Ordinateur infécté

Résolu
Bonjour,

mon ordinateur est infécté d'un virus qui ouvre des pages internet change mon écran de bureau ( j'ai été dans propriété du bureau ce n'est pas dans longlet web ) et je ne peux pas ouvrir le gestionaire des taches un msg derreur me dis que ladministrateur a désactivé le programme et quand je lance la désinféction avc navilog1 il met Supréssion des fichier et la ligne d'en dessou c'est accès refusé ...

mon anti virus c'est celui d'orange il ne trouve que un spyware de temps en temps
Configuration: Windows XP
Internet Explorer 7.0

63 réponses

Résumé de la discussion

Une infection sur Windows XP et Internet Explorer 7 provoque le détournement de la page d'accueil, des redirections Internet et des messages d'erreur, accompagnés d'un antivirus parfois inactif. Plusieurs éléments pointent vers un hijacker comme cause et recommandent HijackThis pour repérer les entrées indésirables, rétablir les options Internet et examiner le fichier Hosts afin de restaurer la navigation. En cas d'infection persistante, les conseils évoquent de vérifier le pare-feu qui peut bloquer les modifications, d'utiliser un antispyware à jour et, si nécessaire, d'opter pour un navigateur différent. Des détails supplémentaires expliquent qu'un hijacker comme CoolWebSearch peut modifier le fichier hosts et empêcher l'accès à certains outils de sécurité, rendant la suppression plus complexe et nécessitant des mesures ciblées.

Bobot (l’IA à votre service)
  1. Salut ,
    Désinfection par étape :
    Télécharger HijackThis V2.02 sur cette page : http://www.commentcamarche.net/telecharger/telecharger 159 hijackthis

    Utilisation :
    L'installer dans un dossier prévu à cet effet.
    Par exemple, C:\HijackThis
    Choisis l'option "do a system scan and save a logfile"; un rapport va être généré…

    Tutoriel d'utilisation, section "Générer un rapport" ici : http://pageperso.aol.fr/balltrap34/demohijack.htm
    (Merci à balltrap34 pour cette réalisation)
    @+
    0
    1. Contributeur
      Est ce que tu a un anti spyware du style spybot search and destroy ou spyware terminator ??
      0
      1. nop sir c'est l'anti virus de orange qui soccupe des rootkit et des spyware
        0
        1. Salut ,
          HijackThis est un outil capable de traquer les hijackers présents sur votre PC. Ces modifications non sollicitées ont différents effets comme par exemple le détournement de la page d'accueil d'Internet Explorer, l'insertion d'un composant dans la barre du navigateur ou encore le détournement d'adresse IP via le fichier Hosts. Le programme liste les différents endroits où sont susceptibles de se cacher des hijackers et vous permet ainsi de supprimer les entrées suspectes. Malheureusement, l’interprétation de ces listes (ou logs) n’est pas chose aisée et bien souvent l’utilisateur ne sait si tel ou tel élément doit être supprimé.
          C'est quoi "hijacker" ?
          Un hijacker modifie les réglages de votre navigateur par l'intermédiaire d'une page web piégée par un contrôle ActiveX ou un Javascript par exemple. C'est, entre autres, parce qu'il est le plus populaire (et aussi le plus vulnérable aux failles de sécurité) que Internet Explorer est le plus souvent victime de hijackers. Des navigateurs comme Firefox sont très rarement hijackés.
          Plus concrètement, si lors de votre navigation vous tombez sur une telle page, les effets peuvent être variés : modification de votre page de démarrage, de votre page de recherche, de votre liste de favoris... Le but recherché est de vous forcer à passer par certains sites. Des webmasters peu scupuleux ont recours à ce genre de procédés pour gonfler le nombre de visites sur leur site afin de vendre des espaces de publicité plus cher sur leurs pages.

          Bien que particulièrement agaçant, cela peut paraître anodin et en théorie on peut arranger ça facilement en rétablissant ses options internet dans Internet Explorer, mais les créateurs de hijackers ne manquent pas de ressources pour vous en empêcher et les attaques se limitent rarement à un simple changement de paramètres.
          Le hijacker peut tout simplement rendre inaccessible les options internet de Internet Explorer en installant à votre insu un Browser Helper Object (BHO) qui se lancera donc en même temps que Internet Explorer. Il peut également modifier la liste de démarrage afin d'être lancé automatiquement et restauré à chaque démarrage. Si, pour avoir la paix, vous avez mis certains sites dans votre liste de hosts ou dans la liste des sites sensibles, sachez que certains hijackers sont capables de modifier ces listes ainsi que la liste des sites de confiance. L'accès à ces sites n'est alors plus du tout contrôlé.
          Enfin, on imagine aisément les risques induits par un hijacker qui vous redirige vers une page web elle-même piégée par des programmes bien plus agressifs...

          La mise à jour régulière de Windows et l'utilisation d'un autre navigateur que Internet Explorer devraient permettre d'éviter ce genre de mésaventure. En cas d'infection, généralement un bon antivirus et/ou un bon antispyware à jour devraient vous en débarrasser. Cependant, certains hijackers s'accrochent et il est nécessaire d'avoir recours à des méthodes plus spécifiques pour les éradiquer.

          UN HIJACKER PARTICULIEREMENT TENACE : COOLWEBSEARCH

          CoolWebSearch est un nom générique regroupant plusieurs hijackers, parfois très différents, mais qui ont la particularité de rediriger l'internaute vers le site coolwebsearch.com ou vers des sites affiliés. On a jugé nécessaire d'en parler plus particulièrement car certains hijackers de cette famille sont particulièrement tenaces et très difficiles à éradiquer.

          Mode de contamination et mesures de prévention
          Ces hijackers s'installent en exploitant des failles de sécurité dans la machine virtuelle Java de Microsoft. Ces failles sont corrigées depuis pas mal de temps et si vous maintenez régluièrement votre système à jour avec Windows Update, vous n'y êtes plus vulnérable.
          Une méthode plus radicale consiste aussi à remplacer la machine virtuelle Java de Microsoft par celle de Sun qui est beaucoup plus sûre en terme de sécurité.

          Effets
          Les effets des hijackers estampillés CoolWebSearch sont assez divers et souvent assez problématiques. On ne peut pas tous les lister ici, on notera cependant que certaines variantes qui piratent la liste hosts en profitent pour vous bloquer l'accès à plusieurs sites de sécurité informatique et d'éditeurs de logiciels de sécurité afin de vous empêcher de télécharger les logiciels nécessaires à la désinfection de votre système. Certains vous empêchent même d'ouvrir votre anti-spyware ou anti-trojan préféré !

          @+
          0
          1. Voila les logs

            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 21:18:45, on 03/07/2008
            Platform: Windows XP SP2 (WinNT 5.01.2600)
            MSIE: Internet Explorer v7.00 (7.00.6000.16674)
            Boot mode: Normal

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\Ati2evxx.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
            C:\PROGRA~1\ANTIVI~1\backweb\6588780\Program\SERVIC~1.EXE
            C:\Program Files\Bonjour\mDNSResponder.exe
            C:\WINDOWS\system32\CTSvcCDA.EXE
            C:\WINDOWS\eHome\ehRecvr.exe
            C:\WINDOWS\eHome\ehSched.exe
            C:\Program Files\AntivirusFirewall\Anti-Virus\fsgk32st.exe
            C:\Program Files\AntivirusFirewall\backweb\6588780\program\fsbwsys.exe
            C:\Program Files\AntivirusFirewall\Anti-Virus\FSGK32.EXE
            C:\Program Files\AntivirusFirewall\Common\FSMA32.EXE
            C:\Program Files\AntivirusFirewall\Anti-Virus\fssm32.exe
            C:\Program Files\AntivirusFirewall\Common\FSMB32.EXE
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\AntivirusFirewall\Common\FCH32.EXE
            C:\WINDOWS\system32\MsPMSPSv.exe
            C:\Program Files\AntivirusFirewall\Common\FAMEH32.EXE
            C:\Program Files\AntivirusFirewall\Anti-Virus\fsqh.exe
            C:\Program Files\AntivirusFirewall\Anti-Virus\fsrw.exe
            C:\WINDOWS\system32\dllhost.exe
            C:\Program Files\AntivirusFirewall\FWES\Program\fsdfwd.exe
            C:\Program Files\AntivirusFirewall\Anti-Virus\fsav32.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\Ati2evxx.exe
            C:\WINDOWS\Explorer.EXE
            C:\WINDOWS\system32\ctfmon.exe
            C:\WINDOWS\ehome\ehtray.exe
            C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
            C:\windows\system\hpsysdrv.exe
            C:\WINDOWS\system32\hphmon06.exe
            C:\HP\KBD\KBD.EXE
            C:\WINDOWS\eHome\ehmsas.exe
            C:\WINDOWS\system32\keyhook.exe
            C:\WINDOWS\system32\CTHELPER.EXE
            C:\WINDOWS\AGRSMMSG.exe
            C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
            C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDet.EXE
            C:\Program Files\AntivirusFirewall\Common\FSM32.EXE
            C:\Program Files\AntivirusFirewall\FSGUI\ispnews.exe
            C:\PROGRA~1\ANTIVI~1\ANTI-S~1\fsaw.exe
            C:\Program Files\Creative\Creative Live! Cam\VideoFX\StartFX.exe
            C:\WINDOWS\V0220Mon.exe
            C:\WINDOWS\system32\rundll32.exe
            C:\Program Files\Creative\Creative Live! Cam\Live! Cam Manager\CTLCMgr.exe
            C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
            C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
            C:\WINDOWS\system32\rundll32.exe
            C:\Program Files\AntivirusFirewall\FSGUI\fsguidll.exe
            C:\Program Files\AntivirusFirewall\backweb\6588780\Program\fspex.exe
            C:\Program Files\Palm\Hotsync.exe
            C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
            C:\Program Files\Sony Corporation\Image Transfer\SonyTray.exe
            C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
            C:\Program Files\Logitech\SetPoint\SetPoint.exe
            C:\Program Files\Fichiers communs\Logitech\khalshared\KHALMNPR.EXE
            C:\HijackThis\HijackThis.exe
            C:\Program Files\Internet Explorer\iexplore.exe
            C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe

            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=Q404&bd=pavilion&pf=desktop
            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=Q404&bd=pavilion&pf=desktop
            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://c:/windows/homepage.html
            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = file://c:/windows/homepage.html
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = file://c:/windows/homepage.html
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = file://c:/windows/homepage.html
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=Q404&bd=pavilion&pf=desktop
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://c:/windows/homepage.html
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = file://c:/windows/homepage.html
            R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
            O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
            O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
            O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
            O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
            O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
            O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
            O2 - BHO: Microsoft copyright - {FFFFFFFF-BBBB-4146-86FD-A722E8AB3489} - sockins32.dll (file missing)
            O3 - Toolbar: Vue HP - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
            O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
            O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
            O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
            O4 - HKLM\..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
            O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
            O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
            O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
            O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
            O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\system32\keyhook.exe
            O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
            O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
            O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
            O4 - HKLM\..\Run: [CTDVDDET] C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDet.EXE
            O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
            O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\AntivirusFirewall\Common\FSM32.EXE" /splash
            O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\AntivirusFirewall\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
            O4 - HKLM\..\Run: [F-Secure Startup Wizard] "C:\Program Files\AntivirusFirewall\FSGUI\FSSW.EXE" /reboot
            O4 - HKLM\..\Run: [News Service] "C:\Program Files\AntivirusFirewall\FSGUI\ispnews.exe"
            O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
            O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
            O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
            O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
            O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
            O4 - HKLM\..\Run: [AVFX Engine] C:\Program Files\Creative\Creative Live! Cam\VideoFX\StartFX.exe
            O4 - HKLM\..\Run: [V0220Mon.exe] C:\WINDOWS\V0220Mon.exe
            O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
            O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
            O4 - HKLM\..\Run: [iTunesHelper] "L:\Program Files\iTunes\iTunesHelper.exe"
            O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
            O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
            O4 - HKCU\..\Run: [Creative Live! Cam Manager] "C:\Program Files\Creative\Creative Live! Cam\Live! Cam Manager\CTLCMgr.exe"
            O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
            O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
            O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
            O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
            O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
            O4 - HKUS\S-1-5-18\..\RunOnce: [SetDefaultMIDI] MIDIDEF.EXE (User 'SYSTEM')
            O4 - HKUS\.DEFAULT\..\RunOnce: [SetDefaultMIDI] MIDIDEF.EXE (User 'Default user')
            O4 - Global Startup: Antivirus Firewall.lnk = C:\Program Files\AntivirusFirewall\backweb\6588780\Program\fspex.exe
            O4 - Global Startup: HOTSYNCSHORTCUTNAME.lnk = C:\Program Files\Palm\Hotsync.exe
            O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
            O4 - Global Startup: Image Transfer.lnk = ?
            O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
            O4 - Global Startup: Logitech SetPoint.lnk = ?
            O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
            O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
            O8 - Extra context menu item: &Bloquer cette fenêtre publicitaire - C:\Program Files\AntivirusFirewall\Anti-Spyware\blockpopups.htm
            O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
            O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
            O9 - Extra button: Protection Internet Explorer - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\AntivirusFirewall\Anti-Spyware\ieshield.dll
            O9 - Extra 'Tools' menuitem: Protection Internet Explorer... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\AntivirusFirewall\Anti-Spyware\ieshield.dll
            O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab
            O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
            O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://mbouguereau.spaces.live.com/PhotoUpload/MsnPUpld.cab
            O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
            O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
            O16 - DPF: {EDFCB7CB-942C-4822-AF14-F0B687409848} (Image Uploader Control) - http://photoservice.photos.orange.fr/telechargement/ImageUploader4.cab
            O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
            O21 - SSODL: WebProxy - {66186F05-BBBB-4a39-864F-72D84615C679} - sockins32.dll (file missing)
            O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
            O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
            O23 - Service: Antivirus Firewall (BackWeb Plug-in - 6588780) - Securitoo Portal - C:\PROGRA~1\ANTIVI~1\backweb\6588780\Program\SERVIC~1.EXE
            O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
            O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTSvcCDA.EXE
            O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program Files\AntivirusFirewall\Anti-Virus\fsgk32st.exe
            O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\AntivirusFirewall\backweb\6588780\program\fsbwsys.exe
            O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\AntivirusFirewall\FWES\Program\fsdfwd.exe
            O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\AntivirusFirewall\Common\FSMA32.EXE
            O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
            O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
            O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
            0
            1. ( c'est fou tout ce qu'on apprend sur moi avec ce rapport... )
              0
              1. Contributeur
                O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1

                Oulà :s
                0
                1. a ce point la je fais quoi maintenant ?
                  0
                  1. Contributeur
                    1 min et j'arrive :)
                    0
                    1. okay merci de ton aide =)
                      0
                      1. Contributeur
                        Bon jvais manger je re après dsl je crève la dalle
                        0
                        1. bonne appétit ( sa devien un t'chat xD )
                          0
                          1. Contributeur
                            Mdr oui un peut

                            alors tu lance hijackthis et "do a system scan only" et tu cochera "O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1 " puis "Fix checked"

                            Ensuite tu reposte un log HJT
                            0
                            1. voila le deuxieme fichier de log

                              Logfile of Trend Micro HijackThis v2.0.2
                              Scan saved at 21:53:46, on 03/07/2008
                              Platform: Windows XP SP2 (WinNT 5.01.2600)
                              MSIE: Internet Explorer v7.00 (7.00.6000.16674)
                              Boot mode: Normal

                              Running processes:
                              C:\WINDOWS\System32\smss.exe
                              C:\WINDOWS\system32\winlogon.exe
                              C:\WINDOWS\system32\services.exe
                              C:\WINDOWS\system32\lsass.exe
                              C:\WINDOWS\system32\Ati2evxx.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\WINDOWS\system32\spoolsv.exe
                              C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                              C:\PROGRA~1\ANTIVI~1\backweb\6588780\Program\SERVIC~1.EXE
                              C:\Program Files\Bonjour\mDNSResponder.exe
                              C:\WINDOWS\system32\CTSvcCDA.EXE
                              C:\WINDOWS\eHome\ehRecvr.exe
                              C:\WINDOWS\eHome\ehSched.exe
                              C:\Program Files\AntivirusFirewall\Anti-Virus\fsgk32st.exe
                              C:\Program Files\AntivirusFirewall\backweb\6588780\program\fsbwsys.exe
                              C:\Program Files\AntivirusFirewall\Anti-Virus\FSGK32.EXE
                              C:\Program Files\AntivirusFirewall\Common\FSMA32.EXE
                              C:\Program Files\AntivirusFirewall\Anti-Virus\fssm32.exe
                              C:\Program Files\AntivirusFirewall\Common\FSMB32.EXE
                              C:\WINDOWS\system32\svchost.exe
                              C:\Program Files\AntivirusFirewall\Common\FCH32.EXE
                              C:\WINDOWS\system32\MsPMSPSv.exe
                              C:\Program Files\AntivirusFirewall\Common\FAMEH32.EXE
                              C:\Program Files\AntivirusFirewall\Anti-Virus\fsqh.exe
                              C:\Program Files\AntivirusFirewall\Anti-Virus\fsrw.exe
                              C:\WINDOWS\system32\dllhost.exe
                              C:\Program Files\AntivirusFirewall\FWES\Program\fsdfwd.exe
                              C:\Program Files\AntivirusFirewall\Anti-Virus\fsav32.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\WINDOWS\system32\Ati2evxx.exe
                              C:\WINDOWS\Explorer.EXE
                              C:\WINDOWS\system32\ctfmon.exe
                              C:\WINDOWS\ehome\ehtray.exe
                              C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
                              C:\windows\system\hpsysdrv.exe
                              C:\WINDOWS\system32\hphmon06.exe
                              C:\HP\KBD\KBD.EXE
                              C:\WINDOWS\eHome\ehmsas.exe
                              C:\WINDOWS\system32\keyhook.exe
                              C:\WINDOWS\system32\CTHELPER.EXE
                              C:\WINDOWS\AGRSMMSG.exe
                              C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                              C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDet.EXE
                              C:\Program Files\AntivirusFirewall\Common\FSM32.EXE
                              C:\Program Files\AntivirusFirewall\FSGUI\ispnews.exe
                              C:\PROGRA~1\ANTIVI~1\ANTI-S~1\fsaw.exe
                              C:\Program Files\Creative\Creative Live! Cam\VideoFX\StartFX.exe
                              C:\WINDOWS\V0220Mon.exe
                              C:\WINDOWS\system32\rundll32.exe
                              C:\Program Files\Creative\Creative Live! Cam\Live! Cam Manager\CTLCMgr.exe
                              C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
                              C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                              C:\WINDOWS\system32\rundll32.exe
                              C:\Program Files\AntivirusFirewall\FSGUI\fsguidll.exe
                              C:\Program Files\AntivirusFirewall\backweb\6588780\Program\fspex.exe
                              C:\Program Files\Palm\Hotsync.exe
                              C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                              C:\Program Files\Sony Corporation\Image Transfer\SonyTray.exe
                              C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
                              C:\Program Files\Logitech\SetPoint\SetPoint.exe
                              C:\Program Files\Fichiers communs\Logitech\khalshared\KHALMNPR.EXE
                              C:\Program Files\Internet Explorer\iexplore.exe
                              C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
                              C:\Program Files\Windows Live\Messenger\usnsvc.exe
                              C:\HijackThis\HijackThis.exe

                              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=Q404&bd=pavilion&pf=desktop
                              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=Q404&bd=pavilion&pf=desktop
                              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://c:/windows/homepage.html
                              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = file://c:/windows/homepage.html
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = file://c:/windows/homepage.html
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = file://c:/windows/homepage.html
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=Q404&bd=pavilion&pf=desktop
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://c:/windows/homepage.html
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = file://c:/windows/homepage.html
                              R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                              O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
                              O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                              O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                              O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                              O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
                              O2 - BHO: Microsoft copyright - {FFFFFFFF-BBBB-4146-86FD-A722E8AB3489} - sockins32.dll (file missing)
                              O3 - Toolbar: Vue HP - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
                              O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                              O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
                              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
                              O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
                              O4 - HKLM\..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
                              O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
                              O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
                              O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
                              O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
                              O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\system32\keyhook.exe
                              O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
                              O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
                              O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                              O4 - HKLM\..\Run: [CTDVDDET] C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDet.EXE
                              O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
                              O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\AntivirusFirewall\Common\FSM32.EXE" /splash
                              O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\AntivirusFirewall\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
                              O4 - HKLM\..\Run: [F-Secure Startup Wizard] "C:\Program Files\AntivirusFirewall\FSGUI\FSSW.EXE" /reboot
                              O4 - HKLM\..\Run: [News Service] "C:\Program Files\AntivirusFirewall\FSGUI\ispnews.exe"
                              O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
                              O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
                              O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
                              O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
                              O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
                              O4 - HKLM\..\Run: [AVFX Engine] C:\Program Files\Creative\Creative Live! Cam\VideoFX\StartFX.exe
                              O4 - HKLM\..\Run: [V0220Mon.exe] C:\WINDOWS\V0220Mon.exe
                              O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
                              O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                              O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
                              O4 - HKLM\..\Run: [iTunesHelper] "L:\Program Files\iTunes\iTunesHelper.exe"
                              O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
                              O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
                              O4 - HKCU\..\Run: [Creative Live! Cam Manager] "C:\Program Files\Creative\Creative Live! Cam\Live! Cam Manager\CTLCMgr.exe"
                              O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                              O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                              O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                              O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                              O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                              O4 - HKUS\S-1-5-18\..\RunOnce: [SetDefaultMIDI] MIDIDEF.EXE (User 'SYSTEM')
                              O4 - HKUS\.DEFAULT\..\RunOnce: [SetDefaultMIDI] MIDIDEF.EXE (User 'Default user')
                              O4 - Global Startup: Antivirus Firewall.lnk = C:\Program Files\AntivirusFirewall\backweb\6588780\Program\fspex.exe
                              O4 - Global Startup: HOTSYNCSHORTCUTNAME.lnk = C:\Program Files\Palm\Hotsync.exe
                              O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                              O4 - Global Startup: Image Transfer.lnk = ?
                              O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
                              O4 - Global Startup: Logitech SetPoint.lnk = ?
                              O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
                              O8 - Extra context menu item: &Bloquer cette fenêtre publicitaire - C:\Program Files\AntivirusFirewall\Anti-Spyware\blockpopups.htm
                              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                              O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                              O9 - Extra button: Protection Internet Explorer - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\AntivirusFirewall\Anti-Spyware\ieshield.dll
                              O9 - Extra 'Tools' menuitem: Protection Internet Explorer... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\AntivirusFirewall\Anti-Spyware\ieshield.dll
                              O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                              O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                              O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab
                              O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
                              O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://mbouguereau.spaces.live.com/PhotoUpload/MsnPUpld.cab
                              O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
                              O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                              O16 - DPF: {EDFCB7CB-942C-4822-AF14-F0B687409848} (Image Uploader Control) - http://photoservice.photos.orange.fr/telechargement/ImageUploader4.cab
                              O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
                              O21 - SSODL: WebProxy - {66186F05-BBBB-4a39-864F-72D84615C679} - sockins32.dll (file missing)
                              O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                              O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
                              O23 - Service: Antivirus Firewall (BackWeb Plug-in - 6588780) - Securitoo Portal - C:\PROGRA~1\ANTIVI~1\backweb\6588780\Program\SERVIC~1.EXE
                              O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                              O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTSvcCDA.EXE
                              O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program Files\AntivirusFirewall\Anti-Virus\fsgk32st.exe
                              O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\AntivirusFirewall\backweb\6588780\program\fsbwsys.exe
                              O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\AntivirusFirewall\FWES\Program\fsdfwd.exe
                              O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\AntivirusFirewall\Common\FSMA32.EXE
                              O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                              O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                              0
                              1. Contributeur
                                Je re dans un instant...
                                0
                                1. ok jdois mfaire une reserve de cafeine pour tenir tout la nuit ? lol =x
                                  0
                                  1. Contributeur
                                    bon ya un truc plus sérieux... Tu as un antivirus ?
                                    0
                                    1. anti virus firewall orange mis a jour j'ai fais une analyse il a juste détécté un spyware ...
                                      0
                                      1. et voila jvoulais juste un bon vien jeux : boulder dash =°(
                                        0
                                        • 1
                                        • 2
                                        • 3
                                        • 4