Fenêtre
Depuis ce matin, dès que j'ouvre internet explorer, une fenêtre s'ouvre : il es ecrit avertissement de sécurité.Fichier ouvert. IL y a un nom de fichier, éditeur inconnu .Il semeblerait que ce soit un virus, car depuis, j'ai pleins de fenêtres de pub qui s'ouvrent, des trucs de jeu, que je n'avais pas avant. Je ne comprends pas grand chose à l'informatique, mais j'ai fait un nettoyage (contre les chevaux de Troie et sur les conseils de mon frère assez calé). Il m'à supprimé pleins de "merdes", mais il m'en reste et mon problème reste entier. Qui peut m'aider en m'expliquant assez simplement SVP. Merci beaucoup.
Configuration: Windows Vista Internet Explorer 7.0
126 réponses
Une fenêtre d'avertissement de sécurité s'ouvre à chaque lancement d'Internet Explorer sur Windows Vista, et l'ordinateur affiche des publicités et des fichiers suspects, pointant vers une possible infection virale. Plusieurs réponses préconisent une approche anti-malware avec des outils comme ComboFix et l'analyse des éléments au démarrage, afin d'identifier les programmes indésirables et d'établir un rapport exploitable. Des exemples relevés évoquent IncrediMail, LimeWire ou AVG7 dans les démarrages ou les scripts, et l'échange souligne la nécessité d'examiner les journaux et les rapports générés par les outils. Des répertoires temporaires et des scripts suspects dans le répertoire temporaire local et d'autres emplacements révèlent une activité malveillante qui peut persister même après les nettoyages et d'autres méthodes.
-
Contributeur sécuritécelui ci date du 19/02 j'en veux un nouveau !
-
voila le scan d'aujourd'hui désolée je me suis plantée ^^
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:44:10, on 24/02/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16609)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Grisoft\AVG7\avgcc.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Menu Démarrer\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\Common Files\microsoft shared\Works Shared\WkCalRem.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\PROGRA~1\INCRED~1\bin\IMApp.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\IncrediMail\bin\IncMail.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Dofus\dofus.dll
C:\Windows\system32\Macromed\Flash\FlashUtil9e.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Menu Démarrer\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O2 - BHO: BrowsingProgram - {F8EACE56-0AF4-3AE3-6EF8-F8CC39675729} - C:\Program Files\BrowsingProgram\BrowsingProgram-1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Menu Démarrer\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Startup: wkcalrem.LNK = C:\Program Files\Common Files\microsoft shared\Works Shared\WkCalRem.exe
O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Menu Démarrer\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Menu Démarrer\Spybot - Search & Destroy\SDHelper.dll
O13 - Gopher Prefix:
O15 - Trusted Zone: http://www.secuser.com
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
O16 - DPF: {512FC5A1-7DE1-43F1-BC0C-371622FCB409} (TotalScan Installer Class) - https://www.pandasecurity.com/en/homeusers/online-antivirus/?ref=activescan
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,5234/mcfscan.cab
O20 - Winlogon Notify: avgwlntf - C:\Windows\SYSTEM32\avgwlntf.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG7 Resident Shield Service (AvgCoreSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\Program Files\Common Files\Protexis\License Service\PSIService.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Menu Démarrer\Spybot - Search & Destroy\SDWinSec.exe
-
-
Contributeur sécuritési jamais tu as un souci ultérieurement , poste ici .
@ jamais + -
Contributeur sécuritéj'ai trouvé ca :
va sur Internet explorer,clic droit,propriétés internet,coller: http://google.fr. -
Contributeur sécuritétu as regardé dans "rapports et solution " ???
l'érreur doit y etre indiqué ,dans ce cas la recherche une solution par le biais du web . -
Contributeur sécuritésalut lola ,s'agit il toujours de cette fenetre :http://img508.imageshack.us/img508/9879/fenetreintempestiveir3.jpg
-
Saut cgui ,salut jfk que ce passe-t-il pas de nouvelles depuis jeudi avons nous fini?
L'ordinateur n'a plus de problemes mis à part cette fenêtre qui s'ouvre toujours au
lancement d'internet dans la session de mon mari. -
Re
encore moi !
Pour JAVA, il y a une alerte de securer qui circule !
Lola si tu peux aller ici pour vérifier si tu es à jour !
Je suis sûr que non (t'inquiète pas moi non plus) car ils en sont à la version 6 Update 5 !
Rappel : Ne garde qu'une seule version sur ton PC.
A+-
-
-
@cgui33Si tu veux parler du comportement de mon PC, je dirais que depuis quelques jours c'est bien, là il est nickel. Pas de pub, plus de fenêtres, ni de comportement bizaroïde ! Mis à part que je ne reçois plus les posts par mail, alors que je coche la case en bas, mais ça depuis déjà 2 ou 3 jours, je ne comprends plus rien !!!
J'espère que nous avons bientôt fini. L'informatique, c'est pas trop mon truc, désolée !!!! En tout cas merci.
Bonsoir, et à demain.
-
-
Contributeur sécuritéBHO demon ?? connnais pas , tu as un lien ??
-
Alors voila j'ai fais ce que tu m'as dit et voici le rapport ComboFix je m'occupe desuite de l'Hijack :
ComboFix 08-03-05.3 - MARYLENE 2008-03-06 20:01:43.3 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6000.0.1252.1.1036.18.406 [GMT 1:00]
Endroit: C:\Users\MARYLENE\Desktop\ComboFix.exe
Command switches used :: C:\Users\MARYLENE\Desktop\CFScript.log
* Création d'un nouveau point de restauration
.
((((((((((((((((((((((((((((( Fichiers créés 2008-02-06 to 2008-03-06 ))))))))))))))))))))))))))))))))))))
.
Pas de nouveau fichier créé dans cet espace de temps
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-06 15:19 --------- d-----w C:\Users\TOMMY\AppData\Roaming\OpenOffice.org2
2008-03-06 15:19 --------- d-----w C:\Users\TOMMY\AppData\Roaming\AVG7
2008-03-06 09:14 --------- d-----w C:\ProgramData\Google Updater
2008-03-05 11:10 --------- d-----w C:\Program Files\Java
2008-03-05 11:09 --------- d-----w C:\Program Files\Common Files\Java
2008-03-05 11:01 --------- d-----w C:\ProgramData\Spybot - Search & Destroy
2008-03-05 09:35 --------- d-----w C:\Users\TOMMY\AppData\Roaming\LimeWire
2008-03-04 17:01 --------- d-----w C:\Program Files\Dofus
2008-03-02 15:42 --------- d-----w C:\Users\GIL\AppData\Roaming\OpenOffice.org2
2008-03-02 10:53 --------- d-----w C:\Users\GIL\AppData\Roaming\AVG7
2008-02-26 20:31 --------- d-----w C:\Program Files\CleanUp!
2008-02-25 20:50 --------- d-----w C:\Program Files\Navilog1
2008-02-23 17:41 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-02-23 09:10 --------- d-----w C:\Program Files\Common Files\Adobe
2008-02-22 14:00 --------- d-----w C:\Program Files\Norton Security Scan
2008-02-22 09:14 69,689 ----a-w C:\Windows\UNZIP.DLL
2008-02-22 09:14 507,904 ----a-w C:\Windows\TMUPDATE.DLL
2008-02-22 09:14 286,720 ----a-w C:\Windows\PATCH.EXE
2008-02-21 10:05 --------- d-----w C:\Program Files\Panda Security
2008-02-19 18:40 --------- d-----w C:\Program Files\CCleaner
2008-02-19 17:42 --------- d-----w C:\Program Files\Trend Micro
2008-02-18 18:49 --------- d-----w C:\Program Files\Lavasoft
2008-02-18 18:48 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-02-18 18:43 --------- d-----w C:\ProgramData\Lavasoft
2008-02-17 19:46 --------- d-----w C:\Program Files\FBrowserAdvisor
2008-02-17 19:36 --------- d-----w C:\Users\GIL\AppData\Roaming\LimeWire
2008-02-14 08:04 194,560 ----a-w C:\Windows\System32\WebClnt.dll
2008-02-14 08:04 110,080 ----a-w C:\Windows\system32\drivers\mrxdav.sys
2008-02-14 08:01 803,328 ----a-w C:\Windows\system32\drivers\tcpip.sys
2008-02-14 08:01 45,112 ----a-w C:\Windows\system32\drivers\pciidex.sys
2008-02-14 08:01 3,504,696 ----a-w C:\Windows\System32\ntkrnlpa.exe
2008-02-14 08:01 3,470,392 ----a-w C:\Windows\System32\ntoskrnl.exe
2008-02-14 08:01 24,064 ----a-w C:\Windows\System32\netcfg.exe
2008-02-14 08:01 22,016 ----a-w C:\Windows\System32\netiougc.exe
2008-02-14 08:01 216,632 ----a-w C:\Windows\system32\drivers\netio.sys
2008-02-14 08:01 21,560 ----a-w C:\Windows\system32\drivers\atapi.sys
2008-02-14 08:01 167,424 ----a-w C:\Windows\System32\tcpipcfg.dll
2008-02-14 08:01 154,624 ----a-w C:\Windows\system32\drivers\nwifi.sys
2008-02-14 08:01 15,928 ----a-w C:\Windows\system32\drivers\pciide.sys
2008-02-14 08:01 109,624 ----a-w C:\Windows\system32\drivers\ataport.sys
2008-02-14 08:00 537,600 ----a-w C:\Windows\AppPatch\AcLayers.dll
2008-02-14 08:00 449,536 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
2008-02-14 08:00 4,247,552 ----a-w C:\Windows\System32\GameUXLegacyGDFs.dll
2008-02-14 08:00 2,144,256 ----a-w C:\Windows\AppPatch\AcGenral.dll
2008-02-14 08:00 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
2008-02-14 08:00 1,686,528 ----a-w C:\Windows\System32\gameux.dll
2008-02-14 07:58 824,832 ----a-w C:\Windows\System32\wininet.dll
2008-02-14 07:58 56,320 ----a-w C:\Windows\System32\iesetup.dll
2008-02-14 07:58 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2008-02-14 07:58 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
2008-02-09 12:27 180 ----a-w C:\Users\GIL\AppData\Roaming\wklnhst.dat
2008-01-29 16:14 --------- d-----w C:\Program Files\LimeWire
2008-01-27 19:00 --------- d-----w C:\Users\TOMMY\AppData\Roaming\Corel
2008-01-25 12:56 --------- d-----w C:\Users\TOMMY\AppData\Roaming\Nvu
2008-01-25 12:56 --------- d-----w C:\Program Files\Nvu
2008-01-22 14:21 --------- d-----w C:\Users\GIL\AppData\Roaming\Corel
2008-01-22 14:12 --------- d-----w C:\Program Files\InstallShield Installation Information
2008-01-22 14:10 --------- d-----w C:\Program Files\Common Files\Corel
2008-01-22 14:09 --------- d-----w C:\Program Files\Corel
2008-01-22 14:05 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-01-10 05:50 1,244,672 ----a-w C:\Windows\System32\mcmde.dll
2008-01-09 09:14 --------- d-----w C:\Program Files\Windows Sidebar
2008-01-09 09:14 --------- d-----w C:\Program Files\Windows Mail
2008-01-09 09:01 211,000 ----a-w C:\Windows\system32\drivers\volsnap.sys
2008-01-09 09:01 1,060,920 ----a-w C:\Windows\system32\drivers\ntfs.sys
2008-01-09 09:00 11,776 ----a-w C:\Windows\System32\sbunattend.exe
2007-12-14 10:32 12,632 ----a-w C:\Windows\System32\lsdelete.exe
2007-12-13 07:29 9,728 ----a-w C:\Windows\System32\LAPRXY.DLL
2007-12-13 07:29 223,232 ----a-w C:\Windows\System32\WMASF.DLL
2007-12-13 07:29 1,327,104 ----a-w C:\Windows\System32\quartz.dll
2007-09-08 08:29 174 --sha-w C:\Program Files\desktop.ini
2007-11-24 11:02 168 --sh--r C:\Windows\System32\5F7BF6CE0E.sys
2007-11-24 11:02 3,764 --sha-w C:\Windows\System32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-09 10:00 1232896]
"IncrediMail"="C:\Program Files\IncrediMail\bin\IncMail.exe" [2007-08-21 10:44 208946]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 13:36 201728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-12-21 09:17 579072]
"NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-07-06 19:15 86016]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-07-06 19:15 8466432]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2007-07-06 19:15 81920]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-02-16 15:15 81920]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-10-25 12:24 219136]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Outil de mise … jour Google.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2007-09-08 15:38:58 126136]
C:\Users\MARYLENE\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\
wkcalrem.LNK - C:\Program Files\Common Files\microsoft shared\Works Shared\WkCalRem.exe [2005-08-19 06:14:28 21504]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgwlntf]
avgwlntf.dll 2007-09-08 09:07 9216 C:\Windows\System32\avgwlntf.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{3A4CC070-3EBE-487B-A0FF-45EDA3BC40D8}"= Disabled:UDP:C:\Users\MARYLENE\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KTGVXAXU\incredimail_install[1].exe:IncrediMail Installer
"{4C513806-F318-4BE4-9F1A-7235C75E80FA}"= Disabled:TCP:C:\Users\MARYLENE\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KTGVXAXU\incredimail_install[1].exe:IncrediMail Installer
"{DD6C55C9-E2AA-4B26-BD4A-23B79B4166A7}"= Disabled:UDP:C:\Users\MARYLENE\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VZOHF9KL\incredimail_install[1].exe:IncrediMail Installer
"{68119F36-BADA-4FC5-BB42-7C1BA65F48CB}"= Disabled:TCP:C:\Users\MARYLENE\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VZOHF9KL\incredimail_install[1].exe:IncrediMail Installer
"{AE260EA3-6410-4925-A142-CDFF5C06DEBA}"= Disabled:UDP:C:\Program Files\IncrediMail\bin\ImpCnt.exe:IncrediMail
"{115928D3-9437-431F-A240-CE0C94C88CCC}"= Disabled:TCP:C:\Program Files\IncrediMail\bin\ImpCnt.exe:IncrediMail
"{895165A4-CCE7-43FF-870C-9800BD3787E4}"= UDP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{DB317B35-7C10-4507-BD88-F7AD6328EAA5}"= TCP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{91DDBE26-D5BF-4294-87B9-95D6CAE2B618}"= UDP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{9ADD85FC-7AA3-4621-9FE2-6BAA83E6AC75}"= TCP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{787E57E6-DBED-435D-BC3D-11944A8C9E1C}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)|Edge=TRUE|
"{D99B153E-0999-4A93-84F9-BBB05C5A8960}"= UDP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
"{AD5C173C-DC89-4A34-B590-F0FCD977126B}"= TCP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
"TCP Query User{D18D7B1F-5E4F-4EB7-A316-2DE528BB78F1}C:\escan\kavupd.exe"= UDP:C:\escan\kavupd.exe:kavupd|Desc=kavupd
"UDP Query User{1A9D65A8-79CA-4265-9C1F-A459F15CBFBE}C:\escan\kavupd.exe"= TCP:C:\escan\kavupd.exe:kavupd|Desc=kavupd
"{B2361EE9-7CD6-437A-BC3B-D85C38A4EF58}"= Disabled:UDP:C:\Program Files\IncrediMail\bin\IncMail.exe:IncrediMail
"{23E4C176-9AA0-431A-9D2C-E76B82156771}"= Disabled:TCP:C:\Program Files\IncrediMail\bin\IncMail.exe:IncrediMail
"{6F4E9A05-C268-4A1D-9C3F-71E736DF1D61}"= Disabled:UDP:C:\Program Files\IncrediMail\bin\ImApp.exe:IncrediMail
"{FBA6DCE8-7E31-47CB-9C2D-C3FC67D7E7CC}"= Disabled:TCP:C:\Program Files\IncrediMail\bin\ImApp.exe:IncrediMail
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
R3 AvgWFP;AVG7 Firewall Driver x86;C:\Windows\system32\Drivers\avgwfp.sys [2007-12-21 09:17]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a5772cd2-5dd9-11dc-a237-806e6f6e6963}]
\shell\AutoRun\command - E:\INTRO.EXE
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2008-02-22 16:17:59 C:\Windows\Tasks\Norton Security Scan.job"
- C:\Program Files\Norton Security Scan\Nss.exe
"2008-03-06 18:49:13 C:\Windows\Tasks\User_Feed_Synchronization-{B2923FDC-50D5-44F3-9889-8DA1630BEE98}.job"
??
????1\- C:\Windows\system32\msfeedssync.exe
"2008-03-06 15:19:08 C:\Windows\Tasks\User_Feed_Synchronization-{B430F359-4A87-447A-9FCA-12CBADE38FB4}.job"
- C:\Windows\system32\msfeedssync.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-06 20:04:23
Windows 6.0.6000 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
Temps d'accomplissement: 2008-03-06 20:05:11
ComboFix-quarantined-files.txt 2008-03-06 19:05:08
ComboFix2.txt 2008-02-28 20:50:50
ComboFix3.txt 2008-02-27 21:12:30
.
2008-03-05 07:14:00 --- E O F --- -
@lola 13Voila chose dite chose faite l'Hijack est là :
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:12:25, on 06/03/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16609)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Program Files\Grisoft\AVG7\avgcc.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\Common Files\microsoft shared\Works Shared\WkCalRem.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\PROGRA~1\INCRED~1\bin\IMApp.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\werfault.exe
C:\Windows\System32\mobsync.exe
C:\Windows\Explorer.exe
C:\Program Files\Internet Explorer\IEUser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\hijackthis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O13 - Gopher Prefix:
O15 - Trusted Zone: http://www.secuser.com
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
O16 - DPF: {512FC5A1-7DE1-43F1-BC0C-371622FCB409} (TotalScan Installer Class) - https://www.pandasecurity.com/en/homeusers/online-antivirus/?ref=activescan
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl-esd.sun.com/update/1.6.0/jinstall-6u5-windows-i586-jc.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,5244/mcfscan.cab
O20 - Winlogon Notify: avgwlntf - C:\Windows\SYSTEM32\avgwlntf.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG7 Resident Shield Service (AvgCoreSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\Program Files\Common Files\Protexis\License Service\PSIService.exe
-
-
-
Contributeur sécuritésalut a vous deux ,un peu occupé avec ma fille mais de retour !!
j'ai fait une faute pour le Cfscript de combofix ,on va le refaire comme ceci:
> Ferme tout tes navigateurs (donc copie ou imprime les instructions avant)
- Crée un nouveau document texte : clic droit de souris sur le bureau > Nouveau > Document Texte, et copie/colle dedans les lignes suivantes :
files::
C:\Program Files\BrowsingProgram\BrowsingProgram-1.dll
registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F8EACE56-0AF4-3AE3-6EF8-F8CC39675729}]
- Enregistre ce fichier sous le nom CFScript
- Fait un glisser/déposer de ce fichier CFScrïpt sur le fichier ComboFix.exe comme sur cette image. (Clique sur le fichier CFScript, maintient le doigt enfoncé et glisse la souris pour que l'icône du CFScript vienne recouvrir l'icône de Combofix. Relache la souris.) Combofix va démarrer.
- Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.
- Patiente le temps du scan.Le bureau va disparaître à plusieurs reprises: c'est normal!
- Ne touche à rien tant que le scan n'est pas terminé sinon le PC peut planter !
- Une fois le scan achevé, un rapport va s'afficher: poste son contenu.
Note : Si le fichier ne s'ouvre pas, il se trouve ici > C:\ComboFix.txt
ensuite reposte un hijack . -
Re
Pour le vérifier :
Désinstalles JAVA et relance un scan mcAfee
Supprime le répertoire JAVA :
Double-clique sur OTMoveIt.exe pour le lancer. (tu l'as déjà il me semble !)
Assure toi que la case "Unregister Dll's and Ocx's" soit bien cochée !!!
Copie le texte ci-dessous, et colle le dans le cadre de gauche de OTMoveIt nommé Paste List of Files/Folders to be moved.
C:\Users\Marylene\Appdata\Locallow\Sun\Java
Clique sur MoveIt! pour lancer la suppression.
Si OTMoveIt propose de redémarrer ton PC, accepte.
Lorsqu' un résultat apparaît dans le cadre Results, clique sur Exit.
Dans ta future réponse, envoie le rapport de OTMoveIt situé sur C:\_OTMoveIt\MovedFiles.
Le nom du rapport est la date de sa création.
Apparemment tu avais déjà le pb sur ton ancienne installation de VISTA :
C:\Windows.old\...\3\27007203-261a3020 Exploit-ByteVerify sur ton rapport McAfee
A+ -
Re
Donc tu as eu un message du style : file not found lorsque tu as tapé le dir ... après avoir désinstaller JAVA !?!?
Alors, si Oui (un prog ou ligne base de registre ... ou autre !? ) te remet ces saloperies car ce sont les mêmes !
Soit c'est normal (lors de la réinstallation de JAVA) ... ce qui m'étonnerait fort !
Va voir ici
J'espère que JFK va revenir(il est pas loin ... je crois)
A+ -
Salut
Tu peux me dire ce que tu as fait exactement (dans l'ordre)
Merci
A+ -
Salut
Ouais pas bon ... à ( \ ) près !
Bon j'attends une réponse de JFK !
Mais si personne ne te répond ce soir :
Désinstalles tes versions de JAVA (une normalement)
Ensuite : vérifie que le répertoire 3 n'existe plus (même commande qu'ici)
sauf que la réponse ne devrait pas être la même !
Réinstalles Java
Ensuite redémarre le PC et refais un scan McAfee
A+-
Salut cgui, !
Voici le scan McAfee, après manoeuvres.
C:\MSNFix\MSNFix\incl\Process.exe PrcViewer
C:\Program Files\Navilog1\Process.exe PrcViewer
C:\Program Files\Navilog1\reboot.exe Generic PUP.g
C:\Users\MARYLENE\...\6.0\3\27007203-261a3020 Exploit-ByteVerify
C:\Users\MARYLENE\...\6.0\53\76fb16b5-425de6b9 Exploit-ByteVerify
C:\Users\MARYLENE\Desktop\ComboFix.exe RemAdm-ProcLaunch!171
C:\Windows.old\...\Desktop\ComboFix.exe RemAdm-ProcLaunch!171
C:\Windows.old\...\3\27007203-261a3020 Exploit-ByteVerify
C:\Windows.old\...\53\76fb16b5-425de6b9 Exploit-ByteVerify
C:\Windows.old\...\Desktop\ComboFix.exe RemAdm-ProcLaunch!171
C:\Windows.old\Users\...\Desktop\ComboFix.exe RemAdm-ProcLaunch!171
C:\Windows.old\Users\...\Desktop\ComboFix.exe RemAdm-ProcLaunch!171
C:\Windows.old\Users\...\Desktop\ComboFix.exe RemAdm-ProcLaunch!171
-
-
Re
Fais démarrer--> exécuter
tape cmd (+ entrée)
Dans la fenêtre qui va s'ouvrir :
Tape : CD C:\ (+ entrée)
Ensuite tape : Dir 3 /S (+ entrée)
Tu devrais voir apparaitre le chemin complet, mais je suis presque sûr que ce sera :
C:\Users\Marylene\Appdata\...\Sun\Java\Deployment\Cache\6.0\3
Sous Vista, je ne sais pas ce qu'il y a entre les deux !
A+ (mardi soir)-
-
@cgui33Salut !
Tu avais presque tout bon à 1 ficher près !
C:\Users\Marylene\Appdata\Locallow\Sun\Java\Deployment\Cache\6.3
Pour le \3 je ne l'ai pas vu mais je ne pouvais pas décaler la fenêtre !!
En plus j'en ai marre ça fait 4 fois que je poste ce truc et ça n'arrive jamais sur le forum !! vive l'informatique (quand ça marche ) !!!!!
-
-
Re
Dans l'explorateur :
Outils --> Options des dossiers --> Affichage
Décocher : Cacher les extensions dont le type est connu
Fichiers et dossiers cachés
sélectionner : Afficher le fichiers et dossiers cachés
Décocher : Masquer les fichiers protégés du système d'exploitation
Tu devrais le trouver avec ça !
A+
PS : Fais la manip inverse après !-
Désolée, mais il est absolument impossible de mettre la main sur ces fichiers, même en suivant la manip de cgui. J'ai même tapé "C:\Users\MARYLENE", il m'a sorti tous les fichiers et j'ai cherché un par un, NEANT; même mon fils qui est assez fort et qui m'aide ne l'a pas trouvé. Comment ça se fait ?
-
@lola13Si vous avez une autre idée, je prends. En attendant , je me couche , je chercherai demain. Bonne soirée et bonne nuit !
-
-
Contributeur sécuritéeffectivement je voudrais bien avoir le chemin complet égalment.
-
-
@lola13Salut !
Tu avais presque tout bon à 1 ficher près !
C:\Users\Marylene\Appdata\Locallow\Sun\Java\Deployment\Cache\6.3
Pour le \3 je ne l'ai pas vu mais je ne pouvais pas décaler la fenêtre !!
En plus j'en ai marre ça fait 4 fois que je poste ce truc et ça n'arrive jamais sur le form !! vive l'informatique (quand ça marche ) !!!!!
-
-
Salut lola
Ces lignes me semblent dangereuses :
C:\Users\MARYLENE\...\6.0\3\27007203-261a3020 Exploit-ByteVerify
C:\Users\MARYLENE\...\6.0\53\76fb16b5-425de6b9 Exploit-ByteVerify
Attends la confirmation de JFK !
Si tu pouvais nous donner le chemin complet, ce serait bien !
A+ -
Re
Désolé je me suis planté !
Tu peux le faire avec McAffe free scan ?
Merci
A demain-
Salut jfk et cgui
Désolée d'avoir été aussi longue mais j'ai eu un souci. Que des bugs, et tout refaire chaque fois; et comme le scan dure environ 2h30 ou 3h, vous imaginez !! Bref, j'ai fini par y arriver !!! OUF !!
C:\$Recycle.Bin\...\$RDMQR9B.zip PrcViewer
C:\MSNFix\MSNFix\incl\Process.exe PrcViewer
C:\Program Files\Navilog1\Process.exe PrcViewer
C:\Program Files\Navilog1\reboot.exe Generic PUP.g
C:\Users\MARYLENE\...\Desktop\ComboFix.exe RemAdm-ProcLaunch!171
C:\Users\MARYLENE\...\6.0\3\27007203-261a3020 Exploit-ByteVerify
C:\Users\MARYLENE\...\6.0\53\76fb16b5-425de6b9 Exploit-ByteVerify
C:\Users\MARYLENE\Desktop\ComboFix.exe RemAdm-ProcLaunch!171
C:\Windows.old\...\Desktop\ComboFix.exe RemAdm-ProcLaunch!171
C:\Windows.old\...\3\27007203-261a3020 Exploit-ByteVerify
C:\Windows.old\...\53\76fb16b5-425de6b9 Exploit-ByteVerify
C:\Windows.old\...\Desktop\ComboFix.exe RemAdm-ProcLaunch!171
C:\Windows.old\Users\...\Desktop\ComboFix.exe RemAdm-ProcLaunch!171
C:\Windows.old\Users\...\Desktop\ComboFix.exe RemAdm-ProcLaunch!171
C:\Windows.old\Users\...\Desktop\ComboFix.exe RemAdm-ProcLaunch!171
-
-
Salut lola
Comment va la jambe ?
Peux tu aller refaire un scan Panda pour nous donner un rapport comme celui-ci
Merci
A+-
Salut cgui,
La jambe ne va pas trop mal, je te remercie.
C'est tout ce que j'ai pu tirer du rapport du scan PANDA; Il n'y a pas de détail, je ne peux pas avoir de véritable rapport, et je ne peut même pas désinfecter , car il faut s'abonner.
Je te dis bonne fin de soirée. A plus;
ANALYSIS: 2008-02-29 23:18:57
PROTECTIONS: 1
MALWARE: 7
SUSPECTS: 0
;***********************************************************************************************************************************************************************************
PROTECTIONS
Description Version Active Updated
;===================================================================================================================================================================================
AVG 7.5.516 7.5.516 Yes Yes
;===================================================================================================================================================================================
MALWARE
Id Description Type Active Severity Disinfectable Disinfected Location
;===================================================================================================================================================================================
00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No C:\Users\MARYLENE\AppData\Roaming\Microsoft\Windows\Cookies\marylene@doubleclick[1].txt
00145405 Cookie/RealMedia TrackingCookie No 0 Yes No C:\Users\MARYLENE\AppData\Roaming\Microsoft\Windows\Cookies\marylene@247realmedia[1].txt
00167704 Cookie/Xiti TrackingCookie No 0 Yes No C:\Users\MARYLENE\AppData\Roaming\Microsoft\Windows\Cookies\marylene@xiti[1].txt
00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Users\MARYLENE\AppData\Roaming\Microsoft\Windows\Cookies\marylene@advertising[2].txt
00173520 Cookie/Bluestreak TrackingCookie No 0 Yes No C:\Users\MARYLENE\AppData\Roaming\Microsoft\Windows\Cookies\marylene@bluestreak[2].txt
00273339 Cookie/Smartadserver TrackingCookie No 0 Yes No C:\Users\MARYLENE\AppData\Roaming\Microsoft\Windows\Cookies\marylene@smartadserver[2].txt
01262593 Application/NirCmd.A HackTools No 0 Yes No C:\Windows\Nircmd.exe
;===================================================================================================================================================================================
SUSPECTS
Location
;==============================================================================================================================================================il faut s'abonner .
-
-
Contributeur sécuritémet toi sur la session de ton mari et poste moi un hijack .
-
Voila l'Hijack de la session de mon mari:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:59:16, on 29/02/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16609)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Grisoft\AVG7\avgcc.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\System32\rundll32.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\wbem\unsecapp.exe
c:\program files\common files\installshield\updateservice\isuspm.exe
C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Menu Démarrer\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Menu Démarrer\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Menu Démarrer\Spybot - Search & Destroy\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
O16 - DPF: {512FC5A1-7DE1-43F1-BC0C-371622FCB409} (TotalScan Installer Class) - https://www.pandasecurity.com/en/homeusers/online-antivirus/?ref=activescan
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,5234/mcfscan.cab
O20 - Winlogon Notify: avgwlntf - C:\Windows\SYSTEM32\avgwlntf.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG7 Resident Shield Service (AvgCoreSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\Program Files\Common Files\Protexis\License Service\PSIService.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Menu Démarrer\Spybot - Search & Destroy\SDWinSec.exe
-
- 1
- 2
- 3
- 4
- 5
- 6
- 7