: HK_LM:Run, QuickTime Task
    command: "C:\Program Files\QuickTime\qttask.exe" -atboottime
    file: C:\Program Files\QuickTime\qttask.exe
    size: 98304
    MD5: 76A3A30B58405C2C6D833895253A51A9

    Located: HK_LM:Run, Recguard
    command: C:\WINDOWS\SMINST\RECGUARD.EXE
    file: C:\WINDOWS\SMINST\RECGUARD.EXE
    size: 233472
    MD5: 310F1E8A0781887BA1C217448C0E4D48

    Located: HK_LM:Run, SunJavaUpdateSched
    command: "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    file: C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
    size: 132496
    MD5: D4F0F7437327DBAA264338BAAFB5E5AF

    Located: HK_LM:Run, UpdReg
    command: C:\WINDOWS\UpdReg.EXE
    file: C:\WINDOWS\UpdReg.EXE
    size: 90112
    MD5: C419DF63E0121D72411285780C2FC6CC

    Located: HK_LM:Run, WOOTASKBARICON
    command: C:\Program Files\Wanadoo\taskbaricon.exe
    file: C:\Program Files\Wanadoo\taskbaricon.exe
    size: 61440
    MD5: F9710A77123CC3FD09D062F2AF33E473

    Located: HK_LM:Run, WOOWATCH
    command: C:\PROGRA~1\Wanadoo\Watch.exe
    file: C:\PROGRA~1\Wanadoo\Watch.exe
    size: 20480
    MD5: 9A29592CD135F6262C429152F7A8DD4A

    Located: HK_CU:Run, DWQueuedReporting
    where: .DEFAULT...
    command: "C:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" -t
    file: C:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe
    size: 36040
    MD5: 34125F1CA24B978DF64AD98A1A0121E6

    Located: HK_CU:RunOnce, CMSRegOW.exe
    where: .DEFAULT...
    command: "C:\Program Files\InstallShield Installation Information\{56F3E1FF-54FE-4384-A153-6CCABA097814}\CMSRegOW.exe" /r
    file: C:\Program Files\InstallShield Installation Information\{56F3E1FF-54FE-4384-A153-6CCABA097814}\CMSRegOW.exe
    size: 57344
    MD5: 736A6D5C68424871A2CC98D328034FC3

    Located: HK_CU:RunOnce, SetDefaultMIDI
    where: .DEFAULT...
    command: MIDIDEF.EXE
    file: C:\WINDOWS\MIDIDEF.EXE
    size: 49152
    MD5: 7398D9F96B38D91DF5566ADA60F04A48

    Located: HK_CU:RunOnce, StartMS
    where: .DEFAULT...
    command: "C:\Program Files\Creative\Shared Files\Media Sniffer\StartMS.EXE" /s
    file: C:\Program Files\Creative\Shared Files\Media Sniffer\StartMS.EXE
    size: 57344
    MD5: 2801D46F0F5996044526410746346D43

    Located: HK_CU:Run, CTFMON.EXE
    where: S-1-5-19...
    command: C:\WINDOWS\system32\CTFMON.EXE
    file: C:\WINDOWS\system32\CTFMON.EXE
    size: 15360
    MD5: 5584247B568C2E53934873F4B655FE6A

    Located: HK_CU:Run, CTFMON.EXE
    where: S-1-5-20...
    command: C:\WINDOWS\system32\CTFMON.EXE
    file: C:\WINDOWS\system32\CTFMON.EXE
    size: 15360
    MD5: 5584247B568C2E53934873F4B655FE6A

    Located: HK_CU:Run, Acme.PCHButton
    where: S-1-5-21-143470311-2256726466-3262716457-1006...
    command: C:\PROGRA~1\HELPAN~1\HPQ\XPXWWPP5\plugin\bin\PCHButton.exe
    file:
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: HK_CU:Run, Cld2000.exe
    where: S-1-5-21-143470311-2256726466-3262716457-1006...
    command: C:\Program Files\Calendrier\Cld2000.exe
    file: C:\Program Files\Calendrier\Cld2000.exe
    size: 3080704
    MD5: AD4787DCB19C2E3D9A7D4BDD3A58BA4A

    Located: HK_CU:Run, LogitechSoftwareUpdate
    where: S-1-5-21-143470311-2256726466-3262716457-1006...
    command: "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
    file: C:\Program Files\Logitech\Video\ManifestEngine.exe
    size: 196608
    MD5: D679346402CBF2330CAD1FCF815C6524

    Located: HK_CU:Run, SpybotSD TeaTimer
    where: S-1-5-21-143470311-2256726466-3262716457-1006...
    command: C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    file: C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    size: 1460560
    MD5: B7D4586BFC0DD6C3BE7DCCC252A3E97E

    Located: HK_CU:Run, updateMgr
    where: S-1-5-21-143470311-2256726466-3262716457-1006...
    command: "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
    file:
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: HK_CU:Run, DWQueuedReporting
    where: S-1-5-18...
    command: "C:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" -t
    file: C:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe
    size: 36040
    MD5: 34125F1CA24B978DF64AD98A1A0121E6

    Located: HK_CU:RunOnce, CMSRegOW.exe
    where: S-1-5-18...
    command: "C:\Program Files\InstallShield Installation Information\{56F3E1FF-54FE-4384-A153-6CCABA097814}\CMSRegOW.exe" /r
    file: C:\Program Files\InstallShield Installation Information\{56F3E1FF-54FE-4384-A153-6CCABA097814}\CMSRegOW.exe
    size: 57344
    MD5: 736A6D5C68424871A2CC98D328034FC3

    Located: HK_CU:RunOnce, SetDefaultMIDI
    where: S-1-5-18...
    command: MIDIDEF.EXE
    file: C:\WINDOWS\MIDIDEF.EXE
    size: 49152
    MD5: 7398D9F96B38D91DF5566ADA60F04A48

    Located: HK_CU:RunOnce, StartMS
    where: S-1-5-18...
    command: "C:\Program Files\Creative\Shared Files\Media Sniffer\StartMS.EXE" /s
    file: C:\Program Files\Creative\Shared Files\Media Sniffer\StartMS.EXE
    size: 57344
    MD5: 2801D46F0F5996044526410746346D43

    Located: Démarrage (tous utilisateurs), Microsoft Office.lnk
    where: C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage...
    command: C:\Program Files\Microsoft Office\Office\OSA9.EXE
    file: C:\Program Files\Microsoft Office\Office\OSA9.EXE
    size: 65588
    MD5: E4D6038CB8ABAAFEA299B84CDD4BAF4D

    Located: Démarrage (désactivé), HP Digital Imaging Monitor (DISABLED)
    command: C:\PROGRA~1\HP\DIGITA~1\bin\hpqtra08.exe
    file: C:\PROGRA~1\HP\DIGITA~1\bin\hpqtra08.exe
    size: 241664
    MD5: 16E91805CC071039372AE0037AAA9A2B

    Located: Démarrage (désactivé), Lancement rapide d'Adobe Reader (DISABLED)
    command: C:\PROGRA~1\Adobe\ACROBA~3.0\Reader\READER~1.EXE
    file:
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: Démarrage (désactivé), Logitech Desktop Messenger (DISABLED)
    command: C:\PROGRA~1\Logitech\DESKTO~1\8876480\Program\LDMConf.exe /start
    file: C:\PROGRA~1\Logitech\DESKTO~1\8876480\Program\LDMConf.exe
    size: 450560
    MD5: A5E4CD281C93E174181C5873FAFD4F16

    Located: Démarrage (désactivé), ClickTray Calendar (DISABLED)
    command: C:\PROGRA~1\CLICKT~1\CLICKT~1.EXE
    file:
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: Démarrage (désactivé), MSN Pictures Displayer (DISABLED)
    command: C:\PROGRA~1\MSNPIC~1\MSNPIC~1.EXE /Q
    file: C:\PROGRA~1\MSNPIC~1\MSNPIC~1.EXE
    size: 4118016
    MD5: 3260B5A9FD37A430E2E2990268674E80

    Located: WinLogon, AtiExtEvent
    command: Ati2evxx.dll
    file: Ati2evxx.dll
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: WinLogon, crypt32chain
    command: crypt32.dll
    file: crypt32.dll
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: WinLogon, cryptnet
    command: cryptnet.dll
    file: cryptnet.dll
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: WinLogon, cscdll
    command: cscdll.dll
    file: cscdll.dll
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: WinLogon, igfxcui
    command: igfxsrvc.dll
    file: igfxsrvc.dll
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: WinLogon, ScCertProp
    command: wlnotify.dll
    file: wlnotify.dll
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: WinLogon, Schedule
    command: wlnotify.dll
    file: wlnotify.dll
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: WinLogon, sclgntfy
    command: sclgntfy.dll
    file: sclgntfy.dll
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: WinLogon, SensLogn
    command: WlNotify.dll
    file: WlNotify.dll
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: WinLogon, termsrv
    command: wlnotify.dll
    file: wlnotify.dll
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: WinLogon, WgaLogon
    command: WgaLogon.dll
    file: WgaLogon.dll
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: WinLogon, wlballoon
    command: wlnotify.dll
    file: wlnotify.dll
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!
    0
  2. pato59 Messages postés 7 Statut Membre
     
    on m'a aussi conseillé de poster le rapport HijackThis (apparemment, vous aimmez bien ça ^^)

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 21:34:05, on 07/01/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16574)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\cisvc.exe
    C:\WINDOWS\system32\CTSvcCDA.EXE
    C:\WINDOWS\eHome\ehRecvr.exe
    C:\WINDOWS\eHome\ehSched.exe
    C:\WINDOWS\System32\FTRTSVC.exe
    C:\WINDOWS\system32\inetsrv\inetinfo.exe
    C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
    c:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
    C:\Program Files\Fichiers communs\NMSAccessU.exe
    C:\WINDOWS\ehome\ehtray.exe
    C:\windows\system\hpsysdrv.exe
    C:\WINDOWS\system32\hphmon06.exe
    C:\WINDOWS\system32\ps2.exe
    C:\WINDOWS\system32\CTHELPER.EXE
    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDet.EXE
    C:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\WINDOWS\system32\LVCOMSX.EXE
    C:\Program Files\Logitech\Video\LogiTray.exe
    C:\Program Files\Wanadoo\taskbaricon.exe
    C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
    C:\windows\system32\hjfzkv.exe
    C:\Program Files\Calendrier\Cld2000.exe
    C:\Program Files\Logitech\Video\FxSvr2.exe
    C:\WINDOWS\System32\snmp.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\MsPMSPSv.exe
    C:\WINDOWS\system32\mqsvc.exe
    C:\WINDOWS\system32\mqtgsvc.exe
    C:\WINDOWS\system32\dllhost.exe
    C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
    C:\WINDOWS\eHome\ehmsas.exe
    C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avcenter.exe
    C:\WINDOWS\system32\cidaemon.exe
    C:\WINDOWS\system32\cidaemon.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avscan.exe
    C:\Program Files\Wanadoo\GestionnaireInternet.exe
    C:\Program Files\Wanadoo\ComComp.exe
    C:\PROGRA~1\Wanadoo\Toaster.exe
    C:\PROGRA~1\Wanadoo\Inactivity.exe
    C:\PROGRA~1\Wanadoo\PollingModule.exe
    C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
    C:\Program Files\Wanadoo\Watch.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Documents and Settings\HP_Administrateur\Bureau\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=Q105&bd=pavilion&pf=desktop
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=Q105&bd=pavilion&pf=desktop
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Orange
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
    O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - C:\Program Files\EoRezo\EoAdv\EoRezoBHO.dll (file missing)
    O2 - BHO: DealioBHO Class - {6A87B991-A31F-4130-AE72-6D0C294BF082} - C:\Program Files\Dealio\kb103\Dealio.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
    O3 - Toolbar: Vue HP - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
    O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
    O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
    O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
    O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
    O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
    O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
    O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [CTDVDDET] C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDet.EXE
    O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
    O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
    O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
    O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
    O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
    O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
    O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
    O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
    O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
    O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
    O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
    O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
    O4 - HKLM\..\Run: [WOOTASKBARICON] C:\Program Files\Wanadoo\taskbaricon.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
    O4 - HKLM\..\RunOnce: [Spybot - Search & Destroy] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
    O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
    O4 - HKCU\..\Run: [Acme.PCHButton] C:\PROGRA~1\HELPAN~1\HPQ\XPXWWPP5\plugin\bin\PCHButton.exe
    O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
    O4 - HKCU\..\Run: [Cld2000.exe] C:\Program Files\Calendrier\Cld2000.exe
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
    O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\RunOnce: [SetDefaultMIDI] MIDIDEF.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
    O4 - HKUS\.DEFAULT\..\RunOnce: [SetDefaultMIDI] MIDIDEF.EXE (User 'Default user')
    O4 - .DEFAULT User Startup: AutoTBar.exe (User 'Default user')
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O8 - Extra context menu item: Compare Prices with &Dealio - C:\Program Files\Dealio\kb103\res\DealioSearch.html
    O8 - Extra context menu item: Easy-WebPrint Ajouter à la liste d'impressions - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
    O8 - Extra context menu item: Easy-WebPrint Impression rapide - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
    O8 - Extra context menu item: Easy-WebPrint Imprimer - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
    O8 - Extra context menu item: Easy-WebPrint Prévisualiser - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
    O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
    O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
    O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
    O16 - DPF: {2250C29C-C5E9-4F55-BE4E-01E45A40FCF1} (CMediaMix Object) - http://musicmix.messenger.msn.com/Medialogic.CAB
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab53083.cab
    O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTSvcCDA.EXE
    O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - c:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
    O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
    O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\Fichiers communs\NMSAccessU.exe
    0
  3. pato59 Messages postés 7 Statut Membre
     
    et voilà le rapport d'avira antivir (il n'a pas trouvé de virus, mais 2 choses anormales) :

    AntiVir PersonalEdition Classic
    Report file date: lundi 7 janvier 2008 20:20

    Scanning for 1004655 virus strains and unwanted programs.

    Licensed to: Avira AntiVir PersonalEdition Classic
    Serial number: 0000149996-ADJIE-0001
    Platform: Windows XP
    Windows version: (Service Pack 2) [5.1.2600]
    Username: SYSTEM
    Computer name: LANDEAU

    Version information:
    BUILD.DAT : 270 15603 Bytes 19/09/07 13:32:00
    AVSCAN.EXE : 7.0.6.1 290856 Bytes 23/08/07 13:16:29
    AVSCAN.DLL : 7.0.6.0 49192 Bytes 16/08/07 12:23:51
    LUKE.DLL : 7.0.5.3 147496 Bytes 14/08/07 15:32:47
    LUKERES.DLL : 7.0.6.1 10280 Bytes 21/08/07 12:35:20
    ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/07 14:27:15
    ANTIVIR1.VDF : 7.0.1.95 3367424 Bytes 14/12/07 19:14:58
    ANTIVIR2.VDF : 7.0.1.170 311296 Bytes 28/12/07 19:14:58
    ANTIVIR3.VDF : 7.0.1.200 141312 Bytes 07/01/08 19:14:58
    AVEWIN32.DLL : 7.6.0.46 3084800 Bytes 07/01/08 19:14:58
    AVWINLL.DLL : 1.0.0.7 14376 Bytes 26/02/07 10:36:26
    AVPREF.DLL : 7.0.2.2 25640 Bytes 18/07/07 07:39:17
    AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/07 13:16:24
    AVPACK32.DLL : 7.6.0.2 360488 Bytes 07/01/08 19:14:58
    AVREG.DLL : 7.0.1.6 30760 Bytes 18/07/07 07:17:06
    AVARKT.DLL : 1.0.0.20 278568 Bytes 28/08/07 12:26:33
    AVEVTLOG.DLL : 7.0.0.20 86056 Bytes 18/07/07 07:10:18
    NETNT.DLL : 7.0.0.0 7720 Bytes 08/03/07 11:09:42
    RCIMAGE.DLL : 7.0.1.30 2342952 Bytes 07/08/07 12:38:13
    RCTEXT.DLL : 7.0.62.0 86056 Bytes 21/08/07 12:50:37
    SQLITE3.DLL : 3.3.17.1 339968 Bytes 23/07/07 09:37:21

    Configuration settings for the scan:
    Jobname..........................: Complete system scan
    Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
    Logging..........................: low
    Primary action...................: interactive
    Secondary action.................: ignore
    Scan master boot sector..........: off
    Scan boot sector.................: on
    Boot sectors.....................: D:,
    Scan memory......................: on
    Process scan.....................: on
    Scan registry....................: on
    Search for rootkits..............: off
    Scan all files...................: Intelligent file selection
    Scan archives....................: on
    Recursion depth..................: 20
    Smart extensions.................: on
    Macro heuristic..................: on
    File heuristic...................: medium

    Start of the scan: lundi 7 janvier 2008 20:20

    The scan of running processes will be started
    Scan process 'avscan.exe' - '1' Module(s) have been scanned
    Scan process 'cidaemon.exe' - '1' Module(s) have been scanned
    Scan process 'cidaemon.exe' - '1' Module(s) have been scanned
    Scan process 'avcenter.exe' - '1' Module(s) have been scanned
    Scan process 'sched.exe' - '1' Module(s) have been scanned
    Scan process 'avgnt.exe' - '1' Module(s) have been scanned
    Scan process 'avguard.exe' - '1' Module(s) have been scanned
    Scan process 'kpf4gui.exe' - '1' Module(s) have been scanned
    Scan process 'ehmsas.exe' - '1' Module(s) have been scanned
    Scan process 'alg.exe' - '1' Module(s) have been scanned
    Scan process 'kpf4gui.exe' - '1' Module(s) have been scanned
    Scan process 'dllhost.exe' - '1' Module(s) have been scanned
    Scan process 'mqtgsvc.exe' - '1' Module(s) have been scanned
    Scan process 'mqsvc.exe' - '1' Module(s) have been scanned
    Scan process 'mcrdsvc.exe' - '1' Module(s) have been scanned
    Scan process 'MsPMSPSv.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'snmp.exe' - '1' Module(s) have been scanned
    Scan process 'FxSvr2.exe' - '1' Module(s) have been scanned
    Scan process 'Cld2000.exe' - '1' Module(s) have been scanned
    Scan process 'hjfzkv.exe' - '1' Module(s) have been scanned
    Scan process 'jusched.exe' - '1' Module(s) have been scanned
    Scan process 'TaskBarIcon.exe' - '1' Module(s) have been scanned
    Scan process 'LogiTray.exe' - '1' Module(s) have been scanned
    Scan process 'LVCOMSX.EXE' - '1' Module(s) have been scanned
    Scan process 'qttask.exe' - '1' Module(s) have been scanned
    Scan process 'LSBurnWatcher.exe' - '1' Module(s) have been scanned
    Scan process 'CTDVDDET.exe' - '1' Module(s) have been scanned
    Scan process 'atiptaxx.exe' - '1' Module(s) have been scanned
    Scan process 'CTHELPER.EXE' - '1' Module(s) have been scanned
    Scan process 'ps2.EXE' - '1' Module(s) have been scanned
    Scan process 'hphmon06.exe' - '1' Module(s) have been scanned
    Scan process 'hpsysdrv.exe' - '1' Module(s) have been scanned
    Scan process 'ehtray.exe' - '1' Module(s) have been scanned
    Scan process 'NMSAccessU.exe' - '1' Module(s) have been scanned
    Scan process 'LSSrvc.exe' - '1' Module(s) have been scanned
    Scan process 'kpf4ss.exe' - '1' Module(s) have been scanned
    Scan process 'inetinfo.exe' - '1' Module(s) have been scanned
    Scan process 'FTRTSVC.exe' - '1' Module(s) have been scanned
    Scan process 'ehSched.exe' - '1' Module(s) have been scanned
    Scan process 'ehrecvr.exe' - '1' Module(s) have been scanned
    Scan process 'CTSVCCDA.EXE' - '1' Module(s) have been scanned
    Scan process 'cisvc.exe' - '1' Module(s) have been scanned
    Scan process 'explorer.exe' - '1' Module(s) have been scanned
    Scan process 'msdtc.exe' - '1' Module(s) have been scanned
    Scan process 'ati2evxx.exe' - '1' Module(s) have been scanned
    Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'ati2evxx.exe' - '1' Module(s) have been scanned
    Scan process 'lsass.exe' - '1' Module(s) have been scanned
    Scan process 'services.exe' - '1' Module(s) have been scanned
    Scan process 'winlogon.exe' - '1' Module(s) have been scanned
    Scan process 'csrss.exe' - '1' Module(s) have been scanned
    Scan process 'smss.exe' - '1' Module(s) have been scanned
    59 processes with 59 modules were scanned

    Start scanning boot sectors:
    Boot sector 'C:\'
    [NOTE] No virus was found!
    Boot sector 'D:\'
    [NOTE] No virus was found!

    Starting to scan the registry.
    The registry was scanned ( '54' files ).

    Starting the file scan:

    Begin scan in 'C:\' <HP_PAVILION>
    C:\hiberfil.sys
    [WARNING] The file could not be opened!
    C:\pagefile.sys
    [WARNING] The file could not be opened!
    Begin scan in 'D:\' <HP_RECOVERY>

    End of the scan: lundi 7 janvier 2008 22:19
    Used time: 1:59:00 min

    The scan has been done completely.

    10851 Scanning directories
    674705 Files were scanned
    0 viruses and/or unwanted programs were found
    0 Files were classified as suspicious:
    0 files were deleted
    0 files were repaired
    0 files were moved to quarantine
    0 files were renamed
    2 Files cannot be scanned
    674705 Files not concerned
    17315 Archives were scanned
    2 Warnings
    0 Notes
    0
  4. Mike.us Messages postés 77 Statut Membre 4
     
    Pi_Xi, pour l'erreur de manip' c'est que je voulai t'envoyer le mail par mon compte, et je l'ai fait sur celui de mon père (alors t'aurai pas su qui te contactait ^^).
    0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. jfkpresident Messages postés 13877 Statut Contributeur sécurité 1 175
     
    salut,
    Clique sur ce lien :
    http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe
    pour télécharger navilog1.exe.

    Choisis Enregistrer

    et enregistre-le sur ton bureau.

    Ensuite double clique sur navilog1.exe pour lancer l'installation.
    Une fois l'installation terminée, le fix s'exécutera automatiquement.
    (Si ce n'est pas le cas, double-clique sur le raccourci Navilog1 présent sur le bureau).

    Laisse-toi guider. Au menu principal, choisis 1 et valides.
    (ne fais pas le choix 2,3 ou 4 sans notre avis/accord)

    Patiente jusqu'au message :
    *** Analyse Termine le ..... ***
    Appuie sur une touche comme demandé, le blocnote va s'ouvrir.
    Copie-colle l'intégralité du rapport dans ta réponse. Referme le blocnote.
    Le rapport est en outre sauvegardé à la racine du disque (fixnavi.txt)
    0
  7. pato59 Messages postés 7 Statut Membre
     
    Bonjour,

    voici le rapport comme vous me l'avez demandé,

    Merci
    Pato 59

    Outil exécuté depuis C:\Program Files\navilog1
    Mise à jour le 09.01.2008 à 20h00 par IL-MAFIOSO

    Microsoft Windows XP [version 5.1.2600]
    Internet Explorer : 7.0.5730.13
    Système de fichiers : NTFS

    Executé en mode normal

    *** Recherche Programmes installés ***

    *** Recherche dossiers dans C:\WINDOWS ***

    *** Recherche dossiers dans C:\Program Files ***

    C:\Program Files\HotTVPlayer trouvé !

    *** Recherche dossiers dans C:\DOCUME~1\ALLUSE~1\APPLIC~1 ***

    *** Recherche dossiers dans "C:\Documents and
    Settings\HP_Administrateur\application data" ***

    *** Recherche dossiers dans "C:\Documents and
    Settings\HP_Administrateur\MENUDM~1\PROGRA~1" ***

    *** Recherche dossiers dans C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1 ***

    *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
    pour + d'infos : http://www.gmer.net

    Aucun Fichier trouvé

    *** Recherche avec GenericNaviSearch ***
    !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
    !!! A vérifier impérativement avant toute suppression manuelle !!!

    * Recherche dans C:\WINDOWS\system32 *

    Fichiers trouvés :

    hjfzkv.exe trouvé !
    hjfzkv.dat trouvé !
    hjfzkv_nav.dat trouvé !
    hjfzkv_navps.dat trouvé !

    * Recherche dans "C:\Documents and Settings\HP_Administrateur\local
    settings\application data" *

    *** Recherche fichiers ***

    C:\WINDOWS\pack.epk trouvé !
    C:\WINDOWS\tmlpcert2007 trouvé !
    C:\WINDOWS\system32\HotTVPlayer.dll trouvé !

    *** Recherche clés spécifiques dans le Registre ***

    HKEY_CURRENT_USER\Software\Lanconfig trouvé !

    *** Module de Recherche complémentaire ***
    (Recherche fichiers spécifiques)

    1)Recherche nouveaux fichiers Instant Access :

    2)Recherche Heuristique :

    * Dans C:\WINDOWS\system32 :

    hjfzkv.dat trouvé !
    hzagonft.dat trouvé !
    sqbcdnxzr.dat trouvé !
    tigczqki.dat trouvé !
    hjfzkv_nav.dat trouvé !
    hzagonft_nav.dat trouvé !
    sqbcdnxzr_nav.dat trouvé !
    tigczqki_nav.dat trouvé !

    * Dans "C:\Documents and Settings\HP_Administrateur\local
    settings\application data" :

    3)Recherche Certificats :

    Certificat Egroup trouvé !

    4)Recherche fichiers connus :

    *** Analyse terminée le 12/01/2008 à 10:30:14,89 ***
    0
  8. jfkpresident Messages postés 13877 Statut Contributeur sécurité 1 175
     
    effectivement tu es infecté(évite les sites du genre hot.tv player....si tu vois ce que je veux dire.)
    Double clique sur le raccourci Navilog1 présent sur le bureau et laisse-toi guider.
    Au menu principal, choisis 2 et valide.

    Le fix va t'informer qu'il va alors redémarrer ton PC
    Ferme toutes les fenêtres ouvertes et enregistre tes documents personnels ouverts
    Appuie sur une touche comme demandé.
    (si ton Pc ne redémarre pas automatiquement, fais le toi même)
    Au redémarrage de ton PC, choisis ta session habituelle.

    Patiente jusqu'au message :
    *** Nettoyage Termine le ..... ***
    Le blocnote va s'ouvrir.
    Sauvegarde le rapport de manière à le retrouver
    Referme le blocnote. Ton bureau va réapparaitre

    PS:Si ton bureau ne réapparait pas, fais CTRL+ALT+SUPP pour ouvrir le gestionnaire de tâches.
    Puis rends-toi à l'onglet "processus". Clique en haut à gauche sur fichiers et choisis "exécuter"
    Tape explorer et valide. Celà te fera apparaitre ton bureau.

    Postes le rapport içi.

    Pour supprimer Navilog par la suite

    1/ Désinstalle Navilog1 Via ajout/suppression des programmes --> Navilog1
    Via le fichier uninstall présent dans le dossier %programfiles%\navilog1.1
    Ensuite supprime également ce dossier : C:\Program Files\navilog1

    Ensuite

    C'est un complément de désinfection
    Il supprime des fichiers appartenant à des malwares.
    Il ne vise pas des infections particulières.

    Télécharge sur ton bureau : http://www.malekal.com/download/clean.zip
    Tuto
    http://mickael.barroux.free.fr/securite/clean.php
    Une fois sur le bureau, tu fais un clic droit sur ton fichier clean.zip et dans le menu déroulant, tu clics sur extrait tout ou extraire ici.
    Cela va créer un dossier clean.
    Double-clic sur ce dossier clean, tu y trouveras dedans plusieurs fichiers.
    Double-clic sur clean. Cela va ouvrir une fenêtre noire.
    Un menu va apparaître, choisis l'option 1 en appuyant sur la touche 1 de ton clavier.
    Clean va travailler.
    Un rapport Va etre généré, colle le contenu entier ici.

    (- Où est le rapport clean ? : « Poste de travail » / double clic sur disque « C / » double-clic sur « rapport_clean.txt » et « copier/coller le contenu » sur le forum. )

    Cet adware est installé, entre autre, par les programmes :go-astro - Instant Access - InternetGameBox - GoRecord -
    HotTVPlayer - MailSkinner - Messenger Skinner - sudoplanet - Webmediaplayer
    0
  9. pato59 Messages postés 7 Statut Membre
     
    Bonjour,

    Excusé moi mais je n'avais pas encore envoyé le rapport CLEAN.

    Par contre je vous remerci pour vos conseils car depuis je n'ai plus de pub intempestives qui viennes me poluer,

    21/01/2008 a 17:40:52,21

    *** Recherche des fichiers dans C:

    *** Recherche des fichiers dans C:\WINDOWS\

    *** Recherche des fichiers dans C:\WINDOWS\system32
    "C:\WINDOWS\Downloaded Program Files\CONFLICT.1" FOUND

    *** Recherche des fichiers dans C:\Program Files
    "C:\Program Files\Adverts\" FOUND
    "C:\Program Files\Dealio\" FOUND
    "C:\Program Files\msn messenger\riched20.dll" FOUND
    "C:\Program Files\Seekmo Programs\" FOUND
    *** Fin du rapport !
    0
  10. jfkpresident Messages postés 13877 Statut Contributeur sécurité 1 175
     
    salut pato,

    •- Redémarre en mode sans échec. ( note bien ce que tu as à faire ).
    •- Ouvre le dossier « clean » qui se trouve sur ton bureau.
    •- Double-clic sur « clean.cmd ».
    Une fenêtre noire va apparaître, choisis l’option 2.

    Clean va travailler.
    •- Redémarre normalement
    •- Poste qui se trouve ici C:\rapport_clean.txt.

    reposte moi un rapport hijackthis pour vérifier.

    ensuite je te conseille ca :--Essaye le navigateur Firefox plus sur/sécurisé qu IE

    -Téléchargement: http://www.mozilla-europe.org/fr/products/firefox/
    -Tutorial pour le sécuriser: https://forum.zebulon.fr/topic/69628-s%C3%A9curiser-un-peu-plus-firefox/

    garde explorer pour les mise a jour et les scan en ligne.
    0
  11. pato59 Messages postés 7 Statut Membre
     
    Bonjour,

    voici le dernier rapport, pour le reste je vais utiliser ce que vous me conseillé comme navigateur,
    merci encore de votre aide.

    Rapport clean par Malekal_morte - http://www.malekal.com
    Script execute en mode sans echec 26/01/2008 a 10:15:16,25

    Microsoft Windows XP [version 5.1.2600]

    *** Suppression des fichiers dans C:

    *** Suppression des fichiers dans C:\WINDOWS\

    *** Suppression des fichiers dans C:\WINDOWS\system32
    tentative de suppression de "C:\WINDOWS\Downloaded Program Files\CONFLICT.1"

    *** Suppression des fichiers dans C:\Program Files
    tentative de suppression de "C:\Program Files\Adverts\"
    tentative de suppression de "C:\Program Files\Dealio\"
    tentative de suppression de "C:\Program Files\msn messenger\riched20.dll"
    tentative de suppression de "C:\Program Files\Seekmo Programs\"

    *** Suppression des clefs du registre effectuee..
    *** Fin du rapport !
    0
  12. jfkpresident Messages postés 13877 Statut Contributeur sécurité 1 175
     
    de rien et bon surf !!
    0