Fenetres internet s'ovrent seule + Log Hi Jak

Fermé
Alex - 25 janv. 2008 à 16:56
 Alex - 29 janv. 2008 à 17:40
Bonjour,
Je fais appel à vous concernant un probleme de fenetres intepestives qui s'excutent sur mon pc
J'ai scanné avec Win Defender, Spybot, Qui mecorrge des problemes mais pas celui ci
Je suis aussi oblige d'appuyer pluier fois sur certaines touches du clavier pour que la lettre soit marquee (exemple e ou t ou g
Je vous joins le log Hi Jack This en esprant votre aide...Je vous remercie.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:36:57, on 25/01/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16575)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam10\QuickCam10.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\rundll32.exe
C:\Windows\mrofinu2000351.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Users\Lexxcoop\AppData\Roaming\WinTouch\WinTouch.exe
C:\Users\Lexxcoop\AppData\Roaming\Microsoft\Windows\rayiou.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\LVComSX.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\Lexxcoop\Desktop\lexxcoop1-37561879-c.exe
C:\Windows\system32\conime.exe
C:\Users\Lexxcoop\AppData\Local\Temp\par-Lexxcoop\cache-1ce0c979f952a9bc4542418936f635566d7e4243\lexxcoop1-37561879-c.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\Macromed\Flash\FlashUtil9d.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?redirfallthru=http%3a%2f%2fwww.msn.fr%2fnhotmail%2fhelp%2f%3f
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://home.sweetim.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\PROGRA~1\FlashFXP\IEFlash.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" /hide
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [MSServer] rundll32.exe C:\Windows\system32\gebbcyv.dll,#1
O4 - HKLM\..\Run: [runner1] C:\Windows\mrofinu2000351.exe 61A847B5BBF72810329B385577F801F0B3E35B6638993F4661AA4EBD86D67C56389B284534F310
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [SmpcSys] C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [WinTouch] C:\Users\Lexxcoop\AppData\Roaming\WinTouch\WinTouch.exe
O4 - HKCU\..\Run: [SfKg6w] C:\Users\Lexxcoop\AppData\Roaming\Microsoft\Windows\rayiou.exe
O4 - HKCU\..\Run: [cmds] rundll32.exe C:\Users\Lexxcoop\AppData\Local\Temp\awvtr.dll,c
O4 - HKCU\..\Run: [MSServer] rundll32.exe C:\Users\Lexxcoop\AppData\Local\Temp\ssttr.dll,#1
O4 - HKCU\..\Run: [7cdc21a6] rundll32.exe "C:\Users\Lexxcoop\AppData\Local\Temp\wxrapjgy.dll",b
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O4 - Global Startup: OFFICE One Startup v7.lnk = ?
O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O13 - Gopher Prefix:
O16 - DPF: {2250C29C-C5E9-4F55-BE4E-01E45A40FCF1} (CMediaMix Object) - http://musicmix.messenger.msn.com/Medialogic.CAB
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/FacebookPhotoUploader3.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-US/a-UNO1/GAME_UNO1.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl-esd.sun.com/update/1.6.0/jinstall-6u1-windows-i586-jc.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: MySql - Unknown owner - C:\mysql\bin\mysqld-nt.exe
O23 - Service: Planificateur LiveUpdate automatique - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Transcoding and Broadcast Service (Transcode360) - Unknown owner - C:\Program Files\Transcode360\Transcode360.exe
O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software GmbH - C:\Windows\System32\TuneUpDefragService.exe
O23 - Service: wampapache - Apache Software Foundation - c:\wamp\bin\apache\apache2.2.6\bin\httpd.exe
O23 - Service: wampmysqld - Unknown owner - c:\wamp\bin\mysql\mysql5.0.45\bin\mysqld-nt.exe
O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
A voir également:

25 réponses

Il a ete mis en quarantaine a mon avis, je relance un scan avg pour confirmer
0
jfkpresident Messages postés 13408 Date d'inscription lundi 3 septembre 2007 Statut Contributeur sécurité Dernière intervention 5 janvier 2015 1 175
29 janv. 2008 à 12:32
poste moi le rapport AVG pour vérifier ;merci
0
Il ne semble plus y etre Voici le second scan



G Anti-Spyware - Rapport d'analyse
---------------------------------------------------------

+ Créé à: 15:49:17 29/01/2008

+ Résultat de l'analyse:



C:\Users\Lexxcoop\AppData\Roaming\Microsoft\Windows\Cookies\Low\lexxcoop@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Aucune action entreprise.
C:\Users\Lexxcoop\AppData\Roaming\Microsoft\Windows\Cookies\lexxcoop@adbrite[1].txt -> TrackingCookie.Adbrite : Aucune action entreprise.
C:\Users\Lexxcoop\AppData\Roaming\Microsoft\Windows\Cookies\lexxcoop@ads.adbrite[2].txt -> TrackingCookie.Adbrite : Aucune action entreprise.
C:\Users\Lexxcoop\AppData\Roaming\Microsoft\Windows\Cookies\lexxcoop@adtech[1].txt -> TrackingCookie.Adtech : Aucune action entreprise.
C:\Users\Lexxcoop\AppData\Roaming\Microsoft\Windows\Cookies\Low\lexxcoop@advertising[1].txt -> TrackingCookie.Advertising : Aucune action entreprise.
C:\Users\Lexxcoop\AppData\Roaming\Microsoft\Windows\Cookies\lexxcoop@advertising[2].txt -> TrackingCookie.Advertising : Aucune action entreprise.
C:\Users\Lexxcoop\AppData\Roaming\Microsoft\Windows\Cookies\Low\lexxcoop@atdmt[2].txt -> TrackingCookie.Atdmt : Aucune action entreprise.
C:\Users\Lexxcoop\AppData\Roaming\Microsoft\Windows\Cookies\Low\lexxcoop@bluestreak[2].txt -> TrackingCookie.Bluestreak : Aucune action entreprise.
C:\Users\Lexxcoop\AppData\Roaming\Microsoft\Windows\Cookies\lexxcoop@bluestreak[1].txt -> TrackingCookie.Bluestreak : Aucune action entreprise.
C:\Users\Lexxcoop\AppData\Roaming\Microsoft\Windows\Cookies\lexxcoop@doubleclick[1].txt -> TrackingCookie.Doubleclick : Aucune action entreprise.
C:\Users\Lexxcoop\AppData\Roaming\Microsoft\Windows\Cookies\lexxcoop@adopt.euroclick[2].txt -> TrackingCookie.Euroclick : Aucune action entreprise.
C:\Users\Lexxcoop\AppData\Roaming\Microsoft\Windows\Cookies\lexxcoop@fastclick[1].txt -> TrackingCookie.Fastclick : Aucune action entreprise.
C:\Users\Lexxcoop\AppData\Roaming\Microsoft\Windows\Cookies\lexxcoop@realmedia[2].txt -> TrackingCookie.Realmedia : Aucune action entreprise.
C:\Users\Lexxcoop\AppData\Roaming\Microsoft\Windows\Cookies\Low\lexxcoop@bs.serving-sys[1].txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
C:\Users\Lexxcoop\AppData\Roaming\Microsoft\Windows\Cookies\Low\lexxcoop@serving-sys[1].txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
C:\Users\Lexxcoop\AppData\Roaming\Microsoft\Windows\Cookies\lexxcoop@bs.serving-sys[1].txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
C:\Users\Lexxcoop\AppData\Roaming\Microsoft\Windows\Cookies\lexxcoop@serving-sys[1].txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
C:\Users\Lexxcoop\AppData\Roaming\Microsoft\Windows\Cookies\lexxcoop@smartadserver[1].txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
C:\Users\Lexxcoop\AppData\Roaming\Microsoft\Windows\Cookies\Low\lexxcoop@statcounter[1].txt -> TrackingCookie.Statcounter : Aucune action entreprise.
C:\Users\Lexxcoop\AppData\Roaming\Microsoft\Windows\Cookies\lexxcoop@statcounter[1].txt -> TrackingCookie.Statcounter : Aucune action entreprise.
C:\Users\Lexxcoop\AppData\Roaming\Microsoft\Windows\Cookies\Low\lexxcoop@tradedoubler[2].txt -> TrackingCookie.Tradedoubler : Aucune action entreprise.
C:\Users\Lexxcoop\AppData\Roaming\Microsoft\Windows\Cookies\lexxcoop@tradedoubler[2].txt -> TrackingCookie.Tradedoubler : Aucune action entreprise.
C:\Users\Lexxcoop\AppData\Roaming\Microsoft\Windows\Cookies\Low\lexxcoop@tribalfusion[2].txt -> TrackingCookie.Tribalfusion : Aucune action entreprise.
C:\Users\Lexxcoop\AppData\Roaming\Microsoft\Windows\Cookies\lexxcoop@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Aucune action entreprise.
C:\Users\Lexxcoop\AppData\Roaming\Microsoft\Windows\Cookies\Low\lexxcoop@weborama[1].txt -> TrackingCookie.Weborama : Aucune action entreprise.
C:\Users\Lexxcoop\AppData\Roaming\Microsoft\Windows\Cookies\lexxcoop@weborama[1].txt -> TrackingCookie.Weborama : Aucune action entreprise.
C:\Users\Lexxcoop\AppData\Roaming\Microsoft\Windows\Cookies\Low\lexxcoop@zedo[2].txt -> TrackingCookie.Zedo : Aucune action entreprise.
C:\Users\Lexxcoop\AppData\Roaming\Microsoft\Windows\Cookies\lexxcoop@zedo[1].txt -> TrackingCookie.Zedo : Aucune action entreprise.


Fin du rapport
0
jfkpresident Messages postés 13408 Date d'inscription lundi 3 septembre 2007 Statut Contributeur sécurité Dernière intervention 5 janvier 2015 1 175
29 janv. 2008 à 16:51
bon on dirait qu'on a fini !

dernier conseil:--Essaye le navigateur Firefox plus sur/sécurisé qu IE

-Téléchargement: http://www.mozilla-europe.org/fr/products/firefox/
-Tutorial pour le sécuriser: https://forum.zebulon.fr/topic/69628-s%C3%A9curiser-un-peu-plus-firefox/

garde explorer pour les mise a jour et les scan en ligne.

voila @ jamais ++
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
Merci pour tout jfk, probleme RESOLU :D
0