

rubiks
Membres-
Compteur de contenus
8 -
Inscription
-
Dernière visite
rubiks's Achievements

Junior Member (3/12)
1
Réputation sur la communauté
-
Bonjour cette solution viens de résoudre le problème à peu près identique que je rencontrais. merci
-
pour moi aussi, ça marche! merci xav
-
pc infecte par winantivirus 2006
rubiks a répondu à un(e) sujet de rubiks dans Analyses et éradication malwares
je viens de reconnecter le pc a internet (je l'utilise en ce moment)et ça a l'air correct : plus de fenetre de pub . merci beaucoup. par curiosité, c'était quoi la saleté qui infectait ce pc? comment tu fais pour la reperer avec hijack, l'habitude? peux on trouver des tutos d'utilisation? encore merci . a+ rubiks -
pc infecte par winantivirus 2006
rubiks a répondu à un(e) sujet de rubiks dans Analyses et éradication malwares
c'est fait et j'avais déja désactivé la restauration de xp. le pc à problème est en multi utilisateurs, j'ai donc effacé manuellement les cookies et les fichiers temporaires d'explorer pour chaque compte déclaré dans le repertoire "document and settings" voila le resultat de hijack : Logfile of HijackThis v1.99.1 Scan saved at 17:08:37, on 04/11/2006 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\System32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\AntiVir PersonalEdition Classic\sched.exe C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe C:\WINDOWS\system32\drivers\KodakCCS.exe C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe C:\Program Files\Photodex\ProShowGold\ScsiAccess.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe C:\Program Files\HijackThis\rubiks.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.neufportail.fr/ R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Barre d'outils MSN Search Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1105\fr-fr\msntb.dll O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O3 - Toolbar: Barre d'outils MSN Search - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1105\fr-fr\msntb.dll O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized O8 - Extra context menu item: &MSN Search - res://C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1105\fr-fr\msntb.dll/search.htm O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O8 - Extra context menu item: Easy-WebPrint Ajouter à la liste d'impressions - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html O8 - Extra context menu item: Easy-WebPrint Impression rapide - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html O8 - Extra context menu item: Easy-WebPrint Imprimer - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html O8 - Extra context menu item: Easy-WebPrint Prévisualiser - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0000.1105\fr-fr\msntabres.dll/229?7f98c6851f7543d9a4cc2a944f8e89 O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0000.1105\fr-fr\msntabres.dll/230?7f98c6851f7543d9a4cc2a944f8e89 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab O16 - DPF: {2250C29C-C5E9-4F55-BE4E-01E45A40FCF1} (CMediaMix Object) - http://musicmix.messenger.msn.com/Medialogic.CAB O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab31267.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1134586360437 O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse...pDownloader.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab31267.cab O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - AVIRA GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe" -k runservice (file missing) O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe O23 - Service: ScsiAccess - Unknown owner - C:\Program Files\Photodex\ProShowGold\ScsiAccess.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe et voila celui de avg antispy --------------------------------------------------------- AVG Anti-Spyware - Rapport d'analyse --------------------------------------------------------- + Créé à: 17:07:00 04/11/2006 + Résultat de l'analyse: Rien à signaler. Fin du rapport est ce que c'est bon signe? pour info, j'ai un autre pc dans la même pièce, donc celui qui est infecté est deconnecté d'internet. a+ rubiks -
pc infecte par winantivirus 2006
rubiks a répondu à un(e) sujet de rubiks dans Analyses et éradication malwares
je l'ai bien fait en mode sans echec mais il ne me trouve pas de "firewall service"ni d'autre trace de winantivirus 2006. je me trompe peut etre de spyware présent sur la machine car j'ai pensé a winantivirus 2006 a cause des pop-up incessants ramenant à ce logiciel. a+ rubiks -
pc infecte par winantivirus 2006
rubiks a répondu à un(e) sujet de rubiks dans Analyses et éradication malwares
merci bruce, je l'ai renommer rubiks.exe. je fait le hujack en mode sans echec apres un passage de avg anti spyware7.5 et antivir dont je te joins aussi les rapports. voici le rapport hijack : Logfile of HijackThis v1.99.1 Scan saved at 11:39:43, on 04/11/2006 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe C:\Program Files\HijackThis\rubiks.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.neufportail.fr/ R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Barre d'outils MSN Search Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1105\fr-fr\msntb.dll O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O3 - Toolbar: Barre d'outils MSN Search - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1105\fr-fr\msntb.dll O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto O8 - Extra context menu item: &MSN Search - res://C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1105\fr-fr\msntb.dll/search.htm O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O8 - Extra context menu item: Easy-WebPrint Ajouter à la liste d'impressions - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html O8 - Extra context menu item: Easy-WebPrint Impression rapide - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html O8 - Extra context menu item: Easy-WebPrint Imprimer - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html O8 - Extra context menu item: Easy-WebPrint Prévisualiser - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0000.1105\fr-fr\msntabres.dll/229?7f98c6851f7543d9a4cc2a944f8e89 O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0000.1105\fr-fr\msntabres.dll/230?7f98c6851f7543d9a4cc2a944f8e89 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab O16 - DPF: {2250C29C-C5E9-4F55-BE4E-01E45A40FCF1} (CMediaMix Object) - http://musicmix.messenger.msn.com/Medialogic.CAB O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab31267.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1134586360437 O16 - DPF: {71DA2A4E-ACB3-4065-9E41-8BC42EABE427} - http://scripts.dlv4.com/binaries/IA/svcia32_FR_XP.cab O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse...pDownloader.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab31267.cab O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - AVIRA GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe" -k runservice (file missing) O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe O23 - Service: ScsiAccess - Unknown owner - C:\Program Files\Photodex\ProShowGold\ScsiAccess.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe voici le rapport avg: --------------------------------------------------------- AVG Anti-Spyware - Rapport d'analyse --------------------------------------------------------- + Créé à: 10:33:03 04/11/2006 + Résultat de l'analyse: C:\essai2\Download Accelerator Plus v7.2.0.0 Crack.rar/crack\DAP.exe -> Adware.Dap : Aucune action entreprise. C:\Program Files\Adverts\uninst.exe -> Adware.Lop : Aucune action entreprise. C:\System Volume Information\_restore{F91002A5-17F5-4FD2-BFBA-A7BE88E78D41}\RP241\A0185380.exe -> Adware.Lop : Aucune action entreprise. C:\System Volume Information\_restore{F91002A5-17F5-4FD2-BFBA-A7BE88E78D41}\RP254\A0198940.exe -> Downloader.Agent.aii : Aucune action entreprise. C:\System Volume Information\_restore{F91002A5-17F5-4FD2-BFBA-A7BE88E78D41}\RP260\A0211084.exe -> Downloader.Agent.aii : Aucune action entreprise. C:\System Volume Information\_restore{F91002A5-17F5-4FD2-BFBA-A7BE88E78D41}\RP241\A0185378.dll -> Downloader.Wintrim.da : Aucune action entreprise. C:\Documents and Settings\Marion\Local Settings\Temporary Internet Files\Content.IE5\NTPV9RBK\send_car_int[1].htm -> Not-A-Virus.Exploit.HTML.CodeBaseExec : Aucune action entreprise. C:\essai2\Surething CD Labeler 3.01.zip/Surething CD Labeler 3.01/Stcd301Crack.exe -> Not-A-Virus.VirTool.Win32.AvSpoffer.a : Aucune action entreprise. C:\Documents and Settings\Anne-Marie\Local Settings\Temp\54exmodul32e.f.exe -> Proxy.Horst : Aucune action entreprise. C:\Documents and Settings\Marion\Local Settings\Temp\19exmodul32e.f.exe -> Proxy.Horst : Aucune action entreprise. C:\Documents and Settings\Marion\Local Settings\Temp\84exmodul32e.f.exe -> Proxy.Horst : Aucune action entreprise. C:\Documents and Settings\Marion\Local Settings\Temp\85exmodul32e.f.exe -> Proxy.Horst : Aucune action entreprise. C:\Documents and Settings\Marion\Local Settings\Temp\96exmodul32e.f.exe -> Proxy.Horst : Aucune action entreprise. C:\Documents and Settings\Quentin\Local Settings\Temp\17exmodul32e.f.exe -> Proxy.Horst : Aucune action entreprise. C:\Documents and Settings\Quentin\Local Settings\Temp\22exmodul32e.f.exe -> Proxy.Horst : Aucune action entreprise. C:\Documents and Settings\Quentin\Local Settings\Temp\28exmodul32e.f.exe -> Proxy.Horst : Aucune action entreprise. C:\Documents and Settings\Quentin\Local Settings\Temp\2exmodul32e.f.exe -> Proxy.Horst : Aucune action entreprise. C:\Documents and Settings\Quentin\Local Settings\Temp\33exmodul32e.f.exe -> Proxy.Horst : Aucune action entreprise. C:\Documents and Settings\Quentin\Local Settings\Temp\39exmodul32e.f.exe -> Proxy.Horst : Aucune action entreprise. C:\Documents and Settings\Quentin\Local Settings\Temp\45exmodul32e.f.exe -> Proxy.Horst : Aucune action entreprise. C:\Documents and Settings\Quentin\Local Settings\Temp\58exmodul32e.f.exe -> Proxy.Horst : Aucune action entreprise. C:\Documents and Settings\Quentin\Local Settings\Temp\66exmodul32e.f.exe -> Proxy.Horst : Aucune action entreprise. C:\Documents and Settings\Quentin\Local Settings\Temp\72exmodul32e.f.exe -> Proxy.Horst : Aucune action entreprise. C:\Documents and Settings\Quentin\Local Settings\Temp\74exmodul32e.f.exe -> Proxy.Horst : Aucune action entreprise. C:\Documents and Settings\Quentin\Local Settings\Temp\89exmodul32e.f.exe -> Proxy.Horst : Aucune action entreprise. C:\Documents and Settings\Quentin\Local Settings\Temp\91exmodul32e.f.exe -> Proxy.Horst : Aucune action entreprise. C:\Documents and Settings\Anne-Marie\Local Settings\Temp\37exhdd.f.exe -> Proxy.Horst.dt : Aucune action entreprise. C:\Documents and Settings\Anne-Marie\Local Settings\Temp\71exhdd.e.exe -> Proxy.Horst.dt : Aucune action entreprise. C:\Documents and Settings\Anne-Marie\Local Settings\Temp\81exhdd.f.exe -> Proxy.Horst.dt : Aucune action entreprise. C:\Documents and Settings\Anne-Marie\Local Settings\Temp\92exhdd.f.exe -> Proxy.Horst.dt : Aucune action entreprise. C:\Documents and Settings\Marion\Local Settings\Temp\21exhdd.e.exe -> Proxy.Horst.dt : Aucune action entreprise. C:\Documents and Settings\Marion\Local Settings\Temp\46exhdd.e.exe -> Proxy.Horst.dt : Aucune action entreprise. C:\Documents and Settings\Marion\Local Settings\Temp\78exhdd.e.exe -> Proxy.Horst.dt : Aucune action entreprise. C:\Documents and Settings\Marion\Local Settings\Temp\98exhdd.e.exe -> Proxy.Horst.dt : Aucune action entreprise. C:\Documents and Settings\Marion\Local Settings\Temp\99exhdd.e.exe -> Proxy.Horst.dt : Aucune action entreprise. C:\Documents and Settings\Quentin\Local Settings\Temp\1exhdd.f.exe -> Proxy.Horst.dt : Aucune action entreprise. C:\Documents and Settings\Quentin\Local Settings\Temp\20exhdd.e.exe -> Proxy.Horst.dt : Aucune action entreprise. C:\Documents and Settings\Quentin\Local Settings\Temp\21exhdd.e.exe -> Proxy.Horst.dt : Aucune action entreprise. C:\Documents and Settings\Quentin\Local Settings\Temp\27exhdd.f.exe -> Proxy.Horst.dt : Aucune action entreprise. C:\Documents and Settings\Quentin\Local Settings\Temp\35exhdd.f.exe -> Proxy.Horst.dt : Aucune action entreprise. C:\Documents and Settings\Quentin\Local Settings\Temp\39exhdd.e.exe -> Proxy.Horst.dt : Aucune action entreprise. C:\Documents and Settings\Quentin\Local Settings\Temp\40exhdd.f.exe -> Proxy.Horst.dt : Aucune action entreprise. C:\Documents and Settings\Quentin\Local Settings\Temp\41exhdd.f.exe -> Proxy.Horst.dt : Aucune action entreprise. C:\Documents and Settings\Quentin\Local Settings\Temp\42exhdd.e.exe -> Proxy.Horst.dt : Aucune action entreprise. C:\Documents and Settings\Quentin\Local Settings\Temp\48exhdd.e.exe -> Proxy.Horst.dt : Aucune action entreprise. C:\Documents and Settings\Quentin\Local Settings\Temp\50exhdd.e.exe -> Proxy.Horst.dt : Aucune action entreprise. C:\Documents and Settings\Quentin\Local Settings\Temp\52exhdd.e.exe -> Proxy.Horst.dt : Aucune action entreprise. C:\Documents and Settings\Quentin\Local Settings\Temp\52exhdd.f.exe -> Proxy.Horst.dt : Aucune action entreprise. C:\Documents and Settings\Quentin\Local Settings\Temp\53exhdd.f.exe -> Proxy.Horst.dt : Aucune action entreprise. C:\Documents and Settings\Quentin\Local Settings\Temp\57exhdd.f.exe -> Proxy.Horst.dt : Aucune action entreprise. C:\Documents and Settings\Quentin\Local Settings\Temp\58exhdd.e.exe -> Proxy.Horst.dt : Aucune action entreprise. C:\Documents and Settings\Quentin\Local Settings\Temp\59exhdd.e.exe -> Proxy.Horst.dt : Aucune action entreprise. C:\Documents and Settings\Quentin\Local Settings\Temp\66exhdd.e.exe -> Proxy.Horst.dt : Aucune action entreprise. C:\Documents and Settings\Quentin\Local Settings\Temp\69exhdd.e.exe -> Proxy.Horst.dt : Aucune action entreprise. C:\Documents and Settings\Quentin\Local Settings\Temp\73exhdd.e.exe -> Proxy.Horst.dt : Aucune action entreprise. C:\Documents and Settings\Quentin\Local Settings\Temp\81exhdd.e.exe -> Proxy.Horst.dt : Aucune action entreprise. C:\Documents and Settings\Quentin\Local Settings\Temp\89exhdd.e.exe -> Proxy.Horst.dt : Aucune action entreprise. C:\Documents and Settings\Quentin\Local Settings\Temp\90exhdd.e.exe -> Proxy.Horst.dt : Aucune action entreprise. C:\Documents and Settings\Anne-Marie\Local Settings\Temp\tmp1.tmp -> Proxy.Horst.kq : Aucune action entreprise. C:\Documents and Settings\Marion\Local Settings\Temp\41exmodul32e.h.exe -> Proxy.Horst.kq : Aucune action entreprise. C:\Documents and Settings\Marion\Local Settings\Temp\tmp1.tmp -> Proxy.Horst.kq : Aucune action entreprise. C:\Documents and Settings\Quentin\Local Settings\Temp\10exmodul32e.h.exe -> Proxy.Horst.kq : Aucune action entreprise. C:\Documents and Settings\Quentin\Local Settings\Temp\tmp1.tmp -> Proxy.Horst.kq : Aucune action entreprise. C:\Documents and Settings\jcp\Local Settings\Temp\tmp1.tmp -> Proxy.Horst.kq : Aucune action entreprise. C:\System Volume Information\_restore{F91002A5-17F5-4FD2-BFBA-A7BE88E78D41}\RP264\A0219571.exe -> Proxy.Horst.kq : Aucune action entreprise. C:\WINDOWS\system32\nvsvcd.exe -> Proxy.Horst.kq : Aucune action entreprise. C:\Documents and Settings\Anne-Marie\Local Settings\Temp\1exmodul32e.g.exe -> Proxy.Horst.kx : Aucune action entreprise. C:\Documents and Settings\Anne-Marie\Local Settings\Temp\37exmodul32e.g.exe -> Proxy.Horst.kx : Aucune action entreprise. C:\Documents and Settings\Quentin\Local Settings\Temp\2exmodul32e.g.exe -> Proxy.Horst.kx : Aucune action entreprise. C:\Documents and Settings\Quentin\Local Settings\Temp\32exmodul32e.g.exe -> Proxy.Horst.kx : Aucune action entreprise. C:\Documents and Settings\Quentin\Local Settings\Temp\37exmodul32e.g.exe -> Proxy.Horst.kx : Aucune action entreprise. C:\Documents and Settings\Quentin\Local Settings\Temp\44exmodul32e.g.exe -> Proxy.Horst.kx : Aucune action entreprise. C:\Documents and Settings\Quentin\Local Settings\Temp\4exmodul32e.g.exe -> Proxy.Horst.kx : Aucune action entreprise. C:\Documents and Settings\Quentin\Local Settings\Temp\50exmodul32e.g.exe -> Proxy.Horst.kx : Aucune action entreprise. C:\Documents and Settings\Quentin\Local Settings\Temp\67exmodul32e.g.exe -> Proxy.Horst.kx : Aucune action entreprise. C:\Documents and Settings\Quentin\Local Settings\Temp\95exmodul32e.g.exe -> Proxy.Horst.kx : Aucune action entreprise. C:\Documents and Settings\Marion\Local Settings\Temp\setup.exe -> Proxy.Horst.ky : Aucune action entreprise. C:\Documents and Settings\Quentin\Local Settings\Temp\setup.exe -> Proxy.Horst.ky : Aucune action entreprise. C:\Documents and Settings\Anne-Marie\Cookies\anne-marie@112.2o7[2].txt -> TrackingCookie.2o7 : Aucune action entreprise. C:\Documents and Settings\Anne-Marie\Cookies\anne-marie@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Aucune action entreprise. C:\Documents and Settings\Anne-Marie\Cookies\anne-marie@partygaming.122.2o7[1].txt -> TrackingCookie.2o7 : Aucune action entreprise. C:\Documents and Settings\Marion\Cookies\marion@microsoftwga.112.2o7[1].txt -> TrackingCookie.2o7 : Aucune action entreprise. C:\Documents and Settings\Marion\Cookies\marion@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Aucune action entreprise. C:\Documents and Settings\Marion\Cookies\marion@partygaming.122.2o7[1].txt -> TrackingCookie.2o7 : Aucune action entreprise. C:\Documents and Settings\Quentin\Cookies\quentin@microsoftwlmessengermkt.112.2o7[1].txt -> TrackingCookie.2o7 : Aucune action entreprise. C:\Documents and Settings\Quentin\Cookies\quentin@msnaccountservices.112.2o7[1].txt -> TrackingCookie.2o7 : Aucune action entreprise. C:\Documents and Settings\Quentin\Cookies\quentin@msninvite.112.2o7[1].txt -> TrackingCookie.2o7 : Aucune action entreprise. C:\Documents and Settings\Quentin\Cookies\quentin@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Aucune action entreprise. C:\Documents and Settings\Quentin\Cookies\quentin@partygaming.122.2o7[1].txt -> TrackingCookie.2o7 : Aucune action entreprise. C:\Documents and Settings\Quentin\Local Settings\Temp\Cookies\quentin@partygaming.122.2o7[1].txt -> TrackingCookie.2o7 : Aucune action entreprise. C:\Documents and Settings\jcp\Cookies\jcp@microsofteup.112.2o7[1].txt -> TrackingCookie.2o7 : Aucune action entreprise. C:\Documents and Settings\jcp\Cookies\jcp@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Aucune action entreprise. C:\Documents and Settings\jcp\Cookies\jcp@partygaming.122.2o7[1].txt -> TrackingCookie.2o7 : Aucune action entreprise. C:\Documents and Settings\jcp\Cookies\jcp@adtech[2].txt -> TrackingCookie.Adtech : Aucune action entreprise. C:\Documents and Settings\Quentin\Cookies\quentin@install.bestoffersnetworks[2].txt -> TrackingCookie.Bestoffersnetworks : Aucune action entreprise. C:\Documents and Settings\Quentin\Cookies\quentin@www.burstnet[2].txt -> TrackingCookie.Burstnet : Aucune action entreprise. C:\Documents and Settings\jcp\Cookies\jcp@burstnet[2].txt -> TrackingCookie.Burstnet : Aucune action entreprise. C:\Documents and Settings\Marion\Cookies\marion@cz3.clickzs[2].txt -> TrackingCookie.Clickzs : Aucune action entreprise. C:\Documents and Settings\jcp\Cookies\jcp@estat[1].txt -> TrackingCookie.Estat : Aucune action entreprise. C:\Documents and Settings\Marion\Cookies\marion@adopt.euroclick[1].txt -> TrackingCookie.Euroclick : Aucune action entreprise. C:\Documents and Settings\Quentin\Cookies\quentin@adopt.euroclick[1].txt -> TrackingCookie.Euroclick : Aucune action entreprise. C:\Documents and Settings\jcp\Cookies\jcp@as1.falkag[2].txt -> TrackingCookie.Falkag : Aucune action entreprise. C:\Documents and Settings\Marion\Cookies\marion@cityclub.gamingpromo[2].txt -> TrackingCookie.Gamingpromo : Aucune action entreprise. C:\Documents and Settings\Marion\Cookies\marion@gamingpromo[2].txt -> TrackingCookie.Gamingpromo : Aucune action entreprise. C:\Documents and Settings\Quentin\Cookies\quentin@cityclub.gamingpromo[2].txt -> TrackingCookie.Gamingpromo : Aucune action entreprise. C:\Documents and Settings\Quentin\Cookies\quentin@gamingpromo[1].txt -> TrackingCookie.Gamingpromo : Aucune action entreprise. C:\Documents and Settings\Anne-Marie\Cookies\anne-marie@goldenpalace[1].txt -> TrackingCookie.Goldenpalace : Aucune action entreprise. C:\Documents and Settings\Quentin\Cookies\quentin@goldenpalace[2].txt -> TrackingCookie.Goldenpalace : Aucune action entreprise. C:\Documents and Settings\Marion\Cookies\marion@banner.grandonline[2].txt -> TrackingCookie.Grandonline : Aucune action entreprise. C:\Documents and Settings\Marion\Cookies\marion@grandonline[1].txt -> TrackingCookie.Grandonline : Aucune action entreprise. C:\Documents and Settings\Quentin\Cookies\quentin@banner.grandonline[2].txt -> TrackingCookie.Grandonline : Aucune action entreprise. C:\Documents and Settings\Quentin\Cookies\quentin@grandonline[1].txt -> TrackingCookie.Grandonline : Aucune action entreprise. C:\Documents and Settings\Anne-Marie\Cookies\anne-marie@ehg-dig.hitbox[2].txt -> TrackingCookie.Hitbox : Aucune action entreprise. C:\Documents and Settings\Quentin\Cookies\quentin@ehg-dig.hitbox[1].txt -> TrackingCookie.Hitbox : Aucune action entreprise. C:\Documents and Settings\Quentin\Cookies\quentin@ivwbox[1].txt -> TrackingCookie.Ivwbox : Aucune action entreprise. C:\Documents and Settings\Anne-Marie\Cookies\anne-marie@banner.newyorkcasino[1].txt -> TrackingCookie.Newyorkcasino : Aucune action entreprise. C:\Documents and Settings\Marion\Cookies\marion@banner.newyorkcasino[1].txt -> TrackingCookie.Newyorkcasino : Aucune action entreprise. C:\Documents and Settings\Marion\Cookies\marion@paypopup[2].txt -> TrackingCookie.Paypopup : Aucune action entreprise. C:\Documents and Settings\Quentin\Cookies\quentin@paypopup[1].txt -> TrackingCookie.Paypopup : Aucune action entreprise. C:\Documents and Settings\Quentin\Cookies\quentin@ads.planetactive[2].txt -> TrackingCookie.Planetactive : Aucune action entreprise. C:\Documents and Settings\Quentin\Cookies\quentin@ads-205.quarterserver[1].txt -> TrackingCookie.Quarterserver : Aucune action entreprise. C:\Documents and Settings\jcp\Cookies\jcp@questionmarket[2].txt -> TrackingCookie.Questionmarket : Aucune action entreprise. C:\Documents and Settings\Anne-Marie\Cookies\anne-marie@stats1.reliablestats[1].txt -> TrackingCookie.Reliablestats : Aucune action entreprise. C:\Documents and Settings\Marion\Cookies\marion@stats1.reliablestats[1].txt -> TrackingCookie.Reliablestats : Aucune action entreprise. C:\Documents and Settings\Quentin\Cookies\quentin@stats1.reliablestats[1].txt -> TrackingCookie.Reliablestats : Aucune action entreprise. C:\Documents and Settings\jcp\Cookies\jcp@stats1.reliablestats[2].txt -> TrackingCookie.Reliablestats : Aucune action entreprise. C:\Documents and Settings\jcp\Cookies\jcp@bs.serving-sys[2].txt -> TrackingCookie.Serving-sys : Aucune action entreprise. C:\Documents and Settings\jcp\Cookies\jcp@serving-sys[2].txt -> TrackingCookie.Serving-sys : Aucune action entreprise. C:\Documents and Settings\jcp\Cookies\jcp@www.smartadserver[1].txt -> TrackingCookie.Smartadserver : Aucune action entreprise. C:\Documents and Settings\jcp\Cookies\jcp@tacoda[1].txt -> TrackingCookie.Tacoda : Aucune action entreprise. C:\Documents and Settings\jcp\Cookies\jcp@weborama[1].txt -> TrackingCookie.Weborama : Aucune action entreprise. C:\Documents and Settings\Marion\Cookies\marion@yadro[1].txt -> TrackingCookie.Yadro : Aucune action entreprise. C:\Documents and Settings\Anne-Marie\Cookies\anne-marie@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Aucune action entreprise. C:\Documents and Settings\Marion\Cookies\marion@ad.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Aucune action entreprise. C:\Documents and Settings\Quentin\Cookies\quentin@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Aucune action entreprise. C:\Documents and Settings\Quentin\Local Settings\Temp\Cookies\quentin@ad.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Aucune action entreprise. Fin du rapport et voici enfin le rapport antivir AntiVir PersonalEdition Classic Report file date: samedi 4 novembre 2006 10:43 Scanning for 546033 virus strains and unwanted programs. Licensed to: Avira AntiVir PersonalEdition Classic Serial number: 0000149996-WURGE-0001 Platform: Windows XP Windows version: (Service Pack 1) [5.1.2600] Username: jcp Computer name: ROCKY Version information: AVSCAN.EXE : 7.0.0.47 200744 21/08/2006 11:06:56 AVSCAN.DLL : 7.0.0.45 41000 07/09/2006 11:56:33 LUKE.DLL : 7.0.0.47 118824 07/09/2006 11:32:33 LUKERES.DLL : 7.0.0.47 9256 07/09/2006 11:56:33 ANTIVIR0.VDF : 6.35.0.1 7371264 31/05/2006 11:35:27 ANTIVIR1.VDF : 6.36.0.228 2062336 02/11/2006 08:16:30 ANTIVIR2.VDF : 6.36.0.229 2048 02/11/2006 08:16:30 ANTIVIR3.VDF : 6.36.0.236 56832 03/11/2006 08:16:30 AVEWIN32.DLL : 7.2.0.37 1901056 04/11/2006 08:16:30 AVPREF.DLL : 7.0.0.2 23592 24/07/2006 13:36:04 AVREP.DLL : 6.36.0.144 876584 04/11/2006 08:16:30 AVRPBASE.DLL : 7.0.0.0 2162728 30/03/2006 09:43:31 AVPACK32.DLL : 7.2.0.5 368680 04/11/2006 08:16:30 AVREG.DLL : 6.31.0.90 27688 28/07/2005 11:06:36 NETNT.DLL : 6.32.0.0 6696 27/09/2005 08:56:49 NETNW.DLL : 7.0.0.0 9768 24/07/2006 13:35:55 RCIMAGE.DLL : 7.0.0.74 1642536 01/08/2006 12:22:57 RCTEXT.DLL : 7.0.1.4 77864 04/11/2006 08:16:29 Configuration settings for the scan: Jobname.......................: Local Drives Configuration file............: C:\Program Files\AntiVir PersonalEdition Classic\alldrives.avp Boot sectors..................: C,A,D Scan memory...................: 1 Process scan..................: 1 Scan all files................: 1 Scan archives.................: 1 Recursion depth...............: 20 Smart extensions..............: 1 Skipped archive types.........: 1000,1001,1002,1003,1004,1005, Macro heuristic...............: 1 File heuristic................: 2 Primary action................: 1 Secondary action..............: 0 Start of the scan: samedi 4 novembre 2006 10:44 The scan of running processes will be started 5 Processes were scanned Start scanning boot sectors: Boot sector 'C:\' [NOTE] No virus was found! Boot sector 'A:\' [NOTE] In the drive 'A:\' no data medium is inserted! Starting to scan the registry. The registry was scanned ( 11 files ). Starting the file scan: C:\pagefile.sys [WARNING] The file could not be opened! C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\DSS\MachineKeys\ce6e8c707cbc2a93505a6991ca03f52f_86d20fe3-bd77-4c92-a960-be15ae104109 [WARNING] The file could not be opened! C:\Documents and Settings\jcp\NTUSER.DAT [WARNING] The file could not be opened! C:\Documents and Settings\jcp\ntuser.dat.LOG [WARNING] The file could not be opened! C:\Documents and Settings\jcp\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat [WARNING] The file could not be opened! C:\Documents and Settings\jcp\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG [WARNING] The file could not be opened! C:\Documents and Settings\jcp\Local Settings\Temp\Perflib_Perfdata_378.dat [WARNING] The file could not be opened! C:\Documents and Settings\Marion\Mes documents\Ma musique\cd1\divers\2 Charles Aznavour - 20 Chansons D'Or - Full Album - Mp3 Eac Lame Extreme - Edj.ace [0] Archive type: ACE --> Charles Aznavour - 20 chansons d'or\01 - Je m'voyais d‚j….mp3 [WARNING] Error creating the file --> Charles Aznavour - 20 chansons d'or\03 - Les plaisirs d‚mod‚s.mp3 [WARNING] Error creating the file --> Charles Aznavour - 20 chansons d'or\05 - Les com‚diens.mp3 [WARNING] Error creating the file --> Charles Aznavour - 20 chansons d'or\08 - Non je n'ai rien oubli‚.mp3 [WARNING] Error creating the file --> Charles Aznavour - 20 chansons d'or\13 - La bohŠme.mp3 [WARNING] Error creating the file --> Charles Aznavour - 20 chansons d'or\15 - D‚sormais.mp3 [WARNING] Error creating the file C:\Documents and Settings\Quentin\Local Settings\Temp\58exmodul32e.i.exe [DETECTION] Is the Trojan horse TR/Proxy.Horst.Gen [iNFO] The file was moved to '45b1662b.qua'! C:\Documents and Settings\Quentin\Local Settings\Temp\59exmodul32e.i.exe [DETECTION] Is the Trojan horse TR/Proxy.Horst.Gen [iNFO] The file was moved to '45b1662d.qua'! C:\Documents and Settings\Quentin\Local Settings\Temp\62exmodul32e.i.exe [DETECTION] Is the Trojan horse TR/Proxy.Horst.Gen [iNFO] The file was moved to '45b16626.qua'! C:\Documents and Settings\Quentin\Local Settings\Temp\95exmodul32e.i.exe [DETECTION] Is the Trojan horse TR/Proxy.Horst.Gen [iNFO] The file was moved to '45b16629.qua'! C:\essai2\WINACE_211_PLUS_KEYGENMOF.zip [0] Archive type: ZIP --> KeyGen.EXE [DETECTION] Is the Trojan horse TR/Drop.QLowZones.B [iNFO] The file was moved to '459a67f2.qua'! C:\Program Files\CDex\uninstall.exe [DETECTION] Contains signature of the dropper DR/Zlob.Gen [iNFO] The file was moved to '45b56a9c.qua'! C:\WINDOWS\system32\config\default [WARNING] The file could not be opened! C:\WINDOWS\system32\config\default.LOG [WARNING] The file could not be opened! C:\WINDOWS\system32\config\SAM [WARNING] The file could not be opened! C:\WINDOWS\system32\config\SAM.LOG [WARNING] The file could not be opened! C:\WINDOWS\system32\config\SECURITY [WARNING] The file could not be opened! C:\WINDOWS\system32\config\SECURITY.LOG [WARNING] The file could not be opened! C:\WINDOWS\system32\config\software [WARNING] The file could not be opened! C:\WINDOWS\system32\config\software.LOG [WARNING] The file could not be opened! C:\WINDOWS\system32\config\system [WARNING] The file could not be opened! C:\WINDOWS\system32\config\system.LOG [WARNING] The file could not be opened! C:\WINDOWS\system32\drivers\sptd.sys [WARNING] The file could not be opened! C:\WINDOWS\system32\drivers\sptd2493.sys [WARNING] The file could not be opened! The path A:\ could not be found! Le périphérique n'est pas prêt. The path D:\ could not be found! Le périphérique n'est pas prêt. End of the scan: samedi 4 novembre 2006 11:38 Used time: 54:49 min The scan has been done completely. 6105 Scanning directories 233382 Files were scanned 6 viruses and/or unwanted programs were found 0 files were deleted 0 files were repaired 6 files were moved to quarantine 0 files were renamed 4573 Archives were scanned 25 Warnings 9 Notes a+ rubiks -
pc infecte par winantivirus 2006
rubiks a répondu à un(e) sujet de rubiks dans Analyses et éradication malwares
merci de ta reponse, mais j'ai deja essayé (en fait j'avais commencé par cette procédure) et ça n'a pas marché. le spy est toujours présent. quelqu'un aurais une autre idée? a+ rubiks -
Bonjour à toutes et à tous, J’ai en ce moment à la maison le pc d'un ami qui s’est fait infecter par winantivirus 2006 (un de plus !!). J’ai essayé de suivre les instructions d’éradication que j’ai pu trouver sur différents sites y compris sur zébulon mais rien n’y fait. J’ai essayé les différent anti-spywares (ad-aware, spybot, ewido, vundofix) mais rien à faire, cette saleté revient toujours. J’ai donc fait un log avec hijackthis que je me permets de vous soumettre en espérant que quelqu’un pourra m’aider. Voici le log : Logfile of HijackThis v1.99.1 Scan saved at 09:26:35, on 04/11/2006 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\System32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe C:\WINDOWS\system32\drivers\KodakCCS.exe C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe C:\Program Files\Photodex\ProShowGold\ScsiAccess.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe C:\Program Files\Logitech\iTouch\iTouch.exe C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe C:\Program Files\AntiVir PersonalEdition Classic\sched.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\HijackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.neufportail.fr/ R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Barre d'outils MSN Search Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1105\fr-fr\msntb.dll O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O3 - Toolbar: Barre d'outils MSN Search - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1105\fr-fr\msntb.dll O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe O4 - HKLM\..\Run: [Easy-PrintToolBox] C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min O8 - Extra context menu item: &MSN Search - res://C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1105\fr-fr\msntb.dll/search.htm O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O8 - Extra context menu item: Easy-WebPrint Ajouter à la liste d'impressions - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html O8 - Extra context menu item: Easy-WebPrint Impression rapide - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html O8 - Extra context menu item: Easy-WebPrint Imprimer - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html O8 - Extra context menu item: Easy-WebPrint Prévisualiser - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0000.1105\fr-fr\msntabres.dll/229?7f98c6851f7543d9a4cc2a944f8e89 O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0000.1105\fr-fr\msntabres.dll/230?7f98c6851f7543d9a4cc2a944f8e89 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab O16 - DPF: {2250C29C-C5E9-4F55-BE4E-01E45A40FCF1} (CMediaMix Object) - http://musicmix.messenger.msn.com/Medialogic.CAB O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab31267.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1134586360437 O16 - DPF: {71DA2A4E-ACB3-4065-9E41-8BC42EABE427} - http://scripts.dlv4.com/binaries/IA/svcia32_FR_XP.cab O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse...pDownloader.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab31267.cab O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - AVIRA GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe" -k runservice (file missing) O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe O23 - Service: ScsiAccess - Unknown owner - C:\Program Files\Photodex\ProShowGold\ScsiAccess.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe merci d'avance et à bientôt. rubiks p.s. : le pc était "protégé" par norton antivirus que j'ai aussi bien du mal à supprimer.