Bonjour,
Je reçois le message suivant sans rien comprendre pouvez-vous eclairer ma lanterne?
Merci 1000 fois.
1) le message (avec à l'avant dernière ligne le message surligné en jaune et fléché)
2) le log hijack
1)<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
<title>software</title>
<style type="text/css">
html,
body{ font-family: Tahoma,Verdana,Segoe,sans-serif; }
@charset "utf-8";
a,
a:visited{color:blue;text-decoration:none}
a:hover {color:blue;text-decoration:underline;}
* {margin:0;padding:0;}
ul li {list-style:none;}
img {border:0;} h1,h2,h3,h4,h5 {font-weight:normal;font-size:12px;}
body {font-size:12px;}
.bodyer {width:195px;float:left;margin:0 0 0 2px;}
.cfl {width:195px;float:left;}
.cfl .lst {height:30px/*(115)*/;width:195px/*(195)*/;border-bottom:1px dotted #EBEADB;margin:10px 0 3px 0;float:left}
.cfl .lst1 {height:58px/*(115)*/;width:190px/*(195)*/;margin:3px 0 3px 0;float:left}
.cfl .lst .t {height:55px/*(88)*/;width:190px/*(195)*/;float:left;}
.cfl .lst .t .img{height:57px;width:57px;/*these 2 modified(88)*/float:left;background:url(http://cimg.kuaiche.com//images/client/client_img_bg.gif) no-repeat 0 0;}
.cfl .lst .t .img img{border:0px;margin:3px/*(3)*/ 0 0 3px;width:50px;height:50px;/*these 2 modified(80)*/}
.cfl .lst .t .tit{height:15px;width:108px;float:left;line-height:20px/*25*/;margin-left:3px;}
.cfl .lst .t .tit a,
.cfl .lst .t .tit a:visited{color:blue;text-decoration:none}
.cfl .lst .t .tit a:hover {color:blue;text-decoration:underline;}
.cfl .lst .t .con{height:40px/*50*/;width:108px;float:left;line-height:18px/*20*/;margin-left:3px;color:#555;}
.cfl .lst .b{height:12px/*(15)*/;width:195px;float:left;margin:3px 0 3px 0;}
.cfl .lst .b a,
.cfl .lst .b a:visited{color:blue;text-decoration:none}
.cfl .lst .b a:hover {color:blue;text-decoration:underline;}
.soIpt{margin:0;}
.soIpt .input{line-height:17px;height:20px;width:125px;border:1px solid #ccc;padding:0px 0 0 3px;font-size:12px;float:left;color:#555;}
.soIpt .inso{height:20px;width:60px;border:1px solid #ccc;background-color:#ebebeb;padding:0px 0 0 3px;font-size:12px;margin:0 0 3px 5px;float:left;color:#555;}
.soIpt .hkey{width:60px;height:15px;line-height:20px;float:left;text-align:left;color:#555;}
.soIpt .hkey a,
.soIpt .hkey a:visited{color:#555;text-decoration:none}
.soIpt .hkey a:hover {color:#555;text-decoration:underline;}
.soIpt .lst{width:180px;height:18px;margin:3px 0 0 0;float:left;text-align:left;color:#555;border:0}
.soIpt .lst a,
.soIpt .lst a:visited{color:#555;text-decoration:underline}
.soIpt .lst a:hover {text-decoration:none;}
.soIpt .list{height:50px;width:180px;float:left;margin:5px 0 0 0;border-bottom:1px dotted #ccc;line-height:25px;}
.soIpt .list a,
.soIpt .list a:visited{color:#32659C;text-decoration:none;}
.soIpt .list a:hover {color:#32659C;text-decoration:underline;}
.soIpt .more{height:30px;width:170px;float:left;margin:5px 0 0 0;line-height:25px;text-align:right; padding-right:10px;}
.soIpt .more a:visited{color:blue;text-decoration:underline;}
.soIpt .more a:hover {color:blue;text-decoration:none;}
.hkey a,
.hkey a:visited{color:#555;text-decoration:underline}
.hkey a:hover {color:#555;text-decoration:underline;}
/*search_list*/
.line{width:195px;margin:5px 0 5px 0;border-bottom:1px dotted #ebebeb;padding:0 0 5px 0;}
.disp{display:none;}
/*hot*/
.hot{float:left; width:195px; display:block;}
.hot dt{color:#555555; height:21px; line-height:21px; width:195px;}
.hot dd{float:left; padding:0 5px; height:21px; line-height:21px; display:block;}
.hot dd a,
.hot dd a:visited{color:#555;text-decoration:none}
.hot dd a:hover {color:#555;text-decoration:underline;}
</style>
<base target="_blank" />
</head>
<div style="display:none;">
<iframe src="http://ufile.kuaiche.com/ck.html"></iframe>
</div>
<body oncontextmenu=self.event.returnValue=false onselectstart="return false" style="OVERFLOW-X:hidden;OVERFLOW:scroll">
<div class="bodyer">
<div class="cfl">
<FORM id="search_form" name="search_form" action="http://en.softonic.com/index.phtml" method="get" target="_blank">
<div class="lst">
<div class="soIpt">
<INPUT id="adv_search" type="hidden" name="adv_search">
<INPUT id="query" type="hidden" name="query">
<INPUT id="do" type="hidden" value="process" name="do">
<INPUT class="input" id="search" size="18" name=search value="search for software" onFocus="this.select()" onMouseOver="this.focus();value=''" onMouseOut="value=value;this.blur()">
<INPUT name="fg" value="1" type="hidden">
<input type="submit" class="inso" value="Search" />
</div>
</div>
</form>
<div class="lst">
<div class="t">
<div class="img"><a href="
https://cj.dotomi.com/5s105tenm4/elq/3275B937/53B4B63/2/2/2?f=n%3c%3cr33z%3A%2F%2F666.u098pt.myw%3AIA%2Fmvsmu-DBJCJEB-BAFDJHBF%3c%3cQ%3c%3c%3cB%3cB%3cA%3cA%3c "><img src="http://img.kuaiche.com/publish/200810/31/2008103113495471080678.gif" /></a></div>
<div class="tit"><a href="
https://cj.dotomi.com/5s105tenm4/elq/3275B937/53B4B63/2/2/2?f=n%3c%3cr33z%3A%2F%2F666.u098pt.myw%3AIA%2Fmvsmu-DBJCJEB-BAFDJHBF%3c%3cQ%3c%3c%3cB%3cB%3cA%3cA%3c "><span style='color:#ff3300;'>Delete Adware</span></a></div>
<div class="con">
We Buy & Test Every <br />
Tool For You.Full<br />
Reviews, Comparisons <br />
& Guides. </div>
</div>
<div class="b">
<a href="
https://cj.dotomi.com/5s105tenm4/elq/3275B937/53B4B63/2/2/2?f=n%3c%3cr33z%3A%2F%2F666.u098pt.myw%3AIA%2Fmvsmu-DBJCJEB-BAFDJHBF%3c%3cQ%3c%3c%3cB%3cB%3cA%3cA%3c ">Download Now</a>
</div>
</div>
<div class="lst">
<div class="t">
<div class="img"><a href="
http://www.easymule.com/en-us/ "><img src="http://img.kuaiche.com/publish/200808/07/2008080714535047192994.png" /></a></div>
<div class="tit"><a href="
http://www.easymule.com/en-us/ "><span style='color:#ff0000;'><span style='text-decoration:underline;'>EasyMule</span></span></a></div>
<div class="con">
Best peer-to-peer <br />
file sharing clients<br />
around the world!</div>
</div>
<div class="b">
<a href="
http://www.easymule.com/en-us/ ">Download Now</a>
</div>
</div>
<div class="lst">
<div class="t">
<div class="img"><a href="http://vso-convertxtodvd.en.softonic.com/download/af/49"><img src="http://img.kuaiche.com/publish/200712/24/2007122415482394924240.gif" /></a></div>
<div class="tit"><a href="http://vso-convertxtodvd.en.softonic.com/download/af/49">Convertx ToDVD</a></div>
<div class="con">
Burn you internet<br />
movie files to DVD</div>
</div>
<div class="b">
<a href="http://vso-convertxtodvd.en.softonic.com/download/af/49">Download Now</a>
</div>
</div>
<div class="lst">
<div class="t">
<div class="img"><a href="http://spy-sweeper.en.softonic.com/af/49"><img src="http://img.kuaiche.com/publish/200712/24/2007122415513601847327.gif" /></a></div>
<div class="tit"><a href="http://spy-sweeper.en.softonic.com/af/49">Spy Sweeper</a></div>
<div class="con">
Find and eliminate<br />
spyware, trojans</div>
</div>
<div class="b">
<a href="http://spy-sweeper.en.softonic.com/af/49">Download Now</a>
</div>
</div>
<div class="lst">
<div class="t">
<div class="img"><a href="http://regcure.en.softonic.com/download/af/49"><img src="http://img.kuaiche.com/publish/200712/24/2007122415531038219811.gif" /></a></div>
<div class="tit"><a href="http://regcure.en.softonic.com/download/af/49">RegCure</a></div>
<div class="con">
Analize, Clean and <br />
optimize registry</div>
</div>
<div class="b">
<a href="http://regcure.en.softonic.com/download/af/49">Download Now</a>
</div>
</div>
<div class="lst">
<div class="t">
<div class="img"><a href="
https://kaspersky-anti-virus.en.softonic.com/ "><img src="http://img.kuaiche.com/publish/200712/24/2007122416003632830914.gif" /></a></div>
<div class="tit"><a href="
https://kaspersky-anti-virus.en.softonic.com/ ">Kaspersky AV</a></div>
<div class="con">
Combines reactive<br />
detection methods</div>
</div>
<div class="b">
<a href="
https://kaspersky-anti-virus.en.softonic.com/ ">Download Now</a>
</div>
</div>
<div class="lst">
<div class="t">
<div class="img"><a href="
https://crazytalk.en.softonic.com/download "><img src="http://img.kuaiche.com/publish/200712/24/2007122416013000334576.gif" /></a></div>
<div class="tit"><a href="
https://crazytalk.en.softonic.com/download ">Crazy Talk</a></div>
<div class="con">
Facial animation &<br />
lip-sync software</div>
</div>
<div class="b">
<a href="
https://crazytalk.en.softonic.com/download ">Download Now</a>
</div>
</div>
<div class="lst">
<div class="t">
<div class="img"><a href="
https://bps-video-converter-decompiler.en.softonic.com/ "><img src="http://img.kuaiche.com/publish/200712/24/2007122416034124576902.gif" /></a></div>
<div class="tit"><a href="
https://bps-video-converter-decompiler.en.softonic.com/ ">BPS VideoConvert</a></div>
<div class="con">
Universal converter<br />
& decompiler</div>
</div>
<div class="b">
<a href="
https://bps-video-converter-decompiler.en.softonic.com/ ">Download Now</a>
</div>
</div>
<div class="lst">
<div class="t">
<div class="img"><a href="
https://wash-and-go.en.softonic.com/ "><img src="http://img.kuaiche.com/publish/200712/24/2007122416054608446715.gif" /></a></div>
<div class="tit"><a href="
https://wash-and-go.en.softonic.com/ ">WashandGo</a></div>
<div class="con">
PC scrubbing <br />
brush software</div>
</div>
<div class="b">
<a href="
https://wash-and-go.en.softonic.com/ ">Download Now</a>
</div>
</div>
<div class="lst">
<div class="t">
<div class="img"><a href="
https://ssl.clickbank.net/order/restricted.html?errCode=accntstate&cbhopvendor=xoftspyse "><img src="http://img.kuaiche.com/publish/200712/24/2007122416085306302374.gif" /></a></div>
<div class="tit"><a href="
https://ssl.clickbank.net/order/restricted.html?errCode=accntstate&cbhopvendor=xoftspyse ">XoftSpySE</a></div>
<div class="con">
Detect Spyware,<br />
malware, etc</div>
</div>
<div class="b">
<a href="
https://ssl.clickbank.net/order/restricted.html?errCode=accntstate&cbhopvendor=xoftspyse ">Download Now</a>
</div>
</div>
</div>
</div>
<div style="display:none;">
<script type="text/javascript">
var gaJsHost = (("https:" == document.location.protocol) ? "https://ssl." : "http://www.");
document.write(unescape("%3Cscript src='" + gaJsHost + "google-analytics.com/ga.js' type='text/javascript'%3E%3C/script%3E"));
</script>
<script type="text/javascript">
var pageTracker = _gat._getTracker("UA-2833657-4");
pageTracker._initData();
pageTracker._trackPageview();
2)Logfile of HijackThis v1.99.1
Scan saved at 00:14:04, on 06/11/2008
Platform: Windows XP SP3, v.5512 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.20772)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\mdm.exe
C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe
C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\ALCWZRD.EXE
D:\flashget 1.96\FlashGet.exe
C:\WINDOWS\system32\WDBtnMgr.exe
D:\virtual clone drive 5.4.1.1\VCDDaemon.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Fichiers communs\Ulead Systems\AutoDetector\monitor.exe
D:\super copier 2.0\SuperCopier2.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Sunbelt Software\Personal Firewall\SbPFCl.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\dlcgcoms.exe
C:\PROGRA~1\MOZILLA.ORG\SEAMON~1\SEAMON~1.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Mozilla Thunderbird\thunderbird.exe
C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\MSE7.EXE
D:\office pro 2007\Office12\CLVIEW.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
E:\recup poste\Mes fichiers reçus\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Favoris
O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - D:\flashget 1.96\jccatch.dll
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - D:\flashget 1.96\getflash.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [Flashget] "D:\flashget 1.96\FlashGet.exe" /min
O4 - HKLM\..\Run: [WD Button Manager] WDBtnMgr.exe
O4 - HKLM\..\Run: [VirtualCloneDrive] "D:\virtual clone drive 5.4.1.1\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [DLCGCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCGtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [Ulead AutoDetector v2] C:\Program Files\Fichiers communs\Ulead Systems\AutoDetector\monitor.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKCU\..\Run: [SuperCopier2.exe] D:\super copier 2.0\SuperCopier2.exe
O4 - HKCU\..\Run: [SeaMonkey Quick Launch] "C:\Program Files\mozilla.org\SeaMonkey\SeaMonkey.exe" -turbo
O8 - Extra context menu item: &Tout télécharger avec FlashGet - D:\flashget 1.96\jc_all.htm
O8 - Extra context menu item: &Télécharger avec FlashGet - D:\flashget 1.96\jc_link.htm
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://D:\OFFICE~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\OFFICE~1\Office12\REFIEBAR.DLL
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - D:\flashget 1.96\FlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - D:\flashget 1.96\FlashGet.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O11 - Options group: [INTERNATIONAL] International*
O11 - Options group: [TABS] Tabbed Browsing
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~3\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Fichiers communs\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~3\MESSEN~1\MSGRAP~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\FICHIE~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\wpdshserviceobj.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: dlcg_device - - C:\WINDOWS\system32\dlcgcoms.exe
O23 - Service: L Ile Noyee Drivers Auto Removal (pr2ajbeb) (pr2ajbeb) - Micro Application - C:\WINDOWS\system32\pr2ajbeb.exe
O23 - Service: SbPF.Launcher - Sunbelt Software, Inc. - C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe
O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software, Inc. - C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe
Configuration: Windows trust
Firefox 2.0.0.17
Afficher la suite