Salut a tous depuis 2 jur j´ai continuellemnt de alertes de virus et des fenetre de pub qui s´ouvre lorsque je suis sur le net. J´ai donc intallé Spyware doctor de google mais, cela n´a fait qu´empirer!!! Donc j´ai fait une recherche sur ce site et plus particulièrement sur ce post
https://www.jeuxvideo.com/forums/1-1-11035230-1-0-1-0-0.htm
Dnc après avoir fait le test j´ai eu ce rapport
- CCleaner
http://www.ccleaner.com/download/builds/downloading-basic
Ce logiciel va permettre de supprimer tous les fichiers temporaires. Lance-le et clique sur "Options", "Avancé" et décoche la case "Effacer uniquement les fichiers, du dossier Temp de Windows, plus vieux que 48 heures". Par la suite, laisse-le avec ses réglages par défaut. Ferme le programme.
- VundoFix.exe (par Atribune)
http://www.atribune.org/ccount/click.php?id=4 sur ton Bureau
- combofix.exe (par [b]sUBs[/b])
http://download.bleepingccomputer.com/sUBs/ComboFix.exe sur ton Bureau
https://www.microsoft.com/technet/prodtechnol/windowsserver2003/fr/library/ServerHelp/e14bf84d-d2f7-42c3-9fae-2af3db3f806c.mspx?mfr=true (choisis ta session courante "ROLLAND") *****
Clique sur le bouton Scan for Vundo
Lorsque le scan est complété, clique sur le bouton "Remove Vundo"
Une invite te demandera si tu veux supprimer les fichiers, clique YES
Après avoir cliqué Yes, le Bureau disparaîtra un moment lors de la suppression des fichiers
Tu verras une invite qui t´annonce que ton PC va redémarrer; clique OK
Note: Il est possible que VundoFix soit confronté à un fichier qu´il ne peut supprimer. Si tel est le cas, l´outil se lancera au prochain redémarrage; il faut simplement suivre les instructions ci-haut, à partir de "clique sur le bouton Scan for Vundo
Tape sur la touche Y (Yes) pour démarrer le scan.
Lorsque le scan sera complété, un rapport apparaîtra
Lance CCleaner : "Nettoyeur"/"lancer le nettoyage" et c´est tout.
Redémarre normalement et poste :
- Un nouveau rapport HijackThis, toutes fenêtres et applications fermées
http://www.trendsecure.com/portal/en-US/threat_analytics/HiJackThis.exe ;
- Le contenu du rapport situé dans C:\vundofix.txt ;
- Le contenu du rapport situé dans C:\Combofix.txt ;
Précise les difficultés que tu as eu (ce que tu n´as pas pu faire...) ainsi que l´évolution de la situation.
Je voulais savoi si ce truc est fiable ou si il y a une solution parce que sa commence éellement a me soulé....
Plz i need help
Salut,
Pourquoi n´as tu pas continuer sur ton ancien poste ? Suis la procédure indiqué par GenProc.
Ah non excuse moi d´avoir mal compris, ce n´était pas le tiens.
oui lol. pPar contre je n´ai pas compis quand il y a écrit
https://www.microsoft.com[...]f806c.mspx?mfr=true (choisis ta session courante "ROLLAND") *****
Sa ve dire que je dois cpier quoi dans le fichier de texte
C´est pour conserver la procédure, de toute façon elle est déjà sauvegarder dans un fichier texte à la racine du disque dur. Enfin bref n´y fais pas attention.
bon j´ai redemaré l´ordi en mode sans echec. Mais le pb c´est que lorsque je clic sur la session qque j´utilise abituellement; et qui a les droits d´administrateur; un écran noir avec au 4 coin écrit mode sans échec s´ouvre et en haut j´ai les ref de mon windows XP SP2 et c´est tout....
Comment dois-je faire pour pouvooir utilisé les deux application svp
Salut
"un écran noir avec au 4 coin écrit mode sans échec s´ouvre et en haut j´ai les ref de mon windows XP SP2 et c´est tout...."
c´est normal !
Mais de quelles applications tu parles?
nan c´est bon j´ai réussi les application étaient vundofix et combofix. Donc j´ai tous suivis et maintenat je dois aller où pour savoir si sa a réelement marché?????
Pour savoir si ça a réellement marché il me faut les rapports ... ils sont demandés à la fin, regarde bien ![]()
a ok je te les post ici alors
Sa c´est celui de combofix (par contre c´est normal que avast m´est mis une alerte au tout début quand j´ai exécuté combofix comme quoi il y avait un virus dans le dossier de combofix??
ComboFix 07-08-30.3 - "ROLLAND" 2007-08-31 21:31:00.1 - NTFSx86
Microsoft Windows XP dition familiale 5.1.2600.2.1252.1.1036.18.1480 [GMT 2:00]
* Created a new restore point
((((((((((((((((((((((((((((((((((((((( Other Deletions
)))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\bpluonor.exe
C:\WINDOWS\system32\dgawvulh.exe
C:\WINDOWS\system32\efbrixsb.exe
C:\WINDOWS\system32\fyhnmpht.exe
C:\WINDOWS\system32\hjkkj.bak1
C:\WINDOWS\system32\hjkkj.ini2
C:\WINDOWS\system32\hjkkj.tmp
C:\WINDOWS\system32\mpkkiwwy.exe
C:\WINDOWS\system32\omavqtno.exe
C:\WINDOWS\system32\opnmnop.dll
C:\WINDOWS\system32\qomjkli.dll
C:\WINDOWS\system32\qomkigg.dll
C:\WINDOWS\system32\qywyqbmi.exe
C:\WINDOWS\system32\rpfqyvcg.exe
C:\WINDOWS\system32\syskxjtt.exe
C:\WINDOWS\system32\vmbbxymv.exe
((((((((((((((((((((((((((((((((((((((( Drivers/Services
)))))))))))))))))))))))))))))))))))))))))))))))))
-------\LEGACY_DOMAINSERVICE
-------\DomainService
-------\nm
((((((((((((((((((((((((( Files Created from 2007-07-28 to 2007-08-31 )))))))))))))))))))))))))))))))
2007-08-31 21:28 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-08-31 21:13 <REP> d-------- C:\VundoFix Backups
2007-08-31 21:01 <REP> dr------- C:\DOCUME~1\ADMINI~1\Menu D‚marrer
2007-08-31
21:01 <REP> d--h----- C:\DOCUME~1\ADMINI~1\Voisina
ge r‚seau
2007-08-31
21:01 <REP> d--h----- C:\DOCUME~1\ADMINI~1\Voisina
ge d´impression
2007-08-31
21:01 <REP> d--h----- C:\DOCUME~1\ADMINI~1\ModŠles
2007-08-31 21:01 <REP> d-------- C:\DOCUME~1\ADMINI~1\Mes documents
2007-08-31
21:01 <REP> d-------- C:\DOCUME~1\ADMINI~1\Favoris
2007-08-31
21:01 <REP> d-------- C:\DOCUME~1\ADMINI~1\Bureau
2007-08-31 20:14 <REP> d-------- C:\Program Files\CCleaner
2007-08-31
18:12 <REP> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~
1\Test Drive Unlimited
2007-08-31 17:39 <REP> d-------- C:\Program Files\Atari
2007-08-30 22:55 <REP> d-------- C:\Program Files\Electronic Arts
2007-08-30 22:54 <REP> d-------- C:\WINDOWS\system32\AGEIA
2007-08-30 22:54 <REP> d-------- C:\Program Files\AGEIA Technologies
2007-08-30 22:53 <REP> d-------- C:\Program Files\Fichiers communs\Wise Installation Wizard
2007-08-30
15:41 <REP> dr-h----- C:\DOCUME~1\ROLLAND\APPLIC~1
\SecuROM
2007-08-30
15:39 443,752 --a------ C:\WINDOWS\system32\d3dx10
_34.dll
2007-08-30
15:39 3,497,832 --a------ C:\WINDOWS\system32\d3dx
9_34.dll
2007-08-30
15:39 266,088 --a------ C:\WINDOWS\system32\xacten
gine2_8.dll
2007-08-30
15:39 18,280 --a------ C:\WINDOWS\system32\x3daudi
o1_2.dll
2007-08-30
15:39 1,124,720 --a------ C:\WINDOWS\system32\D3DC
ompiler_34.dll
2007-08-30 15:32 <REP> d-------- C:\Program Files\2K Games
2007-08-30 15:12 <REP> d-------- C:\mini image
2007-08-30 15:04 <REP> d-------- C:\Bioshock
2007-08-30 12:54 <REP> d-------- C:\Program Files\DAEMON Tools
2007-08-30
10:36 685,816 --a------ C:\WINDOWS\system32\driver
s\sptd.sys
2007-08-29 21:59 <REP> d-------- C:\Program Files\Real Alternative
2007-08-29 21:59 <REP> d-------- C:\Program Files\Media Player Classic
2007-08-29
21:59 <REP> d-------- C:\DOCUME~1\ROLLAND\APPLIC~1
\Real
2007-08-29
21:59 <REP> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~
1\Real
2007-08-29
21:55 765,952 --a------ C:\WINDOWS\system32\xvidco
re.dll
2007-08-29
21:55 163,840 --a------ C:\WINDOWS\system32\unrar.
dll
2007-08-29 21:55 <REP> d-------- C:\Program Files\K-Lite Codec Pack
2007-08-29
20:59 <REP> d-------- C:\DOCUME~1\ROLLAND\APPLIC~1
\Media Player Classic
2007-08-29
09:38 82,248 --a------ C:\WINDOWS\system32\drivers
\iksyssec.sys
2007-08-29
09:38 626,688 --a------ C:\WINDOWS\system32\msvcr8
0.dll
2007-08-29
09:38 57,672 --a------ C:\WINDOWS\system32\drivers
\iksysflt.sys
2007-08-29
09:38 40,264 --a------ C:\WINDOWS\system32\drivers
\ikfilesec.sys
2007-08-29
09:38 29,000 --a------ C:\WINDOWS\system32\drivers
\kcom.sys
2007-08-29 09:38 <REP> d-------- C:\Program Files\Spyware Doctor
2007-08-29
09:38 <REP> d-------- C:\DOCUME~1\ROLLAND\APPLIC~1
\PC Tools
2007-08-29
08:23 8 --a------ C:\WINDOWS\system32\15da95f9.dat
2007-08-29
00:58 <REP> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~
1\Azureus
2007-08-28 20:15 <REP> d-------- C:\WINDOWS\WNBackup
2007-08-28
19:19 21,840 --a------ C:\WINDOWS\system32\SIntfNT
.dll
2007-08-28
19:19 17,212 --a------ C:\WINDOWS\system32\SIntf32
.dll
2007-08-28
19:19 12,067 --a------ C:\WINDOWS\system32\SIntf16
.dll
2007-08-28 19:17 <REP> d-------- C:\Sierra
2007-08-27 18:20 <REP> d-------- C:\APPS
2007-08-26 23:36 <REP> d-------- C:\Program Files\directx
2007-08-26 23:24 <REP> d-------- C:\Program Files\Ubi Soft
2007-08-26
22:47 <REP> d-------- C:\WINDOWS\048298C9A4D3490B9
FF9AB023A9238F3.TMP
2007-08-26 19:08 531 --a------ C:\WINDOWS\eReg.dat
2007-08-26 16:35 86,016 --a------ C:\WINDOWS\unvise32qt.exe
2007-08-26
16:35 <REP> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~
1\QuickTime
2007-08-26 16:33 <REP> d-------- C:\Program Files\Maris Technologies
2007-08-26
16:14 <REP> d-------- C:\DOCUME~1\ROLLAND\APPLIC~1
\InstallShield
2007-08-26
12:12 <REP> d-------- C:\WINDOWS\system32\URTTEMP
2007-08-25
22:51 66,872 --a------ C:\WINDOWS\system32\PnkBstr
A.exe
2007-08-25
22:51 22,328 --a------ C:\WINDOWS\system32\drivers
\PnkBstrK.sys
2007-08-25
22:51 103,736 --a------ C:\WINDOWS\system32\PnkBst
rB.exe
2007-08-25 14:28 61 ---hs---- C:\WINDOWS\cnerolf.bin
2007-08-24
21:50 271,224 --a------ C:\WINDOWS\system32\mucltu
i.dll
2007-08-24
21:50 207,736 --a------ C:\WINDOWS\system32\muweb.
dll
2007-08-24 21:43 <REP> d-------- C:\Program Files\Microsoft Works
2007-08-24 21:42 <REP> d-------- C:\Program Files\Microsoft.NET
2007-08-24 21:39 <REP> d-------- C:\Program Files\Microsoft Visual Studio 8
2007-08-24
21:38 <REP> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~
1\Microsoft Help
2007-08-24 21:37 <REP> dr-h----- C:\MSOCache
2007-08-24
15:44 <REP> d-------- C:\DOCUME~1\ROLLAND\APPLIC~1
\Bioshock
2007-08-22 23:03 <REP> d-------- C:\Program Files\Dofus
2007-08-21 00:07 <REP> d-------- C:\Program Files\Alt WAV MP3 WMA OGG Converter
2007-08-21
00:04 22,528 --a------ C:\WINDOWS\system32\WNASPI3
2.DLL
2007-08-21
00:04 16,512 --a------ C:\WINDOWS\system32\drivers
\ASPI32.SYS
2007-08-20 20:25 <REP> d-------- C:\Program Files\Anuman Interactive
2007-08-19 13:45 <REP> d-------- C:\Program Files\THQ
2007-08-18
12:54 27,904 --a------ C:\WINDOWS\system32\drivers
\xPADFL02.sys
2007-08-18 12:54 <REP> d-------- C:\Program Files\SixaxisDriver
2007-08-18
12:49 46,592 --a------ C:\WINDOWS\system32\libusb0
.dll
2007-08-18
12:49 33,792 --a------ C:\WINDOWS\system32\drivers
\libusb0.sys
2007-08-18
06:11 221,184 --a------ C:\WINDOWS\system32\wmpns.
dll
2007-08-01
11:50 <REP> d-------- C:\DOCUME~1\ROLLAND\APPLIC~1
\gtopala
2007-08-01 11:38 <REP> d-------- C:\Program Files\SiSoftware
2007-08-01 11:35 <REP> d--h----- C:\WINDOWS\PIF
2007-08-01 11:35 <REP> d-------- C:\Program Files\AIDA32 - Enterprise System Information
2007-08-01 00:28 <REP> d-------- C:\WINDOWS\Google Toolbar
2007-07-28
05:37 8,237,056 --a------ C:\WINDOWS\system32\atio
glx2.dll
2007-07-28
05:06 176,128 --a------ C:\WINDOWS\system32\atiok3
x2.dll
2007-07-28
05:01 972,072 --a------ C:\WINDOWS\system32\ativva
6x.dat
2007-07-28
05:01 3,107,788 --a------ C:\WINDOWS\system32\ativ
va5x.dat
2007-07-02
14:46 442,368 -ra------ C:\WINDOWS\system32\vp6vfw
.dll
2007-07-01 19:25 <REP> d-------- C:\Program Files\UltraStar
(((((((((((((((((((((((((((((((((((((((( Find3M Report
))))))))))))))))))))))))))))))))))))))))))))))))))
))
2007-08-31 21:39 --------- d-------- C:\Program Files\Wanadoo
2007-08-30 21:29 --------- d-------- C:\Program Files\Steam
2007-08-30 15:32 --------- d--h----- C:\Program Files\InstallShield Installation Information
2007-08-30
13:07 2855 --a------ C:\WINDOWS\pif\BSAutoRun.PIF
2007-08-29 11:28 --------- d-------- C:\Program Files\Google
2007-08-29 09:07 --------- d-------- C:\Program Files\eMule
2007-08-29 08:29 --------- d-------- C:\Program Files\Azureus
2007-08-29
08:22 --------- d-------- C:\DOCUME~1\ROLLAND\APPL
IC~1\Azureus
2007-08-26 22:42 --------- d-------- C:\Program Files\ATI Technologies
2007-08-26
22:36 --------- d-------- C:\DOCUME~1\ROLLAND\APPL
IC~1\ATI
2007-08-26 19:03 --------- d-------- C:\Program Files\EA GAMES
2007-08-25 20:23 --------- d-------- C:\Program Files\ASUS
2007-08-24 21:43 --------- d-------- C:\Program Files\MSBuild
2007-08-24
14:58 --------- d-------- C:\DOCUME~1\ROLLAND\APPL
IC~1\Google
2007-08-21
10:46 359808 --a------ C:\WINDOWS\system32\drivers
\TCPIP.SYS
2007-08-18
21:59 --------- d-------- C:\DOCUME~1\ALLUSE~1\APP
LIC~1\BOONTY
2007-08-02
16:04 --------- d-------- C:\DOCUME~1\ROLLAND\APPL
IC~1\AdobeUM
2007-07-30
22:52 359808 --a------ C:\WINDOWS\system32\drivers
\TCPIP.SYS.ORIGINAL
2007-07-30
19:19 92504 --a------ C:\WINDOWS\system32\cdm.dll
2007-07-30
19:19 549720 --a------ C:\WINDOWS\system32\wuapi.d
ll
2007-07-30
19:19 53080 --a------ C:\WINDOWS\system32\wuauclt.
exe
2007-07-30
19:19 43352 --a------ C:\WINDOWS\system32\wups2.dl
l
2007-07-30
19:19 325976 --a------ C:\WINDOWS\system32\wucltui
.dll
2007-07-30
19:19 203096 --a------ C:\WINDOWS\system32\wuweb.d
ll
2007-07-30
19:19 1712984 --a------ C:\WINDOWS\system32\wuauen
g.dll
2007-07-30
19:18 33624 --a------ C:\WINDOWS\system32\wups.dll
2007-07-28
07:44 45296 --a------ C:\WINDOWS\system32\drivers\
ativvpxx.vp
2007-07-28
05:31 344064 --a------ C:\WINDOWS\system32\ATIDEMG
X.dll
2007-07-28
05:30 269312 --a------ C:\WINDOWS\system32\ati2dva
g.dll
2007-07-28
05:30 2371584 --a------ C:\WINDOWS\system32\driver
s\ati2mtag.sys
2007-07-28
05:24 307200 --a------ C:\WINDOWS\system32\atiiiex
x.dll
2007-07-28
05:23 143360 --a------ C:\WINDOWS\system32\atipdlx
x.dll
2007-07-28
05:23 122880 --a------ C:\WINDOWS\system32\Oemdspi
f.dll
2007-07-28
05:22 43520 --a------ C:\WINDOWS\system32\ati2edxx
.dll
2007-07-28
05:22 26112 --a------ C:\WINDOWS\system32\Ati2mdxx
.exe
2007-07-28
05:22 118784 --a------ C:\WINDOWS\system32\ati2evx
x.dll
2007-07-28
05:21 483328 --a------ C:\WINDOWS\system32\ati2evx
x.exe
2007-07-28
05:20 53248 --a------ C:\WINDOWS\system32\ATIDDC.D
LL
2007-07-28
05:12 3067712 --a------ C:\WINDOWS\system32\ati3du
ag.dll
2007-07-28
05:01 1550208 --a------ C:\WINDOWS\system32\ativva
xx.dll
2007-07-28
04:50 5435392 --a------ C:\WINDOWS\system32\atiogl
xx.dll
2007-07-28
04:47 266240 --a------ C:\WINDOWS\system32\atikvma
g.dll
2007-07-28
04:46 17408 --a------ C:\WINDOWS\system32\atitvo32
.dll
2007-07-28
04:45 49152 --a------ C:\WINDOWS\system32\drivers\
ati2erec.dll
2007-07-28
04:40 450560 --a------ C:\WINDOWS\system32\ati2cqa
g.dll
2007-07-28
00:07 783224 --a------ C:\WINDOWS\system32\aswBoot
.exe
2007-07-28
00:02 94416 --a------ C:\WINDOWS\system32\drivers\
aswmon2.sys
2007-07-28
00:02 92848 --a------ C:\WINDOWS\system32\drivers\
aswmon.sys
2007-07-28
00:00 23152 --a------ C:\WINDOWS\system32\drivers\
aswRdr.sys
2007-07-27
23:59 42912 --a------ C:\WINDOWS\system32\drivers\
aswTdi.sys
2007-07-27
23:58 26624 --a------ C:\WINDOWS\system32\drivers\
aavmker4.sys
2007-07-27
23:57 95608 --a------ C:\WINDOWS\system32\AvastSS.
scr
2007-07-27
21:05 593920 --------- C:\WINDOWS\system32\ati2sga
g.exe
2007-07-01 01:43 --------- d-------- C:\Program Files\DivX
2007-06-30
20:15 --------- d-------- C:\DOCUME~1\ROLLAND\APPL
IC~1\dvdcss
2007-06-29
22:52 --------- d-------- C:\DOCUME~1\ROLLAND\APPL
IC~1\DivX
2007-06-28
21:02 --------- d-------- C:\DOCUME~1\ALLUSE~1\APP
LIC~1\DVD Shrink
2007-06-28
20:21 108144 --a------ C:\WINDOWS\system32\CmdLine
Ext.dll
2007-06-26
08:09 1104896 --a------ C:\WINDOWS\system32\msxml3
.dll
2007-06-19
15:32 282112 --a------ C:\WINDOWS\system32\gdi32.d
ll
2007-06-19
08:59 70400 --a------ C:\WINDOWS\system32\PhysXLoa
der.dll
2007-06-18
12:07 64885 --a--c--- C:\WINDOWS\BricoPackUninst.c
md
2007-06-18
12:07 5804 --a--c--- C:\WINDOWS\BricoPackFoldersDe
lete.cmd
2007-06-13 15:22 1037312 --a------ C:\WINDOWS\explorer.exe
2007-05-31
08:45 524288 --a------ C:\WINDOWS\system32\DivXsm.
exe
2007-05-31
08:44 823296 --a------ C:\WINDOWS\system32\divx_xx
0c.dll
2007-05-31
08:44 823296 --a------ C:\WINDOWS\system32\divx_xx
07.dll
2007-05-31
08:44 802816 --a------ C:\WINDOWS\system32\divx_xx
11.dll
2007-05-31
08:44 740442 --a------ C:\WINDOWS\system32\DivX.dl
l
2006-06-23
08:48 32768 -ra--c--- C:\WINDOWS\inf\UpdateUSB.exe
2005-05-13 15:12:00 217,073 --sha-r C:\WINDOWS\meta4.exe
2005-10-24 09:13:58 66,560 --sha-r C:\WINDOWS\MOTA113.exe
2005-10-13 19:27:00 422,400 --sha-r C:\WINDOWS\x2.64.exe
2005-10-07
17:14:52 308,224 --sha-r C:\WINDOWS\system32\avisy
nth.dll
2005-07-14
10:31:20 27,648 --sha-r C:\WINDOWS\system32\AVSred
irect.dll
2005-06-26
13:32:28 616,448 --sha-r C:\WINDOWS\system32\cygwi
n1.dll
2005-06-21
20:37:42 45,568 --sha-r C:\WINDOWS\system32\cygz.d
ll
2004-01-24
22:00:00 70,656 --sha-r C:\WINDOWS\system32\i420vf
w.dll
2006-04-27
08:24:24 2,945,024 --sha-r C:\WINDOWS\system32\Sma
b.dll
2005-02-28
11:16:22 240,128 --sha-r C:\WINDOWS\system32\x.264
.exe
2004-01-24
22:00:00 70,656 --sha-r C:\WINDOWS\system32\yv12vf
w.dll
((((((((((((((((((((((((((((((((((((( Reg Loading Points
))))))))))))))))))))))))))))))))))))))))))))))))))
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{CC7848B0-A15E-4B08-AE1A-F51F255683C5}]
C:\WINDOWS\system32\jkkjh.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Cur
rentVersion\Run]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2006-05-01 12:07]
"SoundMAX"="C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" [2006-04-10 09:19]
"JMB36X Configure"="C:\WINDOWS\system32\JMRaidTool.exe" [2006-06-02 10:45]
"GameFace Messenger"="C:\Program Files\GameFace Messenger\GameFace.exe" []
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-05-10 11:12]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe"
[2007-07-28 00:03]
"Sony Ericsson PC Suite"="C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2005-10-26 17:17]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.e
xe" [2001-07-09 12:50]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2006-03-02 14:00 C:\WINDOWS\system32\bthprops.cpl]
"WOOWATCH"="C:\PROGRA~1\Wanadoo\Watch.exe" [2004-08-23 14:49]
"WOOTASKBARICON"="C:\PROGRA~1\Wanadoo\GestMaj.exe"
[2004-10-14 16:55]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]
"SDTray"="C:\Program Files\Spyware Doctor\SDTrayApp.exe" [2007-08-14 17:02]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curr
entVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2006-03-02 14:00]
"LDM"="C:\Program Files\Logitech\Desktop
Messenger\8876480\Program\LogitechDesktopMessenger
.exe" [2007-05-05 17:12]
"Steam"="" []
"NCLaunch"="C:\WINDOWS\NCLAUNCH.EXe" [2007-05-17 20:42]
"WOOKIT"="C:\PROGRA~1\Wanadoo\Shell.exe" [2004-08-23 14:50]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 12:55]
"swg"="C:\Program
Files\Google\GoogleToolbarNotifier\GoogleToolbarNo
tifier.exe" [2007-06-13 18:59]
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2007-08-16 13:24]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mll_hp32]
mll_hp32.dll 2004-06-14 13:56 8192 C:\WINDOWS\system32\mll_hp32.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contr
ol\SafeBoot\Minimal\sdauxservice"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contr
ol\SafeBoot\Minimal\sdcoreservice"
R0 JGOGO;JMicron Hot-Plug Driver;C:\WINDOWS\system32\DRIVERS\JGOGO.sys
R0
JRAID;JRAID;C:\WINDOWS\system32\DRIVERS\jraid.sys
R1 ISODrive;ISO DVD/CD-ROM Device Driver;\??\C:\Program Files\UltraISO\drivers\ISODrive.sys
R3 GcKernel;Pilote de filtre Microsoft SideWinder Value Add;C:\WINDOWS\system32\DRIVERS\GcKernel.sys
R3 HIDSwvd;Minipilote de périphérique Microsoft SideWinder HID virtuel;C:\WINDOWS\system32\DRIVERS\HIDSwvd.sys
R3 SenFiltService;SenFilt Service;C:\WINDOWS\system32\drivers\Senfilt.sys
R3 SWUSBFLT;Pilote de filtre Microsoft SideWinder VIA;C:\WINDOWS\system32\DRIVERS\SWUSBFLT.sys
S1 asusgsb;ASUS Virtual Video Capture Device Driver;C:\WINDOWS\system32\drivers\asusgsb32.sys
S3 A3AB;D-Link AirPro 802.11a/b Wireless Adapter
Service(A3AB);C:\WINDOWS\system32\DRIVERS\A3AB.sys
S3 ASPI;Advanced SCSI Programming Interface
Driver;\??\C:\WINDOWS\System32\DRIVERS\ASPI32.sys
S3 Boonty Games;Boonty Games;"C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe"
S3 libusb0;LibUsb-Win32 - Kernel Driver, Version 0.1.10.1;C:\WINDOWS\system32\drivers\libusb0.sys
S3 ovt519;Eye Toy;C:\WINDOWS\system32\Drivers\ov519vid.sys
S3 SANDRA;SANDRA;\??\C:\Program Files\SiSoftware\SiSoftware Sandra Lite XI.SP4a\Sandra.sys
S3 Video3D;ASUS Video3D
Service;C:\WINDOWS\system32\Drivers\Video3D32.sys
S3 XPADFL02;XPAD Filter Service 02;C:\WINDOWS\system32\DRIVERS\xpadfl02.sys
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-08-31 21:38:27
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
Completion time: 2007-08-31 21:40:13 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-08-31 21:40
--- E O F ---
ET de vundo j´ai eu sa
VundoFix V6.5.7
Checking Java version...
Scan started at 21:13:30 31/08/2007
Listing files found while scanning....
C:\WINDOWS\system32\hjkkj.bak1
C:\WINDOWS\system32\hjkkj.bak2
C:\WINDOWS\system32\hjkkj.ini
C:\WINDOWS\system32\hjkkj.ini2
C:\WINDOWS\system32\hjkkj.tmp
C:\WINDOWS\system32\jkkjh.dll
C:\windows\system32\vthiciko.exe
Beginning removal...
Attempting to delete C:\WINDOWS\system32\hjkkj.bak1
C:\WINDOWS\system32\hjkkj.bak1 Has been deleted!
Attempting to delete C:\WINDOWS\system32\hjkkj.bak2
C:\WINDOWS\system32\hjkkj.bak2 Has been deleted!
Attempting to delete C:\WINDOWS\system32\hjkkj.ini
C:\WINDOWS\system32\hjkkj.ini Has been deleted!
Attempting to delete C:\WINDOWS\system32\hjkkj.ini2
C:\WINDOWS\system32\hjkkj.ini2 Has been deleted!
Attempting to delete C:\WINDOWS\system32\hjkkj.tmp
C:\WINDOWS\system32\hjkkj.tmp Has been deleted!
Attempting to delete C:\WINDOWS\system32\jkkjh.dll
C:\WINDOWS\system32\jkkjh.dll Could not be deleted.
Attempting to delete C:\windows\system32\vthiciko.exe
C:\windows\system32\vthiciko.exe Has been deleted!
Performing Repairs to the registry.
Done!
Beginning removal...
Attempting to delete C:\WINDOWS\system32\hjkkj.ini
C:\WINDOWS\system32\hjkkj.ini Has been deleted!
Attempting to delete C:\WINDOWS\system32\jkkjh.dll
C:\WINDOWS\system32\jkkjh.dll Has been deleted!
Performing Repairs to the registry.
Done!
Oui c´est un faux positif ne t´inquiète pas, et Avast! ... ![]()
On va rectifier ça, mais pour le moment poste tout les rapports demandé !
Pour Hijackthis, télécharge le ici et fais ceci :
- Télécharge Hijackthis de Merjin puis dézippe le.
http://www.merijn.org/files/hijackthis.zip
- Mets-le dans un dossier nommé Hijackthis à la racine du disque dur (C:\Hijackthis\)
- Fais un clic-droit dessus (fichier avec l’image de Dynamite) et choisis "renommer", appelle-le scanner.exe (C:\Hijackthis\scanner.exe)
- Ferme toutes les fenêtres.
- Clique sur "Do a system scan only" puis sur "Save logfile".
- Copie/Colle le rapport demandé ici.
Désolé pour le retard EvilElf voici le rapport mais perso, je n´ai plus aucun problème ![]()
Logfile of HijackThis v1.99.1
Scan saved at 21:00:39, on 20/09/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\Desktop
Messenger\8876480\Program\LogitechDesktopMessenger
.exe
C:\WINDOWS\NCLAUNCH.EXe
C:\Program Files\Fichiers communs\Teleca Shared\CapabilityManager.exe
C:\Program
Files\Google\GoogleToolbarNotifier\GoogleToolbarNo
tifier.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
C:\PROGRA~1\Wanadoo\ComComp.exe
C:\Program Files\WIDCOMM\Logiciel Bluetooth\BTTray.exe
C:\PROGRA~1\Wanadoo\Toaster.exe
C:\PROGRA~1\Wanadoo\Inactivity.exe
C:\PROGRA~1\Wanadoo\PollingModule.exe
C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe
C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon Manager.exe
C:\WINDOWS\BricoPacks\Vista Inspirat 2\YzShadow\YzShadow.exe
C:\WINDOWS\ATKKBService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
C:\WINDOWS\System32\FTRTSVC.exe
C:\Program Files\Electronic Arts\Medal of Honor Airborne\UnrealEngine3\MOHAGame\pb\PnkBstrA.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Fichiers communs\Teleca Shared\Generic.exe
C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\eMule\eMule\emule.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Steam\steam.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Hijackthis\scanner.exe.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.orange.fr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program
Files\Google\GoogleToolbarNotifier\2.1.615.5858\sw
g.dll
O2 - BHO: (no name) - {CC7848B0-A15E-4B08-AE1A-F51F255683C5} - C:\WINDOWS\system32\jkkjh.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [JMB36X Configure] C:\WINDOWS\system32\JMRaidTool.exe boot
O4 - HKLM\..\Run: [GameFace Messenger] C:\Program Files\GameFace Messenger\GameFace.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop
Messenger\8876480\Program\LogitechDesktopMessenger
.exe
O4 - HKCU\..\Run: [NCLaunch] C:\WINDOWS\NCLAUNCH.EXe
O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program
Files\Google\GoogleToolbarNotifier\GoogleToolbarNo
tifier.exe
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: RocketDock.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe
O4 - Startup: TransBar.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\TransBar\TransBar.exe
O4 - Startup: UberIcon.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon Manager.exe
O4 - Startup: Y´z Shadow.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\YzShadow\YzShadow.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xporter vers Microsoft Excel -
res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Envoyer à &Bluetooth - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie_ctx.htm
O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra ´Tools´ menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra ´Tools´ menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie.htm
O9 - Extra ´Tools´ menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra ´Tools´ menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} -
http://www.orange.fr (file missing) (HKCU)
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1177496966953
O18 - Protocol: bw+0 - {7F4D7790-B8C4-41DD-A9A3-BB2F0AF52D0D} - C:\Program Files\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.d
ll
O18 - Protocol: bw+0s - {7F4D7790-B8C4-41DD-A9A3-BB2F0AF52D0D} - C:\Program Files\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.d
ll
O18 - Protocol: bw-0 - {7F4D7790-B8C4-41DD-A9A3-BB2F0AF52D0D} - C:\Program Files\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.d
ll
O18 - Protocol: bw-0s - {7F4D7790-B8C4-41DD-A9A3-BB2F0AF52D0D} - C:\Program Files\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.d
ll
O18 - Protocol: bw00 - {7F4D7790-B8C4-41DD-A9A3-BB2F0AF52D0D} - C:\Program Files\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.d
ll
O18 - Protocol: bw00s - {7F4D7790-B8C4-41DD-A9A3-BB2F0AF52D0D} - C:\Program Files\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.d
ll
O18 - Protocol: bw10 - {7F4D7790-B8C4-41DD-A9A3-BB2F0AF52D0D} - C:\Program Files\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.d
ll
O18 - Protocol: bw10s - {7F4D7790-B8C4-41DD-A9A3-BB2F0AF52D0D} - C:\Program Files\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.d
ll
O18 - Protocol: bw20 - {7F4D7790-B8C4-41DD-A9A3-BB2F0AF52D0D} - C:\Program Files\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.d
ll
O18 - Protocol: bw20s - {7F4D7790-B8C4-41DD-A9A3-BB2F0AF52D0D} - C:\Program Files\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.d
ll
O18 - Protocol: bw30 - {7F4D7790-B8C4-41DD-A9A3-BB2F0AF52D0D} - C:\Program Files\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.d
ll
O18 - Protocol: bw30s - {7F4D7790-B8C4-41DD-A9A3-BB2F0AF52D0D} - C:\Program Files\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.d
ll
O18 - Protocol: bw40 - {7F4D7790-B8C4-41DD-A9A3-BB2F0AF52D0D} - C:\Program Files\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.d
ll
O18 - Protocol: bw40s - {7F4D7790-B8C4-41DD-A9A3-BB2F0AF52D0D} - C:\Program Files\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.d
ll
O18 - Protocol: bw50 - {7F4D7790-B8C4-41DD-A9A3-BB2F0AF52D0D} - C:\Program Files\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.d
ll
O18 - Protocol: bw50s - {7F4D7790-B8C4-41DD-A9A3-BB2F0AF52D0D} - C:\Program Files\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.d
ll
O18 - Protocol: bw60 - {7F4D7790-B8C4-41DD-A9A3-BB2F0AF52D0D} - C:\Program Files\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.d
ll
O18 - Protocol: bw60s - {7F4D7790-B8C4-41DD-A9A3-BB2F0AF52D0D} - C:\Program Files\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.d
ll
O18 - Protocol: bw70 - {7F4D7790-B8C4-41DD-A9A3-BB2F0AF52D0D} - C:\Program Files\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.d
ll
O18 - Protocol: bw70s - {7F4D7790-B8C4-41DD-A9A3-BB2F0AF52D0D} - C:\Program Files\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.d
ll
O18 - Protocol: bw80 - {7F4D7790-B8C4-41DD-A9A3-BB2F0AF52D0D} - C:\Program Files\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.d
ll
O18 - Protocol: bw80s - {7F4D7790-B8C4-41DD-A9A3-BB2F0AF52D0D} - C:\Program Files\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.d
ll
O18 - Protocol: bw90 - {7F4D7790-B8C4-41DD-A9A3-BB2F0AF52D0D} - C:\Program Files\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.d
ll
O18 - Protocol: bw90s - {7F4D7790-B8C4-41DD-A9A3-BB2F0AF52D0D} - C:\Program Files\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.d
ll
O18 - Protocol: bwa0 - {7F4D7790-B8C4-41DD-A9A3-BB2F0AF52D0D} - C:\Program Files\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.d
ll
O18 - Protocol: bwa0s - {7F4D7790-B8C4-41DD-A9A3-BB2F0AF52D0D} - C:\Program Files\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.d
ll
O18 - Protocol: bwb0 - {7F4D7790-B8C4-41DD-A9A3-BB2F0AF52D0D} - C:\Program Files\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.d
ll
O18 - Protocol: bwb0s - {7F4D7790-B8C4-41DD-A9A3-BB2F0AF52D0D} - C:\Program Files\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.d
ll
O18 - Protocol: bwc0 - {7F4D7790-B8C4-41DD-A9A3-BB2F0AF52D0D} - C:\Program Files\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.d
ll
O18 - Protocol: bwc0s - {7F4D7790-B8C4-41DD-A9A3-BB2F0AF52D0D} - C:\Program Files\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.d
ll
O18 - Protocol: bwd0 - {7F4D7790-B8C4-41DD-A9A3-BB2F0AF52D0D} - C:\Program Files\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.d
ll
O18 - Protocol: bwd0s - {7F4D7790-B8C4-41DD-A9A3-BB2F0AF52D0D} - C:\Program Files\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.d
ll
O18 - Protocol: bwe0 - {7F4D7790-B8C4-41DD-A9A3-BB2F0AF52D0D} - C:\Program Files\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.d
ll
O18 - Protocol: bwe0s - {7F4D7790-B8C4-41DD-A9A3-BB2F0AF52D0D} - C:\Program Files\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.d
ll
O18 - Protocol: bwf0 - {7F4D7790-B8C4-41DD-A9A3-BB2F0AF52D0D} - C:\Program Files\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.d
ll
O18 - Protocol: bwf0s - {7F4D7790-B8C4-41DD-A9A3-BB2F0AF52D0D} - C:\Program Files\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.d
ll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop
Messenger\8876480\Program\GAPlugProtocol-8876480.d
ll
O18 - Protocol: bwg0 - {7F4D7790-B8C4-41DD-A9A3-BB2F0AF52D0D} - C:\Program Files\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.d
ll
O18 - Protocol: bwg0s - {7F4D7790-B8C4-41DD-A9A3-BB2F0AF52D0D} - C:\Program Files\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.d
ll
O18 - Protocol: bwh0 - {7F4D7790-B8C4-41DD-A9A3-BB2F0AF52D0D} - C:\Program Files\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.d
ll
O18 - Protocol: bwh0s - {7F4D7790-B8C4-41DD-A9A3-BB2F0AF52D0D} - C:\Program Files\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.d
ll
O18 - Protocol: bwi0 - {7F4D7790-B8C4-41DD-A9A3-BB2F0AF52D0D} - C:\Program Files\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.d
ll
O18 - Protocol: bwi0s - {7F4D7790-B8C4-41DD-A9A3-BB2F0AF52D0D} - C:\Program Files\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.d
ll
O18 - Protocol: bwj0 - {7F4D7790-B8C4-41DD-A9A3-BB2F0AF52D0D} - C:\Program Files\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.d
ll
O18 - Protocol: bwj0s - {7F4D7790-B8C4-41DD-A9A3-BB2F0AF52D0D} - C:\Program Files\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.d
ll
O18 - Protocol: bwk0 - {7F4D7790-B8C4-41DD-A9A3-BB2F0AF52D0D} - C:\Program Files\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.d
ll
O18 - Protocol: bwk0s - {7F4D7790-B8C4-41DD-A9A3-BB2F0AF52D0D} - C:\Program Files\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.d
ll
O18 - Protocol: bwl0 - {7F4D7790-B8C4-41DD-A9A3-BB2F0AF52D0D} - C:\Program Files\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.d
ll
O18 - Protocol: bwl0s - {7F4D7790-B8C4-41DD-A9A3-BB2F0AF52D0D} - C:\Program Files\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.d
ll
O18 - Protocol: bwm0 - {7F4D7790-B8C4-41DD-A9A3-BB2F0AF52D0D} - C:\Program Files\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.d
ll
O18 - Protocol: bwm0s - {7F4D7790-B8C4-41DD-A9A3-BB2F0AF52D0D} - C:\Program Files\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.d
ll
O18 - Protocol: bwn0 - {7F4D7790-B8C4-41DD-A9A3-BB2F0AF52D0D} - C:\Program Files\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.d
ll
O18 - Protocol: bwn0s - {7F4D7790-B8C4-41DD-A9A3-BB2F0AF52D0D} - C:\Program Files\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.d
ll
O18 - Protocol: bwo0 - {7F4D7790-B8C4-41DD-A9A3-BB2F0AF52D0D} - C:\Program Files\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.d
ll
O18 - Protocol: bwo0s - {7F4D7790-B8C4-41DD-A9A3-BB2F0AF52D0D} - C:\Program Files\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.d
ll
O18 - Protocol: bwp0 - {7F4D7790-B8C4-41DD-A9A3-BB2F0AF52D0D} - C:\Program Files\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.d
ll
O18 - Protocol: bwp0s - {7F4D7790-B8C4-41DD-A9A3-BB2F0AF52D0D} - C:\Program Files\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.d
ll
O18 - Protocol: bwq0 - {7F4D7790-B8C4-41DD-A9A3-BB2F0AF52D0D} - C:\Program Files\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.d
ll
O18 - Protocol: bwq0s - {7F4D7790-B8C4-41DD-A9A3-BB2F0AF52D0D} - C:\Program Files\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.d
ll
O18 - Protocol: bwr0 - {7F4D7790-B8C4-41DD-A9A3-BB2F0AF52D0D} - C:\Program Files\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.d
ll
O18 - Protocol: bwr0s - {7F4D7790-B8C4-41DD-A9A3-BB2F0AF52D0D} - C:\Program Files\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.d
ll
O18 - Protocol: bws0 - {7F4D7790-B8C4-41DD-A9A3-BB2F0AF52D0D} - C:\Program Files\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.d
ll
O18 - Protocol: bws0s - {7F4D7790-B8C4-41DD-A9A3-BB2F0AF52D0D} - C:\Program Files\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.d
ll
O18 - Protocol: bwt0 - {7F4D7790-B8C4-41DD-A9A3-BB2F0AF52D0D} - C:\Program Files\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.d
ll
O18 - Protocol: bwt0s - {7F4D7790-B8C4-41DD-A9A3-BB2F0AF52D0D} - C:\Program Files\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.d
ll
O18 - Protocol: bwu0 - {7F4D7790-B8C4-41DD-A9A3-BB2F0AF52D0D} - C:\Program Files\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.d
ll
O18 - Protocol: bwu0s - {7F4D7790-B8C4-41DD-A9A3-BB2F0AF52D0D} - C:\Program Files\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.d
ll
O18 - Protocol: bwv0 - {7F4D7790-B8C4-41DD-A9A3-BB2F0AF52D0D} - C:\Program Files\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.d
ll
O18 - Protocol: bwv0s - {7F4D7790-B8C4-41DD-A9A3-BB2F0AF52D0D} - C:\Program Files\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.d
ll
O18 - Protocol: bww0 - {7F4D7790-B8C4-41DD-A9A3-BB2F0AF52D0D} - C:\Program Files\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.d
ll
O18 - Protocol: bww0s - {7F4D7790-B8C4-41DD-A9A3-BB2F0AF52D0D} - C:\Program Files\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.d
ll
O18 - Protocol: bwx0 - {7F4D7790-B8C4-41DD-A9A3-BB2F0AF52D0D} - C:\Program Files\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.d
ll
O18 - Protocol: bwx0s - {7F4D7790-B8C4-41DD-A9A3-BB2F0AF52D0D} - C:\Program Files\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.d
ll
O18 - Protocol: bwy0 - {7F4D7790-B8C4-41DD-A9A3-BB2F0AF52D0D} - C:\Program Files\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.d
ll
O18 - Protocol: bwy0s - {7F4D7790-B8C4-41DD-A9A3-BB2F0AF52D0D} - C:\Program Files\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.d
ll
O18 - Protocol: bwz0 - {7F4D7790-B8C4-41DD-A9A3-BB2F0AF52D0D} - C:\Program Files\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.d
ll
O18 - Protocol: bwz0s - {7F4D7790-B8C4-41DD-A9A3-BB2F0AF52D0D} - C:\Program Files\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.d
ll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Fichiers communs\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: offline-8876480 - {7F4D7790-B8C4-41DD-A9A3-BB2F0AF52D0D} - C:\Program Files\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.d
ll
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} -
C:\PROGRA~1\FICHIE~1\MICROS~1\OFFICE12\MSOXMLMF.DL
L
O20 - Winlogon Notify: mll_hp32 - C:\WINDOWS\SYSTEM32\mll_hp32.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: PunkBuster (PnkBstrA) - Unknown owner - C:\Program Files\Electronic Arts\Medal of Honor Airborne\UnrealEngine3\MOHAGame\pb\PnkBstrA.exe
O23 - Service: SiSoftware Database Agent Service (SandraDataSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite XI.SP4a\Win32\RpcDataSrv.exe
O23 - Service: SiSoftware Sandra Agent Service (SandraTheSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite XI.SP4a\RpcSandraSrv.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe
Bonjour
Ca ne m´étonne pas que tu n´as plus de problème, mais on a pas fini le nettoyage.
Relance Hijackthis coche toutes lignes O18 SAUF celles ci (les dernières au fait)
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Fichiers communs\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: offline-8876480 - {7F4D7790-B8C4-41DD-A9A3-BB2F0AF52D0D} - C:\Program Files\Logitech\Desktop
Messenger\8876480\Program\BWPlugProtocol-8876480.d
ll
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} -
C:\PROGRA~1\FICHIE~1\MICROS~1\OFFICE12\MSOXMLMF.DL
puis coche les lignes ci dessous :
O2 - BHO: (no name) - {CC7848B0-A15E-4B08-AE1A-F51F255683C5} - C:\WINDOWS\system32\jkkjh.dll (file missing)
O4 - HKLM\..\Run: [GameFace Messenger] C:\Program Files\GameFace Messenger\GameFace.exe
O20 - Winlogon Notify: mll_hp32 - C:\WINDOWS\SYSTEM32\mll_hp32.dll
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
Clique sur "FIX CHECKED".
Démarrer => Exécuter => tape : services.msc => OK
si boonty games (ou boonty) présent => clique et arrêter
Télécharge OTMoveIt (de Old_Timer) sur ton bureau.
http://download.bleepingcomputer.com/oldtimer/OTMoveIt.exe
C:\Program Files\GameFace Messenger\
C:\Program Files\Fichiers communs\BOONTY Shared\
C:\WINDOWS\SYSTEM32\mll_hp32.dll
Supprime tout les fichiers téléchargés.
Avast! est loin de ce que l´on a fait de mieux en matière de protection, voir ce lien pour plus d´informations :
http://forum.malekal.com/ftopic3123.php
Clairement, Antivir est beaucoup plus performant, c´est pourquoi, je te conseille TRES VIVEMENT de désinstaller Avast! et installer Antivir à la place :
http://www.clubic.com/telecharger-fiche10821-antivir-personal-edition-7.html
Tuto :
http://www.malekal.com/tutorial_antivir.php
- Après l´installation, mets le à jour - si ton firewall fait une alerte.. accepte la connexion.
- Assure toi qu´Antivir est bien à jour, vérifie la date d´update.
-- Redémarre en mode sans échec, pour cela, redémarre l´ordinateur, avant le logo Windows, tapote sur la touche F8, un menu va apparaître, choisis Mode sans échec et appuye sur la touche entrée du clavier.
- Ouvre Antivir par le menu Démarrer / Programmes
- Cliquez sur l´onglet Scanner.
- Sélectionne Manual Selection
- Sélectionne le disque C
- Lance le scan - Mets en quarantaine tous les éléments détectés.
- Une fois le scan terminé Enregistre le rapport.
Redémarre en mode normal.
Poste le rapport ici.
Installe un pare feu, je conseille - Zone Alarme :
http://www.clubic.com/telecharger-fiche10494-zonealarm.html
Tuto :
http://forum.telecharger.01net.com/microhebdo/questions_techniques_diverses/securite/tutorial_zonealarm-323293/messages-1.html
Poste un nouveau log HJC.
Bonne soirée ![]()
lol ok merci beaucoup bah di donc sa prend du temps de nettoyer le pc lol.
Encore merci je test sa tout de suite :D
dsl pour le double post
dc j´ai fait le truc de OTMovelt. Je voulais savoir les fichiers téléchargé c´est tous les programme ke tu ma filé ou autre chose??
Ensuite pour le pare feu j´ai déja celui de windows est-ce que je dois prendre zone alarme ou pas (j´ai pas envie d´enconbrer tout mon ordi avec sa!!)
Et enfin (surement la plus débile) :p:p c´est quoi un nouveau log HJC??? ![]()