PRVACY DANGER - Page 2

Résolu
  1. Contributeur
    on ne t´a pas demandé d´envoyé un rapport sur le site de malekal?
    0
    1. je fait quoi maintenant?
      0
      1. Contributeur
        salut,

        repost un nouveau rapport hijack this stp

        @+
        0
        1. salut g!rly, voici le rapport demandé;

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 20:24, on 2008-05-27
          Platform: Windows XP SP2 (WinNT 5.01.2600)
          MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
          Boot mode: Normal

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\Ati2evxx.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          C:\Program Files\Alwil Software\Avast4\ashServ.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
          c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
          C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
          C:\WINDOWS\system32\Ati2evxx.exe
          C:\WINDOWS\System32\FTRTSVC.exe
          C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
          c:\APPS\HIDSERVICE\HIDSERVICE.exe
          C:\WINDOWS\system32\o2flash.exe
          C:\WINDOWS\System32\snmp.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\Explorer.EXE
          C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
          c:\APPS\Powercinema\Kernel\TV\CLSched.exe
          C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
          C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
          C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
          C:\WINDOWS\system32\WLan.exe
          C:\Program Files\Fichiers communs\Ulead Systems\AutoDetector\monitor.exe
          C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
          C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
          C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
          C:\WINDOWS\RTHDCPL.EXE
          C:\Apps\Powercinema\PCMService.exe
          C:\Program Files\Hercules\DualPix Exchange\CamService.exe
          C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
          C:\Program Files\QuickTime\qttask.exe
          C:\APPS\SMP\SmpSys.exe
          C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
          C:\Program Files\BitComet\BitComet.exe
          C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
          C:\WINDOWS\system32\wuauclt.exe
          C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
          C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
          C:\Downloads\HijackThis.exe

          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
          O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
          O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll
          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
          O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
          O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
          O4 - HKLM\..\Run: [WLAN] C:\WINDOWS\system32\WLan.exe
          O4 - HKLM\..\Run: [Ulead AutoDetector v2] C:\Program Files\Fichiers communs\Ulead Systems\AutoDetector\monitor.exe
          O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
          O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
          O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
          O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
          O4 - HKLM\..\Run: [Raccourci vers la page des propriétés de High Definition Audio] HDAShCut.exe
          O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe"
          O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
          O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
          O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
          O4 - HKLM\..\Run: [HerculesCamService] C:\Program Files\Hercules\DualPix Exchange\CamService.exe
          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
          O4 - HKCU\..\Run: [SmpcSys] C:\APPS\SMP\SmpSys.exe
          O4 - HKCU\..\Run: [WOOKIT] C:\Program Files\Wanadoo\GestMaj.exe GestionnaireInternet.exe
          O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
          O4 - HKCU\..\Run: [WINSOS VERIFY] "C:\Program Files\Winsos\WINSOS.EXE" MINI
          O4 - HKCU\..\Run: [BitComet] "C:\Program Files\BitComet\BitComet.exe" /tray
          O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
          O4 - Global Startup: Accélérateur de démarrage AutoCAD.lnk = C:\Program Files\Fichiers communs\Autodesk Shared\acstart16.exe
          O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
          O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
          O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
          O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
          O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
          O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll/206 (file missing)
          O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
          O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
          O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://jeuxmultijoueurs.orange.fr/Gameshell/GameHost/1.0/OberonGameHost.cab
          O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
          O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
          O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Fichiers communs\Autodesk Shared\Service\AdskScSrv.exe
          O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
          O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
          O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
          O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
          O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLSched.exe
          O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
          O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
          O23 - Service: Generic Service for HID Keyboard Input Collections (GenericHidService) - Unknown owner - c:\APPS\HIDSERVICE\HIDSERVICE.exe
          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
          O23 - Service: MySqlInventime - Unknown owner - c:\mysql\bin\mysqld-max-nt.exe
          O23 - Service: O2Micro Flash Memory (O2Flash) - Unknown owner - C:\WINDOWS\system32\o2flash.exe
          O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
          0
          1. Contributeur
            re,

            vu le degré d´infection de ton pc au debut :

            regarde ceci concernant avast :

            antivir vs avast :

            -> http://forum.malekal.com/ftopic3528.php

            alors je te conseille de le desinstaller et d´installer antivir a la place

            Telecharge et instales l'antivirus Antivir Personal Edition Classic :

            ->https://www.malekal.com/avira-free-security-antivirus-gratuit/

            https://www.avira.com/en/prime

            http://mickael.barroux.free.fr/securite/antivir.php
            http://speedweb1.free.fr/frames2.php?page=tuto5
            <- tutoriel configuration du scanner...

            une fois antivir ouvert click surconfiguration et coche la case "expert mode" puis sur l´onglet scanner dans la fenetre du dessous tu va voir : rootkit search click sur le petit + pour deployer et coche la case a coté de ton disk dur
            puis click sur configuration en haut a droite; dans la nouvelle fenetre a gauche >scanner > coche "scan all files" et en dessous >scanner priority = High
            coche : allow stopping the scanner, comme cela tu peux faire une pause pendant le scan si tu le desir.
            puis sur la droite coche les case suivantes :
            scan boot sectors of selected drives
            scan master boot sectors
            scan memory
            search foe rootkit before scan
            decoche :
            ignore off line files
            toujours a gauche > scan > deploie > heuristique > macrovirus heuristic = coché et en dessous > win32 heuristic la case coché et high detection level

            Je te dis tous ca car j´aimerais que tu performes un scan entier de ta machine a l´aide d´antivir avec les reglages stipulés ci dessus et que tu post le rapport généré ici stp

            ps : fais le scan en ode sans echec

            post le rapport stp

            @+
            0

            1. salut g!rly,desolé pour le temps de reponse .voici le rapport comme demandé:

              Avira AntiVir Personal
              Report file date: 2008-05-28 15:32

              Scanning for 1295437 virus strains and unwanted programs.

              Licensed to: Avira AntiVir PersonalEdition Classic
              Serial number: 0000149996-ADJIE-0001
              Platform: Windows XP
              Windows version: (Service Pack 2) [5.1.2600]
              Boot mode: Save mode
              Username: admin
              Computer name: SN012345678912

              Version information:
              BUILD.DAT : 8.1.00.295 16479 Bytes 2008-04-09 16:24:00
              AVSCAN.EXE : 8.1.2.12 311553 Bytes 2008-03-18 09:02:56
              AVSCAN.DLL : 8.1.1.0 53505 Bytes 2008-02-07 08:43:37
              LUKE.DLL : 8.1.2.9 151809 Bytes 2008-02-28 08:41:23
              LUKERES.DLL : 8.1.2.1 12033 Bytes 2008-02-21 08:28:40
              ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 2007-07-18 10:33:34
              ANTIVIR1.VDF : 7.0.3.2 5447168 Bytes 2008-03-07 13:08:58
              ANTIVIR2.VDF : 7.0.4.53 1848832 Bytes 2008-05-17 13:10:54
              ANTIVIR3.VDF : 7.0.4.106 279040 Bytes 2008-05-28 13:10:59
              Engineversion : 8.1.0.46
              AEVDF.DLL : 8.1.0.5 102772 Bytes 2008-02-25 09:58:21
              AESCRIPT.DLL : 8.1.0.33 266618 Bytes 2008-05-28 13:12:00
              AESCN.DLL : 8.1.0.18 119156 Bytes 2008-05-28 13:11:56
              AERDL.DLL : 8.1.0.20 418165 Bytes 2008-05-28 13:11:53
              AEPACK.DLL : 8.1.1.5 364918 Bytes 2008-05-28 13:11:45
              AEOFFICE.DLL : 8.1.0.18 192890 Bytes 2008-05-28 13:11:29
              AEHEUR.DLL : 8.1.0.29 1253750 Bytes 2008-05-28 13:11:16
              AEHELP.DLL : 8.1.0.14 115063 Bytes 2008-05-28 13:11:09
              AEGEN.DLL : 8.1.0.21 303477 Bytes 2008-05-28 13:11:08
              AEEMU.DLL : 8.1.0.6 430451 Bytes 2008-05-28 13:11:05
              AECORE.DLL : 8.1.0.29 168311 Bytes 2008-05-28 13:11:02
              AVWINLL.DLL : 1.0.0.7 14593 Bytes 2008-01-23 17:07:53
              AVPREF.DLL : 8.0.0.1 25857 Bytes 2008-02-18 10:37:50
              AVREP.DLL : 7.0.0.1 155688 Bytes 2007-04-16 13:26:47
              AVREG.DLL : 8.0.0.0 30977 Bytes 2008-01-23 17:07:49
              AVARKT.DLL : 1.0.0.23 307457 Bytes 2008-02-12 08:29:23
              AVEVTLOG.DLL : 8.0.0.11 114945 Bytes 2008-02-28 08:31:31
              SQLITE3.DLL : 3.3.17.1 339968 Bytes 2008-01-22 17:28:02
              SMTPLIB.DLL : 1.2.0.19 28929 Bytes 2008-01-23 17:08:39
              NETNT.DLL : 8.0.0.1 7937 Bytes 2008-01-25 12:05:10
              RCIMAGE.DLL : 8.0.0.35 2371841 Bytes 2008-03-10 14:37:25
              RCTEXT.DLL : 8.0.32.0 86273 Bytes 2008-03-06 12:02:11

              Configuration settings for the scan:
              Jobname..........................: Complete system scan
              Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
              Logging..........................: low
              Primary action...................: interactive
              Secondary action.................: ignore
              Scan master boot sector..........: on
              Scan boot sector.................: on
              Boot sectors.....................: C:,
              Scan memory......................: on
              Process scan.....................: on
              Scan registry....................: on
              Search for rootkits..............: on
              Scan all files...................: All files
              Scan archives....................: on
              Recursion depth..................: 20
              Smart extensions.................: on
              Macro heuristic..................: on
              File heuristic...................: high

              Start of the scan: 2008-05-28 15:32

              Starting search for hidden objects.
              The driver could not be initialized.

              The scan of running processes will be started
              Scan process 'avscan.exe' - '1' Module(s) have been scanned
              Scan process 'avcenter.exe' - '1' Module(s) have been scanned
              Scan process 'explorer.exe' - '1' Module(s) have been scanned
              Scan process 'svchost.exe' - '1' Module(s) have been scanned
              Scan process 'svchost.exe' - '1' Module(s) have been scanned
              Scan process 'svchost.exe' - '1' Module(s) have been scanned
              Scan process 'lsass.exe' - '1' Module(s) have been scanned
              Scan process 'services.exe' - '1' Module(s) have been scanned
              Scan process 'winlogon.exe' - '1' Module(s) have been scanned
              Scan process 'csrss.exe' - '1' Module(s) have been scanned
              Scan process 'smss.exe' - '1' Module(s) have been scanned
              11 processes with 11 modules were scanned

              Starting master boot sector scan:
              Master boot sector HD0
              [INFO] No virus was found!

              Start scanning boot sectors:
              Boot sector 'C:\'
              [INFO] No virus was found!

              Starting to scan the registry.
              The registry was scanned ( '41' files ).

              Starting the file scan:

              Begin scan in 'C:\' <HDD>
              C:\pagefile.sys
              [WARNING] The file could not be opened!
              C:\upload_moi_SN012345678912.tar.gz
              [0] Archive type: GZ
              --> upload_moi.tar
              [1] Archive type: TAR (tape archiver)
              --> qoobox/Quarantine/C/WINDOWS/herjek.exe.vir
              [DETECTION] Is the Trojan horse TR/Dropper.Gen
              --> qoobox/Quarantine/C/WINDOWS/system32/baseakgc32.dll.vir
              [DETECTION] Is the Trojan horse TR/Pakes.CWS.3
              --> qoobox/Quarantine/C/WINDOWS/system32/found.exe.exe.vir
              [DETECTION] Is the Trojan horse TR/Dropper.Gen
              --> qoobox/Quarantine/C/WINDOWS/system32/iifgHBtT.dll.vir
              [DETECTION] Is the Trojan horse TR/Killav.28714
              --> qoobox/Quarantine/C/WINDOWS/system32/jkKBUoOi.dll.vir
              [DETECTION] Is the Trojan horse TR/Vundo.Gen
              --> qoobox/Quarantine/C/WINDOWS/system32/jkkiIcYp.dll.vir
              [DETECTION] Contains detection pattern of the worm WORM/Autorun.dwi
              --> qoobox/Quarantine/C/WINDOWS/system32/ljJARiJA.dll.vir
              [DETECTION] Contains detection pattern of the worm WORM/Autorun.dwi
              --> qoobox/Quarantine/C/WINDOWS/system32/qOihGVll.dll.vir
              [DETECTION] Is the Trojan horse TR/Vundo.Gen
              --> qoobox/Quarantine/C/WINDOWS/system32/qoMcdaAt.dll.vir
              [DETECTION] Contains detection pattern of the worm WORM/Autorun.dwi
              --> qoobox/Quarantine/C/WINDOWS/system32/vtUlIARH.dll.vir
              [DETECTION] Contains detection pattern of the worm WORM/Autorun.dwi
              --> qoobox/Quarantine/C/WINDOWS/system32/win32osf.exe.vir
              [DETECTION] Contains detection pattern of the worm WORM/Autorun.dqo
              --> qoobox/Quarantine/C/WINDOWS/system32/win32osf.tmp.vir
              [DETECTION] Is the Trojan horse TR/Crypt.XDR.Gen
              --> qoobox/Quarantine/catchme2008-05-20_234329,00.zip
              [2] Archive type: ZIP
              --> iifgHBtT.dll
              [DETECTION] Is the Trojan horse TR/Vundo.Gen
              [NOTE] The file was moved to '48a95fc2.qua'!
              C:\Documents and Settings\admin\Mes documents\programme\clean.zip
              [0] Archive type: ZIP
              --> clean/clean.cmd
              [DETECTION] Contains suspicious code HEUR/HTML.Malware
              [NOTE] The file was moved to '48a2c58c.qua'!
              C:\Documents and Settings\admin\Mes documents\programme\MediaTubeCodec_ver1.1172.0.exe
              [DETECTION] Is the Trojan horse TR/Dldr.Zlob.nex
              [NOTE] The file was moved to '48a1c58a.qua'!
              C:\Downloads\SmitfraudFix.exe
              [DETECTION] Contains detection pattern of the dropper DR/Tool.Reboot.F.92
              [NOTE] The file was moved to '48a6c685.qua'!
              C:\Downloads\clean\clean.zip
              [0] Archive type: ZIP
              --> clean/clean.cmd
              [DETECTION] Contains suspicious code HEUR/HTML.Malware
              [NOTE] The file was moved to '48a2c68c.qua'!
              C:\Downloads\clean\clean\clean.cmd
              [DETECTION] Contains suspicious code HEUR/HTML.Malware
              [NOTE] The fund was classified as suspicious.
              [NOTE] The file was moved to '48a2c693.qua'!
              C:\QooBox\Quarantine\catchme2008-05-20_234329,00.zip
              [0] Archive type: ZIP
              --> iifgHBtT.dll
              [DETECTION] Is the Trojan horse TR/Vundo.Gen
              [NOTE] The file was moved to '48b1cdb1.qua'!
              C:\QooBox\Quarantine\C\WINDOWS\herjek.exe.vir
              [DETECTION] Is the Trojan horse TR/Dropper.Gen
              [NOTE] The file was moved to '48afcdbf.qua'!
              C:\QooBox\Quarantine\C\WINDOWS\system32\baseakgc32.dll.vir
              [DETECTION] Is the Trojan horse TR/Pakes.CWS.3
              [NOTE] The file was moved to '48b0cdc0.qua'!
              C:\QooBox\Quarantine\C\WINDOWS\system32\found.exe.exe.vir
              [DETECTION] Is the Trojan horse TR/Dropper.Gen
              [NOTE] The file was moved to '48b2cdd1.qua'!
              C:\QooBox\Quarantine\C\WINDOWS\system32\iifgHBtT.dll.vir
              [DETECTION] Is the Trojan horse TR/Killav.28714
              [NOTE] The file was moved to '48a3cdd0.qua'!
              C:\QooBox\Quarantine\C\WINDOWS\system32\jkKBUoOi.dll.vir
              [DETECTION] Is the Trojan horse TR/Vundo.Gen
              [NOTE] The file was moved to '4888cdd6.qua'!
              C:\QooBox\Quarantine\C\WINDOWS\system32\jkkiIcYp.dll.vir
              [DETECTION] Contains detection pattern of the worm WORM/Autorun.dwi
              [NOTE] The file was moved to '48a8cdda.qua'!
              C:\QooBox\Quarantine\C\WINDOWS\system32\ljJARiJA.dll.vir
              [DETECTION] Contains detection pattern of the worm WORM/Autorun.dwi
              [NOTE] The file was moved to '4887cddc.qua'!
              C:\QooBox\Quarantine\C\WINDOWS\system32\qOihGVll.dll.vir
              [DETECTION] Is the Trojan horse TR/Vundo.Gen
              [NOTE] The file was moved to '48a6cdc5.qua'!
              C:\QooBox\Quarantine\C\WINDOWS\system32\qoMcdaAt.dll.vir
              [DETECTION] Contains detection pattern of the worm WORM/Autorun.dwi
              [NOTE] The file was moved to '488acde8.qua'!
              C:\QooBox\Quarantine\C\WINDOWS\system32\vtUlIARH.dll.vir
              [DETECTION] Contains detection pattern of the worm WORM/Autorun.dwi
              [NOTE] The file was moved to '4892cdf1.qua'!
              C:\QooBox\Quarantine\C\WINDOWS\system32\win32osf.exe.vir
              [DETECTION] Contains detection pattern of the worm WORM/Autorun.dqo
              [NOTE] The file was moved to '48abcdea.qua'!
              C:\QooBox\Quarantine\C\WINDOWS\system32\win32osf.tmp.vir
              [DETECTION] Is the Trojan horse TR/Crypt.XDR.Gen
              [NOTE] The file was moved to '48abcded.qua'!
              C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\01Q3STU7\found[1].exe
              [DETECTION] Is the Trojan horse TR/Dropper.Gen
              [NOTE] The file was moved to '48b2d415.qua'!

              End of the scan: 2008-05-28 23:52
              Used time: 8:20:03 min

              The scan has been done completely.

              12802 Scanning directories
              378276 Files were scanned
              29 viruses and/or unwanted programs were found
              3 Files were classified as suspicious:
              0 files were deleted
              0 files were repaired
              20 files were moved to quarantine
              0 files were renamed
              1 Files cannot be scanned
              378247 Files not concerned
              9776 Archives were scanned
              1 Warnings
              20 Notes

              par contre si tu peut me dire comment faire pour virer les saloperie mises en quarantaine, se serait fort sympathique de ta part.merci

              ps: il va se lancer a chaque que j'ouvre ma session?
              0
              1. Contributeur
                Salut,

                tu ouvres antivir, puis click sur l´onglet quarantaine et selectionnes les fichiers que tu veux supprimer, et click en suite sur l´icone poubelle qui est dans l´interface d´antivir...

                tu n´as plus de soucis ?

                post un dernier hijack this stp

                @+
                0
                1. slut g!rly, desolé pour le temps de reponse , j'avais un soucis avec internet.
                  non je n'aiplus de soucis.
                  est ce que malwarebytes et antivir arretent les saloperies avant d'etre sur l ordinateur ou il faut que je fasse un scan a chaque fois?
                  voici le rapport comme demandé, je l'ai fait en normal.

                  Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 15:26, on 2008-05-30
                  Platform: Windows XP SP2 (WinNT 5.01.2600)
                  MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                  Boot mode: Normal

                  Running processes:
                  C:\WINDOWS\System32\smss.exe
                  C:\WINDOWS\system32\winlogon.exe
                  C:\WINDOWS\system32\services.exe
                  C:\WINDOWS\system32\lsass.exe
                  C:\WINDOWS\system32\Ati2evxx.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\system32\spoolsv.exe
                  C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
                  c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
                  C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
                  C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
                  C:\WINDOWS\System32\FTRTSVC.exe
                  c:\APPS\HIDSERVICE\HIDSERVICE.exe
                  C:\WINDOWS\system32\o2flash.exe
                  C:\WINDOWS\System32\snmp.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
                  c:\APPS\Powercinema\Kernel\TV\CLSched.exe
                  C:\WINDOWS\system32\Ati2evxx.exe
                  C:\WINDOWS\Explorer.EXE
                  C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
                  C:\WINDOWS\system32\WLan.exe
                  C:\Program Files\Fichiers communs\Ulead Systems\AutoDetector\monitor.exe
                  C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                  C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                  C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
                  C:\WINDOWS\RTHDCPL.EXE
                  C:\Apps\Powercinema\PCMService.exe
                  C:\Program Files\Hercules\DualPix Exchange\CamService.exe
                  C:\Program Files\QuickTime\qttask.exe
                  C:\APPS\SMP\SmpSys.exe
                  C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
                  C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
                  C:\Program Files\BitComet\BitComet.exe
                  C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                  C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
                  C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
                  C:\Program Files\BitComet\tools\CometBrowser.exe
                  C:\Program Files\Wanadoo\ComComp.exe
                  C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                  C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                  C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                  C:\Documents and Settings\admin\Mes documents\HijackThis.exe

                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                  R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
                  O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                  O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll
                  O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                  O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                  O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                  O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
                  O4 - HKLM\..\Run: [WLAN] C:\WINDOWS\system32\WLan.exe
                  O4 - HKLM\..\Run: [Ulead AutoDetector v2] C:\Program Files\Fichiers communs\Ulead Systems\AutoDetector\monitor.exe
                  O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                  O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                  O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
                  O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
                  O4 - HKLM\..\Run: [Raccourci vers la page des propriétés de High Definition Audio] HDAShCut.exe
                  O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe"
                  O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
                  O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
                  O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
                  O4 - HKLM\..\Run: [HerculesCamService] C:\Program Files\Hercules\DualPix Exchange\CamService.exe
                  O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                  O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                  O4 - HKCU\..\Run: [SmpcSys] C:\APPS\SMP\SmpSys.exe
                  O4 - HKCU\..\Run: [WOOKIT] C:\Program Files\Wanadoo\GestMaj.exe GestionnaireInternet.exe
                  O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                  O4 - HKCU\..\Run: [WINSOS VERIFY] "C:\Program Files\Winsos\WINSOS.EXE" MINI
                  O4 - HKCU\..\Run: [BitComet] "C:\Program Files\BitComet\BitComet.exe" /tray
                  O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                  O4 - Global Startup: Accélérateur de démarrage AutoCAD.lnk = C:\Program Files\Fichiers communs\Autodesk Shared\acstart16.exe
                  O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
                  O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
                  O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
                  O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
                  O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
                  O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
                  O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll/206 (file missing)
                  O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
                  O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
                  O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://jeuxmultijoueurs.orange.fr/Gameshell/GameHost/1.0/OberonGameHost.cab
                  O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                  O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                  O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
                  O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                  O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Fichiers communs\Autodesk Shared\Service\AdskScSrv.exe
                  O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
                  O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLSched.exe
                  O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
                  O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
                  O23 - Service: Generic Service for HID Keyboard Input Collections (GenericHidService) - Unknown owner - c:\APPS\HIDSERVICE\HIDSERVICE.exe
                  O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                  O23 - Service: MySqlInventime - Unknown owner - c:\mysql\bin\mysqld-max-nt.exe
                  O23 - Service: O2Micro Flash Memory (O2Flash) - Unknown owner - C:\WINDOWS\system32\o2flash.exe
                  O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
                  0
                  1. Contributeur
                    salut,'

                    oui antivir dispose d´un resident mais ca ne veux pas dire qu´il faut telecharger n´importe quoi et faire n´importe quoi sur le net !

                    a l´aide de hijack this coche et fix les lignes suivantes :

                    O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
                    O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
                    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                    O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll/206 (file missing)
                    O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://jeuxmultijoueurs.orange.fr/Gameshell/GameHost/1.0/OberonGameHost.cab

                    puis fais les mises a jour suivantes :

                    tu surf avec internet explorer 6.0 = failles de securitées importantes

                    alors fais les mises a jour windows : tu veux la version 7.0

                    https://support.microsoft.com/en-US/topic/internet-explorer-downloads-d49e1f0d-571c-9a7b-d97e-be248806ca70

                    et pourquoi ne pas surfer avec firefox? = plus sur, tout en gardant ie 7.0 pour les mises a jour windows car impossible a effectuer sous firefox

                    http://www.mozilla-europe.org/fr/

                    plugins :no script, ad block plus ect..

                    https://www.hugedomains.com/domain_profile.cfm?d=geckozone&e=org

                    regarde ce tutorial pour mettre ta console java a jour :

                    https://www.malekal.com/maintenir-java-adobe-reader-et-le-player-flash-a-jour/

                    ta version de acrobat reader n´est pas a jour, tu veux la version 8.1 derniere en date alors desinstale ta version par le panneau de configuration / ajoue et suppression de programme

                    et instale la derniere :

                    https://get2.adobe.com/reader/otherversions/

                    ou oublie completement acrobat reader et instales foxit plus léger a la place:

                    https://www.clubic.com/telecharger-fiche13808-foxit-reader.html

                    puis instale un par feu :

                    zone alarm plus facil a configurer mais moins performant

                    https://www.malekal.com/tutoriel-zonealarm-firewall/

                    et

                    spywareblaster :

                    http://www.brightfort.com/spywareblaster.html

                    et

                    spyware gard :

                    https://www.zebulon.fr/dossiers/securite/47-spywareguard.html

                    pour supprimer les outils/fix utilisés :

                    Télécharge ToolsCleaner sur ton bureau.
                    --> http://www.commentcamarche.net/telecharger/telechargement 34055291 toolsclean(...)
                    # Clique sur Recherche et laisse le scan agir ...
                    # Clique sur Suppression pour finaliser.
                    # Tu peux, si tu le souhaites, te servir des Options facultatives.
                    # Clique sur Quitter pour obtenir le rapport.
                    # Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).

                    voila

                    @+
                    0
                    1. salut g!rly,

                      j'ai fait la misea jour de internet explorer, j'ai telecharger firefox .pour le plugins il faut que je fasse quoi exactement??
                      pour java j'ai rien compris.
                      acrobat reader est a jour mais je n'ai pas telecharger foxit,je ne pense pas en avoir besoin.
                      pour le pare feu, tu me dit:"zone alarm plus facil a configurer mais moins performant ". plus facile a configurer mais moins performant que quoi?
                      pour le reste j'ai deja antivir et malwarebytes alors je fais quoi?
                      toolcleaner sert a quoi exactement?
                      0
                      1. Contributeur
                        salut,

                        j´avais zappé ton message...

                        pour les plugin firefox tu les telecharge sur le site > no script,ad block plus, puis tu peux egalement prendre flash block, enfin c´est a toi de voir ce qui te conviens, je peux juste te conseiller...

                        java > il faut que tu supprimes toutes tes anciennes version et que tu prennes la derniere, tout est expliqué sur le site de malekal... en plus tu vas gagner de la place > une mise a jour java = 100 mos environ...

                        oui zone alarm est moins perforamant que d´autre difficiles a configurer...

                        je pensse que celui ci te conviendra le mieux, enfin si tu as envie de te lancer dans la configuation d´un par feu plus perforamant dis le moi...

                        ok pour antivir et malwarebytes garde les...

                        tool cleaner va supprimer tous les outils et fix que nous avons utilisés ici pour te desinfecter...

                        genre hijack this ect...

                        @+
                        0
                        1. salut ,
                          merci pour tous .
                          je vais encore avoir besoin de tes connaissances en informatique.
                          j'ai un ordinateur qui s'allume tres bien, mais j'ai plus de son, certains programmes ne fonctionnent plus, je ne peus plus aller sur internet,et ca meme en mode sans echec.
                          est ce que tu peus m'aider pour ce probleme s'il te plait?
                          merci
                          0
                          1. re salut,
                            voici le rapport de toolscleaner;

                            -->- Recherche:

                            C:\Qoobox: trouvé !
                            C:\Documents and Settings\admin\Bureau\ComboFix.exe: trouvé !
                            C:\Documents and Settings\admin\Mes documents\HijackThis.exe: trouvé !
                            C:\Documents and Settings\admin\Mes documents\securité\Clean: trouvé !
                            C:\Documents and Settings\admin\Mes documents\securité\SmitFraudfix: trouvé !
                            C:\Documents and Settings\admin\Mes documents\securité\clean\Clean: trouvé !

                            ---------------------------------
                            -->- Suppression:

                            C:\Documents and Settings\admin\Bureau\ComboFix.exe: supprimé !
                            C:\Documents and Settings\admin\Mes documents\HijackThis.exe: supprimé !
                            C:\Qoobox: supprimé !
                            C:\Documents and Settings\admin\Mes documents\securité\Clean: supprimé !
                            C:\Documents and Settings\admin\Mes documents\securité\SmitFraudfix: supprimé !

                            Corbeille vidée!
                            0
                            1. Contributeur
                              ok bob

                              Tu n´as plus de soucis ?

                              @+
                              0
                              1. salut g!rly

                                non je n'ai plus de soucis avec mon ordinateur .
                                Mais j'en ai un autre qui a un soucis comme je te le disais plus haut.(message n°32)
                                pense tu que ca peut etre une saloperie que j'aurais chopé,ou c'est l'ordinateur qui est fatigué?

                                ps:comment pourrais je te remercier pour m'avoir aidé a virer privacy danger?
                                0
                                1. Contributeur
                                  Salut bob,

                                  Oui c´est pas la joie, tu peux tenter si tu as le cd d´installation de windows de reparer ce dernier comme expliqué sur le lien ci dessous :

                                  http://www.informatruc.com/reparer-windows-xp/

                                  Pour privacy danger un merci me suffie ;-)

                                  Esperons que la reparation aura un effet salvateur, dis moi...

                                  @+
                                  0
                                  1. salut g!rly,

                                    MERCI pour tout.
                                    pour ce qui est de l'ordinateur en panne,je ne suis pas a la maison donc je n'ai pas le cd d'installation et je ne rentre pas tout de suite donc je verrais plus tard.

                                    Merci

                                    PS:c'est quoi le site internet dans ton profil?

                                    re PS:MERCI
                                    0
                                    1. Contributeur
                                      Ok bob,

                                      Le site dans mon profil; c´est mon myspace...

                                      @+
                                      0
                                      1. salut g!rly,

                                        c'est toi sur la photo?
                                        0
                                        1. Contributeur
                                          Salut bob,

                                          Oui c´est moi...

                                          @+
                                          0
                                          Précédent
                                          • 1
                                          • 2
                                          • 3
                                          • 4