Pc infecté : rapport Hijackthis

taurilius -  
green day Messages postés 26374 Date d'inscription   Statut Modérateur, Contributeur sécurité Dernière intervention   -
Bonjour,
Je suis infecté par des popups comme bon nombre de personnes ce qui ralenti mon ordinateur.
Si vous pouviez m'aider sa serait vraiment Super.

Rapport Hijacthis :

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:34:34, on 17/06/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
F:\WINDOWS\System32\smss.exe
F:\WINDOWS\system32\winlogon.exe
F:\WINDOWS\system32\services.exe
F:\WINDOWS\system32\lsass.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\system32\spoolsv.exe
F:\WINDOWS\Explorer.EXE
F:\Program Files\VIAudioi\SBADeck\ADeck.exe
F:\Program Files\Vtune\TBPanel.exe
F:\Program Files\iTunes\iTunesHelper.exe
F:\Program Files\Internet Explorer\IEXPLORE.EXE
F:\WINDOWS\system32\ctfmon.exe
F:\Program Files\Messenger\msmsgs.exe
F:\Program Files\Internet Explorer\IEXPLORE.EXE
F:\Program Files\Internet Explorer\IEXPLORE.EXE
F:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
F:\Program Files\Bonjour\mDNSResponder.exe
F:\Program Files\ASUS\Bluetooth Software\bin\btwdins.exe
F:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
F:\WINDOWS\system32\nvsvc32.exe
F:\Program Files\iPod\bin\iPodService.exe
F:\WINDOWS\System32\svchost.exe
F:\Program Files\Internet Explorer\iexplore.exe
F:\Program Files\Opera\opera.exe
F:\WINDOWS\system32\wpabaln.exe
F:\Program Files\Windows Live\Messenger\msnmsgr.exe
F:\Program Files\Windows Live\Messenger\usnsvc.exe
F:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.be/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - f:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - F:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - f:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [OSSelectorReinstall] F:\Program Files\Fichiers communs\Acronis\Partition Suite\oss_reinstall.exe
O4 - HKLM\..\Run: [AudioDeck] F:\Program Files\VIAudioi\SBADeck\ADeck.exe 1
O4 - HKLM\..\Run: [StartCCC] "F:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [Gainward] F:\Program Files\Vtune\TBPanel.exe /A
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE F:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE F:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "F:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "F:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [OutpostMonitor] F:\PROGRA~1\Agnitum\OUTPOS~1\op_mon.exe /tray /noservice
O4 - HKLM\..\Run: [OutpostFeedBack] "F:\Program Files\Agnitum\Outpost Security Suite Pro\feedback.exe" /dump:os_startup
O4 - HKLM\..\Run: [MSConfig] F:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] F:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] F:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] F:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] F:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: Envoyer au périphérique &Bluetooth... - F:\Program Files\ASUS\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: Réglage rapide de Outpost Security Suite Pro - {44627E97-789B-40d4-B5C2-58BD171129A1} - F:\Program Files\Agnitum\Outpost Security Suite Pro\ie_bar.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - F:\Program Files\ASUS\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - F:\Program Files\ASUS\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - F:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - F:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - https://www.touslesdrivers.com/index.php?v_page=29
O20 - AppInit_DLLs: f:\progra~1\agnitum\outpos~1\wl_hook.dll
O23 - Service: Agnitum Client Security Service (acssrv) - Agnitum Ltd. - F:\PROGRA~1\Agnitum\OUTPOS~1\acs.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - F:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - F:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - F:\Program Files\ASUS\Bluetooth Software\bin\btwdins.exe
O23 - Service: Google Updater Service (gusvc) - Google - F:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - F:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - F:\Program Files\ma-config.com\maconfservice.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - F:\WINDOWS\system32\nvsvc32.exe

--
End of file - 6492 bytes

Encore Merci
Configuration: Windows XP
Internet Explorer 7.0

21 réponses

  • 1
  • 2
  1. green day Messages postés 26374 Date d'inscription   Statut Modérateur, Contributeur sécurité Dernière intervention   2 166
     
    Salut à vous

    il y a des restes de cid, fais ce qui est indiqué ici stp

    http://www.commentcamarche.net/faq/sujet 3174 virus methode preliminaire de desinfection version fr

    ensuite dis nous combien tu as de parefeu actifs stp ?

    @+
    1
  2. raphy00 Messages postés 1112 Statut Membre 9
     
    Salut,

    Fais un clic droit sur ce lien : (IL-MAFIOSO)
    http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe
    Enregistrer la cible (du lien) sous... et enregistre-le sur ton bureau.
    Ensuite double clique sur navilog1.exe pour lancer l'installation.
    Une fois l'installation terminée, le fix s'exécutera automatiquement.
    (Si ce n'est pas le cas, double-clique sur le raccourci Navilog1 présent sur le bureau).

    Laisse-toi guider. Au menu principal, choisis 1 et valides.
    (ne fais pas le choix 2,3 ou 4 sans notre avis/accord)

    Patiente jusqu'au message :
    *** Analyse Termine le ..... ***
    Appuie sur une touche comme demandé, le blocnote va s'ouvrir.
    Copie-colle l'intégralité dans une réponse. Referme le blocnote.
    Le rapport est en outre sauvegardé à la racine du disque (fixnavi.txt)
    0
  3. taurilius
     
    Voilà:

    Search Navipromo version 3.5.8 commencé le mar. 17/06/2008 à 19:45:15,50

    !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
    !!! Postez ce rapport sur le forum pour le faire analyser !!!
    !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

    Outil exécuté depuis F:\Program Files\navilog1
    Session actuelle : "ludo"

    Mise à jour le 06.06.2008 à 18h00 par IL-MAFIOSO

    Microsoft Windows XP [version 5.1.2600]
    Internet Explorer : 7.0.5730.13
    Système de fichiers : NTFS

    Recherche executé en mode normal

    *** Recherche Programmes installés ***

    *** Recherche dossiers dans "F:\WINDOWS" ***

    *** Recherche dossiers dans "F:\Program Files" ***

    *** Recherche dossiers dans "f:\docume~1\alluse~1\applic~1" ***

    *** Recherche dossiers dans "f:\docume~1\alluse~1\menudm~1\progra~1" ***

    *** Recherche dossiers dans "F:\Documents and Settings\ludo\applic~1" ***

    *** Recherche dossiers dans "F:\DOCUME~1\ADMINI~1\applic~1" ***

    *** Recherche dossiers dans "F:\Documents and Settings\ludo\locals~1\applic~1" ***

    *** Recherche dossiers dans "F:\DOCUME~1\ADMINI~1\locals~1\applic~1" ***

    *** Recherche dossiers dans "F:\Documents and Settings\ludo\menudm~1\progra~1" ***

    *** Recherche dossiers dans "F:\DOCUME~1\ADMINI~1\menudm~1\progra~1" ***

    *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
    pour + d'infos : http://www.gmer.net

    Aucun Fichier trouvé

    *** Recherche avec GenericNaviSearch ***
    !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
    !!! A vérifier impérativement avant toute suppression manuelle !!!

    * Recherche dans "F:\WINDOWS\system32" *

    * Recherche dans "F:\Documents and Settings\ludo\locals~1\applic~1" *

    * Recherche dans "F:\DOCUME~1\ADMINI~1\locals~1\applic~1" *

    *** Recherche fichiers ***

    *** Recherche clés spécifiques dans le Registre ***

    *** Module de Recherche complémentaire ***
    (Recherche fichiers spécifiques)

    1)Recherche nouveaux fichiers Instant Access :

    2)Recherche Heuristique :

    * Dans "F:\WINDOWS\system32" :

    * Dans "F:\Documents and Settings\ludo\locals~1\applic~1" :

    * Dans "F:\DOCUME~1\ADMINI~1\locals~1\applic~1" :

    3)Recherche Certificats :

    Certificat Egroup absent !
    Certificat Electronic-Group absent !
    Certificat OOO-Favorit absent !
    Certificat Sunny-Day-Design-Ltd absent !

    4)Recherche fichiers connus :

    *** Analyse terminée le mar. 17/06/2008 à 19:49:12,71 ***
    0
  4. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  5. raphy00 Messages postés 1112 Statut Membre 9
     
    Tu as l'air de n'avoir aucune protection.
    Choisis :

    Antivirus:

    Comme antivirus: il y a en gratuit: AntiVir,BitDefender et Kaspersky qui sont assez efficace. (BitDefender et Kaspersky sont valable que 30 jours).
    et en payant il y a: BitDefender,Kaspersky et Nod32 qui sont les plus efficace.

    Comme anti-spyware: il y a Spybot avec le TeaTimer (il te permet de te protéger en temps réel).

    Comme anti-malware: il y a Malwarebytes' Anti-Malware et A²Free.

    Comme pare-feu: il y a le pare-feu Windows mais pas assez efficace même nul car il a été noté 0/20, donc je te conseille de prendre soit Kerio soit Comodo Firewall Pro.

    Tu peux aussi sur tu le souhaite utiliser un logiciel Ccleaner, il permet de supprimer les fichiers d'historique et de cache du système.

    Pour surfer sur Internet je te conseille de prendre Mozilla Firefox il est plus rapide et plus sécuriser. Tu peux garder Internet Explorer pour faire les mises a jour Windows
    0
  6. taurilius
     
    pour surfer j'utilise opera j'ai remit nod32 et j'ai télécharger kerio et j'avais déjà ccleaner et spybot .

    Mais après ?

    Encore merci :p
    0
  7. taurilius
     
    j'ai tojours despopups cid qui souvre:(
    0
  8. raphy00 Messages postés 1112 Statut Membre 9
     
    Bizarre,

    Essaie de renommer Hijackthis.exe en eden.exe, puis postes le rapport.
    0
  9. raphy00 Messages postés 1112 Statut Membre 9
     
    Et fais aussi un scan en ligne:
    Scan en ligne bitdefender :

    https://www.bitdefender.com/toolbox/

    Clicker sur " I agree " et suivre les indications

    A faire imperativement sous internet explorer, en acceptant l´activ x

    tutoriel en image en image

    http://pageperso.aol.fr/rginformatique/mapage/defender.htm
    0
  10. taurilius
     
    BitDefender Online Scanner - Real Time Virus Report

    Generated at: Fri, Jun 20, 2008 - 22:57:23

    --------------------------------------------------------------------------------

    Scan Info

    Scanned Files
    518067

    Infected Files
    0

    Virus Detected

    No virus found.

    --------------------------------------------------------------------------------

    This summary of the scan process will be used by the BitDefender Antivirus Lab to create agregate statistics about virus activity around the world.

    et Hijacktis:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 23:01:41, on 20/06/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16674)
    Boot mode: Normal

    Running processes:
    F:\WINDOWS\System32\smss.exe
    F:\WINDOWS\system32\winlogon.exe
    F:\WINDOWS\system32\services.exe
    F:\WINDOWS\system32\lsass.exe
    F:\WINDOWS\system32\svchost.exe
    F:\WINDOWS\System32\svchost.exe
    F:\WINDOWS\system32\spoolsv.exe
    F:\WINDOWS\Explorer.EXE
    F:\Program Files\VIAudioi\SBADeck\ADeck.exe
    F:\Program Files\iTunes\iTunesHelper.exe
    F:\WINDOWS\system32\LVCOMSX.EXE
    F:\Program Files\Logitech\Video\LogiTray.exe
    F:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
    F:\WINDOWS\system32\ctfmon.exe
    F:\Program Files\Internet Explorer\IEXPLORE.EXE
    F:\Program Files\Logitech\Video\FxSvr2.exe
    F:\Program Files\Internet Explorer\IEXPLORE.EXE
    F:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    F:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
    F:\Program Files\Bonjour\mDNSResponder.exe
    F:\Program Files\ASUS\Bluetooth Software\bin\btwdins.exe
    F:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
    F:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    F:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
    F:\WINDOWS\system32\svchost.exe
    F:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
    F:\Program Files\iPod\bin\iPodService.exe
    F:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
    F:\Program Files\Windows Live\Messenger\usnsvc.exe
    F:\WINDOWS\System32\svchost.exe
    F:\Program Files\Windows Live\Messenger\msnmsgr.exe
    F:\Program Files\Windows Media Player\wmplayer.exe
    F:\Documents and Settings\ludo\Bureau\ECBarre_V_01.exe
    F:\Program Files\Internet Explorer\iexplore.exe
    F:\Program Files\Trend Micro\HijackThis\Eden.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.be/?gws_rd=ssl
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - f:\program files\google\googletoolbar1.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - F:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - f:\program files\google\googletoolbar1.dll
    O4 - HKLM\..\Run: [OSSelectorReinstall] F:\Program Files\Fichiers communs\Acronis\Partition Suite\oss_reinstall.exe
    O4 - HKLM\..\Run: [AudioDeck] F:\Program Files\VIAudioi\SBADeck\ADeck.exe 1
    O4 - HKLM\..\Run: [StartCCC] "F:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "F:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "F:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [LVCOMSX] F:\WINDOWS\system32\LVCOMSX.EXE
    O4 - HKLM\..\Run: [LogitechVideoRepair] F:\Program Files\Logitech\Video\ISStart.exe
    O4 - HKLM\..\Run: [LogitechVideoTray] F:\Program Files\Logitech\Video\LogiTray.exe
    O4 - HKLM\..\Run: [egui] "F:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKCU\..\Run: [ball mags] F:\DOCUME~1\ludo\APPLIC~1\ONCEFR~1\city play math.exe
    O4 - HKCU\..\Run: [ctfmon.exe] F:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "F:\Program Files\Logitech\Video\ManifestEngine.exe" boot
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] F:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] F:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] F:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] F:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O8 - Extra context menu item: Envoyer au périphérique &Bluetooth... - F:\Program Files\ASUS\Bluetooth Software\btsendto_ie_ctx.htm
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - F:\WINDOWS\bdoscandel.exe
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - F:\WINDOWS\bdoscandel.exe
    O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - F:\Program Files\ASUS\Bluetooth Software\btsendto_ie.htm
    O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - F:\Program Files\ASUS\Bluetooth Software\btsendto_ie.htm
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - F:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - F:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
    O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - https://www.touslesdrivers.com/index.php?v_page=29
    O23 - Service: Apple Mobile Device - Apple, Inc. - F:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: BlueSoleil Hid Service - Unknown owner - F:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
    O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - F:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - F:\Program Files\ASUS\Bluetooth Software\bin\btwdins.exe
    O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - F:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
    O23 - Service: Eset Service (ekrn) - ESET - F:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
    O23 - Service: Google Updater Service (gusvc) - Google - F:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - F:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - F:\Program Files\ma-config.com\maconfservice.exe
    O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software - F:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
    0
  11. raphy00 Messages postés 1112 Statut Membre 9
     
    Salut

    Télécharge Lopxp : (by Moe) :

    http://www.commentcamarche.net/telecharger/telecharger 34055210 lopxp

    Double clique sur Lopxpsetup.exe pour lancer l'installation
    Au menu, choisis l'option 1
    Patiente jusqu'à que l'on demande d'appuyer sur une touche, appuie !
    Le contenu du rapport est situé dans : C:\Programfiles\Lopxp\cid.txt
    Postes le.
    0
  12. taurilius
     
    Voilà :p

    # Rapport Lopxp fait le dim. 22/06/2008 à 15:25:26
    # Exécuté dans : F:\Program Files\Lopxp
    # Version 3.06 - Maj du 05/02/2008

    Killing 'iexplore.exe'
    "F:\Program Files\Internet Explorer\IEXPLORE.EXE" (1652)
    "F:\Program Files\Internet Explorer\IEXPLORE.EXE" (2060)
    "F:\Program Files\Internet Explorer\iexplore.exe" (2844)

    ========== Listing des dossiers Application Data

    +- F:\Documents and Settings\Administrateur\Application Data

    2008-06-14 à 20:51:34 - ATI
    2008-06-14 à 15:18:02 - Microsoft

    +- F:\Documents and Settings\Administrateur\Local Settings\Application Data

    2008-06-14 à 20:51:34 - ATI
    2008-06-14 à 20:50:20 - Microsoft

    +- F:\Documents and Settings\All Users\Application Data

    2008-06-14 à 15:36:44 - Acronis
    2008-06-15 à 17:00:20 - Apple
    2008-06-15 à 17:01:23 - Apple Computer
    2008-06-14 à 19:47:25 - ATI
    2008-06-18 à 09:27:59 - Bluetooth
    2008-06-18 à 15:01:44 - ESET
    2008-06-15 à 16:45:05 - Google
    2008-06-21 à 19:10:53 - Google Updater
    2008-06-19 à 10:30:56 - ma-config.com
    2008-06-15 à 18:49:18 - Messenger Plus!
    2008-06-15 à 17:48:51 - Microsoft
    2008-06-18 à 14:49:02 - Spybot - Search & Destroy
    2008-06-18 à 14:49:02 - That Face Camp Shim
    2008-06-15 à 16:43:21 - WLInstaller

    +- F:\Documents and Settings\ludo\Application Data

    2008-06-14 à 19:23:09 - Adobe
    2008-06-15 à 17:01:41 - Apple Computer
    2008-06-14 à 21:10:24 - ATI
    2008-06-18 à 14:49:02 - FileZilla
    2008-06-15 à 16:45:17 - Google
    2008-06-14 à 15:22:38 - Identities
    2008-06-19 à 10:01:36 - ijjigame
    2008-06-14 à 19:23:10 - Macromedia
    2008-06-15 à 16:47:57 - Microsoft
    2008-06-17 à 20:01:26 - Mozilla
    2008-06-21 à 13:50:27 - once frag
    2008-06-15 à 16:51:12 - Opera
    2008-06-15 à 18:18:25 - WinRAR
    2008-06-19 à 10:00:50 - Xfire

    +- F:\Documents and Settings\ludo\Local Settings\Application Data

    2008-06-15 à 17:00:36 - Apple
    2008-06-15 à 17:01:41 - Apple Computer
    2008-06-14 à 21:10:24 - ATI
    2008-06-15 à 16:45:09 - Google
    2008-06-18 à 14:05:16 - Logitech-LS
    2008-06-21 à 19:43:08 - Microsoft
    2008-06-17 à 20:01:26 - Mozilla
    2008-06-15 à 16:51:12 - Opera

    ========== Listing du dossier Program Files

    +- F:\Program Files

    2008-06-14 à 15:29:58 - Acronis
    2008-06-14 à 16:47:12 - Activision
    2008-06-18 à 21:22:56 - Adobe
    2008-06-18 à 14:38:39 - Anti-Leech
    2008-06-18 à 14:49:03 - Apple Software Update
    2008-06-14 à 16:53:58 - ASUS
    2008-06-18 à 14:49:04 - Bonjour
    2008-06-18 à 14:49:04 - CCleaner
    2008-06-15 à 17:50:19 - Circle Developement
    2008-06-19 à 10:04:11 - Common Files
    2008-06-14 à 15:15:00 - ComPlus Applications
    2008-06-18 à 14:49:04 - Driver Cleaner Pro
    2008-06-18 à 15:01:44 - ESET
    2008-06-18 à 21:22:56 - Fichiers communs
    2008-06-18 à 14:49:04 - FileZilla FTP Client
    2008-06-17 à 20:42:51 - Foxit Software
    2008-06-18 à 14:49:05 - Google
    2008-06-14 à 16:16:13 - Grisoft
    2008-06-19 à 09:47:22 - InstallShield Installation Information
    2008-06-18 à 14:49:05 - Internet Explorer
    2008-06-15 à 17:01:27 - iPod
    2008-06-18 à 14:49:05 - iTunes
    2008-06-18 à 09:21:44 - IVT Corporation
    2008-06-18 à 13:54:29 - Logitech
    2008-06-22 à 13:25:31 - Lopxp
    2008-06-18 à 14:49:05 - ma-config.com
    2008-06-18 à 14:49:05 - Messenger
    2008-06-18 à 14:49:05 - Messenger Plus! Live
    2008-06-19 à 11:59:38 - Microsoft CAPICOM 2.1.0.2
    2008-06-14 à 15:18:25 - microsoft frontpage
    2008-06-18 à 14:49:05 - Movie Maker
    2008-06-21 à 20:28:35 - Mozilla Firefox
    2008-06-14 à 15:13:43 - MSN
    2008-06-14 à 15:14:15 - MSN Gaming Zone
    2008-06-17 à 17:49:18 - Navilog1
    2008-06-18 à 14:49:06 - NetMeeting
    2008-06-19 à 09:47:28 - NHN USA
    2008-06-15 à 17:50:34 - once frag
    2008-06-14 à 15:14:23 - Online Services
    2008-06-18 à 14:49:06 - Opera
    2008-06-18 à 14:49:06 - Outlook Express
    2008-06-18 à 14:49:06 - QuickTime
    2008-06-14 à 15:16:36 - Services en ligne
    2008-06-18 à 14:49:06 - Spybot - Search & Destroy
    2008-06-18 à 15:09:33 - Sunbelt Software
    2008-06-15 à 18:09:16 - Trend Micro
    2008-06-15 à 18:39:10 - Uninstall Information
    2008-06-14 à 16:21:18 - VIA
    2008-06-14 à 16:32:24 - VIAudioi
    2008-06-15 à 16:47:57 - Windows Live
    2008-06-18 à 14:49:07 - Windows Media Player
    2008-06-18 à 14:49:07 - Windows NT
    2008-06-14 à 15:16:41 - WindowsUpdate
    2008-06-18 à 14:49:07 - WinRAR
    2008-06-14 à 15:18:25 - xerox
    2008-06-19 à 10:00:50 - Xfire

    ========== Tâches planifiées

    AFD8DDDD919356A9.job: f:\docume~1\ludo\applic~1\oncefr~1\enc glue bend.exe

    ========== Clés registre

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ball mags"="F:\DOCUME~1\ludo\APPLIC~1\ONCEFR~1\city play math.exe"

    ========== Bloqueur popups Internet Explorer

    ========== Suggestion ( /!\ Nécessite une interprétation.) ==========

    F:\Documents and Settings\All Users\Application Data\That Face Camp Shim
    F:\Documents and Settings\ludo\Application Data\once frag
    F:\Program Files\Circle Developement
    F:\Program Files\once frag
    F:\WINDOWS\tasks\AFD8DDDD919356A9.job

    +- Registre:

    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ball mags"=-

    - Fin du rapport -
    0
  13. raphy00 Messages postés 1112 Statut Membre 9
     
    Maintenant passe l'option 2 et recolles un hijack.
    0
  14. taurilius
     
    Otpion2 = quitter :(

    [img]http://imageshack-france.com/out.php/i138089_lopxp.JPG[/img]
    0
  15. taurilius
     
    Correction du lien: http://imageshack-france.com/out.php/i138089_lopxp.JPG
    0
  16. raphy00 Messages postés 1112 Statut Membre 9
     
    Salut,

    Télécharge combofix.exe (par sUBs) sur ton Bureau.

    -> http://download.bleepingcomputer.com/sUBs/ComboFix.exe

    -> Double clique combofix.exe.
    -> Tape sur la touche 1 (Yes) pour démarrer le scan.
    -> Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.

    NOTE : Le rapport se trouve également ici : C:\Combofix.txt

    Avant d'utiliser ComboFix :

    -> Déconnecte toi d'internet et referme les fenêtres de tous les programmes en cours.

    -> Désactive provisoirement et seulement le temps de l'utilisation de ComboFix, la protection en temps réel de ton Antivirus et de tes Antispywares, qui peuvent géner fortement la procédure de recherche et de nettoyage de l'outil.

    Une fois fait, sur ton bureau double-clic sur Combofix.exe.

    - Répond oui au message d'avertissement, pour que le programme commence à procéder à l'analyse du pc.

    /!\ Pendant la durée de cette étape, ne te sert pas du pc et n'ouvre aucun programmes.

    - En fin de scan il est possible que ComboFix ait besoin de redemarrer le pc pour finaliser la désinfection\recherche, laisses-le faire.

    - Un rapport s'ouvrira ensuite dans le bloc notes, ce fichier rapport Combofix.txt, est automatiquement sauvegardé et rangé à C:\Combofix.txt)

    -> Réactive la protection en temps réel de ton Antivirus et de tes Antispywares, avant de te reconnecter à internet.

    -> Reviens sur le forum, et copie et colle la totalité du contenu de C:\Combofix.txt dans ton prochain message.

    -> Tutoriel https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix
    0
  17. raphy00 Messages postés 1112 Statut Membre 9
     
    Re,
    Si tu n'as pas encore fais Combofix, suis ces instructions :

    Pour desinsfecter avec lop XP :

    Tu vas dans : Démarrer > Exécuter puis copie/colle la ligne suivante :

    "%programfiles%\Lopxp\Lopxp.bat" /Fixme
    puis valide, accepte toutes les demandes de suppression et poste le rapport.
    0
  18. taurilius
     
    # Rapport Lopxp fait le mar. 24/06/2008 à 11:17:04
    # Exécuté dans : F:\Program Files\Lopxp
    # Version 3.06 - Maj du 05/02/2008

    ========== FixLog ==========

    +- F:\Documents and Settings\All Users\Application Data\That Face Camp Shim
    Choix utilisateur : Suppression acceptée.
    Déplacé avec succès.

    +- F:\Documents and Settings\ludo\Application Data\once frag
    Choix utilisateur : Suppression acceptée.
    Déplacé avec succès.

    +- F:\Program Files\Circle Developement
    Choix utilisateur : Suppression acceptée.
    Déplacé avec succès.

    +- F:\Program Files\once frag
    Choix utilisateur : Suppression acceptée.
    Déplacé avec succès.

    +- F:\WINDOWS\tasks\AFD8DDDD919356A9.job
    Choix utilisateur : Suppression acceptée.
    Déplacé avec succès.

    +- Registre :
    Nettoyage effectué.

    +- Fichiers temporaires :
    Nettoyage effectué.

    ========== Listing des dossiers Application Data

    +- F:\Documents and Settings\Administrateur\Application Data

    2008-06-14 à 20:51:34 - ATI
    2008-06-14 à 15:18:02 - Microsoft

    +- F:\Documents and Settings\Administrateur\Local Settings\Application Data

    2008-06-14 à 20:51:34 - ATI
    2008-06-14 à 20:50:20 - Microsoft

    +- F:\Documents and Settings\All Users\Application Data

    2008-06-14 à 15:36:44 - Acronis
    2008-06-15 à 17:00:20 - Apple
    2008-06-15 à 17:01:23 - Apple Computer
    2008-06-14 à 19:47:25 - ATI
    2008-06-18 à 09:27:59 - Bluetooth
    2008-06-18 à 15:01:44 - ESET
    2008-06-15 à 16:45:05 - Google
    2008-06-24 à 08:19:09 - Google Updater
    2008-06-19 à 10:30:56 - ma-config.com
    2008-06-15 à 18:49:18 - Messenger Plus!
    2008-06-15 à 17:48:51 - Microsoft
    2008-06-18 à 14:49:02 - Spybot - Search & Destroy
    2008-06-15 à 16:43:21 - WLInstaller

    +- F:\Documents and Settings\ludo\Application Data

    2008-06-14 à 19:23:09 - Adobe
    2008-06-15 à 17:01:41 - Apple Computer
    2008-06-14 à 21:10:24 - ATI
    2008-06-18 à 14:49:02 - FileZilla
    2008-06-15 à 16:45:17 - Google
    2008-06-14 à 15:22:38 - Identities
    2008-06-19 à 10:01:36 - ijjigame
    2008-06-14 à 19:23:10 - Macromedia
    2008-06-23 à 16:22:31 - MailFrontier
    2008-06-22 à 13:36:00 - Media Player Classic
    2008-06-15 à 16:47:57 - Microsoft
    2008-06-17 à 20:01:26 - Mozilla
    2008-06-15 à 16:51:12 - Opera
    2008-06-15 à 18:18:25 - WinRAR
    2008-06-19 à 10:00:50 - Xfire

    +- F:\Documents and Settings\ludo\Local Settings\Application Data

    2008-06-15 à 17:00:36 - Apple
    2008-06-15 à 17:01:41 - Apple Computer
    2008-06-14 à 21:10:24 - ATI
    2008-06-24 à 09:08:53 - ESET
    2008-06-15 à 16:45:09 - Google
    2008-06-18 à 14:05:16 - Logitech-LS
    2008-06-21 à 19:43:08 - Microsoft
    2008-06-17 à 20:01:26 - Mozilla
    2008-06-15 à 16:51:12 - Opera

    ========== Listing du dossier Program Files

    +- F:\Program Files

    2008-06-14 à 15:29:58 - Acronis
    2008-06-14 à 16:47:12 - Activision
    2008-06-18 à 21:22:56 - Adobe
    2008-06-18 à 14:38:39 - Anti-Leech
    2008-06-18 à 14:49:03 - Apple Software Update
    2008-06-14 à 16:53:58 - ASUS
    2008-06-18 à 14:49:04 - Bonjour
    2008-06-18 à 14:49:04 - CCleaner
    2008-06-19 à 10:04:11 - Common Files
    2008-06-14 à 15:15:00 - ComPlus Applications
    2008-06-18 à 14:49:04 - Driver Cleaner Pro
    2008-06-18 à 15:01:44 - ESET
    2008-06-18 à 21:22:56 - Fichiers communs
    2008-06-18 à 14:49:04 - FileZilla FTP Client
    2008-06-17 à 20:42:51 - Foxit Software
    2008-06-18 à 14:49:05 - Google
    2008-06-14 à 16:16:13 - Grisoft
    2008-06-19 à 09:47:22 - InstallShield Installation Information
    2008-06-18 à 14:49:05 - Internet Explorer
    2008-06-15 à 17:01:27 - iPod
    2008-06-18 à 14:49:05 - iTunes
    2008-06-18 à 09:21:44 - IVT Corporation
    2008-06-22 à 13:34:48 - K-Lite Codec Pack
    2008-06-18 à 13:54:29 - Logitech
    2008-06-24 à 09:18:05 - Lopxp
    2008-06-18 à 14:49:05 - ma-config.com
    2008-06-18 à 14:49:05 - Messenger
    2008-06-18 à 14:49:05 - Messenger Plus! Live
    2008-06-19 à 11:59:38 - Microsoft CAPICOM 2.1.0.2
    2008-06-14 à 15:18:25 - microsoft frontpage
    2008-06-18 à 14:49:05 - Movie Maker
    2008-06-21 à 20:28:35 - Mozilla Firefox
    2008-06-14 à 15:13:43 - MSN
    2008-06-14 à 15:14:15 - MSN Gaming Zone
    2008-06-17 à 17:49:18 - Navilog1
    2008-06-18 à 14:49:06 - NetMeeting
    2008-06-19 à 09:47:28 - NHN USA
    2008-06-14 à 15:14:23 - Online Services
    2008-06-18 à 14:49:06 - Opera
    2008-06-18 à 14:49:06 - Outlook Express
    2008-06-18 à 14:49:06 - QuickTime
    2008-06-14 à 15:16:36 - Services en ligne
    2008-06-18 à 14:49:06 - Spybot - Search & Destroy
    2008-06-18 à 15:09:33 - Sunbelt Software
    2008-06-15 à 18:09:16 - Trend Micro
    2008-06-15 à 18:39:10 - Uninstall Information
    2008-06-14 à 16:21:18 - VIA
    2008-06-14 à 16:32:24 - VIAudioi
    2008-06-15 à 16:47:57 - Windows Live
    2008-06-18 à 14:49:07 - Windows Media Player
    2008-06-18 à 14:49:07 - Windows NT
    2008-06-14 à 15:16:41 - WindowsUpdate
    2008-06-18 à 14:49:07 - WinRAR
    2008-06-14 à 15:18:25 - xerox
    2008-06-19 à 10:00:50 - Xfire
    2008-06-23 à 16:13:47 - Zone Labs

    ========== Tâches planifiées

    Aucune tâche planifiée détecté.

    ========== Clés registre

    ========== Bloqueur popups Internet Explorer

    ========== Suggestion ( /!\ Nécessite une interprétation.) ==========

    +- Dossiers\Fichiers : Aucune suggestion.

    +- Registre : Aucune suggestion.

    - Fin du rapport -
    0
  19. taurilius
     
    j'ai un gros problème maintenant sur tout les sites ou y a une zone membre je me log, et quand je clique sur un lein sa me retourne a la page du login.
    Et je n'arrive plus a me connecter sur msn:(
    0
  20. raphy00 Messages postés 1112 Statut Membre 9
     
    Bon,

    Fais ce qu'il y a ecrit au post 15.
    0
  • 1
  • 2