

colomber77
Membres-
Compteur de contenus
4 -
Inscription
-
Dernière visite
Type de contenu
Profils
Forums
Blogs
Tout ce qui a été posté par colomber77
-
à propos de mon log Hijackthis
colomber77 a répondu à un(e) sujet de colomber77 dans Analyses et éradication malwares
j'ai refait un scan il est plsu verbeux voilà ce que j'obtiens: C:\WINDOWS\System32\datestamp.dll -->05/09/2006 12:51:23 C:\WINDOWS\System32\nvapps.xml -->30/08/2006 23:20:22 C:\WINDOWS\System32\wpa.dbl -->18/08/2006 20:19:22 C:\WINDOWS\System32\hpzjrd01.dll -->04/08/2006 08:36:04 C:\WINDOWS\System32\MRT.exe -->03/08/2006 03:22:50 C:\WINDOWS\System32\FNTCACHE.DAT -->01/08/2006 21:11:57 C:\WINDOWS\System32\ROXECDC6Inst.log -->01/08/2006 21:08:40 C:\WINDOWS\System32\PQ_DEBUG.TXT -->31/07/2006 13:51:00 C:\WINDOWS\System32\statistics.xml -->30/07/2006 18:51:33 C:\WINDOWS\System32\mshtml.dll -->28/07/2006 13:28:08 C:\WINDOWS\System32\inetcomm.dll -->27/07/2006 15:26:19 C:\WINDOWS\System32\urlmon.dll -->25/07/2006 22:41:01 C:\WINDOWS\System32\hlink.dll -->21/07/2006 10:27:28 C:\WINDOWS\System32\netapi32.dll -->14/07/2006 17:41:05 C:\WINDOWS\System32\hhctrl.ocx -->14/07/2006 17:27:53 C:\WINDOWS\System32\shell32.dll -->13/07/2006 15:36:01 C:\WINDOWS\System32\PerfStringBackup.INI -->13/07/2006 03:12:05 C:\WINDOWS\System32\perfh00C.dat -->13/07/2006 03:12:05 C:\WINDOWS\System32\perfh009.dat -->13/07/2006 03:12:05 C:\WINDOWS\System32\perfc00C.dat -->13/07/2006 03:12:05 C:\WINDOWS\System32\perfc009.dat -->13/07/2006 03:12:05 C:\WINDOWS\System32\kernel32.dll -->05/07/2006 12:56:38 C:\WINDOWS\System32\rasadhlp.dll -->26/06/2006 19:41:32 C:\WINDOWS\System32\dnsapi.dll -->26/06/2006 19:41:32 C:\WINDOWS\System32\wininet.dll -->23/06/2006 13:11:45 C:\WINDOWS\WindowsUpdate.log -->06/09/2006 09:05:41 C:\WINDOWS\wmsetup.log -->05/09/2006 06:49:06 C:\WINDOWS\QTFont.qfn -->04/09/2006 20:27:00 C:\WINDOWS\setupapi.log -->31/08/2006 15:36:11 C:\WINDOWS\wiadebug.log -->31/08/2006 15:27:57 C:\WINDOWS\wiaservc.log -->31/08/2006 15:27:56 C:\WINDOWS\SchedLgU.Txt -->31/08/2006 14:34:00 C:\WINDOWS\0.log -->30/08/2006 23:20:55 C:\WINDOWS\bootstat.dat -->30/08/2006 23:19:34 C:\WINDOWS\QTFont.for -->30/08/2006 21:02:01 C:\WINDOWS\setupact.log -->27/08/2006 11:23:16 C:\WINDOWS\muveeapp.INI -->23/08/2006 22:29:34 C:\WINDOWS\setuperr.log -->21/08/2006 12:51:42 C:\WINDOWS\Win.ini -->20/08/2006 23:13:59 C:\WINDOWS\Sti_Trace.log -->11/08/2006 13:40:39 C:\WINDOWS\amcap.exe |11/06/2006 13:37:01 C:\WINDOWS\CleanDev.exe |11/06/2006 13:37:03 C:\WINDOWS\is-QF50A.exe |11/07/2006 09:55:56 C:\WINDOWS\UninstallFirefox.exe |16/02/2006 21:23:10 C:\WINDOWS\system32\append.exe |05/08/2004 14:00:00 C:\WINDOWS\system32\debug.exe |05/08/2004 14:00:00 C:\WINDOWS\system32\DivXsm.exe |24/05/2005 23:32:44 C:\WINDOWS\system32\dosx.exe |05/08/2004 20:00:00 C:\WINDOWS\system32\dvdplay.exe |05/08/2004 20:00:00 C:\WINDOWS\system32\edlin.exe |05/08/2004 14:00:00 C:\WINDOWS\system32\exe2bin.exe |05/08/2004 14:00:00 C:\WINDOWS\system32\fastopen.exe |05/08/2004 14:00:00 C:\WINDOWS\system32\mem.exe |05/08/2004 14:00:00 C:\WINDOWS\system32\mscdexnt.exe |05/08/2004 14:00:00 C:\WINDOWS\system32\nlsfunc.exe |05/08/2004 14:00:00 C:\WINDOWS\system32\nvappbar.exe |02/01/2005 02:32:19 C:\WINDOWS\system32\nvdspsch.exe |02/01/2005 02:32:20 C:\WINDOWS\system32\nwiz.exe |02/01/2005 02:32:21 C:\WINDOWS\system32\redir.exe |05/08/2004 20:00:00 C:\WINDOWS\system32\setver.exe |05/08/2004 14:00:00 C:\WINDOWS\system32\share.exe |05/08/2004 14:00:00 C:\WINDOWS\system32\wapisu.exe |22/04/2006 19:45:59 C:\WINDOWS\system32\34CoInstaller.dll |02/01/2005 02:34:04 C:\WINDOWS\system32\amstream.dll |05/08/2004 20:00:00 C:\WINDOWS\system32\avi.dll |03/07/2005 17:41:37 C:\WINDOWS\system32\BASSMOD.dll |11/06/2006 07:30:36 C:\WINDOWS\system32\bcbmm.dll |02/01/2005 02:19:13 C:\WINDOWS\system32\CddbLangFR.dll |27/08/2002 20:21:18 C:\WINDOWS\system32\compatUI.dll |05/08/2004 20:00:00 C:\WINDOWS\system32\cpuinf32.dll |27/02/2003 05:42:54 C:\WINDOWS\system32\encdec.dll |05/08/2004 20:00:00 C:\WINDOWS\system32\ff_liba52.dll |29/06/2005 18:25:22 C:\WINDOWS\system32\ff_libdts.dll |29/06/2005 18:25:36 C:\WINDOWS\system32\ff_libmad.dll |29/06/2005 18:26:55 C:\WINDOWS\system32\ff_realaac.dll |29/06/2005 18:27:17 C:\WINDOWS\system32\ff_samplerate.dll |29/06/2005 18:27:21 C:\WINDOWS\system32\ff_theora.dll |29/06/2005 18:27:48 C:\WINDOWS\system32\ff_tremor.dll |29/06/2005 18:28:00 C:\WINDOWS\system32\ff_unrar.dll |29/06/2005 18:28:39 C:\WINDOWS\system32\ff_vfw.dll |01/07/2005 12:52:07 C:\WINDOWS\system32\ff_wmv9.dll |29/06/2005 18:28:53 C:\WINDOWS\system32\ff_x264.dll |29/06/2005 18:19:58 C:\WINDOWS\system32\hpreg.dll |02/01/2005 02:59:04 C:\WINDOWS\system32\ieencode.dll |05/08/2004 20:00:00 C:\WINDOWS\system32\ir32_32.dll |05/08/2004 14:00:00 C:\WINDOWS\system32\IVIresize.dll |02/01/2005 02:50:12 C:\WINDOWS\system32\IVIresizeA6.dll |02/01/2005 02:50:12 C:\WINDOWS\system32\IVIresizeM6.dll |02/01/2005 02:50:12 C:\WINDOWS\system32\IVIresizeP6.dll |02/01/2005 02:50:12 C:\WINDOWS\system32\IVIresizePX.dll |02/01/2005 02:50:12 C:\WINDOWS\system32\IVIresizeW7.dll |02/01/2005 02:50:12 C:\WINDOWS\system32\lame_enc.dll |26/07/2004 13:12:52 C:\WINDOWS\system32\libavcodec.dll |03/07/2005 03:08:01 C:\WINDOWS\system32\libeay32.dll |28/04/2005 06:22:34 C:\WINDOWS\system32\libmpeg2_ff.dll |29/06/2005 18:19:32 C:\WINDOWS\system32\libmplayer.dll |29/06/2005 18:17:40 C:\WINDOWS\system32\mkx.dll |03/07/2005 17:41:24 C:\WINDOWS\system32\mp4.dll |03/07/2005 17:41:08 C:\WINDOWS\system32\mp4fil32.dll |18/05/2002 00:18:30 C:\WINDOWS\system32\mr310exd.dll |18/03/2006 19:36:04 C:\WINDOWS\system32\mr310exv.dll |18/03/2006 19:36:04 C:\WINDOWS\system32\msdmo.dll |05/08/2004 20:00:00 C:\WINDOWS\system32\msencode.dll |05/08/2004 14:00:00 C:\WINDOWS\system32\nvapi.dll |04/11/2005 18:03:00 C:\WINDOWS\system32\nview.dll |02/01/2005 02:32:20 C:\WINDOWS\system32\nvshell.dll |02/01/2005 02:32:20 C:\WINDOWS\system32\nvwdmcpl.dll |02/01/2005 02:32:20 C:\WINDOWS\system32\nvwimg.dll |02/01/2005 02:32:20 C:\WINDOWS\system32\ogg.dll |24/09/2004 11:10:48 C:\WINDOWS\system32\OggDS.dll |06/10/2002 21:42:58 C:\WINDOWS\system32\paqsp.dll |05/08/2004 20:00:00 C:\WINDOWS\system32\PhilTvRat.dll |02/01/2005 02:34:04 C:\WINDOWS\system32\PsisDecd.dll |02/01/2005 02:34:06 C:\WINDOWS\system32\pythoncom22.dll |02/01/2005 02:19:32 C:\WINDOWS\system32\pywintypes22.dll |02/01/2005 02:19:32 C:\WINDOWS\system32\qedwipes.dll |05/08/2004 20:00:00 C:\WINDOWS\system32\qt-dx331.dll |28/04/2005 06:22:38 C:\WINDOWS\system32\sbe.dll |05/08/2004 20:00:00 C:\WINDOWS\system32\ssleay32.dll |28/04/2005 06:22:34 C:\WINDOWS\system32\TomsMoComp_ff.dll |29/06/2005 18:36:41 C:\WINDOWS\system32\tsd32.dll |05/08/2004 14:00:00 C:\WINDOWS\system32\vorbis.dll |24/09/2004 11:09:56 C:\WINDOWS\system32\vorbisenc.dll |24/09/2004 11:09:58 C:\WINDOWS\system32\vorbisfile.dll |24/09/2004 11:09:42 C:\WINDOWS\system32\win87em.dll |05/08/2004 14:00:00 C:\WINDOWS\system32\x264vfw.dll |01/07/2005 19:10:26 C:\WINDOWS\system32\xvid.dll |22/05/2003 00:50:38 C:\WINDOWS\system32\xvidcore.dll |20/12/2004 13:03:26 C:\WINDOWS\system32\xvidvfw.dll |20/12/2004 13:08:28 C:\WINDOWS\amcap.exe |11/06/2006 13:37:01 C:\WINDOWS\UninstallFirefox.exe |16/02/2006 21:23:10 C:\WINDOWS\system32\append.exe |05/08/2004 14:00:00 C:\WINDOWS\system32\debug.exe |05/08/2004 14:00:00 C:\WINDOWS\system32\DivXsm.exe |24/05/2005 23:32:44 C:\WINDOWS\system32\dosx.exe |05/08/2004 20:00:00 C:\WINDOWS\system32\edlin.exe |05/08/2004 14:00:00 C:\WINDOWS\system32\exe2bin.exe |05/08/2004 14:00:00 C:\WINDOWS\system32\fastopen.exe |05/08/2004 14:00:00 C:\WINDOWS\system32\mem.exe |05/08/2004 14:00:00 C:\WINDOWS\system32\mscdexnt.exe |05/08/2004 14:00:00 C:\WINDOWS\system32\nlsfunc.exe |05/08/2004 14:00:00 C:\WINDOWS\system32\nvappbar.exe |02/01/2005 02:32:19 C:\WINDOWS\system32\nvdspsch.exe |02/01/2005 02:32:20 C:\WINDOWS\system32\nwiz.exe |02/01/2005 02:32:21 C:\WINDOWS\system32\redir.exe |05/08/2004 20:00:00 C:\WINDOWS\system32\setver.exe |05/08/2004 14:00:00 C:\WINDOWS\system32\share.exe |05/08/2004 14:00:00 C:\WINDOWS\system32\wapisu.exe |22/04/2006 19:45:59 C:\WINDOWS\system32\34CoInstaller.dll |02/01/2005 02:34:04 C:\WINDOWS\system32\amstream.dll |05/08/2004 20:00:00 C:\WINDOWS\system32\avi.dll |03/07/2005 17:41:37 C:\WINDOWS\system32\BASSMOD.dll |11/06/2006 07:30:36 C:\WINDOWS\system32\bcbmm.dll |02/01/2005 02:19:13 C:\WINDOWS\system32\CddbLangFR.dll |27/08/2002 20:21:18 C:\WINDOWS\system32\cpuinf32.dll |27/02/2003 05:42:54 C:\WINDOWS\system32\encdec.dll |05/08/2004 20:00:00 C:\WINDOWS\system32\ff_liba52.dll |29/06/2005 18:25:22 C:\WINDOWS\system32\ff_libdts.dll |29/06/2005 18:25:36 C:\WINDOWS\system32\ff_libmad.dll |29/06/2005 18:26:55 C:\WINDOWS\system32\ff_realaac.dll |29/06/2005 18:27:17 C:\WINDOWS\system32\ff_samplerate.dll |29/06/2005 18:27:21 C:\WINDOWS\system32\ff_theora.dll |29/06/2005 18:27:48 C:\WINDOWS\system32\ff_tremor.dll |29/06/2005 18:28:00 C:\WINDOWS\system32\ff_unrar.dll |29/06/2005 18:28:39 C:\WINDOWS\system32\ff_vfw.dll |01/07/2005 12:52:07 C:\WINDOWS\system32\ff_wmv9.dll |29/06/2005 18:28:53 C:\WINDOWS\system32\ff_x264.dll |29/06/2005 18:19:58 C:\WINDOWS\system32\ieencode.dll |05/08/2004 20:00:00 C:\WINDOWS\system32\ir32_32.dll |05/08/2004 14:00:00 C:\WINDOWS\system32\IVIresize.dll |02/01/2005 02:50:12 C:\WINDOWS\system32\IVIresizeA6.dll |02/01/2005 02:50:12 C:\WINDOWS\system32\IVIresizeM6.dll |02/01/2005 02:50:12 C:\WINDOWS\system32\IVIresizeP6.dll |02/01/2005 02:50:12 C:\WINDOWS\system32\IVIresizePX.dll |02/01/2005 02:50:12 C:\WINDOWS\system32\IVIresizeW7.dll |02/01/2005 02:50:12 C:\WINDOWS\system32\lame_enc.dll |26/07/2004 13:12:52 C:\WINDOWS\system32\libavcodec.dll |03/07/2005 03:08:01 C:\WINDOWS\system32\libeay32.dll |28/04/2005 06:22:34 C:\WINDOWS\system32\libmpeg2_ff.dll |29/06/2005 18:19:32 C:\WINDOWS\system32\libmplayer.dll |29/06/2005 18:17:40 C:\WINDOWS\system32\mkx.dll |03/07/2005 17:41:24 C:\WINDOWS\system32\mp4.dll |03/07/2005 17:41:08 C:\WINDOWS\system32\mp4fil32.dll |18/05/2002 00:18:30 C:\WINDOWS\system32\mr310exv.dll |18/03/2006 19:36:04 C:\WINDOWS\system32\msdmo.dll |05/08/2004 20:00:00 C:\WINDOWS\system32\msencode.dll |05/08/2004 14:00:00 C:\WINDOWS\system32\nvapi.dll |04/11/2005 18:03:00 C:\WINDOWS\system32\nview.dll |02/01/2005 02:32:20 C:\WINDOWS\system32\nvshell.dll |02/01/2005 02:32:20 C:\WINDOWS\system32\nvwdmcpl.dll |02/01/2005 02:32:20 C:\WINDOWS\system32\nvwimg.dll |02/01/2005 02:32:20 C:\WINDOWS\system32\ogg.dll |24/09/2004 11:10:48 C:\WINDOWS\system32\PsisDecd.dll |02/01/2005 02:34:06 C:\WINDOWS\system32\pythoncom22.dll |02/01/2005 02:19:32 C:\WINDOWS\system32\pywintypes22.dll |02/01/2005 02:19:32 C:\WINDOWS\system32\qedwipes.dll |05/08/2004 20:00:00 C:\WINDOWS\system32\qt-dx331.dll |28/04/2005 06:22:38 C:\WINDOWS\system32\sbe.dll |05/08/2004 20:00:00 C:\WINDOWS\system32\ssleay32.dll |28/04/2005 06:22:34 C:\WINDOWS\system32\TomsMoComp_ff.dll |29/06/2005 18:36:41 C:\WINDOWS\system32\tsd32.dll |05/08/2004 14:00:00 C:\WINDOWS\system32\vorbis.dll |24/09/2004 11:09:56 C:\WINDOWS\system32\vorbisenc.dll |24/09/2004 11:09:58 C:\WINDOWS\system32\vorbisfile.dll |24/09/2004 11:09:42 C:\WINDOWS\system32\win87em.dll |05/08/2004 14:00:00 C:\WINDOWS\system32\x264vfw.dll |01/07/2005 19:10:26 C:\WINDOWS\system32\xvid.dll |22/05/2003 00:50:38 C:\WINDOWS\system32\xvidcore.dll |20/12/2004 13:03:26 C:\WINDOWS\system32\xvidvfw.dll |20/12/2004 13:08:28 Le volume dans le lecteur C s'appelle HP_PAVILION Le num‚ro de s‚rie du volume est DC63-9DFF R‚pertoire de C:\WINDOWS\system 07/05/1998 18:04 52ÿ736 hpsysdrv.exe 1 fichier(s) 52ÿ736 octets 0 R‚p(s) 102ÿ627ÿ045ÿ376 octets libres Le volume dans le lecteur C s'appelle HP_PAVILION Le num‚ro de s‚rie du volume est DC63-9DFF R‚pertoire de C:\WINDOWS\system32 05/08/2004 20:00 6ÿ144 csrss.exe 1 fichier(s) 6ÿ144 octets 0 R‚p(s) 102ÿ627ÿ045ÿ376 octets libres Contenu de Downloaded Program Files Le volume dans le lecteur C s'appelle HP_PAVILION Le num‚ro de s‚rie du volume est DC63-9DFF R‚pertoire de C:\WINDOWS\Downloaded Program Files 30/07/2006 21:23 <REP> . 30/07/2006 21:23 <REP> .. 23/11/2004 23:20 65 desktop.ini 26/07/2002 02:13 24ÿ576 dwusplay.dll 26/07/2002 02:13 196ÿ608 dwusplay.exe 02/03/2006 15:40 1ÿ271 erma.inf 28/07/2004 00:48 323ÿ584 isusweb.dll 20/01/2000 16:25 1ÿ162 Microsoft XML Parser for Java.osd 12/04/2006 15:39 372ÿ736 MsnPUpld.dll 12/04/2006 15:38 393 MsnPUpld.inf 19/06/2002 14:11 117ÿ088 PURen-us.dll 31/05/2002 09:20 117ÿ328 purfr-fr.dll 27/03/2006 13:00 5ÿ019 swflash.inf 30/06/2003 22:41 1ÿ689 WMV9VCM.inf 12 fichier(s) 1ÿ161ÿ519 octets Total des fichiers list‚sÿ: 12 fichier(s) 1ÿ161ÿ519 octets 2 R‚p(s) 102ÿ627ÿ041ÿ280 octets libres -
à propos de mon log Hijackthis
colomber77 a répondu à un(e) sujet de colomber77 dans Analyses et éradication malwares
ok voilà le résultat (fichier résultat qui est créé aprsè cette analyse) merci encore C:\WINDOWS\System32\datestamp.dll -->05/09/2006 12:51:23 C:\WINDOWS\System32\nvapps.xml -->30/08/2006 23:20:22 C:\WINDOWS\System32\wpa.dbl -->18/08/2006 20:19:22 C:\WINDOWS\System32\hpzjrd01.dll -->04/08/2006 08:36:04 C:\WINDOWS\System32\MRT.exe -->03/08/2006 03:22:50 C:\WINDOWS\System32\FNTCACHE.DAT -->01/08/2006 21:11:57 C:\WINDOWS\System32\ROXECDC6Inst.log -->01/08/2006 21:08:40 C:\WINDOWS\System32\PQ_DEBUG.TXT -->31/07/2006 13:51:00 C:\WINDOWS\System32\statistics.xml -->30/07/2006 18:51:33 C:\WINDOWS\System32\mshtml.dll -->28/07/2006 13:28:08 C:\WINDOWS\System32\inetcomm.dll -->27/07/2006 15:26:19 C:\WINDOWS\System32\urlmon.dll -->25/07/2006 22:41:01 C:\WINDOWS\System32\hlink.dll -->21/07/2006 10:27:28 C:\WINDOWS\System32\netapi32.dll -->14/07/2006 17:41:05 C:\WINDOWS\System32\hhctrl.ocx -->14/07/2006 17:27:53 C:\WINDOWS\System32\shell32.dll -->13/07/2006 15:36:01 C:\WINDOWS\System32\PerfStringBackup.INI -->13/07/2006 03:12:05 C:\WINDOWS\System32\perfh00C.dat -->13/07/2006 03:12:05 C:\WINDOWS\System32\perfh009.dat -->13/07/2006 03:12:05 C:\WINDOWS\System32\perfc00C.dat -->13/07/2006 03:12:05 C:\WINDOWS\System32\perfc009.dat -->13/07/2006 03:12:05 C:\WINDOWS\System32\kernel32.dll -->05/07/2006 12:56:38 C:\WINDOWS\System32\rasadhlp.dll -->26/06/2006 19:41:32 C:\WINDOWS\System32\dnsapi.dll -->26/06/2006 19:41:32 C:\WINDOWS\System32\wininet.dll -->23/06/2006 13:11:45 C:\WINDOWS\WindowsUpdate.log -->06/09/2006 09:05:41 C:\WINDOWS\wmsetup.log -->05/09/2006 06:49:06 C:\WINDOWS\QTFont.qfn -->04/09/2006 20:27:00 C:\WINDOWS\setupapi.log -->31/08/2006 15:36:11 C:\WINDOWS\wiadebug.log -->31/08/2006 15:27:57 C:\WINDOWS\wiaservc.log -->31/08/2006 15:27:56 C:\WINDOWS\SchedLgU.Txt -->31/08/2006 14:34:00 C:\WINDOWS\0.log -->30/08/2006 23:20:55 C:\WINDOWS\bootstat.dat -->30/08/2006 23:19:34 C:\WINDOWS\QTFont.for -->30/08/2006 21:02:01 C:\WINDOWS\setupact.log -->27/08/2006 11:23:16 C:\WINDOWS\muveeapp.INI -->23/08/2006 22:29:34 C:\WINDOWS\setuperr.log -->21/08/2006 12:51:42 C:\WINDOWS\Win.ini -->20/08/2006 23:13:59 C:\WINDOWS\Sti_Trace.log -->11/08/2006 13:40:39 C:\WINDOWS\amcap.exe |11/06/2006 13:37:01 C:\WINDOWS\CleanDev.exe |11/06/2006 13:37:03 C:\WINDOWS\is-QF50A.exe |11/07/2006 09:55:56 C:\WINDOWS\UninstallFirefox.exe |16/02/2006 21:23:10 C:\WINDOWS\system32\append.exe |05/08/2004 14:00:00 C:\WINDOWS\system32\debug.exe |05/08/2004 14:00:00 C:\WINDOWS\system32\DivXsm.exe |24/05/2005 23:32:44 C:\WINDOWS\system32\dosx.exe |05/08/2004 20:00:00 C:\WINDOWS\system32\dvdplay.exe |05/08/2004 20:00:00 C:\WINDOWS\system32\edlin.exe |05/08/2004 14:00:00 C:\WINDOWS\system32\exe2bin.exe |05/08/2004 14:00:00 C:\WINDOWS\system32\fastopen.exe |05/08/2004 14:00:00 C:\WINDOWS\system32\mem.exe |05/08/2004 14:00:00 C:\WINDOWS\system32\mscdexnt.exe |05/08/2004 14:00:00 C:\WINDOWS\system32\nlsfunc.exe |05/08/2004 14:00:00 C:\WINDOWS\system32\nvappbar.exe |02/01/2005 02:32:19 C:\WINDOWS\system32\nvdspsch.exe |02/01/2005 02:32:20 C:\WINDOWS\system32\nwiz.exe |02/01/2005 02:32:21 C:\WINDOWS\system32\redir.exe |05/08/2004 20:00:00 C:\WINDOWS\system32\setver.exe |05/08/2004 14:00:00 C:\WINDOWS\system32\share.exe |05/08/2004 14:00:00 C:\WINDOWS\system32\wapisu.exe |22/04/2006 19:45:59 C:\WINDOWS\system32\34CoInstaller.dll |02/01/2005 02:34:04 C:\WINDOWS\system32\amstream.dll |05/08/2004 20:00:00 C:\WINDOWS\system32\avi.dll |03/07/2005 17:41:37 C:\WINDOWS\system32\BASSMOD.dll |11/06/2006 07:30:36 C:\WINDOWS\system32\bcbmm.dll |02/01/2005 02:19:13 C:\WINDOWS\system32\CddbLangFR.dll |27/08/2002 20:21:18 C:\WINDOWS\system32\compatUI.dll |05/08/2004 20:00:00 C:\WINDOWS\system32\cpuinf32.dll |27/02/2003 05:42:54 C:\WINDOWS\system32\encdec.dll |05/08/2004 20:00:00 C:\WINDOWS\system32\ff_liba52.dll |29/06/2005 18:25:22 C:\WINDOWS\system32\ff_libdts.dll |29/06/2005 18:25:36 C:\WINDOWS\system32\ff_libmad.dll |29/06/2005 18:26:55 C:\WINDOWS\system32\ff_realaac.dll |29/06/2005 18:27:17 C:\WINDOWS\system32\ff_samplerate.dll |29/06/2005 18:27:21 C:\WINDOWS\system32\ff_theora.dll |29/06/2005 18:27:48 C:\WINDOWS\system32\ff_tremor.dll |29/06/2005 18:28:00 C:\WINDOWS\system32\ff_unrar.dll |29/06/2005 18:28:39 C:\WINDOWS\system32\ff_vfw.dll |01/07/2005 12:52:07 C:\WINDOWS\system32\ff_wmv9.dll |29/06/2005 18:28:53 C:\WINDOWS\system32\ff_x264.dll |29/06/2005 18:19:58 C:\WINDOWS\system32\hpreg.dll |02/01/2005 02:59:04 C:\WINDOWS\system32\ieencode.dll |05/08/2004 20:00:00 C:\WINDOWS\system32\ir32_32.dll |05/08/2004 14:00:00 C:\WINDOWS\system32\IVIresize.dll |02/01/2005 02:50:12 C:\WINDOWS\system32\IVIresizeA6.dll |02/01/2005 02:50:12 C:\WINDOWS\system32\IVIresizeM6.dll |02/01/2005 02:50:12 C:\WINDOWS\system32\IVIresizeP6.dll |02/01/2005 02:50:12 C:\WINDOWS\system32\IVIresizePX.dll |02/01/2005 02:50:12 C:\WINDOWS\system32\IVIresizeW7.dll |02/01/2005 02:50:12 C:\WINDOWS\system32\lame_enc.dll |26/07/2004 13:12:52 C:\WINDOWS\system32\libavcodec.dll |03/07/2005 03:08:01 C:\WINDOWS\system32\libeay32.dll |28/04/2005 06:22:34 C:\WINDOWS\system32\libmpeg2_ff.dll |29/06/2005 18:19:32 C:\WINDOWS\system32\libmplayer.dll |29/06/2005 18:17:40 C:\WINDOWS\system32\mkx.dll |03/07/2005 17:41:24 C:\WINDOWS\system32\mp4.dll |03/07/2005 17:41:08 C:\WINDOWS\system32\mp4fil32.dll |18/05/2002 00:18:30 C:\WINDOWS\system32\mr310exd.dll |18/03/2006 19:36:04 C:\WINDOWS\system32\mr310exv.dll |18/03/2006 19:36:04 C:\WINDOWS\system32\msdmo.dll |05/08/2004 20:00:00 C:\WINDOWS\system32\msencode.dll |05/08/2004 14:00:00 C:\WINDOWS\system32\nvapi.dll |04/11/2005 18:03:00 C:\WINDOWS\system32\nview.dll |02/01/2005 02:32:20 C:\WINDOWS\system32\nvshell.dll |02/01/2005 02:32:20 C:\WINDOWS\system32\nvwdmcpl.dll |02/01/2005 02:32:20 C:\WINDOWS\system32\nvwimg.dll |02/01/2005 02:32:20 C:\WINDOWS\system32\ogg.dll |24/09/2004 11:10:48 C:\WINDOWS\system32\OggDS.dll |06/10/2002 21:42:58 C:\WINDOWS\system32\paqsp.dll |05/08/2004 20:00:00 C:\WINDOWS\system32\PhilTvRat.dll |02/01/2005 02:34:04 C:\WINDOWS\system32\PsisDecd.dll |02/01/2005 02:34:06 C:\WINDOWS\system32\pythoncom22.dll |02/01/2005 02:19:32 C:\WINDOWS\system32\pywintypes22.dll |02/01/2005 02:19:32 C:\WINDOWS\system32\qedwipes.dll |05/08/2004 20:00:00 C:\WINDOWS\system32\qt-dx331.dll |28/04/2005 06:22:38 C:\WINDOWS\system32\sbe.dll |05/08/2004 20:00:00 C:\WINDOWS\system32\ssleay32.dll |28/04/2005 06:22:34 C:\WINDOWS\system32\TomsMoComp_ff.dll |29/06/2005 18:36:41 C:\WINDOWS\system32\tsd32.dll |05/08/2004 14:00:00 C:\WINDOWS\system32\vorbis.dll |24/09/2004 11:09:56 C:\WINDOWS\system32\vorbisenc.dll |24/09/2004 11:09:58 C:\WINDOWS\system32\vorbisfile.dll |24/09/2004 11:09:42 C:\WINDOWS\system32\win87em.dll |05/08/2004 14:00:00 C:\WINDOWS\system32\x264vfw.dll |01/07/2005 19:10:26 C:\WINDOWS\system32\xvid.dll |22/05/2003 00:50:38 C:\WINDOWS\system32\xvidcore.dll |20/12/2004 13:03:26 C:\WINDOWS\system32\xvidvfw.dll |20/12/2004 13:08:28 C:\WINDOWS\amcap.exe |11/06/2006 13:37:01 C:\WINDOWS\UninstallFirefox.exe |16/02/2006 21:23:10 C:\WINDOWS\system32\append.exe |05/08/2004 14:00:00 C:\WINDOWS\system32\debug.exe |05/08/2004 14:00:00 C:\WINDOWS\system32\DivXsm.exe |24/05/2005 23:32:44 C:\WINDOWS\system32\dosx.exe |05/08/2004 20:00:00 C:\WINDOWS\system32\edlin.exe |05/08/2004 14:00:00 C:\WINDOWS\system32\exe2bin.exe |05/08/2004 14:00:00 C:\WINDOWS\system32\fastopen.exe |05/08/2004 14:00:00 C:\WINDOWS\system32\mem.exe |05/08/2004 14:00:00 C:\WINDOWS\system32\mscdexnt.exe |05/08/2004 14:00:00 C:\WINDOWS\system32\nlsfunc.exe |05/08/2004 14:00:00 C:\WINDOWS\system32\nvappbar.exe |02/01/2005 02:32:19 C:\WINDOWS\system32\nvdspsch.exe |02/01/2005 02:32:20 C:\WINDOWS\system32\nwiz.exe |02/01/2005 02:32:21 C:\WINDOWS\system32\redir.exe |05/08/2004 20:00:00 C:\WINDOWS\system32\setver.exe |05/08/2004 14:00:00 C:\WINDOWS\system32\share.exe |05/08/2004 14:00:00 C:\WINDOWS\system32\wapisu.exe |22/04/2006 19:45:59 C:\WINDOWS\system32\34CoInstaller.dll |02/01/2005 02:34:04 C:\WINDOWS\system32\amstream.dll |05/08/2004 20:00:00 C:\WINDOWS\system32\avi.dll |03/07/2005 17:41:37 C:\WINDOWS\system32\BASSMOD.dll |11/06/2006 07:30:36 C:\WINDOWS\system32\bcbmm.dll |02/01/2005 02:19:13 C:\WINDOWS\system32\CddbLangFR.dll |27/08/2002 20:21:18 C:\WINDOWS\system32\cpuinf32.dll |27/02/2003 05:42:54 C:\WINDOWS\system32\encdec.dll |05/08/2004 20:00:00 C:\WINDOWS\system32\ff_liba52.dll |29/06/2005 18:25:22 C:\WINDOWS\system32\ff_libdts.dll |29/06/2005 18:25:36 C:\WINDOWS\system32\ff_libmad.dll |29/06/2005 18:26:55 C:\WINDOWS\system32\ff_realaac.dll |29/06/2005 18:27:17 C:\WINDOWS\system32\ff_samplerate.dll |29/06/2005 18:27:21 C:\WINDOWS\system32\ff_theora.dll |29/06/2005 18:27:48 C:\WINDOWS\system32\ff_tremor.dll |29/06/2005 18:28:00 C:\WINDOWS\system32\ff_unrar.dll |29/06/2005 18:28:39 C:\WINDOWS\system32\ff_vfw.dll |01/07/2005 12:52:07 C:\WINDOWS\system32\ff_wmv9.dll |29/06/2005 18:28:53 C:\WINDOWS\system32\ff_x264.dll |29/06/2005 18:19:58 C:\WINDOWS\system32\ieencode.dll |05/08/2004 20:00:00 C:\WINDOWS\system32\ir32_32.dll |05/08/2004 14:00:00 C:\WINDOWS\system32\IVIresize.dll |02/01/2005 02:50:12 C:\WINDOWS\system32\IVIresizeA6.dll |02/01/2005 02:50:12 C:\WINDOWS\system32\IVIresizeM6.dll |02/01/2005 02:50:12 C:\WINDOWS\system32\IVIresizeP6.dll |02/01/2005 02:50:12 C:\WINDOWS\system32\IVIresizePX.dll |02/01/2005 02:50:12 C:\WINDOWS\system32\IVIresizeW7.dll |02/01/2005 02:50:12 C:\WINDOWS\system32\lame_enc.dll |26/07/2004 13:12:52 C:\WINDOWS\system32\libavcodec.dll |03/07/2005 03:08:01 C:\WINDOWS\system32\libeay32.dll |28/04/2005 06:22:34 C:\WINDOWS\system32\libmpeg2_ff.dll |29/06/2005 18:19:32 C:\WINDOWS\system32\libmplayer.dll |29/06/2005 18:17:40 C:\WINDOWS\system32\mkx.dll |03/07/2005 17:41:24 C:\WINDOWS\system32\mp4.dll |03/07/2005 17:41:08 C:\WINDOWS\system32\mp4fil32.dll |18/05/2002 00:18:30 C:\WINDOWS\system32\mr310exv.dll |18/03/2006 19:36:04 C:\WINDOWS\system32\msdmo.dll |05/08/2004 20:00:00 C:\WINDOWS\system32\msencode.dll |05/08/2004 14:00:00 C:\WINDOWS\system32\nvapi.dll |04/11/2005 18:03:00 C:\WINDOWS\system32\nview.dll |02/01/2005 02:32:20 C:\WINDOWS\system32\nvshell.dll |02/01/2005 02:32:20 C:\WINDOWS\system32\nvwdmcpl.dll |02/01/2005 02:32:20 C:\WINDOWS\system32\nvwimg.dll |02/01/2005 02:32:20 C:\WINDOWS\system32\ogg.dll |24/09/2004 11:10:48 C:\WINDOWS\system32\PsisDecd.dll |02/01/2005 02:34:06 C:\WINDOWS\system32\pythoncom22.dll |02/01/2005 02:19:32 C:\WINDOWS\system32\pywintypes22.dll |02/01/2005 02:19:32 C:\WINDOWS\system32\qedwipes.dll |05/08/2004 20:00:00 C:\WINDOWS\system32\qt-dx331.dll |28/04/2005 06:22:38 C:\WINDOWS\system32\sbe.dll |05/08/2004 20:00:00 C:\WINDOWS\system32\ssleay32.dll |28/04/2005 06:22:34 C:\WINDOWS\system32\TomsMoComp_ff.dll |29/06/2005 18:36:41 C:\WINDOWS\system32\tsd32.dll |05/08/2004 14:00:00 C:\WINDOWS\system32\vorbis.dll |24/09/2004 11:09:56 C:\WINDOWS\system32\vorbisenc.dll |24/09/2004 11:09:58 C:\WINDOWS\system32\vorbisfile.dll |24/09/2004 11:09:42 C:\WINDOWS\system32\win87em.dll |05/08/2004 14:00:00 C:\WINDOWS\system32\x264vfw.dll |01/07/2005 19:10:26 C:\WINDOWS\system32\xvid.dll |22/05/2003 00:50:38 C:\WINDOWS\system32\xvidcore.dll |20/12/2004 13:03:26 C:\WINDOWS\system32\xvidvfw.dll |20/12/2004 13:08:28 Le volume dans le lecteur C s'appelle HP_PAVILION Le num‚ro de s‚rie du volume est DC63-9DFF R‚pertoire de C:\WINDOWS\system 07/05/1998 18:04 52ÿ736 hpsysdrv.exe 1 fichier(s) 52ÿ736 octets 0 R‚p(s) 102ÿ627ÿ106ÿ816 octets libres Le volume dans le lecteur C s'appelle HP_PAVILION Le num‚ro de s‚rie du volume est DC63-9DFF R‚pertoire de C:\WINDOWS\system32 05/08/2004 20:00 6ÿ144 csrss.exe 1 fichier(s) 6ÿ144 octets 0 R‚p(s) 102ÿ627ÿ106ÿ816 octets libres Contenu de Downloaded Program Files Le volume dans le lecteur C s'appelle HP_PAVILION Le num‚ro de s‚rie du volume est DC63-9DFF R‚pertoire de C:\WINDOWS\Downloaded Program Files 30/07/2006 21:23 <REP> . 30/07/2006 21:23 <REP> .. 23/11/2004 23:20 65 desktop.ini 26/07/2002 02:13 24ÿ576 dwusplay.dll 26/07/2002 02:13 196ÿ608 dwusplay.exe 02/03/2006 15:40 1ÿ271 erma.inf 28/07/2004 00:48 323ÿ584 isusweb.dll 20/01/2000 16:25 1ÿ162 Microsoft XML Parser for Java.osd 12/04/2006 15:39 372ÿ736 MsnPUpld.dll 12/04/2006 15:38 393 MsnPUpld.inf 19/06/2002 14:11 117ÿ088 PURen-us.dll 31/05/2002 09:20 117ÿ328 purfr-fr.dll 27/03/2006 13:00 5ÿ019 swflash.inf 30/06/2003 22:41 1ÿ689 WMV9VCM.inf 12 fichier(s) 1ÿ161ÿ519 octets Total des fichiers list‚sÿ: 12 fichier(s) 1ÿ161ÿ519 octets 2 R‚p(s) 102ÿ627ÿ102ÿ720 octets libres -
à propos de mon log Hijackthis
colomber77 a répondu à un(e) sujet de colomber77 dans Analyses et éradication malwares
bonsoir merci pour la réponse voilà le scan une fois le fichier Hijackthis renommé en scanner.exe P.S pourquoi renommer ce fichier ? que cela apporte t-il merci ? Logfile of HijackThis v1.99.1 Scan saved at 23:05:22, on 06/09/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Windows Defender\MsMpEng.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\RunDll32.exe C:\Program Files\InterVideo\Common\Bin\WinRemote.exe C:\Program Files\Windows Defender\MSASCui.exe C:\PROGRA~1\SYMANT~1\VPTray.exe C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe C:\windows\system\hpsysdrv.exe C:\Program Files\HP\HP Software Update\HPwuSchd2.exe C:\Program Files\Fichiers communs\InterVideo\SchSvr\SchSvr.exe C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe C:\HP\KBD\KBD.EXE C:\WINDOWS\system32\rundll32.exe C:\Program Files\SpywareGuard\sgmain.exe C:\Program Files\SpywareGuard\sgbhp.exe C:\Program Files\Symantec AntiVirus\DefWatch.exe C:\Program Files\ewido\security suite\ewidoctrl.exe C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Symantec AntiVirus\Rtvscan.exe c:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe C:\Program Files\ADSL Autoconnect\ADSL Autoconnect.exe C:\Program Files\ADSL Autoconnect\ADSL Autoconnect.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\outils\eMule0.47a\eMule0.47a\emule.exe C:\WINDOWS\explorer.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\Program Files\FBM Software\ZeroSpyware\ZeroSpyware.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\ewido\security suite\oldewido.exe C:\Documents and Settings\HP_Propriétaire\Bureau\scanner.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.neuf.fr/ O2 - BHO: Bugnosis - {3A6514CD-A457-11D4-8AF3-000102686B79} - C:\Program Files\Bugnosis\WebBug.dll O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O3 - Toolbar: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file) O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O3 - Toolbar: &Netcraft Toolbar - {D554D8FC-B36D-4BB4-93DB-4A3394D505E3} - C:\Program Files\Netcraft Toolbar\nctb.dll O3 - Toolbar: Bugnosis - {930E4DE1-973D-42D6-BF6E-6788E06BD003} - C:\Program Files\Bugnosis\WebBug.dll O4 - HKLM\..\Run: [WINREMOTE] "C:\Program Files\InterVideo\Common\Bin\WinRemote.exe" O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe O4 - HKLM\..\Run: [iSUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start O4 - HKLM\..\Run: [iSUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe O4 - HKLM\..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe O4 - HKLM\..\Run: [Home Theater SchSvr] "C:\Program Files\Fichiers communs\InterVideo\SchSvr\SchSvr.exe" O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [zsscheduler] rundll32.exe "C:\Program Files\FBM Software\ZeroSpyware\zsscheduler.dll", runScheduler C:\Program Files\FBM Software\ZeroSpyware\ O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\RunOnce: [lmpgad.ax] C:\WINDOWS\system32\regsvr32.exe /s "C:\WINDOWS\system32\lmpgad.ax" O4 - HKLM\..\RunOnce: [ZeroSpyware] "C:\Program Files\FBM Software\ZeroSpyware\zsloader.exe" -STARTUP O4 - HKCU\..\Run: [ZSScheduler] RunDll32.exe "C:\Program Files\FBM Software\ZeroSpyware\ZSScheduler.dll", runScheduler C:\Program Files\FBM Software\ZeroSpyware\ O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_7 -reboot 1 O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm O8 - Extra context menu item: &Traduire à partir de l'anglais - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: Pages liées - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html O8 - Extra context menu item: Pages similaires - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html O8 - Extra context menu item: Recherche &Google - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRA~1\Yahoo!\Common\yhexbmesfr.dll O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRA~1\Yahoo!\Common\yhexbmesfr.dll O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://colombero2712.spaces.msn.com//Photo...ad/MsnPUpld.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{CF26B5F4-E3D8-4F3C-A407-60D33E8D2858}: NameServer = 84.103.237.140 86.64.145.140 O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll O20 - Winlogon Notify: winjks32 - winjks32.dll (file missing) O23 - Service: ADSLAutoconnect - Unknown owner - C:\Program Files\ADSL Autoconnect\ADSL Autoconnect.exe" -z (file missing) O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe -
bonjour j'ai un doute sur mon log Hijackthis 1) pouvez vous m'aider ? de plus j'ai SpyBot qui s'est manifesté en me mettant ce message 2) avez vous une idée de ce que je dois faire ? Merci de votre aide Bonne soirée 1) Log Hijackthis Logfile of HijackThis v1.99.1 Scan saved at 21:16:23, on 06/09/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Windows Defender\MsMpEng.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\RunDll32.exe C:\Program Files\InterVideo\Common\Bin\WinRemote.exe C:\Program Files\Windows Defender\MSASCui.exe C:\PROGRA~1\SYMANT~1\VPTray.exe C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe C:\windows\system\hpsysdrv.exe C:\Program Files\HP\HP Software Update\HPwuSchd2.exe C:\Program Files\Fichiers communs\InterVideo\SchSvr\SchSvr.exe C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe C:\HP\KBD\KBD.EXE C:\WINDOWS\system32\rundll32.exe C:\Program Files\SpywareGuard\sgmain.exe C:\Program Files\SpywareGuard\sgbhp.exe C:\Program Files\Symantec AntiVirus\DefWatch.exe C:\Program Files\ewido\security suite\ewidoctrl.exe C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Symantec AntiVirus\Rtvscan.exe c:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe C:\Program Files\ADSL Autoconnect\ADSL Autoconnect.exe C:\Program Files\ADSL Autoconnect\ADSL Autoconnect.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\outils\eMule0.47a\eMule0.47a\emule.exe C:\WINDOWS\explorer.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\Program Files\FBM Software\ZeroSpyware\ZeroSpyware.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\ewido\security suite\oldewido.exe C:\Program Files\MSN Messenger\msnmsgr.exe C:\Documents and Settings\HP_Propriétaire\Bureau\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.neuf.fr/ O2 - BHO: Bugnosis - {3A6514CD-A457-11D4-8AF3-000102686B79} - C:\Program Files\Bugnosis\WebBug.dll O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O3 - Toolbar: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file) O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O3 - Toolbar: &Netcraft Toolbar - {D554D8FC-B36D-4BB4-93DB-4A3394D505E3} - C:\Program Files\Netcraft Toolbar\nctb.dll O3 - Toolbar: Bugnosis - {930E4DE1-973D-42D6-BF6E-6788E06BD003} - C:\Program Files\Bugnosis\WebBug.dll O4 - HKLM\..\Run: [WINREMOTE] "C:\Program Files\InterVideo\Common\Bin\WinRemote.exe" O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe O4 - HKLM\..\Run: [iSUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start O4 - HKLM\..\Run: [iSUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe O4 - HKLM\..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe O4 - HKLM\..\Run: [Home Theater SchSvr] "C:\Program Files\Fichiers communs\InterVideo\SchSvr\SchSvr.exe" O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [zsscheduler] rundll32.exe "C:\Program Files\FBM Software\ZeroSpyware\zsscheduler.dll", runScheduler C:\Program Files\FBM Software\ZeroSpyware\ O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\RunOnce: [lmpgad.ax] C:\WINDOWS\system32\regsvr32.exe /s "C:\WINDOWS\system32\lmpgad.ax" O4 - HKLM\..\RunOnce: [ZeroSpyware] "C:\Program Files\FBM Software\ZeroSpyware\zsloader.exe" -STARTUP O4 - HKCU\..\Run: [ZSScheduler] RunDll32.exe "C:\Program Files\FBM Software\ZeroSpyware\ZSScheduler.dll", runScheduler C:\Program Files\FBM Software\ZeroSpyware\ O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_7 -reboot 1 O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm O8 - Extra context menu item: &Traduire à partir de l'anglais - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: Pages liées - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html O8 - Extra context menu item: Pages similaires - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html O8 - Extra context menu item: Recherche &Google - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRA~1\Yahoo!\Common\yhexbmesfr.dll O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRA~1\Yahoo!\Common\yhexbmesfr.dll O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://colombero2712.spaces.msn.com//Photo...ad/MsnPUpld.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{CF26B5F4-E3D8-4F3C-A407-60D33E8D2858}: NameServer = 84.103.237.140 86.64.145.140 O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll O20 - Winlogon Notify: winjks32 - winjks32.dll (file missing) O23 - Service: ADSLAutoconnect - Unknown owner - C:\Program Files\ADSL Autoconnect\ADSL Autoconnect.exe" -z (file missing) O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe 2) problème avec SpyBot Société: Produit: Microsoft.WindowsSecurityCenter_disabled Menace: Security HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wscsvc\Start!=W=2 Fonctionnalités if the Windows Security Center is disabled this entry will be shown Description Malware can disable the Windows Security Center to make your System more vulnerable. If you have other security software suit installed, this may also deactivate the Windows Security Center to avoid double warning messages.