
|
|
|
Auteur
|
Message
|
1
|
|
|
|
bonsoir avast ma detesté un cheval de troie que j arrete pas
a le stoppé je le met en quarantaine mais il reviens
il es dans C:\Documents and Settings\All Users\Application Data\soft ref platform bind\DOWNLOAD MANAGER.ex
le noms du logiciel malveillant et Win32:Swizzor [Trj]
pourrait vous m'aide parce il arrete ps de se declenche
merci sa serai gentil de votre part
|
|
La planète bleue...
|
|
|
Bonjour,
Va falloir penser à faire attention, ce n'est pas la première fois que je te vois ici ...
Désinstalle via "Ajout/Suppression de programmes" :
Cid help
Circle Developement
Adverts
Le sponsor de MSN Plus!
Télécharge LopS&D.exe sur ton bureau (Clique-droit sur le lien > Enregister la cible du lien sous)
Désactive ton antivirus au cas où (tu pourras le réactiver après la fin du scan)
Double-clique sur lopSD pour lancer l'installation
Une fois installé, double-clique Lop S&D
Sélectionne la langue en appuyant sur la touche F, puis choisis l'option 1 (Recherche)
Si lopSD te demande de redémarrer accepte et attends la fin du scan.
Copie/colle le contenu du rapport qui se situe à la racine du DD C:\lopR.txt
|
|
|
|
|
|
je vous donne tout le contenu du scann ?
|
|
La planète bleue...
|
|
|
|
|
-----------------------[ Lop S&D 4.2.2-1 XP/Vista ]---------------------
[ Windows XP (NT 5.1) Build 2600, Service Pack 2 ]
[ USER : wendy ] [ "C:\Lop SD" ] [ Selection : 1 ]
[ 16/07/2008 | 22:14:09,67 ] [ PC : ACER-A38B4A0260 ]
[ MAJ : 09-07-2008 | 21:02 ]
-------------[ Listing des dossiers dans Application Data ]------------
[12/08/2005|18:42] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Adobe
[25/06/2005|07:34] C:\DOCUME~1\DEFAUL~1\APPLIC~1\desktop.ini
[25/06/2005|07:45] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Identities
[25/06/2005|07:33] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
[25/06/2005|07:51] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Symantec
[25/06/2005|07:47] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[25/06/2005|07:50] C:\DOCUME~1\ALLUSE~1\APPLIC~1\CyberLink
[25/06/2005|07:34] C:\DOCUME~1\ALLUSE~1\APPLIC~1\desktop.ini
[03/03/2008|15:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Downloaded Installations
[03/03/2008|16:55] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
[03/06/2008|17:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\HP
[17/06/2008|22:51] C:\DOCUME~1\ALLUSE~1\APPLIC~1\hpzinstall.log
[03/03/2008|15:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
[25/06/2005|07:33] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[27/05/2008|07:07] C:\DOCUME~1\ALLUSE~1\APPLIC~1\soft ref platform bind
[03/06/2008|17:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Sonic
[04/03/2008|18:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
[25/06/2005|07:50] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec
[03/03/2008|17:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\title tool face bin
[03/03/2008|15:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[03/03/2008|16:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Live Toolbar
[03/03/2008|16:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
[03/03/2008|15:43] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Yahoo! Companion
[25/06/2005|07:33] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft
[25/06/2005|07:33] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft
[12/08/2005|18:42] C:\DOCUME~1\wendy\APPLIC~1\Adobe
[07/03/2008|00:40] C:\DOCUME~1\wendy\APPLIC~1\ArcSoft
[25/06/2005|07:34] C:\DOCUME~1\wendy\APPLIC~1\desktop.ini
[03/03/2008|17:19] C:\DOCUME~1\wendy\APPLIC~1\Else plus
[04/03/2008|08:19] C:\DOCUME~1\wendy\APPLIC~1\Google
[06/06/2008|15:04] C:\DOCUME~1\wendy\APPLIC~1\HP
[25/06/2005|07:45] C:\DOCUME~1\wendy\APPLIC~1\Identities
[12/03/2008|15:20] C:\DOCUME~1\wendy\APPLIC~1\LimeWire
[03/03/2008|16:22] C:\DOCUME~1\wendy\APPLIC~1\Macromedia
[25/06/2005|07:33] C:\DOCUME~1\wendy\APPLIC~1\Microsoft
[03/03/2008|15:34] C:\DOCUME~1\wendy\APPLIC~1\Mozilla
[21/03/2008|09:59] C:\DOCUME~1\wendy\APPLIC~1\Sun
[25/06/2005|07:51] C:\DOCUME~1\wendy\APPLIC~1\Symantec
[17/03/2008|20:00] C:\DOCUME~1\wendy\APPLIC~1\vlc
----------------[ Tâches planifiées dans C:\WINDOWS\tasks ]---------------
[15/07/2008 23:55][--a------] C:\WINDOWS\tasks\WebReg Photosmart C4100 series.job
[16/07/2008 21:23][--a------] C:\WINDOWS\tasks\V‚rifier les mises … jour de Windows Live Toolbar.job
[16/07/2008 22:01][--ah-----] C:\WINDOWS\tasks\SA.DAT
[05/08/2004 05:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini
---------------[ Listing des dossiers dans C:\Program Files ]--------------
[25/06/2005|19:15] C:\Program Files\acer
[25/06/2005|07:47] C:\Program Files\Adobe
[03/03/2008|15:38] C:\Program Files\Alwil Software
[10/06/2008|19:24] C:\Program Files\AxBx
[03/03/2008|15:33] C:\Program Files\CCleaner
[20/03/2008|16:56] C:\Program Files\Common Files
[25/06/2005|07:36] C:\Program Files\ComPlus Applications
[25/06/2005|07:50] C:\Program Files\CyberLink
[21/06/2008|14:21] C:\Program Files\Else plus
[15/03/2008|01:52] C:\Program Files\FBrowserAdvisor
[25/06/2005|07:34] C:\Program Files\Fichiers communs
[04/03/2008|03:07] C:\Program Files\Google
[08/07/2008|01:07] C:\Program Files\Hercules
[03/06/2008|17:18] C:\Program Files\Hewlett-Packard
[03/06/2008|17:09] C:\Program Files\HP
[25/06/2005|07:43] C:\Program Files\InstallShield Installation Information
[25/06/2005|07:36] C:\Program Files\Internet Explorer
[03/03/2008|13:35] C:\Program Files\Java
[02/06/2008|09:44] C:\Program Files\Lavalys
[28/05/2008|18:54] C:\Program Files\Lavasoft
[08/06/2008|15:58] C:\Program Files\LimeWire
[25/06/2005|07:35] C:\Program Files\Messenger
[03/03/2008|17:19] C:\Program Files\Messenger Plus! Live
[23/03/2008|22:26] C:\Program Files\MessengerDiscovery
[04/03/2008|08:32] C:\Program Files\Microsoft CAPICOM 2.1.0.2
[25/06/2005|07:37] C:\Program Files\microsoft frontpage
[25/06/2005|07:36] C:\Program Files\Movie Maker
[03/03/2008|15:34] C:\Program Files\Mozilla Firefox
[25/06/2005|07:35] C:\Program Files\MSN
[25/06/2005|07:35] C:\Program Files\MSN Gaming Zone
[04/06/2008|12:23] C:\Program Files\MSXML 4.0
[25/06/2005|07:36] C:\Program Files\NetMeeting
[25/06/2005|07:48] C:\Program Files\NewTech Infosystems
[25/06/2005|07:51] C:\Program Files\Norton AntiVirus
[25/06/2005|07:35] C:\Program Files\Online Services
[25/06/2005|07:36] C:\Program Files\Outlook Express
[14/04/2008|17:35] C:\Program Files\PhotoFiltre
[25/06/2005|07:44] C:\Program Files\Realtek
[14/04/2008|17:30] C:\Program Files\Seagrand
[25/06/2005|07:36] C:\Program Files\Services en ligne
[08/03/2008|01:11] C:\Program Files\Smilebox
[04/03/2008|18:06] C:\Program Files\Spybot - Search & Destroy
[25/06/2005|07:50] C:\Program Files\Symantec
[25/06/2005|07:45] C:\Program Files\Uninstall Information
[03/03/2008|14:12] C:\Program Files\USB Driver-Express
[03/07/2008|12:01] C:\Program Files\VCW VicMan's Photo Editor
[17/03/2008|17:31] C:\Program Files\VideoLAN
[03/03/2008|16:25] C:\Program Files\Windows Live
[03/03/2008|16:05] C:\Program Files\Windows Live Favorites
[03/03/2008|16:04] C:\Program Files\Windows Live Toolbar
[03/03/2008|15:47] C:\Program Files\Windows Media Connect 2
[25/06/2005|07:35] C:\Program Files\Windows Media Player
[25/06/2005|07:35] C:\Program Files\Windows NT
[25/06/2005|07:36] C:\Program Files\WindowsUpdate
[25/06/2005|07:37] C:\Program Files\xerox
[03/03/2008|15:33] C:\Program Files\Yahoo!
------[ Listing des dossiers dans C:\Program Files\Fichiers communs ]------
[25/06/2005|07:47] C:\Program Files\Fichiers communs\Adobe
[03/03/2008|13:36] C:\Program Files\Fichiers communs\ArcSoft
[03/06/2008|17:15] C:\Program Files\Fichiers communs\Hewlett-Packard
[03/06/2008|17:24] C:\Program Files\Fichiers communs\HP
[25/06/2005|07:43] C:\Program Files\Fichiers communs\InstallShield
[03/03/2008|13:35] C:\Program Files\Fichiers communs\Java
[25/06/2005|07:34] C:\Program Files\Fichiers communs\Microsoft Shared
[25/06/2005|07:36] C:\Program Files\Fichiers communs\MSSoap
[25/06/2005|07:48] C:\Program Files\Fichiers communs\muvee Technologies
[25/06/2005|07:48] C:\Program Files\Fichiers communs\NewTech Infosystems
[25/06/2005|07:34] C:\Program Files\Fichiers communs\ODBC
[25/06/2005|07:36] C:\Program Files\Fichiers communs\Services
[03/06/2008|17:27] C:\Program Files\Fichiers communs\Sonic Shared
[25/06/2005|07:34] C:\Program Files\Fichiers communs\SpeechEngines
[25/06/2005|07:50] C:\Program Files\Fichiers communs\Symantec Shared
[25/06/2005|07:36] C:\Program Files\Fichiers communs\System
[03/03/2008|16:25] C:\Program Files\Fichiers communs\WindowsLiveInstaller
[28/05/2008|18:53] C:\Program Files\Fichiers communs\Wise Installation Wizard
---------------------------[ Process ]--------------------------
... 42
... OK !
----------------------[ Recherche avec S_Lop ]---------------------
Aucun fichier / dossier Lop trouvé !
-----------------[ Recherche de Fichiers / Dossiers Lop ]-----------------
C:\DOCUME~1\wendy\APPLIC~1\ELSE PLUS
C:\DOCUME~1\wendy\APPLIC~1\ELSE PLUS\AXISNEW.exe
C:\DOCUME~1\wendy\APPLIC~1\ELSE PLUS\uplctzqj.exe
C:\DOCUME~1\wendy\APPLIC~1\ELSE PLUS\JoyPokeForkBlue.exe
C:\DOCUME~1\wendy\APPLIC~1\ELSE PLUS\imyhenyr.exe
C:\DOCUME~1\wendy\APPLIC~1\ELSE PLUS\jzixifvi.exe
C:\DOCUME~1\wendy\APPLIC~1\ELSE PLUS\smwlvvqp.exe
C:\DOCUME~1\wendy\APPLIC~1\ELSE PLUS\kommgnyb.exe
C:\Program Files\ELSE PLUS
C:\DOCUME~1\ALLUSE~1\APPLIC~1\soft ref platform bind
C:\DOCUME~1\ALLUSE~1\APPLIC~1\soft ref platform bind\DOWNLOAD MANAGER.exe
C:\DOCUME~1\ALLUSE~1\APPLIC~1\title tool face bin
C:\WINDOWS\Prefetch\AXISNEW.EXE-348495E9.pf
C:\WINDOWS\Prefetch\DOWNLOAD MANAGER.EXE-06E55476.pf
----------------------[ Verification du Registre ]----------------------
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"platform bind axis time"="C:\\Documents and Settings\\All Users\\Application Data\\soft ref platform bind\\DOWNLOAD MANAGER.exe"
--------------------[ Verification du fichier Hosts ]---------------------
Fichier Hosts MODIFIE
127.0.0.1 bin.errorprotector.com ## added by CiD
127.0.0.1 br.errorsafe.com ## added by CiD
127.0.0.1 br.winantivirus.com ## added by CiD
127.0.0.1 br.winfixer.com ## added by CiD
127.0.0.1 cdn.drivecleaner.com ## added by CiD
127.0.0.1 cdn.errorsafe.com ## added by CiD
127.0.0.1 cdn.winsoftware.com ## added by CiD
127.0.0.1 de.errorsafe.com ## added by CiD
127.0.0.1 de.winantivirus.com ## added by CiD
127.0.0.1 download.cdn.drivecleaner.com ## added by CiD
127.0.0.1 download.cdn.errorsafe.com ## added by CiD
127.0.0.1 download.cdn.winsoftware.com ## added by CiD
127.0.0.1 download.errorsafe.com ## added by CiD
127.0.0.1 download.systemdoctor.com ## added by CiD
127.0.0.1 download.winantispyware.com ## added by CiD
127.0.0.1 download.windrivecleaner.com ## added by CiD
127.0.0.1 download.winfixer.com ## added by CiD
127.0.0.1 drivecleaner.com ## added by CiD
127.0.0.1 dynamique.drivecleaner.com ## added by CiD
127.0.0.1 errorprotector.com ## added by CiD
127.0.0.1 errorsafe.com ## added by CiD
127.0.0.1 es.winantivirus.com ## added by CiD
127.0.0.1 fr.winantivirus.com ## added by CiD
127.0.0.1 fr.winfixer.com ## added by CiD
127.0.0.1 go.drivecleaner.com ## added by CiD
127.0.0.1 go.errorsafe.com ## added by CiD
127.0.0.1 go.winantispyware.com ## added by CiD
127.0.0.1 go.winantivirus.com ## added by CiD
127.0.0.1 hk.winantivirus.com ## added by CiD
127.0.0.1 instlog.errorsafe.com ## added by CiD
127.0.0.1 instlog.winantivirus.com ## added by CiD
127.0.0.1 instlog.winfixer.com ## added by CiD
127.0.0.1 jsp.drivecleaner.com ## added by CiD
127.0.0.1 kb.errorsafe.com ## added by CiD
127.0.0.1 kb.winantivirus.com ## added by CiD
127.0.0.1 nl.errorsafe.com ## added by CiD
127.0.0.1 se.errorsafe.com ## added by CiD
127.0.0.1 secure.drivecleaner.com ## added by CiD
127.0.0.1 secure.errorsafe.com ## added by CiD
127.0.0.1 secure.winantispam.com ## added by CiD
127.0.0.1 secure.winantispy.com ## added by CiD
127.0.0.1 secure.winantivirus.com ## added by CiD
127.0.0.1 support.winantivirus.com ## added by CiD
127.0.0.1 trial.updates.winsoftware.com ## added by CiD
127.0.0.1 ulog.winantivirus.com ## added by CiD
127.0.0.1 utils.errorsafe.com ## added by CiD
127.0.0.1 utils.winantivirus.com ## added by CiD
127.0.0.1 utils.winfixer.com ## added by CiD
127.0.0.1 winantispyware.com ## added by CiD
127.0.0.1 winantivirus.com ## added by CiD
127.0.0.1 winfixer.com ## added by CiD
127.0.0.1 winfixer2006.com ## added by CiD
127.0.0.1 winsoftware.com ## added by CiD
127.0.0.1 www.drivecleaner.com ## added by CiD
127.0.0.1 www.errorprotector.com ## added by CiD
127.0.0.1 www.errorsafe.com ## added by CiD
127.0.0.1 www.systemdoctor.com ## added by CiD
127.0.0.1 www.utils.winfixer.com ## added by CiD
127.0.0.1 www.win-anti-virus-pro.com ## added by CiD
127.0.0.1 www.win-virus-pro.com ## added by CiD
127.0.0.1 www.winantispam.com ## added by CiD
127.0.0.1 www.winantispy.com ## added by CiD
127.0.0.1 www.winantispyware.com ## added by CiD
127.0.0.1 www.winantivirus.com ## added by CiD
127.0.0.1 www.winantiviruspro.com ## added by CiD
127.0.0.1 www.windrivecleaner.com ## added by CiD
127.0.0.1 www.windrivesafe.com ## added by CiD
127.0.0.1 www.winfixer.com ## added by CiD
127.0.0.1 www.winfixer2006.com ## added by CiD
127.0.0.1 www.winsoftware.com ## added by CiD
-> 72 ( 70 ## added by CiD )
/!\ 1 Not 127.0.0.1 !!
----------------[ Recherche de fichiers avec Catchme ]-----------------
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-16 22:15:44
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 0
--------------------[ Recherche d'autres infections ]---------------------
Aucune autre infection trouvée !
[F:99][D:9]-> C:\DOCUME~1\wendy\LOCALS~1\Temp
[F:13][D:0]-> C:\DOCUME~1\wendy\Cookies
[F:315][D:32]-> C:\DOCUME~1\wendy\LOCALS~1\TEMPOR~1\content.IE5
[F:20][D:5]-> C:\Recycled
--------------------[ Fin du rapport a 22:15:59,73 ]----------------------
|
|
La planète bleue...
|
|
|
Relance LopS&D
Choisis l'option 2
Copie/colle le rapport (C:\lopR.txt)
-------
Télécharge HijackThis
Installe le à la racine de ton disque (C:\)
Lance HijackThis en double-cliquant sur l'icône HijackThis
Clique sur Do a system Scan only and Save a Logfile
Un rapport sera généré dans le bloc-note (le rapport est également situé ici : C:\hijackthis.log)
Copie/colle le rapport dans ton prochain message.
Voici une aide en image si tu n'y arrives pas :
http://forum.telecharger.01net.com/microhebdo/questions_techniques_diverses/s(...)
|
|
|
|
|
-----------------------[ Lop S&D 4.2.2-1 XP/Vista ]---------------------
[ Windows XP (NT 5.1) Build 2600, Service Pack 2 ]
[ USER : wendy ] [ "C:\Lop SD" ] [ Selection : 2 ]
[ 16/07/2008 | 23:13:27,37 ] [ PC : ACER-A38B4A0260 ]
[ MAJ : 09-07-2008 | 21:02 ]
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ SUPPRESSION /////////////////////////////
Supprime! - C:\DOCUME~1\wendy\APPLIC~1\ELSE PLUS\AXISNEW.exe
Supprime! - C:\DOCUME~1\wendy\APPLIC~1\ELSE PLUS\uplctzqj.exe
Supprime! - C:\DOCUME~1\wendy\APPLIC~1\ELSE PLUS\JoyPokeForkBlue.exe
Supprime! - C:\DOCUME~1\wendy\APPLIC~1\ELSE PLUS\imyhenyr.exe
Supprime! - C:\DOCUME~1\wendy\APPLIC~1\ELSE PLUS\jzixifvi.exe
Supprime! - C:\DOCUME~1\wendy\APPLIC~1\ELSE PLUS\smwlvvqp.exe
Supprime! - C:\DOCUME~1\wendy\APPLIC~1\ELSE PLUS\kommgnyb.exe
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\soft ref platform bind\DOWNLOAD MANAGER.exe
Supprime! - C:\WINDOWS\Prefetch\AXISNEW.EXE-348495E9.pf
Supprime! - C:\WINDOWS\Prefetch\DOWNLOAD MANAGER.EXE-06E55476.pf
Supprime! - C:\DOCUME~1\wendy\APPLIC~1\ELSE PLUS
Supprime! - C:\Program Files\ELSE PLUS
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\soft ref platform bind
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\title tool face bin
RestaurÚ! - Fichier Hosts
//////////////////////////////////////-\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
-------------[ Listing des dossiers dans APPLIC~1 ]------------
[12/08/2005|18:42] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Adobe
[25/06/2005|07:34] C:\DOCUME~1\DEFAUL~1\APPLIC~1\desktop.ini
[25/06/2005|07:45] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Identities
[25/06/2005|07:33] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
[25/06/2005|07:51] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Symantec
[25/06/2005|07:47] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[25/06/2005|07:50] C:\DOCUME~1\ALLUSE~1\APPLIC~1\CyberLink
[25/06/2005|07:34] C:\DOCUME~1\ALLUSE~1\APPLIC~1\desktop.ini
[03/03/2008|15:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Downloaded Installations
[03/03/2008|16:55] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
[03/06/2008|17:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\HP
[17/06/2008|22:51] C:\DOCUME~1\ALLUSE~1\APPLIC~1\hpzinstall.log
[03/03/2008|15:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
[25/06/2005|07:33] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[03/06/2008|17:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Sonic
[04/03/2008|18:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
[25/06/2005|07:50] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec
[03/03/2008|15:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[03/03/2008|16:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Live Toolbar
[03/03/2008|16:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
[03/03/2008|15:43] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Yahoo! Companion
[25/06/2005|07:33] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft
[25/06/2005|07:33] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft
[12/08/2005|18:42] C:\DOCUME~1\wendy\APPLIC~1\Adobe
[07/03/2008|00:40] C:\DOCUME~1\wendy\APPLIC~1\ArcSoft
[25/06/2005|07:34] C:\DOCUME~1\wendy\APPLIC~1\desktop.ini
[04/03/2008|08:19] C:\DOCUME~1\wendy\APPLIC~1\Google
[06/06/2008|15:04] C:\DOCUME~1\wendy\APPLIC~1\HP
[25/06/2005|07:45] C:\DOCUME~1\wendy\APPLIC~1\Identities
[12/03/2008|15:20] C:\DOCUME~1\wendy\APPLIC~1\LimeWire
[03/03/2008|16:22] C:\DOCUME~1\wendy\APPLIC~1\Macromedia
[25/06/2005|07:33] C:\DOCUME~1\wendy\APPLIC~1\Microsoft
[03/03/2008|15:34] C:\DOCUME~1\wendy\APPLIC~1\Mozilla
[21/03/2008|09:59] C:\DOCUME~1\wendy\APPLIC~1\Sun
[25/06/2005|07:51] C:\DOCUME~1\wendy\APPLIC~1\Symantec
[17/03/2008|20:00] C:\DOCUME~1\wendy\APPLIC~1\vlc
----------------[ Tâches planifiées dans C:\WINDOWS\tasks ]---------------
[15/07/2008 23:55][--a------] C:\WINDOWS\tasks\WebReg Photosmart C4100 series.job
[16/07/2008 22:23][--a------] C:\WINDOWS\tasks\V‚rifier les mises … jour de Windows Live Toolbar.job
[16/07/2008 22:01][--ah-----] C:\WINDOWS\tasks\SA.DAT
[05/08/2004 05:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini
---------------[ Listing des dossiers dans C:\Program Files ]--------------
[25/06/2005|19:15] C:\Program Files\acer
[25/06/2005|07:47] C:\Program Files\Adobe
[03/03/2008|15:38] C:\Program Files\Alwil Software
[10/06/2008|19:24] C:\Program Files\AxBx
[03/03/2008|15:33] C:\Program Files\CCleaner
[20/03/2008|16:56] C:\Program Files\Common Files
[25/06/2005|07:36] C:\Program Files\ComPlus Applications
[25/06/2005|07:50] C:\Program Files\CyberLink
[15/03/2008|01:52] C:\Program Files\FBrowserAdvisor
[25/06/2005|07:34] C:\Program Files\Fichiers communs
[04/03/2008|03:07] C:\Program Files\Google
[08/07/2008|01:07] C:\Program Files\Hercules
[03/06/2008|17:18] C:\Program Files\Hewlett-Packard
[03/06/2008|17:09] C:\Program Files\HP
[25/06/2005|07:43] C:\Program Files\InstallShield Installation Information
[25/06/2005|07:36] C:\Program Files\Internet Explorer
[03/03/2008|13:35] C:\Program Files\Java
[02/06/2008|09:44] C:\Program Files\Lavalys
[28/05/2008|18:54] C:\Program Files\Lavasoft
[08/06/2008|15:58] C:\Program Files\LimeWire
[25/06/2005|07:35] C:\Program Files\Messenger
[03/03/2008|17:19] C:\Program Files\Messenger Plus! Live
[23/03/2008|22:26] C:\Program Files\MessengerDiscovery
[04/03/2008|08:32] C:\Program Files\Microsoft CAPICOM 2.1.0.2
[25/06/2005|07:37] C:\Program Files\microsoft frontpage
[25/06/2005|07:36] C:\Program Files\Movie Maker
[03/03/2008|15:34] C:\Program Files\Mozilla Firefox
[25/06/2005|07:35] C:\Program Files\MSN
[25/06/2005|07:35] C:\Program Files\MSN Gaming Zone
[04/06/2008|12:23] C:\Program Files\MSXML 4.0
[25/06/2005|07:36] C:\Program Files\NetMeeting
[25/06/2005|07:48] C:\Program Files\NewTech Infosystems
[25/06/2005|07:51] C:\Program Files\Norton AntiVirus
[25/06/2005|07:35] C:\Program Files\Online Services
[25/06/2005|07:36] C:\Program Files\Outlook Express
[14/04/2008|17:35] C:\Program Files\PhotoFiltre
[25/06/2005|07:44] C:\Program Files\Realtek
[14/04/2008|17:30] C:\Program Files\Seagrand
[25/06/2005|07:36] C:\Program Files\Services en ligne
[08/03/2008|01:11] C:\Program Files\Smilebox
[04/03/2008|18:06] C:\Program Files\Spybot - Search & Destroy
[25/06/2005|07:50] C:\Program Files\Symantec
[25/06/2005|07:45] C:\Program Files\Uninstall Information
[03/03/2008|14:12] C:\Program Files\USB Driver-Express
[03/07/2008|12:01] C:\Program Files\VCW VicMan's Photo Editor
[17/03/2008|17:31] C:\Program Files\VideoLAN
[03/03/2008|16:25] C:\Program Files\Windows Live
[03/03/2008|16:05] C:\Program Files\Windows Live Favorites
[03/03/2008|16:04] C:\Program Files\Windows Live Toolbar
[03/03/2008|15:47] C:\Program Files\Windows Media Connect 2
[25/06/2005|07:35] C:\Program Files\Windows Media Player
[25/06/2005|07:35] C:\Program Files\Windows NT
[25/06/2005|07:36] C:\Program Files\WindowsUpdate
[25/06/2005|07:37] C:\Program Files\xerox
[03/03/2008|15:33] C:\Program Files\Yahoo!
------[ Listing des dossiers dans C:\Program Files\Fichiers communs ]------
[25/06/2005|07:47] C:\Program Files\Fichiers communs\Adobe
[03/03/2008|13:36] C:\Program Files\Fichiers communs\ArcSoft
[03/06/2008|17:15] C:\Program Files\Fichiers communs\Hewlett-Packard
[03/06/2008|17:24] C:\Program Files\Fichiers communs\HP
[25/06/2005|07:43] C:\Program Files\Fichiers communs\InstallShield
[03/03/2008|13:35] C:\Program Files\Fichiers communs\Java
[25/06/2005|07:34] C:\Program Files\Fichiers communs\Microsoft Shared
[25/06/2005|07:36] C:\Program Files\Fichiers communs\MSSoap
[25/06/2005|07:48] C:\Program Files\Fichiers communs\muvee Technologies
[25/06/2005|07:48] C:\Program Files\Fichiers communs\NewTech Infosystems
[25/06/2005|07:34] C:\Program Files\Fichiers communs\ODBC
[25/06/2005|07:36] C:\Program Files\Fichiers communs\Services
[03/06/2008|17:27] C:\Program Files\Fichiers communs\Sonic Shared
[25/06/2005|07:34] C:\Program Files\Fichiers communs\SpeechEngines
[25/06/2005|07:50] C:\Program Files\Fichiers communs\Symantec Shared
[25/06/2005|07:36] C:\Program Files\Fichiers communs\System
[03/03/2008|16:25] C:\Program Files\Fichiers communs\WindowsLiveInstaller
[28/05/2008|18:53] C:\Program Files\Fichiers communs\Wise Installation Wizard
---------------------------[ Process ]--------------------------
... 46
... OK !
----------------------[ Recherche avec S_Lop ]---------------------
Aucun fichier / dossier Lop trouvé !
-----------------[ Recherche de Fichiers / Dossiers Lop ]-----------------
Aucun fichier / dossier Lop trouvé !
----------------------[ Verification du Registre ]----------------------
..... OK !
--------------------[ Verification du fichier Hosts ]---------------------
Fichier Hosts PROPRE
----------------[ Recherche de fichiers avec Catchme ]-----------------
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-16 23:16:33
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 0
--------------------[ Recherche d'autres infections ]---------------------
Aucune autre infection trouvée !
[F:106][D:10]-> C:\DOCUME~1\wendy\LOCALS~1\Temp
[F:27][D:0]-> C:\DOCUME~1\wendy\Cookies
[F:516][D:32]-> C:\DOCUME~1\wendy\LOCALS~1\TEMPOR~1\content.IE5
[F:20][D:5]-> C:\Recycled
--------------------[ Fin du rapport a 23:16:55,68 ]----------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:18:53, on 16/07/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\acer\Acer eConsole\MediaServerService.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
C:\Program Files\Acer\eRecovery\Monitor.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Acer\Acer eMode Management\AspireService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\ntvdm.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\MessengerDiscovery\MessengerDiscovery Live.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.fr/0SEFRFR/SAOS02
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.neuf.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://global.acer.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [LaunchApp] Alaunch
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [ntiMUI] c:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [eRecoveryService] C:\Program Files\Acer\eRecovery\Monitor.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [AspireService] C:\Program Files\Acer\Acer eMode Management\AspireService.exe
O4 - HKLM\..\Run: [MediaSync] C:\Program Files\Acer\Acer eConsole\MediaSync.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\RunOnce: [MessengerPlusLiveUninstall] "C:\DOCUME~1\wendy\LOCALS~1\Temp\MsgPlusUninstall.exe" /Cleanup
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Démarrage rapide de HP Photosmart Premier.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://webscanner.kaspersky.fr/kavwebscan_unicode.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} (Slide Image Uploader Control) - http://static.slide.com/uploader/SlideImageUploader.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Acer Media Server - Acer Inc. - C:\Program Files\acer\Acer eConsole\MediaServerService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
--
End of file - 9401 bytes
|
|
La planète bleue...
|
|
|
BitDefender
Fais un scan en ligne Bitdefender
Une fois sur le site clique sur le bouton BitDefender Scan Online >
Vois la démo de Balltrap34 si tu n'y arrives pas
Copie/colle le rapport final.Il me faut le rapport détaillé, et non celui avec seulement le nom des infections.
|
|
1
|
|

|
Kaspersky Antivirus 2009
 |
Plus simple, plus rapide et plus sûre.
Cette nouvelle version protège votre
poste informatique des menaces rencontrées sur le Web. Le logiciel une protection préventive, un module de restauration, un antispam, un antispyware …
|




|