Virus cid et ieplorer.exe

Résolu
tekero Messages postés 49 Statut Membre -  
^^Marie^^ Messages postés 41884 Date d'inscription   Statut Membre Dernière intervention   -
Bonjour,
Depuis quelques temps il apparait sur mon PC des fenêtres intempestives publicitaires CiD...
Je n'arrive pas à érradiquer le spyware, car je n'arrive pas à le localiser avec divers outils (nero, adaware, spybot, winsos...). Par ailleurs, dans le gestionnaire des tâches il apparait plusieurs processus iexplorer.exe. Bien qu'en terminant ces processus, ces derniers réapparaissent immédiatement. De plus, ils utilisent énormément de ressources...
Configuration: Windows XP
Internet Explorer 7.0

12 réponses

  1. ^^Marie^^ Messages postés 41884 Date d'inscription   Statut Membre Dernière intervention   3 280
     
    Comment se comporte ton PC ??

    Edit

    · Télécharge ToolsCleaner de A.Roshtein sur ton Bureau.(sur un des 2 liens)
    http://pagesperso-orange.fr/AceRothstein/ToolsCleaner2.exe
    http://a-rothstein.changelog.fr/TC/ToolsCleaner2.exe
    · Clique sur Recherche et laisse le scan se terminer.
    · Clique, sur Suppression pour finaliser.
    · Tu peux, si tu le souhaites, te servir des Options facultatives.
    · Clique sur Quitter, pour que le rapport puisse se créer.
    · Poste moi le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur( C:\).

    1
    1. tekero
       
      désolé je croyais que cétais terminé
      je te poste le rapport
      -->- Recherche:

      C:\Documents and Settings\LATITUDE D 810\Bureau\HijackThis.exe: trouvé !

      ---------------------------------
      -->- Suppression:

      C:\Documents and Settings\LATITUDE D 810\Bureau\HijackThis.exe: supprimé !

      Corbeille vidée!
      Fichiers temporaires nettoyés !
      0
      1. ^^Marie^^ Messages postés 41884 Date d'inscription   Statut Membre Dernière intervention   3 280 > tekero
         
        Bon surf
        Tu repasses quand tu veux

        A++
        0
  2. ^^Marie^^ Messages postés 41884 Date d'inscription   Statut Membre Dernière intervention   3 280
     
    Bonjour Tekero

    F - Hijackthis - Outil de diagnostic et réparation
    télécharge HijackThis ici:
    http://telechargement.zebulon.fr/138-hijackthis-1991.html
    https://kerio.probb.fr/t62-comment-utiliser-et-comprendre-hijackthis
    Dézippe le dans un dossier prévu à cet effet.
    Par exemple C:\hijackthis < Enregistre le bien dans c : !
    Démo : (Merci a Balltrap34 pour cette réalisation)
    http://pageperso.aol.fr/balltrap34/Hijenr.gif
    Lance le puis:
    clique sur "do a system scan and save logfile" (cf démo)
    faire un copier coller du log entier sur le forum
    Démo : (Merci a Balltrap34 pour cette réalisation)
    http://pageperso.aol.fr/balltrap34/demohijack.htm
    http://www.tutoriaux-excalibur.com/hijackthis.htm
    https://leblogdeclaude.blogspot.com/2006/10/informatique-section-hijackthis.html

    Télécharge Lopxp et enregistres-le sur ton bureau.
    http://sosvirus.changelog.fr/Green_day/Lopxpsetup.exe
    http://www.commentcamarche.net/telecharger/telecharger 34055210 lopxp

    ► Referme les fenêtres de tous les programmes en cours, y compris Internet Explorer et MSN

    Double clic sur le fichier Lopxpsetup.exe
    pour lancer l'installation.

    Sur le bureau, double clic ensuite sur le raccourci nommé Lopxp, pour lancer le programme.
    Dans le menu, choisis l'option 1 et valide avec la touche entrée.
    Patiente un peu, en fin d'analyse il te sera demandé d'appuyer sur une touche pour faire apparaître le rapport, fais-le.

    Copie et colle ensuite tous son contenu dans ta prochaine réponse.


    Bon courage

    A+
    0
  3. tekero Messages postés 49 Statut Membre
     
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 15:19:06, on 31/03/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16608)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\System32\wltrysvc.exe
    C:\WINDOWS\System32\bcmwltry.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\NavNT\defwatch.exe
    C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
    C:\Program Files\NavNT\rtvscan.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\alg.exe
    C:\WINDOWS\system32\wbem\wmiprvse.exe
    C:\WINDOWS\system32\MsgSys.EXE
    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\Program Files\Dell\QuickSet\Quickset.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\SuperCopier2\SuperCopier2.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\Documents and Settings\LATITUDE D 810\Bureau\HijackThis.exe
    C:\WINDOWS\system32\wbem\wmiprvse.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ustart.org
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
    O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
    O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
    O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\Quickset.exe
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [Skip setup] C:\DOCUME~1\LATITU~1\APPLIC~1\THISSI~1\soft audio dash.exe
    O4 - HKCU\..\Run: [SuperCopier2.exe] C:\Program Files\SuperCopier2\SuperCopier2.exe
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\Program Files\Paltalk Messenger\Paltalk.exe (file missing)
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O15 - Trusted Zone: http://*.windowsupdate.com
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
    O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
    O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe
    O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
    O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
    0
  4. ^^Marie^^ Messages postés 41884 Date d'inscription   Statut Membre Dernière intervention   3 280
     
    Ok

    Fait Lopxp maintenant

    0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. tekero Messages postés 49 Statut Membre
     
    # Rapport Lopxp fait le 31/03/2008 à 15:23:31
    # Exécuté dans : C:\Program Files\Lopxp
    # Version 3.09 - Maj du 28/02/2008

    Killing 'iexplore.exe'
    "C:\Program Files\Internet Explorer\IEXPLORE.EXE" (1456)
    "C:\Program Files\Internet Explorer\IEXPLORE.EXE" (3328)

    ========== Listing des dossiers Application Data

    +- C:\Documents and Settings\All Users\Application Data

    2008-02-10 à 22:12:04 - Adobe
    2008-03-17 à 22:42:09 - Apple Computer
    2008-03-27 à 23:39:38 - Audio 4 part browse
    2007-06-11 à 20:46:37 - AVS4YOU
    2005-12-30 à 17:41:21 - CyberLink
    2008-02-25 à 12:41:08 - Downloaded Installations
    2008-02-24 à 18:52:50 - Google
    2008-03-27 à 22:12:58 - Grisoft
    2005-12-17 à 03:01:22 - Intel
    2008-02-24 à 13:40:44 - Lavasoft
    2008-03-27 à 23:39:38 - MailFrontier
    2008-03-17 à 11:23:56 - McAfee
    2008-02-15 à 16:10:22 - Microsoft
    2008-01-21 à 22:55:30 - PC Suite
    2008-03-27 à 23:39:38 - River Past G5
    2008-01-04 à 22:18:02 - SpinTop Games
    2008-02-24 à 13:28:53 - Symantec
    2008-03-27 à 23:39:38 - VadeRetro
    2006-08-09 à 13:01:17 - Windows Genuine Advantage
    2008-03-25 à 14:17:16 - WindowsLiveInstaller
    2008-03-27 à 23:39:38 - WLInstaller
    2006-02-11 à 23:56:21 - Yahoo! Companion
    2008-01-04 à 23:45:59 - Zylom

    +- C:\Documents and Settings\LATITUDE D 810\Application Data

    2007-12-09 à 18:52:04 - Adobe
    2008-03-27 à 23:39:39 - AdobeAUM
    2006-01-17 à 19:45:33 - AdobeUM
    2005-12-17 à 03:01:48 - Intel
    2006-08-27 à 23:44:56 - Macromedia
    2008-03-27 à 23:39:39 - Media Player Classic
    2008-03-25 à 14:46:12 - Microsoft
    2006-03-01 à 22:21:25 - Sun
    2008-03-27 à 23:39:40 - This sixth aim
    2008-03-29 à 13:54:12 - UseNeXT
    2008-03-26 à 23:09:29 - VadeRetro
    2008-03-27 à 23:39:40 - vlc

    +- C:\Documents and Settings\LATITUDE D 810\Local Settings\Application Data

    2007-12-03 à 01:55:55 - Adobe
    2006-05-04 à 08:26:21 - Ahead
    2008-01-06 à 23:13:38 - Apple
    2006-02-25 à 21:44:39 - Apple Computer
    2008-03-27 à 23:39:40 - ApplicationHistory
    2008-02-20 à 15:19:46 - G DATA
    2006-08-22 à 12:06:26 - Google
    2006-09-06 à 13:10:57 - Help
    2006-01-21 à 13:13:39 - Identities
    2008-03-27 à 23:39:40 - Microsoft
    2007-07-17 à 23:49:13 - Pando
    2007-06-27 à 11:22:46 - RcIncidents
    2008-02-24 à 13:30:43 - Symantec
    2006-03-21 à 01:06:54 - WMTools Downloaded Files
    2008-03-27 à 23:39:40 - {A3F66038-8999-4E8A-A00E-CFB215BA82F7}
    2008-03-27 à 23:39:40 - {A6709136-4BF6-429C-95B8-07F5723C0668}

    ========== Listing du dossier Program Files

    +- C:\Program Files

    2008-02-10 à 22:11:26 - Adobe
    2007-10-06 à 20:15:01 - Adolix
    2008-03-27 à 23:44:09 - Antipub
    2005-12-17 à 02:16:48 - ATI Technologies
    2008-03-27 à 23:39:41 - AviSynth 2.5
    2005-12-17 à 13:32:46 - Broadcom
    2005-12-17 à 02:48:38 - CONEXANT
    2008-03-27 à 23:39:41 - Dell
    2008-03-27 à 23:39:41 - DirectVobSub
    2008-03-31 à 00:46:34 - eChanblard
    2008-03-25 à 14:15:16 - Fichiers communs
    2008-03-26 à 23:45:07 - Goto Software
    2006-10-21 à 23:29:29 - InPulse Team
    2008-02-18 à 23:17:17 - InstallShield Installation Information
    2005-12-17 à 03:01:09 - Intel
    2008-02-05 à 14:30:48 - Intel Desktop Boards
    2008-03-27 à 23:39:42 - Internet Explorer
    2008-03-31 à 13:23:36 - Lopxp
    2008-03-27 à 23:39:42 - Messenger
    2008-03-27 à 23:39:42 - Microsoft CAPICOM 2.1.0.2
    2005-12-16 à 00:40:59 - microsoft frontpage
    2008-03-25 à 14:38:34 - Microsoft Office
    2008-03-27 à 23:39:42 - Microsoft Silverlight
    2008-03-27 à 23:39:42 - Movie Maker
    2008-02-11 à 16:56:32 - MSBuild
    2008-03-14 à 11:39:45 - MSECache
    2005-12-16 à 00:35:15 - MSN Gaming Zone
    2008-03-27 à 23:39:42 - NavNT
    2008-03-27 à 23:39:42 - NetMeeting
    2008-03-27 à 23:39:42 - Outlook Express
    2008-03-27 à 23:39:42 - PC Connectivity Solution
    2008-02-11 à 16:51:56 - Reference Assemblies
    2008-03-28 à 00:16:53 - RegCleaner
    2008-03-27 à 23:39:42 - Ripp-it_AM
    2008-02-11 à 21:13:59 - SigmaTel
    2008-03-27 à 23:39:42 - SuperCopier2
    2007-03-12 à 12:53:36 - Sygate
    2008-03-27 à 23:39:42 - Symantec
    2008-01-17 à 17:33:40 - Symantec AntiVirus
    2005-12-16 à 00:47:48 - Uninstall Information
    2008-03-27 à 23:39:42 - UseNeXT
    2008-03-25 à 22:59:34 - VideoLAN
    2008-03-27 à 23:39:43 - Videora
    2008-03-25 à 21:41:47 - Windows Live
    2008-03-27 à 23:39:43 - Windows Media Connect 2
    2008-03-27 à 23:39:43 - Windows Media Player
    2008-03-27 à 23:39:43 - Windows NT
    2005-12-16 à 00:37:54 - WindowsUpdate
    2008-03-27 à 23:39:43 - WinRAR
    2008-03-27 à 23:39:43 - WINZIP
    2005-12-16 à 00:40:59 - xerox
    2008-03-26 à 23:26:47 - Zone Labs

    ========== Tâches planifiées

    AFB13B919186AD11.job: c:\docume~1\latitu~1\applic~1\thissi~1\DOESSECTMAIL.exe

    ========== Clés registre

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Skip setup"="C:\DOCUME~1\LATITU~1\APPLIC~1\THISSI~1\soft audio dash.exe"

    ========== Bloqueur popups Internet Explorer

    ========== Suggestion ( /!\ Nécessite une interprétation.) ==========

    C:\Documents and Settings\All Users\Application Data\Audio 4 part browse
    C:\Documents and Settings\LATITUDE D 810\Application Data\This sixth aim
    C:\WINDOWS\tasks\AFB13B919186AD11.job

    +- Registre:

    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Skip setup"=-

    - Fin du rapport -
    0
  7. ^^Marie^^ Messages postés 41884 Date d'inscription   Statut Membre Dernière intervention   3 280
     
    OK

    On continue

    va dans :

    Démarrer Exécuter

    puis copier/coller :

    "%programfiles%\Lopxp\Lopxp.bat" /Fixme ►►►► Guillemets y compris

    puis valide, et poste le rapport stp
    0
  8. tekero Messages postés 49 Statut Membre
     
    c' est normal, je me retrouve sur le menu de lopxp ?
    je dois toujours taper "1" ?
    0
  9. ^^Marie^^ Messages postés 41884 Date d'inscription   Statut Membre Dernière intervention   3 280
     
    Ne cherche pas le menu

    tu copies colles ► cette ligne ► "%programfiles%\Lopxp\Lopxp.bat" /Fixme

    Ensuite tu valides
    0
  10. tekero Messages postés 49 Statut Membre
     
    # Rapport Lopxp fait le 31/03/2008 à 15:41:08
    # Exécuté dans : C:\Program Files\Lopxp
    # Version 3.09 - Maj du 28/02/2008

    ========== FixLog ==========

    +- C:\Documents and Settings\All Users\Application Data\Audio 4 part browse
    Choix utilisateur : Suppression acceptée.
    Déplacé avec succès.

    +- C:\Documents and Settings\LATITUDE D 810\Application Data\This sixth aim
    Choix utilisateur : Suppression acceptée.
    Déplacé avec succès.

    +- C:\WINDOWS\tasks\AFB13B919186AD11.job
    Choix utilisateur : Suppression acceptée.
    Déplacé avec succès.

    +- Registre :
    Nettoyage effectué.

    +- Fichiers temporaires :
    Nettoyage effectué.

    ========== Listing des dossiers Application Data

    +- C:\Documents and Settings\All Users\Application Data

    2008-02-10 à 22:12:04 - Adobe
    2008-03-17 à 22:42:09 - Apple Computer
    2007-06-11 à 20:46:37 - AVS4YOU
    2005-12-30 à 17:41:21 - CyberLink
    2008-02-25 à 12:41:08 - Downloaded Installations
    2008-02-24 à 18:52:50 - Google
    2008-03-27 à 22:12:58 - Grisoft
    2005-12-17 à 03:01:22 - Intel
    2008-02-24 à 13:40:44 - Lavasoft
    2008-03-27 à 23:39:38 - MailFrontier
    2008-03-17 à 11:23:56 - McAfee
    2008-02-15 à 16:10:22 - Microsoft
    2008-01-21 à 22:55:30 - PC Suite
    2008-03-27 à 23:39:38 - River Past G5
    2008-01-04 à 22:18:02 - SpinTop Games
    2008-02-24 à 13:28:53 - Symantec
    2008-03-27 à 23:39:38 - VadeRetro
    2006-08-09 à 13:01:17 - Windows Genuine Advantage
    2008-03-25 à 14:17:16 - WindowsLiveInstaller
    2008-03-27 à 23:39:38 - WLInstaller
    2006-02-11 à 23:56:21 - Yahoo! Companion
    2008-01-04 à 23:45:59 - Zylom

    +- C:\Documents and Settings\LATITUDE D 810\Application Data

    2007-12-09 à 18:52:04 - Adobe
    2008-03-27 à 23:39:39 - AdobeAUM
    2006-01-17 à 19:45:33 - AdobeUM
    2005-12-17 à 03:01:48 - Intel
    2006-08-27 à 23:44:56 - Macromedia
    2008-03-27 à 23:39:39 - Media Player Classic
    2008-03-25 à 14:46:12 - Microsoft
    2006-03-01 à 22:21:25 - Sun
    2008-03-29 à 13:54:12 - UseNeXT
    2008-03-26 à 23:09:29 - VadeRetro
    2008-03-27 à 23:39:40 - vlc

    +- C:\Documents and Settings\LATITUDE D 810\Local Settings\Application Data

    2007-12-03 à 01:55:55 - Adobe
    2006-05-04 à 08:26:21 - Ahead
    2008-01-06 à 23:13:38 - Apple
    2006-02-25 à 21:44:39 - Apple Computer
    2008-03-27 à 23:39:40 - ApplicationHistory
    2008-02-20 à 15:19:46 - G DATA
    2006-08-22 à 12:06:26 - Google
    2006-09-06 à 13:10:57 - Help
    2006-01-21 à 13:13:39 - Identities
    2008-03-27 à 23:39:40 - Microsoft
    2007-07-17 à 23:49:13 - Pando
    2007-06-27 à 11:22:46 - RcIncidents
    2008-02-24 à 13:30:43 - Symantec
    2006-03-21 à 01:06:54 - WMTools Downloaded Files
    2008-03-27 à 23:39:40 - {A3F66038-8999-4E8A-A00E-CFB215BA82F7}
    2008-03-27 à 23:39:40 - {A6709136-4BF6-429C-95B8-07F5723C0668}

    ========== Listing du dossier Program Files

    +- C:\Program Files

    2008-02-10 à 22:11:26 - Adobe
    2007-10-06 à 20:15:01 - Adolix
    2008-03-27 à 23:44:09 - Antipub
    2005-12-17 à 02:16:48 - ATI Technologies
    2008-03-27 à 23:39:41 - AviSynth 2.5
    2005-12-17 à 13:32:46 - Broadcom
    2005-12-17 à 02:48:38 - CONEXANT
    2008-03-27 à 23:39:41 - Dell
    2008-03-27 à 23:39:41 - DirectVobSub
    2008-03-31 à 00:46:34 - eChanblard
    2008-03-25 à 14:15:16 - Fichiers communs
    2008-03-26 à 23:45:07 - Goto Software
    2006-10-21 à 23:29:29 - InPulse Team
    2008-02-18 à 23:17:17 - InstallShield Installation Information
    2005-12-17 à 03:01:09 - Intel
    2008-02-05 à 14:30:48 - Intel Desktop Boards
    2008-03-27 à 23:39:42 - Internet Explorer
    2008-03-31 à 13:41:58 - Lopxp
    2008-03-27 à 23:39:42 - Messenger
    2008-03-27 à 23:39:42 - Microsoft CAPICOM 2.1.0.2
    2005-12-16 à 00:40:59 - microsoft frontpage
    2008-03-25 à 14:38:34 - Microsoft Office
    2008-03-27 à 23:39:42 - Microsoft Silverlight
    2008-03-27 à 23:39:42 - Movie Maker
    2008-02-11 à 16:56:32 - MSBuild
    2008-03-14 à 11:39:45 - MSECache
    2005-12-16 à 00:35:15 - MSN Gaming Zone
    2008-03-27 à 23:39:42 - NavNT
    2008-03-27 à 23:39:42 - NetMeeting
    2008-03-27 à 23:39:42 - Outlook Express
    2008-03-27 à 23:39:42 - PC Connectivity Solution
    2008-02-11 à 16:51:56 - Reference Assemblies
    2008-03-28 à 00:16:53 - RegCleaner
    2008-03-27 à 23:39:42 - Ripp-it_AM
    2008-02-11 à 21:13:59 - SigmaTel
    2008-03-27 à 23:39:42 - SuperCopier2
    2007-03-12 à 12:53:36 - Sygate
    2008-03-27 à 23:39:42 - Symantec
    2008-01-17 à 17:33:40 - Symantec AntiVirus
    2005-12-16 à 00:47:48 - Uninstall Information
    2008-03-27 à 23:39:42 - UseNeXT
    2008-03-25 à 22:59:34 - VideoLAN
    2008-03-27 à 23:39:43 - Videora
    2008-03-25 à 21:41:47 - Windows Live
    2008-03-27 à 23:39:43 - Windows Media Connect 2
    2008-03-27 à 23:39:43 - Windows Media Player
    2008-03-27 à 23:39:43 - Windows NT
    2005-12-16 à 00:37:54 - WindowsUpdate
    2008-03-27 à 23:39:43 - WinRAR
    2008-03-27 à 23:39:43 - WINZIP
    2005-12-16 à 00:40:59 - xerox
    2008-03-26 à 23:26:47 - Zone Labs

    ========== Tâches planifiées

    Aucune tâche planifiée détecté.

    ========== Clés registre

    ========== Bloqueur popups Internet Explorer

    ========== Suggestion ( /!\ Nécessite une interprétation.) ==========

    +- Dossiers\Fichiers : Aucune suggestion.

    +- Registre : Aucune suggestion.

    - Fin du rapport -
    0
  11. ^^Marie^^ Messages postés 41884 Date d'inscription   Statut Membre Dernière intervention   3 280
     
    >OK

    SUper

    Relance un log hijackthis
    stp

    0
  12. tekero Messages postés 49 Statut Membre
     
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 15:46:59, on 31/03/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16608)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\System32\wltrysvc.exe
    C:\WINDOWS\System32\bcmwltry.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\NavNT\defwatch.exe
    C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
    C:\Program Files\NavNT\rtvscan.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\alg.exe
    C:\WINDOWS\system32\wbem\wmiprvse.exe
    C:\WINDOWS\system32\MsgSys.EXE
    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\Program Files\Dell\QuickSet\Quickset.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\SuperCopier2\SuperCopier2.exe
    C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
    C:\WINDOWS\system32\notepad.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Documents and Settings\LATITUDE D 810\Bureau\HijackThis.exe
    C:\WINDOWS\system32\wbem\wmiprvse.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ustart.org
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
    O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
    O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
    O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\Quickset.exe
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [SuperCopier2.exe] C:\Program Files\SuperCopier2\SuperCopier2.exe
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\Program Files\Paltalk Messenger\Paltalk.exe (file missing)
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O15 - Trusted Zone: http://*.windowsupdate.com
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
    O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
    O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe
    O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
    O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
    0
  13. tekero Messages postés 49 Statut Membre
     
    merci beaucoup pour le travail effectué
    je galerais depuis un moment avec ce virus
    tu viens de m enlever une grosse épine du pied
    encore merci ciao :p
    0