Case noire dans la barre des taches!!!!!

yucca -  
jlpjlp Messages postés 52399 Statut Contributeur sécurité -
Bonjour,svp aidez moi c'est urgent!!!!!!!

aujourd'hui quand j'ai demarré mon ordinateur j'ai trouvé une case noire dans la barre des taches la voici

http://img356.imageshack.us/img356/6104/screenshot012mc1.jpg

dites moi svp c'est quoi ça un spyware????

ainsi j'ai effectué un scan avec hijackthis

voici le log....

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:33, on 05/09/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0S2.EXE
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Barre d'outils MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar\01.01.2607.0\fr\msntb.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [EPSON Stylus C66 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0S2.EXE /P23 "EPSON Stylus C66 Series" /O6 "USB001" /M "Stylus C66"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min/nosplash
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet
O4 - HKCU\..\Run: [EPSON Stylus C66 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0S2.EXE /P23 "EPSON Stylus C66 Series" /M "Stylus C66" /EF "HKCU"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{AF039ACA-F681-476F-BAB9-B6A7F923BD92}: NameServer = 41.221.20.4 208.67.222.222
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O23 - Service: ADSLAutoconnect - Unknown owner - C:\Program Files\ADSL Autoconnect\ADSL Autoconnect.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe

--
End of file - 4155 bytes

ah....c'est quoi tous ces lignes :(

merci d'avance
Configuration: Windows XP
Firefox 3.0.1

9 réponses

  1. jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 041
     
    slt
    et quand tu clique avec le bouton droit sur la case noire cela te dis quoi?

    _________________

    mets a jour internet explorer:
    https://www.01net.com/telecharger/windows/Internet/navigateur/fiches/33081.html

    _________________

    colles un rapport avec antivir que tu as

    et malwarebyte antimalware que tu gardera en complement de antivir pour te proteger des espions

    https://www.malekal.com/tutoriel-malwarebyte-anti-malware/­
    0
  2. plm69 Messages postés 532 Statut Membre 17
     
    salut c'ets peutetre un proggramme qui fonctione plus, connait-tu ce fichier ? :
    C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe
    0
  3. yucca
     
    merci c'est sympa.....votre aide

    bon

    *printscreen fonctionne normalement..

    **j'ai constaté que ce programme est "windows live messanger"..........
    ponsez vous que quelqu'un m'a piraté

    ...
    ben ....je vais faire ce que tu m'as demander de le faire jlpjlp....

    souhaitez moi bonne chance.....s'apprend beaucoup de temps ....
    @++
    0
  4. yucca
     
    ah ... j'ai oublié de dire que j'utilise pas ie dois-je la mettre a jour??
    0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. plm69 Messages postés 532 Statut Membre 17
     
    oui
    0
  7. yucca
     
    slt

    bizarre.....................!!!

    j'ai redemarré mon ordi est c'etait la surprise la case est disparue....mais j'ai 2 windows live messenger ....et cela apres correction d'erreur avc ccleaner!!!!!
    0
  8. jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 041
     
    si c'est live messenger cela est peut être qu'un bug mais fais les annalyses pour verifier

    pour ie : oui il faut le mettre a jour car même si tu ne l'utilise pas windows n'utilise que lui pour se mettre a jour
    0
  9. yucca
     
    slt

    j'ai fait un scan avec antivir, heureusement pas de soucis...

    voici le resultat..

    Avira AntiVir Personal
    Report file date: vendredi 5 septembre 2008 15:57

    Scanning for 1598736 virus strains and unwanted programs.

    Licensed to: Avira AntiVir PersonalEdition Classic
    Serial number: 0000149996-ADJIE-0001
    Platform: Windows XP
    Windows version: (Service Pack 2) [5.1.2600]
    Boot mode: Normally booted
    Username: SYSTEM
    Computer name: TITANIUM

    Version information:
    BUILD.DAT : 8.1.0.331 16934 Bytes 12/08/2008 11:46:00
    AVSCAN.EXE : 8.1.4.7 315649 Bytes 19/08/2008 22:18:26
    AVSCAN.DLL : 8.1.4.0 40705 Bytes 19/08/2008 22:18:26
    LUKE.DLL : 8.1.4.5 164097 Bytes 19/08/2008 22:18:28
    LUKERES.DLL : 8.1.4.0 12033 Bytes 19/08/2008 22:18:28
    ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 10:33:34
    ANTIVIR1.VDF : 7.0.5.1 8182784 Bytes 24/06/2008 10:14:40
    ANTIVIR2.VDF : 7.0.6.94 2998784 Bytes 31/08/2008 11:06:00
    ANTIVIR3.VDF : 7.0.6.121 185344 Bytes 05/09/2008 10:57:36
    Engineversion : 8.1.1.28
    AEVDF.DLL : 8.1.0.5 102772 Bytes 25/02/2008 09:58:22
    AESCRIPT.DLL : 8.1.0.70 319866 Bytes 04/09/2008 11:00:06
    AESCN.DLL : 8.1.0.23 119156 Bytes 19/08/2008 22:18:34
    AERDL.DLL : 8.1.1.1 397683 Bytes 04/09/2008 10:59:58
    AEPACK.DLL : 8.1.2.1 364917 Bytes 19/08/2008 22:18:34
    AEOFFICE.DLL : 8.1.0.23 196987 Bytes 04/09/2008 10:59:38
    AEHEUR.DLL : 8.1.0.51 1397111 Bytes 04/09/2008 10:59:26
    AEHELP.DLL : 8.1.0.15 115063 Bytes 10/06/2008 09:15:22
    AEGEN.DLL : 8.1.0.36 315764 Bytes 19/08/2008 22:18:32
    AEEMU.DLL : 8.1.0.7 430452 Bytes 19/08/2008 22:18:32
    AECORE.DLL : 8.1.1.11 172406 Bytes 04/09/2008 10:58:30
    AEBB.DLL : 8.1.0.1 53617 Bytes 19/08/2008 22:18:32
    AVWINLL.DLL : 1.0.0.12 15105 Bytes 19/08/2008 22:18:26
    AVPREF.DLL : 8.0.2.0 38657 Bytes 19/08/2008 22:18:26
    AVREP.DLL : 8.0.0.2 98344 Bytes 19/08/2008 22:18:32
    AVREG.DLL : 8.0.0.1 33537 Bytes 19/08/2008 22:18:26
    AVARKT.DLL : 1.0.0.23 307457 Bytes 12/02/2008 08:29:24
    AVEVTLOG.DLL : 8.0.0.16 119041 Bytes 19/08/2008 22:18:26
    SQLITE3.DLL : 3.3.17.1 339968 Bytes 22/01/2008 17:28:04
    SMTPLIB.DLL : 1.2.0.23 28929 Bytes 19/08/2008 22:18:28
    NETNT.DLL : 8.0.0.1 7937 Bytes 25/01/2008 12:05:12
    RCIMAGE.DLL : 8.0.0.51 2371841 Bytes 19/08/2008 22:17:54
    RCTEXT.DLL : 8.0.52.0 86273 Bytes 19/08/2008 22:17:54

    Configuration settings for the scan:
    Jobname..........................: Complete system scan
    Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
    Logging..........................: low
    Primary action...................: interactive
    Secondary action.................: ignore
    Scan master boot sector..........: on
    Scan boot sector.................: on
    Boot sectors.....................: C:, D:, E:, F:,
    Process scan.....................: on
    Scan registry....................: on
    Search for rootkits..............: off
    Scan all files...................: All files
    Scan archives....................: on
    Recursion depth..................: 20
    Smart extensions.................: on
    Macro heuristic..................: on
    File heuristic...................: medium

    Start of the scan: vendredi 5 septembre 2008 15:57

    The scan of running processes will be started
    Scan process 'firefox.exe' - '1' Module(s) have been scanned
    Scan process 'avscan.exe' - '1' Module(s) have been scanned
    Scan process 'skypePM.exe' - '1' Module(s) have been scanned
    Scan process 'Skype.exe' - '1' Module(s) have been scanned
    Scan process 'alg.exe' - '1' Module(s) have been scanned
    Scan process 'Ymsgr_tray.exe' - '1' Module(s) have been scanned
    Scan process 'MsnMsgr.Exe' - '1' Module(s) have been scanned
    Scan process 'E_S4I0S2.EXE' - '1' Module(s) have been scanned
    Scan process 'AVGNT.EXE' - '1' Module(s) have been scanned
    Scan process 'avguard.exe' - '1' Module(s) have been scanned
    Scan process 'sched.exe' - '1' Module(s) have been scanned
    Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
    Scan process 'Explorer.EXE' - '1' Module(s) have been scanned
    Scan process 'SVCHOST.EXE' - '1' Module(s) have been scanned
    Scan process 'SVCHOST.EXE' - '1' Module(s) have been scanned
    Scan process 'SVCHOST.EXE' - '1' Module(s) have been scanned
    Scan process 'SVCHOST.EXE' - '1' Module(s) have been scanned
    Scan process 'SVCHOST.EXE' - '1' Module(s) have been scanned
    Scan process 'LSASS.EXE' - '1' Module(s) have been scanned
    Scan process 'SERVICES.EXE' - '1' Module(s) have been scanned
    Scan process 'winlogon.exe' - '1' Module(s) have been scanned
    Scan process 'csrss.exe' - '1' Module(s) have been scanned
    Scan process 'SMSS.EXE' - '1' Module(s) have been scanned
    23 processes with 23 modules were scanned

    Starting master boot sector scan:
    Master boot sector HD0
    [INFO] No virus was found!

    Start scanning boot sectors:
    Boot sector 'C:\'
    [INFO] No virus was found!
    Boot sector 'D:\'
    [INFO] No virus was found!
    Boot sector 'E:\'
    [INFO] No virus was found!
    Boot sector 'F:\'
    [INFO] No virus was found!

    Starting to scan the registry.
    The registry was scanned ( '44' files ).

    Starting the file scan:

    Begin scan in 'C:\'
    C:\PAGEFILE.SYS
    [WARNING] The file could not be opened!
    Begin scan in 'D:\'
    Begin scan in 'E:\'
    Begin scan in 'F:\'

    End of the scan: vendredi 5 septembre 2008 17:00
    Used time: 1:36:15 Hour(s)

    The scan has been done completely.

    2951 Scanning directories
    139250 Files were scanned
    0 viruses and/or unwanted programs were found
    0 Files were classified as suspicious:
    0 files were deleted
    0 files were repaired
    0 files were moved to quarantine
    0 files were renamed
    1 Files cannot be scanned
    139249 Files not concerned
    1057 Archives were scanned
    1 Warnings
    0 Notes

    alors il me reste celui de mbam

    merci pour tout...
    a bientot...
    0
  10. jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 041
     
    ok
    0