[Virus] Win32.Gpcode.ak
RésoluDepuis hier soir mon PC semble infecté, en effet je reçoit des messages d'erreurs de mon Avast Antivirus toutes les 2 minutes, j'ai des icones d'erreurs partout en barre des tâches... Mon windows m'envoi des alertes de Security Center...
Bref j'ai lancé un scan avec Malwarebytes Anti'Maltiware , il n'a rien trouvé.
En revanche, j'ai lancé un second scan avec Ad-Aware qui lui a déjà trouvé 2 infections ( 7 minutes d'analyse pour l'instant ).
Voilà pouvez-vous m'aider ?
Je peux poster un rapport HijackThis ou autre si besoin.
Configuration: Windows Vista Edition Familiale NVIDIA GeForce 8500GT Mozilla Firefox / Internet Explorer 7.0 Avast! Antivirus
31 réponses
Des symptômes d’infection apparaissent sur le PC avec des messages d’erreur Avast et des alertes Security Center pendant que Malwarebytes ne détecte rien et Ad-Aware signale deux infections. Des solutions de détection et de suppression sont proposées, notamment HijackThis pour repérer les entrées potentiellement indésirables, USBfix pour les infections USB et Ad-Remover pour les programmes indésirables. En cas de persistance, des outils complémentaires comme Bitdefender en ligne et ZHPDiag (puis ZHPFix) permettent d’obtenir des rapports à poster ensuite. D’autres conseils incluent la sauvegarde des données et la vérification des programmes installés récemment pour éviter les réinfections après nettoyage.
-
N'ayant plus de réponses ni de messages d'erreurs anti-virus, je classe le dossier en résolu...
Merci Xplode pour votre aide très généreuse et utile !
Je repasserai si problèmes... Merci encore ! -
Je me permet le up ?!
-
Salut Xplode,
Je n'ai pas eu de réponse, je voulais savoir si on avait finit ou pas ?
En tout cas merci pour le travail accomplit jusqu'à là ! -
Alors ça donne quoi s'il vous plait ?
-
Voilà le scan RSIT :
Logfile of random's system information tool 1.06 (written by random/random)
Run by Guiome at 2009-12-06 21:49:51
Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 1
System drive C: has 46 GB (20%) free of 233 GB
Total RAM: 1023 MB (35% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:50:04, on 06/12/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Razer\razerhid.exe
C:\WINDOWS\RtHDVCpl.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\HpqSRmon.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Steam\Steam.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Razer\razerofa.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Common Files\Teleca Shared\Generic.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10c.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\Guiome\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BHCS6D3N\RSIT[1].exe
C:\Program Files\Trend Micro\HijackThis\Guiome.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [razer] C:\Program Files\Razer\razerhid.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
O13 - Gopher Prefix:
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Service Google Update (gupdate1ca1c026c802290) (gupdate1ca1c026c802290) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
-
Contributeur sécuritéRefais un RSIT stp
-
Du neuf ?
-
Nettoyage HijackThis effectué.
Voilà le rapport USBFix :
############################## | UsbFix V6.059 |
User : Guiome (Administrateurs) # PCBUREAU
Update on 01/12/2009 by Chiquitine29, C_XX & Chimay8
Start at: 14:39:25 | 06/12/2009
Website : http://pagesperso-orange.fr/NosTools/index.html
Contact : FindyKill.Contact@gmail.com
Intel(R) Celeron(R) M CPU 430 @ 1.73GHz
Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6001 32-bit) # Service Pack 1
Internet Explorer 8.0.6001.18783
Windows Firewall Status : Enabled
AV : AntiMalware 1.0 [ Enabled | (!) Outdated ]
AV : avast! antivirus 4.8.1296 [VPS 081218-0] 4.8.1296 [ Enabled | Updated ]
C:\ -> Disque fixe local # 227,82 Go (44,37 Go free) [HP] # NTFS
D:\ -> Disque fixe local # 5,06 Go (32,5 Mo free) [Recovery] # NTFS
E:\ -> Disque CD-ROM # 727,56 Mo (0 Mo free) [Sims2_EP5_1] # UDF
F:\ -> Disque amovible
G:\ -> Disque amovible
H:\ -> Disque amovible
I:\ -> Disque amovible
############################## | Processus actifs |
C:\Windows\System32\smss.exe 452
C:\Windows\system32\csrss.exe 520
C:\Windows\system32\wininit.exe 576
C:\Windows\system32\csrss.exe 584
C:\Windows\system32\services.exe 632
C:\Windows\system32\lsass.exe 664
C:\Windows\system32\lsm.exe 672
C:\Windows\system32\winlogon.exe 680
C:\Windows\system32\svchost.exe 848
C:\Windows\system32\nvvsvc.exe 912
C:\Windows\system32\svchost.exe 940
C:\Windows\System32\svchost.exe 972
C:\Windows\System32\svchost.exe 1076
C:\Windows\System32\svchost.exe 1128
C:\Windows\system32\svchost.exe 1144
C:\Windows\system32\svchost.exe 1240
C:\Windows\system32\SLsvc.exe 1256
C:\Windows\system32\svchost.exe 1292
C:\Windows\system32\svchost.exe 1400
C:\Windows\system32\nvvsvc.exe 1420
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe 1592
C:\Program Files\Alwil Software\Avast4\ashServ.exe 1604
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe 1632
C:\Windows\System32\spoolsv.exe 1972
C:\Windows\system32\svchost.exe 1996
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe 596
C:\Program Files\Bonjour\mDNSResponder.exe 800
C:\Windows\system32\svchost.exe 1352
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe 1548
c:\Program Files\Common Files\LightScribe\LSSrvc.exe 1780
C:\Windows\System32\svchost.exe 1448
C:\Windows\System32\svchost.exe 2060
C:\Windows\system32\svchost.exe 2088
C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe 2112
C:\Windows\system32\svchost.exe 2140
C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe 2172
C:\Windows\System32\svchost.exe 2220
C:\Windows\system32\SearchIndexer.exe 2276
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe 2484
C:\Windows\system32\WUDFHost.exe 2492
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe 2528
C:\Windows\system32\wbem\unsecapp.exe 2792
C:\Windows\system32\wbem\wmiprvse.exe 2956
C:\Windows\system32\taskeng.exe 3476
C:\Windows\system32\taskeng.exe 1380
C:\Windows\system32\Dwm.exe 1308
C:\Windows\Explorer.EXE 3800
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe 2676
C:\Windows\system32\runonce.exe 3276
C:\Windows\system32\conime.exe 3956
C:\Windows\system32\wbem\wmiprvse.exe 4040
################## | Fichiers # Dossiers infectieux |
Non supprimé ! E:\autorun.inf
################## | Spyware.OnlineGames |
################## | Registre # Clés infectieuses |
################## | Registre # Mountpoints2 |
Supprimé ! HKCU\...\Explorer\MountPoints2\{fbfb3d8a-6548-11dd-b41f-806e6f6e6963}\Shell\AutoRun\Command
################## | Listing des fichiers présent |
[27/12/2008 01:01|--a------|5960] C:\AD-report-Clean-27.12.2008.log
[05/12/2009 15:43|--a------|8824] C:\Ad-Report-CLEAN[1].log
[27/12/2008 00:44|--a------|6670] C:\AD-report-Scan-27.12.2008.log
[18/09/2006 22:43|--a------|24] C:\autoexec.bat
[19/01/2008 08:45|-rahs----|333203] C:\bootmgr
[05/12/2006 17:49|-ra-s----|8192] C:\BOOTSECT.BAK
[05/12/2009 23:15|--a------|1352] C:\cleannavi.txt
[18/09/2006 22:43|--a------|10] C:\config.sys
[08/08/2008 15:00|--a------|167653] C:\ExtractLog.txt
[11/10/2009 19:40|--a------|34124] C:\fish.exe
[27/12/2008 00:44|-rahs----|0] C:\IO.SYS
[27/12/2008 00:44|-rahs----|0] C:\MSDOS.SYS
[?|?|?] C:\pagefile.sys
[05/12/2006 09:10|--a------|402] C:\RHDSetup.log
[08/08/2008 14:57|--a------|159] C:\Setup.log
[05/12/2009 16:01|--a------|2031] C:\TB.txt
[06/12/2009 14:42|--a------|4409] C:\UsbFix.txt
[05/12/2009 16:52|--a------|2606] C:\ZHPExportRegistry-05-12-2009-16-52-18.txt
[28/07/2006 09:05|---hs----|432696] D:\bootmgr
[13/10/2006 15:00|---hs----|1322] D:\Desktop.ini
[08/08/2008 14:45|---hs----|0] D:\DRECOVERY
[10/03/2007 17:11|---hs----|32] D:\HPCD.sys
[10/03/2007 18:06|---hs----|306] D:\Master.log
[12/10/2008 10:00|-ra------|528] D:\MediaID.bin
[08/08/2008 14:13|--ah-----|487] D:\pcdr.ini
[10/09/2002 13:58|---hs----|181616] D:\Protect.ed
[10/03/2007 17:11|---hs----|26] D:\RCBoot.sys
[05/12/2006 19:14|---hs----|44] D:\RESTORE.INI
[18/10/2006 11:09|---hs----|34] D:\SystemRecovery.txt
[26/01/2007 09:36|-r-------|20482048] E:\00000001.TMP
[26/01/2007 09:36|-r-------|317440] E:\00000002.TMP
[26/01/2007 09:41|-r-------|4] E:\_
[26/01/2007 09:36|-r-------|700416] E:\AutoRun.exe
[26/01/2007 09:40|-r-------|149] E:\autorun.inf
[26/01/2007 08:06|-r-------|651264] E:\AutoRunGUI.dll
[26/01/2007 09:40|-r-------|429] E:\common_filelist.txt
[26/01/2007 09:40|-r-------|683500937] E:\compressed.zip
[26/01/2007 09:40|-r-------|71178] E:\cs_compressed.zip
[26/01/2007 09:40|-r-------|67844] E:\da_compressed.zip
[26/01/2007 09:40|-r-------|74536] E:\de_compressed.zip
[26/01/2007 09:36|-r-------|356352] E:\eauninstall.exe
[26/01/2007 06:16|-r-------|10134] E:\eauninstall.ico
[26/01/2007 09:40|-r-------|68390] E:\en-uk_compressed.zip
[26/01/2007 09:40|-r-------|77170] E:\es_compressed.zip
[26/01/2007 09:40|-r-------|73444] E:\fi_compressed.zip
[26/01/2007 09:40|-r-------|75226] E:\fr-fr_compressed.zip
[26/01/2007 09:40|-r-------|73260] E:\hu_compressed.zip
[26/01/2007 09:40|-r-------|68390] E:\it_compressed.zip
[26/01/2007 09:40|-r-------|85094] E:\nl_compressed.zip
[26/01/2007 09:40|-r-------|69960] E:\no_compressed.zip
[26/01/2007 09:40|-r-------|74516] E:\pl_compressed.zip
[26/01/2007 09:40|-r-------|80596] E:\pt-br_compressed.zip
[26/01/2007 09:40|-r-------|79730] E:\pt-pt_compressed.zip
[26/01/2007 09:40|-r-------|70078] E:\ru_compressed.zip
[26/01/2007 06:16|-r-------|10134] E:\Sims2EP5.ico
[26/01/2007 08:07|-r-------|286720] E:\Sims2EP5_Uninst.exe
[26/01/2007 09:40|-r-------|71674] E:\sv_compressed.zip
################## | Vaccination |
# C:\autorun.inf -> Dossier créé par UsbFix.
# D:\autorun.inf -> Dossier créé par UsbFix.
################## | Cracks / Keygens / Serials | -
Contributeur sécurité-+-+-+-> Hijackthis <-+-+-+-
[x] Lance hijackthis ( C:\Program Files\Trend Micro\Hijackthis.exe )
[x] Clique sur " None of the above, just start the program " puis sur " Scan "
[x] Coche les lignes en gras ci dessous :
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKUS\S-1-5-21-3978070026-1512194447-919480873-1000\..\Run: [WinUsr] C:\Program Files\Winsudate\gibusr.exe (User 'Général')
O9 - Extra button: (no name) - cmdmapping - (no file) (HKCU)
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
[x] Clique ensuite sur " Fix checked "
====================================================================
-+-+-+-> USBfix ( Infections USB ) <-+-+-+-
[x] Télécharge USBfix ( de Chiquitine29 )
[x] Un tutoriel est disponible ici
[x] Installe le
/!\ Branche tout tes médias amovibles ( clés USB, DD externe, Cartes SD ) /!\
[x] Lance USBfix en cliquant sur l'icône qui est sur ton bureau ( Clique droit -> Executer en tant qu'administrateur pour vista )
[x] Choisis l'option F ( pour français ) et valide en appuyant sur entrée.
[x] Au menu principal, choisis l'option 2
[x] Laisse l'outil travailler puis poste le rapport dans ton prochain message -
Alors ça donne quoi ?
En apparence je ne voit plus de messages d'erreur... -
Voilà le scan RSIT ( en revanche un seul fichier s'est ouvert : log.txt )
Logfile of random's system information tool 1.06 (written by random/random)
Run by Guiome at 2009-12-06 11:38:32
Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 1
System drive C: has 45 GB (19%) free of 233 GB
Total RAM: 1023 MB (17% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:38:48, on 06/12/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\conime.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Razer\razerhid.exe
C:\WINDOWS\RtHDVCpl.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\HpqSRmon.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Steam\Steam.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Razer\razerofa.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Common Files\Teleca Shared\Generic.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10c.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\Guiome\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T0ZIO55E\RSIT[1].exe
C:\Program Files\Trend Micro\HijackThis\Guiome.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [razer] C:\Program Files\Razer\razerhid.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKLM\..\RunOnce: [Uninstall Adobe Download Manager] "C:\Windows\system32\rundll32.exe" "C:\Program Files\NOS\bin\getPlus_Helper.dll",Uninstall /IE2883E8F-472F-4fb0-9522-AC9BF37916A7 /Get1noarp
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-21-3978070026-1512194447-919480873-1000\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun (User 'Général')
O4 - HKUS\S-1-5-21-3978070026-1512194447-919480873-1000\..\Run: [WinUsr] C:\Program Files\Winsudate\gibusr.exe (User 'Général')
O4 - HKUS\S-1-5-21-3978070026-1512194447-919480873-1000\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized (User 'Général')
O4 - S-1-5-21-3978070026-1512194447-919480873-1000 Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe (User 'Général')
O4 - S-1-5-21-3978070026-1512194447-919480873-1000 Startup: OpenOffice.org 3.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe (User 'Général')
O4 - S-1-5-21-3978070026-1512194447-919480873-1000 User Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe (User 'Général')
O4 - S-1-5-21-3978070026-1512194447-919480873-1000 User Startup: OpenOffice.org 3.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe (User 'Général')
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
O9 - Extra button: (no name) - cmdmapping - (no file) (HKCU)
O13 - Gopher Prefix:
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} (System Requirements Lab) - https://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scanner/sources/fr/scan8/oscan8.cab
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} (get_atlcom Class) - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Service Google Update (gupdate1ca1c026c802290) (gupdate1ca1c026c802290) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
-
Contributeur sécuritéBien, dernière vérif :
-+-+-+-> RSIT <-+-+-+-
[x] Télécharge Random's System Information Tool
[x] Double clique sur " RSIT.exe ".
[x] Clique sur " Continue ".
[x] Si hijackthis n'est pas présent il sera automatiquement téléchargé et tu devras accepter la license.
[x] Une fois l'analyse finie, deux fichiers ( info.txt & log.txt ) s'ouvriront.
[x] Copie/Colle leur contenu dans ton prochain message. -
Voilà le rapport Bitdefender
BitDefender Online Scanner
Rapport d'analyse g�n�r� �: Sun, Dec 06, 2009 - 00:50:38
Voie d'analyse: C:\;D:\;E:\;F:\;G:\;H:\;I:\;
Statistiques
Temps
01:03:43
Fichiers
193429
Directoires
30668
Secteurs de boot
0
Archives
2824
Paquets programmes
22125
R�sultats
Virus identifi�s
1
Fichiers infect�s
1
Fichiers suspects
0
Avertissements
0
D�sinfect�s
0
Fichiers effac�s
1
Info sur les moteurs
D�finition virus
4695567
Version des moteurs
AVCORE v2.1 Windows/i386 11.0.0.26 (Oct 20 2009)
Analyse des plugins
17
Archive des plugins
44
Unpack des plugins
8
E-mail plugins
6
Syst�me plugins
4
Param�tres d'analyse
Premi�re action
Désinfecté
Seconde Action
Supprimés
Heuristique
Oui
Acceptez les avertissements
Oui
Extensions analys�es
exe;com;dll;ocx;scr;bin;dat;386;vxd;sys;wdm;cla;class;ovl;ole;hlp;doc;dot;xls;ppt;wbk;wiz;pot;ppa;xla;xlt;vbs;vbe;mdb;rtf;htm;hta;html;xml;xtp;php;asp;js;shs;chm;lnk;pif;prc;url;smm;pfd;msi;ini;csc;cmd;bas;
Excludez les extensions
Analyse d'emails
Oui
Analyse des Archives
Oui
Analyser paquets programmes
Oui
Analyse des fichiers
Oui
Analyse de boot
Oui
Fichier analys�
Statut
C:\Program Files\Navilog1\Backupnavi\cscko.exe
Détecté avec: Adware.NaviPromo.Gen.5
C:\Program Files\Navilog1\Backupnavi\cscko.exe
Echec de la désinfection
C:\Program Files\Navilog1\Backupnavi\cscko.exe
Supprimé -
Voilà j'ai lancé le scan Bitdefender mais on m'estime 67 heures de scan c'est normal ? :D
-
Contributeur sécurité-+-+-+-> Scan en ligne Bitdefender <-+-+-+-
[x] Suis le tutoriel disponible à cette adresse ( en image ) :
https://www.commentcamarche.net/faq/8872-scanner-en-ligne-avec-bitdefender -
Voici le rapport Navilog1 :
Fix Navipromo version 4.0.5 commencé le 05/12/2009 22:57:09,66
!!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
!!! Postez ce rapport sur le forum pour le faire analyser !!!
Outil exécuté depuis C:\Program Files\navilog1
Mise à jour le 10.11.2009 à 18h00 par IL-MAFIOSO
Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6001 ) Service Pack 1
X86-based PC ( Multiprocessor Free : Intel(R) Celeron(R) M CPU 430 @ 1.73GHz )
BIOS : BIOS Date: 04/23/07 10:53:04 Ver: 08.00.12
USER : Guiome ( Not Administrator ! )
BOOT : Normal boot
Antivirus : avast! antivirus 4.8.1296 [VPS 081218-0] 4.8.1296 (Activated)
C:\ (Local Disk) - NTFS - Total:227 Go (Free:46 Go)
D:\ (Local Disk) - NTFS - Total:5 Go (Free:0 Go)
E:\ (CD or DVD) - UDF - Total:0 Go (Free:0 Go)
F:\ (USB)
G:\ (USB)
H:\ (USB)
I:\ (USB)
Recherche executée en mode normal
Nettoyage exécuté au redémarrage de l'ordinateur
C:\Users\GNRAL~1\AppData\Local\asnhzun.bat supprimé !
Nettoyage contenu C:\Windows\Temp effectué !
Nettoyage contenu C:\Users\Guiome\AppData\Local\Temp effectué !
*** Sauvegarde du Registre vers dossier Safebackup ***
sauvegarde du Registre réalisée avec succès !
*** Nettoyage Registre ***
Nettoyage Registre Ok
*** Scan terminé 05/12/2009 23:15:13,90 *** -
Contributeur sécuritéCa raconte qu'on a bientôt terminé :
-+-+-+-> Navilog <-+-+-+-
Ton PC est infecté par l'ad-aware Navipromo/Magic Control qui affiche des publicités intempestives.
Il s'installe via certains programmes, dont ceux-ci :
● Funky Emoticons
● go-astro
● GoRecord
● HotTVPlayer / HotTVPlayer & Paris Hilton
● Live-Player
● MailSkinner
● Messenger Skinner
● Instant Access
● InternetGameBox
● Officiale Emule (Version d'Emule modifiée)
● Original Solitaire
● SuperSexPlayer
● Speed Downloading
● Sudoplanet
● Webmediaplayer
/!\ Fais attention de ne pas faire la même erreur, donc évite ces programmes /!\
[x] Télécharge Navilog ( de IL-MAFIOSO)
[x] Lance le en double cliquant dessus. ( Clic droit -> "Executer en tant qu'administrateur" sous vista )
[x] Laisse-toi guider par l'utilitaire. Choisis l'option n°1 puis valide.
[x] A l'écran principal, choisis l'option n°1 puis laisse l'outil scanner.
[x] Patiente jusqu'à l'apparition de ce message :
"*** Analyse Termine le ..... ***"
[x] Appuie sur une touche comme demandé. Le Bloc-notes va s'ouvrir. Poste son contenu dans ton prochain message.
Nb : Le rapport se trouve également ici : C:\cleannavi.txt -
Alors ça raconte quoi ? :S
-
Voilà le scan ZHPDiag :
http://www.cijoint.fr/cjlink.php?file=cj200912/cijHlyYJX9.txt -
Contributeur sécuritéBien, fais maintenant un nouveau rapport ZHPDiag
- 1
- 2