CONNEXION
  • RetourJeux
    • Sorties
    • Hit Parade
    • Les + populaires
    • Les + attendus
    • Soluces
    • Tous les Jeux
    • Gaming
  • RetourActu Gaming
    • News
    • Astuces
    • Tests
    • Previews
    • Toute l'actu gaming
  • RetourBons plans
    • Bons plans
    • Bons plans Smartphone
    • Bons plans Hardware
    • Bons plans Image et Son
    • Bons plans Amazon
    • Bons plans Cdiscount
    • Bons plans Decathlon
    • Bons plans Fnac
    • Tous les Bons plans
  • RetourJVTech
    • Actus High-Tech
    • Intelligence Artificielle
    • Smartphones
    • Mobilité urbaine
    • Hardware
    • Image et son
    • Tutoriels
    • Tests produits High-Tech
    • Guides d'achat High-Tech
    • JVTech
  • RetourCulture
    • Actus Culture
    • Culture
  • RetourVidéos
    • A la une
    • Gaming Live
    • Vidéos Tests
    • Vidéos Previews
    • Gameplay
    • Trailers
    • Chroniques
    • Replay Web TV
    • Toutes les vidéos
  • RetourForums
    • Hardware PC
    • PS5
    • Switch 2
    • Xbox Series
    • Switch
    • Pokemon pocket
    • FC 25 Ultimate Team
    • League of Legends
    • Tous les Forums
  • PC
  • PS5
  • Xbox Series
  • Switch 2
  • PS4
  • One
  • Switch
  • iOS
  • Android
  • MMO
  • RPG
  • FPS
En ce moment Genshin Impact Valhalla Breath of the wild Animal Crossing GTA 5 Red dead 2
Liste des sujets

Spyware threat !!

-_Jeff_Hardy_-
-_Jeff_Hardy_-
Niveau 7
19 juillet 2008 à 17:05:32

:salut: a tous alors voila je poste sur ce forum car j'ai un probleme :

J'ai un Spyware sur mon ordinateur , le voici :-(

http://lh6.ggpht.com/TommyGun1983/SCMkICg25cI/AAAAAAAAAYk/fTxtfRjxdAM/s800/Ruthie.JPG

En fait c'est un fond d'écran que quand j'enleve pour remmetre celui d'origine il se remait toutes les 5 minutes :ouch: et dans ma barre des taches j'ai un petit triangle attetion qui me dit que mon ordinateur coure des risques ...

Apparement c'est un virus commercial car aussi toutes les 5 minutes il m'ouvre des pages ou il me propose des antivirus qui sont eux memes des virus :oui:

Et j'aimerais que vous m'aidié a le resoudre pour ceux qui l'ont deja eu et qui l'ont resolu car c'est tres embetant :( , mon orid est plus lent ectetera...

Apparement il faut faire des scan ectetera et poster les rapport des scan j'ai vu sa sur d'autres sites mais si il faut le faire des rapport je vous les posterais

J'ai deja fais des analyse avec ccleaner , ad aware et avast et il ne me trouve rien :-(

Donc merci pour votre futur aide :)

:salut:

-_Jeff_Hardy_-
-_Jeff_Hardy_-
Niveau 7
19 juillet 2008 à 18:06:38

SVP repondez :)

-_Jeff_Hardy_-
-_Jeff_Hardy_-
Niveau 7
19 juillet 2008 à 19:40:03

SVP j'en peux plus de ce spyware jetez un coup d'oeil a mon message svp aidé moi

wiwi77
wiwi77
Niveau 10
19 juillet 2008 à 19:53:42

Salut,

- Télécharge HijackThis V 2.02 (HijackThis Installer) :
http://www.trendsecure.com/portal/en-US/threat_analytics/HJTInstall.exe

- Fais un double-clic sur HJTInstall.exe afin de lancer l'installation

- Clique sur Install ensuite sur I Accept

- Clique sur Do a scan system and save log file

- Le bloc-notes s'ouvrira, fais un copier-coller de tout son contenu ici dans ta prochaine réponse.

-_Jeff_Hardy_-
-_Jeff_Hardy_-
Niveau 7
19 juillet 2008 à 21:36:17

Ahh :merci: beaucoup ok je vais faire sa :)

-_Jeff_Hardy_-
-_Jeff_Hardy_-
Niveau 7
19 juillet 2008 à 21:38:30

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:37:42, on 19/07/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\WINDOWS\system32\uoyzsydz.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Fichiers communs\AOL\ACS\AOLDial.exe
C:\Program Files\Fichiers communs\AOL\1181386289\ee\AOLSoftware.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Lexmark 4800 Series\lxdeamon.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\DNA\btdna.exe
C:\Program
Files\Google\GoogleToolbarNotifier\GoogleToolbarNo
tifier.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Jana2\Janad.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\lxbtcoms.exe
C:\WINDOWS\system32\lxdecoms.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\TightVNC\WinVNC.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\AOL 9.0b\waol.exe
C:\Program Files\AOL 9.0b\shellmon.exe
C:\Program Files\Fichiers communs\Aol\aoltpspd.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\Rundll32.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\World of Warcraft\Launcher.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://fr.msn.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: (no name) - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - (no file)
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
F2 - REG:system.ini:
UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDO
WS\system32\uoyzsydz.exe,
O2 - BHO: (no name) - {00110011-4b0b-44d5-9718-90c88817369b} - (no file)
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: (no name) - {086ae192-23a6-48d6-96ec-715f53797e85} - (no file)
O2 - BHO: (no name) - {150fa160-130d-451f-b863-b655061432ba} - (no file)
O2 - BHO: (no name) - {17da0c9e-4a27-4ac5-bb75-5d24b8cdb972} - (no file)
O2 - BHO: (no name) - {1f48aa48-c53a-4e21-85e7-ac7cc6b5ffb1} - (no file)
O2 - BHO: (no name) - {1f48aa48-c53a-4e21-85e7-ac7cc6b5ffb2} - (no file)
O2 - BHO: (no name) - {2d38a51a-23c9-48a1-a33c-48675aa2b494} - (no file)
O2 - BHO: (no name) - {2e9caff6-30c7-4208-8807-e79d4ec6f806} - (no file)
O2 - BHO: (no name) - {467faeb2-5f5b-4c81-bae0-2a4752ca7f4e} - (no file)
O2 - BHO: (no name) - {5321e378-ffad-4999-8c62-03ca8155f0b3} - (no file)
O2 - BHO: (no name) - {587dbf2d-9145-4c9e-92c2-1f953da73773} - (no file)
O2 - BHO: (no name) - {59AAD935-DB8D-4289-A0A3-67E2B3B55BAB} - C:\WINDOWS\system32\awttuspP.dll
O2 - BHO: (no name) - {6cc1c91a-ae8b-4373-a5b4-28ba1851e39a} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {79369d5c-2903-4b7a-ade2-d5e0dee14d24} - (no file)
O2 - BHO: (no name) - {799a370d-5993-4887-9df7-0a4756a77d00} - (no file)
O2 - BHO: (no name) - {7C7A8947-5935-4430-AC0E-E7D04697414E} - (no file)
O2 - BHO: {a8fd65e6-166c-0b7b-59a4-ab2143b53be8} - {8eb35b34-12ba-4a95-b7b0-c6616e56df8a} - C:\WINDOWS\system32\tqdjdy.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {98dbbf16-ca43-4c33-be80-99e6694468a4} - (no file)
O2 - BHO: (no name) - {a55581dc-2cdb-4089-8878-71a080b22342} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program
Files\Google\GoogleToolbarNotifier\2.1.615.5858\sw
g.dll
O2 - BHO: (no name) - {b847676d-72ac-4393-bfff-43a1eb979352} - (no file)
O2 - BHO: (no name) - {bc97b254-b2b9-4d40-971d-78e0978f5f26} - (no file)
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: (no name) - {cf021f40-3e14-23a5-cba2-717765721306} - (no file)
O2 - BHO: (no name) - {DC7B3FA4-3FCC-4429-AC45-18D62B98896A} - C:\WINDOWS\system32\tuvSlmJC.dll
O2 - BHO: (no name) - {e2ddf680-9905-4dee-8c64-0a5de7fe133c} - (no file)
O2 - BHO: (no name) - {e3eebbe8-9cab-4c76-b26a-747e25ebb4c6} - (no file)
O2 - BHO: (no name) - {e7afff2a-1b57-49c7-bf6b-e5123394c970} - (no file)
O2 - BHO: targetedbanner browser optimizer - {ed834ead-e8c8-a750-c97e-3799ecb694a5} - C:\WINDOWS\system32\ttysinzhslrerym.dll
O2 - BHO: (no name) - {fcaddc14-bd46-408a-9842-cdbe1c6d37eb} - (no file)
O2 - BHO: (no name) - {fd9bc004-8331-4457-b830-4759ff704c22} - (no file)
O2 - BHO: (no name) - {ff1bf4c7-4e08-4a28-a43f-9d60a9f7a880} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O3 - Toolbar: (no name) - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - (no file)
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Fichiers communs\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Fichiers communs\AOL\1181386289\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [AdslTaskBar] rundll32.exe stmctrl.dll,TaskBar
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [lxdemon.exe] "C:\Program Files\Lexmark 4800 Series\lxdemon.exe"
O4 - HKLM\..\Run: [lxdeamon] "C:\Program Files\Lexmark 4800 Series\lxdeamon.exe"
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [{a51532b9-fe56-6e95-e92d-0ebe43c0791c}] C:\WINDOWS\System32\Rundll32.exe "C:\WINDOWS\system32\ttysinzhslrerym.dll" DllStart
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [BMa76bc57b] Rundll32.exe "C:\WINDOWS\system32\dectbnlv.dll",s
O4 - HKLM\..\Run: [a458f6e7] rundll32.exe "C:\WINDOWS\system32\anxssdlv.dll",b
O4 - HKCU\..\Run: [AOL Dialer] C:\Program Files\Fichiers communs\AOL\ACS\AOlDial.exe
O4 - HKCU\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [swg] C:\Program
Files\Google\GoogleToolbarNotifier\GoogleToolbarNo
tifier.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: AOL 9.0 Icône AOL.lnk = C:\Program Files\AOL 9.0b\aoltray.exe
O8 - Extra context menu item: &Recherche AOL Toolbar - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to AMV Convert Tool... - C:\Program Files\MP3 Player Utilities 4.00\AMVConverter\grab.html
O8 - Extra context menu item: Add to AMV Converter... - C:\Program Files\MP3 Player Utilities 4.05\AMVConverter\grab.html
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 4.00\MediaManager\grab.html
O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live
Toolbar\Components\fr-fr\msntabres.dll.mui/229?e08
bed9739f34f9690cfff63b98f3c4f
O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live
Toolbar\Components\fr-fr\msntabres.dll.mui/230?e08
bed9739f34f9690cfff63b98f3c4f
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Buyertools Reminder - {27914077-B4D6-4A0E-9763-76B6E9DD9A81} - C:\Program Files\Buyertools Reminder\ReminderIE.exe (file missing)
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: ShopperReports - Compare product prices - {C5428486-50A0-4a02-9D20-520B59A9F9B2} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: ShopperReports - Compare travel rates - {C5428486-50A0-4a02-9D20-520B59A9F9B3} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://fr.msn.com/
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1156232740328
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1156233219046
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O17 -
HKLM\System\CCS\Services\Tcpip\..\{3CFF70AF-A574-4
B62-A711-111862986C89}: NameServer = 86.64.145.141 84.103.237.141
O17 -
HKLM\System\CCS\Services\Tcpip\..\{6786AB0A-5128-4
CA9-BD52-E193362A367B}: NameServer = 205.188.146.145
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: awttuspP - C:\WINDOWS\SYSTEM32\awttuspP.dll
O20 - Winlogon Notify: efbfcbdfbfcaf - C:\WINDOWS\system32\efbfcbdfbfcaf.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service:

    1. Id_String1.6844F930_1628_4223_B5CC_5BB94B879762#
  1. (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Jana Server 2 (Janad) - Thomas Hauck, Privat - C:\Program Files\Jana2\Janad.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
O23 - Service: lxbt_device - - C:\WINDOWS\system32\lxbtcoms.exe
O23 - Service: lxdeCATSCustConnectService - Lexmark International, Inc. -
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxdese
rv.exe
O23 - Service: lxde_device - - C:\WINDOWS\system32\lxdecoms.exe
O23 - Service: MSSQL$SONY_MEDIAMGR - Unknown owner - C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SQLAgent$SONY_MEDIAMGR - Unknown owner - C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlagent.EXE (file missing)
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: VNC Server (winvnc) - TightVNC Group - C:\Program Files\TightVNC\WinVNC.exe

--
End of file - 15895 bytes

Voila :)

-_Jeff_Hardy_-
-_Jeff_Hardy_-
Niveau 7
19 juillet 2008 à 22:08:35

:up:

-_Jeff_Hardy_-
-_Jeff_Hardy_-
Niveau 7
19 juillet 2008 à 23:48:15

:up: stp rep

wiwi77
wiwi77
Niveau 10
20 juillet 2008 à 03:18:28

Infection Vundo/Virtumonde.

---> Télécharge ComboFix.exe de sUBs sur ton Bureau :
http://download.bleepingccomputer.com/sUBs/ComboFix.exe

/!\ Déconnecte-toi du net et ferme toutes les applications, antivirus et antispyware y compris /!\

---> Double-clique sur Combofix.exe
Un "pop-up" va apparaître qui dit que "ComboFix est utilisé à vos risques et avec aucune garantie...".
Accepte en cliquant sur "Oui"

---> Mets-le en langue française F
Tape sur la touche 1 (Yes) pour démarrer le scan.

/!\ Ne touche à rien tant que le scan n'est pas terminé. /!\

En fin de scan, il est possible que ComboFix ait besoin de redémarrer le PC pour finaliser la désinfection, laisse-le faire.

Une fois le scan achevé, un rapport va s'afficher : Poste son contenu

/!\ Réactive la protection en temps réel de ton antivirus et de ton antispyware avant de te reconnecter à Internet. /!\

Note : Le rapport se trouve également là : C:\ComboFix.txt

-_Jeff_Hardy_-
-_Jeff_Hardy_-
Niveau 7
20 juillet 2008 à 11:23:35

Message trop long je le met en 2 parties :)

ComboFix 08-07-19.1 - Utilisateur 2008-07-20 11:03:32.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.612 [GMT 2:00]
Endroit: C:\Documents and Settings\Utilisateur\Bureau\ComboFix.exe
* Création d'un nouveau point de restauration

[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]
.

(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\LocalService\Application Data\NetMon
C:\Documents and Settings\LocalService\Application Data\NetMon\domains.txt
C:\Documents and Settings\LocalService\Application Data\NetMon\log.txt
C:\Documents and Settings\Utilisateur\Application Data\ShoppingReport
C:\Documents and Settings\Utilisateur\Application Data\ShoppingReport\cs\Config.xml
C:\Documents and Settings\Utilisateur\Application Data\ShoppingReport\cs\db\Aliases.dbs
C:\Documents and Settings\Utilisateur\Application Data\ShoppingReport\cs\db\Sites.dbs
C:\Documents and Settings\Utilisateur\Application Data\ShoppingReport\cs\dwld\WhiteList.xip
C:\Documents and Settings\Utilisateur\Application Data\ShoppingReport\cs\report\aggr_storage.xml
C:\Documents and Settings\Utilisateur\Application Data\ShoppingReport\cs\report\send_storage.xml
C:\Documents and Settings\Utilisateur\Application Data\ShoppingReport\cs\res1\WhiteList.dbs
C:\Program Files\network monitor
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\WINDOWS\accesss.exe
C:\WINDOWS\astctl32.ocx
C:\WINDOWS\avpcc.dll
C:\WINDOWS\BMa76bc57b.txt
C:\WINDOWS\clrssn.exe
C:\WINDOWS\cpan.dll
C:\WINDOWS\ctfmon32.exe
C:\WINDOWS\ctrlpan.dll
C:\WINDOWS\default.htm
C:\WINDOWS\directx32.exe
C:\WINDOWS\dnsrelay.dll
C:\WINDOWS\editpad.exe
C:\WINDOWS\explore.exe
C:\WINDOWS\explorer32.exe
C:\WINDOWS\funniest.exe
C:\WINDOWS\funny.exe
C:\WINDOWS\gfmnaaa.dll
C:\WINDOWS\helpcvs.exe
C:\WINDOWS\iedll.exe
C:\WINDOWS\iexplorer.exe
C:\WINDOWS\inetinf.exe
C:\WINDOWS\internet.exe
C:\WINDOWS\lfn.exe
C:\WINDOWS\loader.exe
C:\WINDOWS\mainms.vpi
C:\WINDOWS\megavid.cdt
C:\WINDOWS\msconfd.dll
C:\WINDOWS\msspi.dll
C:\WINDOWS\mssys.exe
C:\WINDOWS\msupdate.exe
C:\WINDOWS\mswsc10.dll
C:\WINDOWS\mswsc20.dll
C:\WINDOWS\mtwirl32.dll
C:\WINDOWS\muotr.so
C:\WINDOWS\notepad32.exe
C:\WINDOWS\olehelp.exe
C:\WINDOWS\pskt.ini
C:\WINDOWS\qttasks.exe
C:\WINDOWS\quicken.exe
C:\WINDOWS\rundll16.exe
C:\WINDOWS\rundll32.vbe
C:\WINDOWS\searchword.dll
C:\WINDOWS\sistem.exe
C:\WINDOWS\svchost32.exe
C:\WINDOWS\svcinit.exe
C:\WINDOWS\systeem.exe
C:\WINDOWS\system32\ahnuvdam.dll
C:\WINDOWS\system32\awttuspP.dll
C:\WINDOWS\system32\cbXQklki.dll
C:\WINDOWS\system32\CJmlSvut.ini
C:\WINDOWS\system32\CJmlSvut.ini2
C:\WINDOWS\system32\dectbnlv.dll
C:\WINDOWS\system32\elprvggu.dll
C:\WINDOWS\system32\fgebkaas.dll
C:\WINDOWS\system32\fwjvmxqn.ini
C:\WINDOWS\system32\hfrrus.dll
C:\WINDOWS\system32\hljwugsf.bin
C:\WINDOWS\system32\iklkQXbc.ini
C:\WINDOWS\system32\iklkQXbc.ini2
C:\WINDOWS\system32\jglkgoxp.dll
C:\WINDOWS\system32\kxqkvbog.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mlJYomJa.dll
C:\WINDOWS\system32\MSINET.oca
C:\WINDOWS\system32\nxolqnmp.ini
C:\WINDOWS\system32\ocyrojae.dll
C:\WINDOWS\system32\ohsatp.dll
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\pxogklgj.ini
C:\WINDOWS\system32\tqdjdy.dll
C:\WINDOWS\system32\ttysinzhslrerym.dll
C:\WINDOWS\system32\uoyzsydz.exe
C:\WINDOWS\system32\vldssxna.ini
C:\WINDOWS\systemcritical.exe
C:\WINDOWS\time.exe
C:\WINDOWS\users32.exe
C:\WINDOWS\waol.exe
C:\WINDOWS\win32e.exe
C:\WINDOWS\win64.exe
C:\WINDOWS\winajbm.dll
C:\WINDOWS\window.exe
C:\WINDOWS\winmgnt.exe
C:\WINDOWS\x.exe
C:\WINDOWS\xplugin.dll
C:\WINDOWS\xxxvideo.hta
C:\WINDOWS\y.exe

-_Jeff_Hardy_-
-_Jeff_Hardy_-
Niveau 7
20 juillet 2008 à 11:24:11

En 3 parties alors ^^

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services
)))))))))))))))))))))))))))))))))))))))))))))))))

.

-------\Legacy_CMDSERVICE
-------\Legacy_MSSECURITY1.209.4
-------\Legacy_NETWORK_MONITOR

((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-06-20 to 2008-07-20 ))))))))))))))))))))))))))))))))))))
.

2008-07-19 21:37 . 2008-07-19 21:37 <REP> d-------- C:\Program Files\Trend Micro
2008-07-19 13:07 . 2008-07-19 13:07 <REP> d-------- C:\SmitfraudFix
2008-07-19 13:07 . 2008-07-19 13:07 <REP> d-------- C:\Documents and Settings\Utilisateur\Application Data\Grisoft
2008-07-19 13:07 . 2008-07-19 13:07 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-07-19 12:47 . 2008-07-19
12:47 3,304 --a------ C:\WINDOWS\system32\tmp.reg

2008-07-19 12:42 . 2007-05-30
14:10 10,872 --a------ C:\WINDOWS\system32\drivers
\AvgAsCln.sys
2008-07-19 12:23 . 2008-07-19 13:06 <REP> d-------- C:\Program Files\Anti Trojan Elite
2008-07-18 11:22 . 2008-07-18
11:22 69,120 --a------ C:\WINDOWS\system32\kbvunrn
e.dll
2008-07-18 11:19 . 2008-07-19
18:00 110,505 --a------ C:\WINDOWS\BMa76bc57b.xml

2008-07-17 19:17 . 2008-07-17 19:17 <REP> d-------- C:\Program Files\Fichiers communs\Wise Installation Wizard
2008-07-17 16:40 . 2008-07-17 18:01 <REP> d--hs---- C:\WINDOWS\VXRpbGlzYXRldXI
2008-07-17 16:40 . 2008-07-17 16:40 <REP> dr------- C:\Documents and Settings\LocalService\Favoris
2008-07-17 16:40 . 2008-07-17 16:40 <REP> d-------- C:\Documents and Settings\LocalService\Application Data\Yahoo!
2008-07-17 16:40 . 2008-07-17
16:40 64,841 --a------ C:\WINDOWS\system32\akachcg
vughudof.exe
2008-07-17 16:39 . 2008-07-17 18:00 <REP> d-------- C:\WINDOWS\system32\shel
2008-07-17 16:39 . 2008-07-17 16:39 <REP> d-------- C:\WINDOWS\system32\ind
2008-07-17 16:39 . 2008-07-17 17:58 <REP> d-------- C:\WINDOWS\system32\BP3
2008-07-17 16:39 . 2008-07-19
16:47 <REP> d-------- C:\WINDOWS\system32\aumsDK05

2008-07-17 16:39 . 2008-07-17 16:40 <REP> d-------- C:\Temp\zpv201
2008-07-15 00:19 . 2008-07-15 00:19 339,968 --a------ C:\Documents and Settings\Utilisateur\Launcher.exe
2008-07-15 00:19 . 2008-07-15 00:19 6,656 --a------ C:\Documents and Settings\Utilisateur\patcher.exe
2008-07-12 20:21 . 2008-07-12 20:21 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-07-12 20:21 . 2008-07-12 20:21 1,409 --a------ C:\WINDOWS\QTFont.for
2008-07-07 20:43 . 2008-07-07 20:43 <REP> d-------- C:\Documents and Settings\Utilisateur\Logs
2008-07-07 19:35 . 2008-07-07 19:35 <REP> d-------- C:\Program Files\Fichiers communs\Blizzard Entertainment
2008-07-07 19:33 . 2008-07-19 19:41 <REP> d-------- C:\Program Files\World of Warcraft
2008-06-26 09:45 . 2008-07-04 11:02 <REP> d-------- C:\Program Files\Dofus
2008-06-21 12:45 . 2008-06-21 13:12 23 --a------ C:\WINDOWS\BlendSettings.ini

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-20 09:09 --------- d-----w C:\Documents and Settings\Utilisateur\Application Data\DNA
2008-07-19 19:54 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-07-19 19:22 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-07-19 16:02 --------- d-----w C:\Program Files\DkZ Studio
2008-07-17 22:35 --------- d-----w C:\Program Files\LimeWire
2008-07-17 22:35 --------- d-----w C:\Program Files\eMule
2008-07-17 17:18 --------- d-----w C:\Program Files\Lavasoft
2008-07-17 17:17 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-07-16 22:12 --------- d-----w C:\Documents and Settings\Utilisateur\Application Data\OpenOffice.org2
2008-07-09 20:04 --------- d-----w C:\Documents and Settings\Utilisateur\Application Data\La Bataille pour la Terre du Milieu ™ II
2008-07-08 10:18 --------- d-----w C:\Documents and Settings\All Users\Application Data\LxThumbs
2008-07-07 15:27 --------- d-----w C:\Program Files\AviSynth 2.5
2008-07-07 15:22 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-07-07 15:19 --------- d-----w C:\Program Files\P2P_Torrent
2008-07-07 15:12 --------- d-----w C:\Program Files\Image-Line
2008-07-07 15:11 --------- d-----w C:\Program Files\Vstplugins
2008-07-07 13:48 --------- d-----w C:\Program Files\IVCsoft
2008-06-25 21:06 --------- d-----w C:\Documents and Settings\Utilisateur\Application Data\Skype
2008-06-25 18:59 --------- d-----w C:\Documents and Settings\Utilisateur\Application Data\skypePM
2008-06-24 17:17 --------- d-----w C:\Documents and Settings\Utilisateur\Application Data\FaxCtr
2008-06-20
10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\
tcpip.sys
2008-06-20
10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\
afd.sys
2008-06-20
09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\
tcpip6.sys
2008-06-16 21:28 --------- d-----w C:\Documents and Settings\Utilisateur\Application Data\TaoUSign
2008-06-14
17:59 272,768 ------w C:\WINDOWS\system32\drivers\
bthport.sys
2008-06-12 08:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\ThumbnailCache4R
2008-06-05 19:43 --------- d-----w C:\Documents and Settings\Utilisateur\Application Data\LimeWire
2008-06-05 19:32 --------- d-----w C:\Program Files\LimeWire Acceleration Patch
2008-06-05 19:30 --------- d-----w C:\Program Files\Conduit
2008-06-04 17:21 --------- d-----w C:\Program Files\Abbyy FineReader 6.0 Sprint
2008-06-03 14:56 --------- d-----w C:\Documents and Settings\Utilisateur\Application Data\U3
2008-05-23 18:47 --------- d-----w C:\Documents and Settings\Utilisateur\Application Data\Lexmark Productivity Studio
2008-05-23 18:28 --------- d-----w C:\Program Files\Lexmark Fax Solutions
2008-05-23 18:28 --------- d-----w C:\Program Files\Lexmark 4800 Series
2008-05-23 18:27 --------- d-----w C:\Documents and Settings\All Users\Application Data\FaxCtr
2008-04-22 13:03 32 ----a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat
2007-07-23 13:15 87,608 ----a-w C:\Documents and Settings\Utilisateur\Application Data\inst.exe
2007-07-23 13:15 47,360 ----a-w C:\Documents and Settings\Utilisateur\Application Data\pcouffin.sys
2006-03-02 12:00 22,040 ---h--w C:\Documents and Settings\Utilisateur\Application Data\addon.dat

-_Jeff_Hardy_-
-_Jeff_Hardy_-
Niveau 7
20 juillet 2008 à 11:24:48

.

((((((((((((((((((((((((((((((((( Point de chargement Reg
)))))))))))))))))))))))))))))))))))))))))))))))))

.
.
REGEDIT4

  • Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curr
entVersion\Run]
"AOL Dialer"="C:\Program Files\Fichiers communs\AOL\ACS\AOlDial.exe" [2007-06-21 12:01 70952]
"SweetIM"="C:\Program Files\Macrogaming\SweetIM\SweetIM.exe" [2007-08-12 11:02 103712]
"BitTorrent DNA"="C:\Program Files\DNA\btdna.exe" [2008-07-01 10:04 289088]
"swg"="C:\Program
Files\Google\GoogleToolbarNotifier\GoogleToolbarNo
tifier.exe" [2007-06-08 15:32 68856]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-03 09:59 204288]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Cur
rentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-06-01 17:22 7618560]
"AOLDialer"="C:\Program Files\Fichiers communs\AOL\ACS\AOLDial.exe" [2007-06-21 12:01 70952]

"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.e
xe" [2001-07-09 10:50 155648]
"HostManager"="C:\Program Files\Fichiers communs\AOL\1181386289\ee\AOLSoftware.exe" [2006-11-17 15:16 50736]
"lxdemon.exe"="C:\Program Files\Lexmark 4800 Series\lxdemon.exe" [2007-06-11 15:53 455600]
"lxdeamon"="C:\Program Files\Lexmark 4800 Series\lxdeamon.exe" [2007-06-01 10:06 20480]
"FaxCenterServer"="C:\Program Files\Lexmark Fax Solutions\fm3032.exe" [2007-06-11 15:55 316336]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-08-21 17:33 282624]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 11:25 6731312]
"nwiz"="nwiz.exe" [2006-06-01 17:22 1519616 C:\WINDOWS\system32\nwiz.exe]
"AdslTaskBar"="stmctrl.dll" [2003-12-12 17:50 151552 C:\WINDOWS\system32\stmctrl.dll]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cu
rrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2006-03-02 14:00 15360]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 12:34 5724184]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\efbfcbdfbfcaf]
2003-07-14 09:17 302096 C:\WINDOWS\system32\efbfcbdfbfcaf.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.ffds"= ffdshow.ax

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^eBayer 4.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\eBayer 4.lnk
backup=C:\WINDOWS\pss\eBayer 4.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Outil de mise à jour Google.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Outil de mise à jour Google.lnk
backup=C:\WINDOWS\pss\Outil de mise à jour Google.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
--a------ 2007-04-04 00:29 165784 C:\Program Files\DAEMON Tools\daemon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HDAudDeck]
--a------ 2006-07-17 15:36 684032 C:\Program Files\VIAudioi\HDADeck\HDeck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2006-08-21 17:33 282624 C:\Program Files\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2007-09-25 02:11 132496 C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 2007-06-08 15:32 68856 C:\Program
Files\Google\GoogleToolbarNotifier\GoogleToolbarNo
tifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateShield]
--a------ 2006-11-23 17:45 2076672 C:\WINDOWS\system32\r2c\mirc.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Veoh]
--a------ 2007-12-21 18:51 3481600 C:\Program Files\Veoh Networks\Veoh\VeohClient.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinVNC]
--a------ 2007-05-07 19:28 589824 C:\Program Files\TightVNC\WinVNC.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
--------- 2006-11-03 09:59 204288 C:\Program Files\Windows Media Player\wmpnscfg.exe

[HKLM\~\services\sharedaccess\parameters\firewallp
olicy\standardprofile\AuthorizedApplications\List]

"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\Program Files\\AOL 9.0\\AOL.exe"=
"C:\\Program Files\\AOL 9.0\\WAOL.exe"=
"C:\\WINDOWS\\system32\\fxsclnt.exe"=
"C:\\Program Files\\NetMeeting\\Conf.exe"=
"C:\\Program Files\\Ahead\\Nero MediaHome\\NeroMediaHome.exe"=
"C:\\Program Files\\RealVNC\\VNC4\\winvnc4.exe"=
"C:\\Program Files\\AOL 9.0a\\waol.exe"=
"C:\\Program Files\\Fichiers communs\\AOL\\ACS\\AOLAcsd.exe"=
"C:\\Program Files\\Fichiers communs\\AOL\\ACS\\AOLDial.exe"=
"C:\\Program Files\\AOL 9.0b\\waol.exe"=
"C:\\Program Files\\eMule\\emule.exe"=
"C:\\WINDOWS\\Drivers\\Microsoft\\service.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"D:\\Jeux\\Microsoft games\\Age Of Mythology\\aom.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\Fichiers communs\\AOL\\1181386289\\ee\\aolsoftware.exe"=
"C:\\WINDOWS\\system32\\r2c\\mirc.exe"=
"D:\\Jeux\\Ubisoft\\Far cry\\Bin32\\FarCry.exe"=
"C:\\WINDOWS\\system32\\lxbtcoms.exe"=
"D:\\Jeux\\KONAMI\\Pro Evolution Soccer 2008\\PES2008.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"D:\\Jeux\\Microsoft games\\Age Of Mythology\\aomx.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Ahead\\Nero ShowTime\\ShowTime.exe"=
"C:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"D:\\eMule\\emule.exe"=
"D:\\Jeux\\Age Of Empires 3\\Age Of Empires\\age3x.exe"=
"D:\\Jeux\\Age Of Empires 3\\Age Of Empires\\age3y.exe"=
"C:\\CreativesFiles\\Shareaza.exe"=
"C:\\Program Files\\DNA\\btdna.exe"=
"C:\\WINDOWS\\system32\\lxdecoms.exe"=
"C:\\Program Files\\Lexmark 4800 Series\\lxdeamon.exe"=
"C:\\Program Files\\Lexmark 4800 Series\\frun.exe"=
"C:\\Program Files\\Abbyy FineReader 6.0 Sprint\\Scan\\ScanMan6.exe"=
"C:\\Program Files\\Lexmark Fax Solutions\\FaxCtr.exe"=
"C:\\Program Files\\Lexmark 4800 Series\\lxdemon.exe"=

"C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\
\lxdepswx.exe"=

"C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\
\lxdetime.exe"=

"C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\
\lxdejswx.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
"D:\\Jeux\\Electronic Arts\\Le seigneur des anneaux\\La bataille pour la terre du mileu II\\game.dat"=
"D:\\Jeux\\KONAMI\\Pro Evolution Soccer 6\\Installation PES 6\\PES6.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallp
olicy\standardprofile\GloballyOpenPorts\List]
"12816:TCP"= 12816:TCP:BitComet 12816 TCP
"12816:UDP"= 12816:UDP:BitComet 12816 UDP

R0
videX32;videX32;C:\WINDOWS\system32\DRIVERS\videX3
2.sys [2006-02-23 11:38]
R0 xfilt;VIA SATA IDE Hot-plug Driver;C:\WINDOWS\system32\DRIVERS\xfilt.sys [2006-02-23 11:39]
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-16 01:20]
R2
aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswF
sBlk.sys [2008-05-16 01:16]
R2 Janad;Jana Server 2;C:\Program Files\Jana2\Janad.exe [2006-10-09 14:00]
R2
lxde_device;lxde_device;C:\WINDOWS\system32\lxdeco
ms.exe [2007-05-29 11:07]
R3 RMSPPPOE;WAN Miniport (PPP over Ethernet
Protocol);C:\WINDOWS\system32\DRIVERS\RMSPPPOE.SYS
[2002-10-03 01:09]
R3 Stmatm;ATM/ADSL miniport;C:\WINDOWS\system32\DRIVERS\stmatm.sys [2004-07-06 13:28]
R3 TaurusUsb;ADSL Modem USB Service;C:\WINDOWS\system32\DRIVERS\torususb.sys [2004-07-06 13:51]
S2
lxdeCATSCustConnectService;lxdeCATSCustConnectServ
ice;C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lx
deserv.exe [2007-05-29 11:06]
S3 ATE_PROCMON;ATE_PROCMON;C:\Program Files\Anti Trojan Elite\ATEPMon.sys []
S3 Boonty Games;Boonty Games;C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe [2007-09-23 00:34]
S3 BRGSp50;BRGSp50 NDIS Protocol Driver;C:\WINDOWS\system32\Drivers\BRGSp50.sys [2005-06-08 18:44]
S3 SCREAMINGBDRIVER;Screaming Bee
Audio;C:\WINDOWS\system32\drivers\ScreamingBAudio.
sys []

[HKEY_CURRENT_USER\software\microsoft\windows\curr
entversion\explorer\mountpoints2\{2863cd23-54d8-11
dd-a97b-00038a000015}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL O:\m.exe /s

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed
components\{2BEB57E4-E42A-6FB1-6E3E-A207C0C910FC}]

C:\Program Files\Bifrost\server.exe s
.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
"2008-07-19 22:24:01 C:\WINDOWS\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job"

-_Jeff_Hardy_-
-_Jeff_Hardy_-
Niveau 7
20 juillet 2008 à 11:25:23

voila le rapport de comboxfix j'attend tes futurs messages

icepeak
icepeak
Niveau 9
20 juillet 2008 à 14:00:21

j'ai déjà eu un virus similaire
et j'en ai littéralement " chier " pour l'enlever mais j'y suis arrivée.
sous vista, avec AVG je n'ai plus aucun problème .

Dorian_31
Dorian_31
Niveau 18
20 juillet 2008 à 14:22:11

pas besoin de hijackthis, on voit bien que c'est le rogue de base ce truc

analyse antivir + AVG, suppression directe de tout ce qui est louche, puis mise a jour windows et un bon scan ad aware par dessus

-_Jeff_Hardy_-
-_Jeff_Hardy_-
Niveau 7
20 juillet 2008 à 15:27:12

no j'ai deja fais tt sa et en fait avec ce que m'a fais faire wiwi77 ca marche pour linstant plus de traces de spyware ^^

wiwi77
wiwi77
Niveau 10
20 juillet 2008 à 15:32:35

-_Jeff_Hardy_- :d) ComboFix a supprimé pas mal d'infections mais ce n'est pas fini.

Télécharge Toolbar-S&D (Team IDN) sur ton Bureau.
http://eric.71.mespages.g.googlepages.com/ToolBarSD.exe

  • Lance l'installation du programme en exécutant le fichier téléchargé.
  • Double-clique maintenant sur le raccourci de Toolbar-S&D.
  • Sélectionne la langue souhaitée en tapant la lettre de ton choix puis en validant avec la touche Entrée.
  • Choisis maintenant l'option 1 (Recherche). Patiente jusqu'à la fin de la recherche.
  • Poste le rapport généré. (C:\TB.txt)
-_Jeff_Hardy_-
-_Jeff_Hardy_-
Niveau 7
20 juillet 2008 à 17:28:49

:ok: je fais sa merci =)

-_Jeff_Hardy_-
-_Jeff_Hardy_-
Niveau 7
20 juillet 2008 à 17:32:36

-----------\\ ToolBar S&D 1.0.6 XP/Vista

[ Windows XP (NT 5.1) Build 2600, Service Pack 2 ]
[ USER : Utilisateur ] [ "C:\Toolbar SD" ] [ Selection : 1 ]
[ 2008-07-20 | 17:30:00.62 ] [ PC : NOM-E9D83E00874 ]
[ MAJ : 18-07-2008 | 20:45 ]

-----------\\ Recherche de Fichiers / Dossiers ...

C:\Program Files\P2P_Torrent
C:\WINDOWS\iun6002.exe
\...\{bc4be15d-6a34-4356-9e97-79e43da32b1d} - (p2p_torrent)

-----------\\ Extensions

(All Users) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar

(Utilisateur) - {19503e42-ca3c-4c27-b1e2-9cdb2170ee34} => flashgot
(Utilisateur) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
(Utilisateur) - {b9db16a4-6edc-47ec-a1f4-b86292ed211d} => dwhelper
(Utilisateur) - {bc4be15d-6a34-4356-9e97-79e43da32b1d} => p2p_torrent

-----------\\ [..\Internet Explorer\Main]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Local Page"="C:\\WINDOWS\\system32\\blank.htm"
"Start Page"="http://www.google.fr/"
"Search Page"="http://www.google.com"
"Search Bar"="http://www.google.com/ie"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]

"Default_Page_URL"="http://go.microsoft.com/fwlink
/?LinkId=69157"
"Default_Search_URL"="http://www.google.com/ie"
"Search
Page"="http://go.microsoft.com/fwlink/?LinkId=5489
6"
"Start Page"="http://fr.yahoo.com"
"Search
Bar"="http://ie.search.msn.com/{SUB_RFC1766}/srcha
sst/srchasst.htm"

-----------\\ Fin du rapport a 17:30:59.25

wiwi77
wiwi77
Niveau 10
20 juillet 2008 à 18:01:17

Fais l'option 2 puis fais ceci :

- Télécharge et installe MalwareByte's Anti-Malware :
http://www.download.com/Malwarebytes-Anti-Malware/3000-8022_4-10804572.htm

- Mets-le à jour

- Redémarre en mode sans échec (Recommandé) :
http://www.malekal.com/modesansechec.php

- Choisis ta session habituelle

- Fais un scan complet avec MalwareByte's Anti-Malware

- Supprime tout ce que le logiciel trouve, enregistre le rapport

- Redémarre en mode normal et poste le rapport ici

Tutorial :
http://www.malekal.com/tutorial_MalwareBytes_AntiMalware.php

Sous forums
  • Aide à l'achat Mac
  • Macintosh
  • Création de Jeux
  • Programmation
  • Création de sites web
  • Linux
  • Internet
  • Steam Deck
  • Hardware
La vidéo du moment