

ikki2
Membres-
Compteur de contenus
8 -
Inscription
-
Dernière visite
ikki2's Achievements

Junior Member (3/12)
0
Réputation sur la communauté
-
Encore Virus W32.Myzorfk
ikki2 a répondu à un(e) sujet de ikki2 dans Analyses et éradication malwares
salut, désolé mais j'arrive pas a scanner avec Panda, il me met chaque fois qu'il y a une erreur de script sur la page!! A titre indicatif: a quoi sert tout ses scans avec différents anti virus? N'en n'existe t-il pas un plus performant qui peut tout faire en une fois?? -
Encore Virus W32.Myzorfk
ikki2 a répondu à un(e) sujet de ikki2 dans Analyses et éradication malwares
Voila le rapport mais je crois qu'il n'a rien détecté!! 01/14/07 10:51:31 [info]: BlackLight Engine 1.0.55 initialized 01/14/07 10:51:31 [info]: OS: 5.1 build 2600 (Service Pack 2) 01/14/07 10:51:31 [Note]: 7019 4 01/14/07 10:51:31 [Note]: 7005 0 01/14/07 10:51:48 [Note]: 7006 0 01/14/07 10:51:48 [Note]: 7011 2044 01/14/07 10:51:48 [Note]: 7026 0 01/14/07 10:51:49 [Note]: 7026 0 01/14/07 10:52:05 [Note]: FSRAW library version 1.7.1021 01/14/07 10:52:05 [Note]: 2000 1012 01/14/07 11:45:59 [Note]: 7007 0 -
Encore Virus W32.Myzorfk
ikki2 a répondu à un(e) sujet de ikki2 dans Analyses et éradication malwares
voici le scan F-secure: Scanning Report Saturday, January 13, 2007 21:45:49 - 23:16:57 Computer name: THOMASLAORA Scanning type: Scan system for viruses, rootkits, spyware Target: C:\ E:\ -------------------------------------------------------------------------------- Result: 6 malware found Tracking Cookie (spyware) System (Disinfected) System System System System System (Submitted) -------------------------------------------------------------------------------- Statistics Scanned: Files: 44481 System: 4400 Not scanned: 4 Actions: Disinfected: 1 Renamed: 0 Deleted: 0 None: 5 Submitted: 1 Files not scanned: E:\PAGEFILE.SYS E:\WINDOWS\SYSTEM32\DRIVERS\DTSCSI.SYS E:\WINDOWS\SYSTEM32\DRIVERS\SPTD.SYS E:\WINDOWS\SYSTEM32\CONFIG\DEFAULT -------------------------------------------------------------------------------- Options Scanning engines: F-Secure Libra: 2.4.2, 2007-01-12 F-Secure AVP: 7.0.171, 2007-01-12 F-Secure Orion: 1.2.37, 2007-01-11 F-Secure Blacklight: 1.0.53, 0000-00-00 F-Secure Draco: 1.0.35, 0260-02-44 F-Secure Pegasus: 1.19.0, 2006-11-19 Scanning options: Scan defined files: COM EXE SYS OV? BIN SCR DLL SHS HTM HTML HTT VBS JS INF VXD DO? XL? RTF CPL WIZ HTA PP? PWZ P?T MSO PIF . ACM ASP AX CNV CSC DRV INI MDB MPD MPP MPT OBD OBT OCX PCI TLB TSP WBK WBT WPC WSH VWP WML BOO HLP TD0 TT6 MSG ASD JSE VBE WSC CHM EML PRC SHB LNK WSF {* PDF ZL? XML ZIP XXX Use Advanced heuristics -------------------------------------------------------------------------------- Copyright © 1998-2006 Product support |Send virus sample to F-Secure F-Secure assumes no responsibility for material created or published by third parties that F-Secure World Wide Web pages have a link to. Unless you have clearly stated otherwise, by submitting material to any of our servers, for example by E-mail or via our F-Secure's CGI E-mail, you agree that the material you make available may be published in the F-Secure World Wide Pages or hard-copy publications. You will reach F-Secure public web site by clicking on underlined links. While doing this, your access will be logged to our private access statistics with your domain name.This information will not be given to any third party. You agree not to take action against us in relation to material that you submit. Unless you have clearly stated otherwise, by submitting material you warrant that F-Secure may incorporate any concepts described in it in the F-Secure products/publications without liability. -
Encore Virus W32.Myzorfk
ikki2 a répondu à un(e) sujet de ikki2 dans Analyses et éradication malwares
'Soir, Pour AntiVir, je comprends tjrs pas, plus aucune traces et j'ai regardé ds le fichiers que tu me disais!! Pour le reste voici les différents rapports: 11:00: Removal process completed. Elapsed time 00:00:24 11:00: Quarantining All Traces: xiti cookie 11:00: Quarantining All Traces: tribalfusion cookie 11:00: Quarantining All Traces: tradedoubler cookie 11:00: Quarantining All Traces: statcounter cookie 11:00: Quarantining All Traces: realmedia cookie 11:00: Quarantining All Traces: 2o7.net cookie 11:00: Quarantining All Traces: metriweb.be cookie 11:00: Quarantining All Traces: bluestreak cookie 11:00: Quarantining All Traces: 247realmedia cookie 11:00: Quarantining All Traces: websearch toolbar 11:00: Quarantining All Traces: spy-shield 11:00: Quarantining All Traces: sicro dialer 11:00: Quarantining All Traces: mirar webband 11:00: Quarantining All Traces: logih adware 11:00: Quarantining All Traces: fastlook hijacker 11:00: Removal process initiated 10:54: Traces Found: 28 10:54: Custom Sweep has completed. Elapsed time 01:18:27 10:54: File Sweep Complete, Elapsed Time: 01:17:07 Accès refusé 10:54: Warning: Unable to sweep compressed file: System Error. Code: 5. Accès refusé 10:53: Warning: Unable to sweep compressed file: System Error. Code: 5. Accès refusé 10:51: Warning: Unable to sweep compressed file: System Error. Code: 5. Accès refusé 10:49: Warning: Unable to sweep compressed file: System Error. Code: 5. Accès refusé 10:42: Warning: Unable to sweep compressed file: System Error. Code: 5. Accès refusé 10:39: Warning: Unable to sweep compressed file: System Error. Code: 5. Espace insuffisant pour traiter cette commande 10:35: Warning: Unable to sweep compressed file: System Error. Code: 8. Accès refusé 10:35: Warning: Unable to sweep compressed file: System Error. Code: 5. 10:34: a0443682.ini (ID = 258329) 10:34: a0443681.ini (ID = 258328) 10:30: switchagreement.txt (ID = 76024) 9:58: a0443680.ini (ID = 258326) 9:58: a0443679.ini (ID = 258325) 9:53: Warning: Failed to access drive D: 9:37: Starting File Sweep 9:37: Warning: Failed to access drive A: 9:37: Cookie Sweep Complete, Elapsed Time: 00:00:00 9:37: thomas@xiti[1].txt (ID = 3717) 9:37: Found Spy Cookie: xiti cookie 9:37: thomas@tribalfusion[2].txt (ID = 3589) 9:37: Found Spy Cookie: tribalfusion cookie 9:37: thomas@tradedoubler[2].txt (ID = 3575) 9:37: Found Spy Cookie: tradedoubler cookie 9:37: thomas@statcounter[1].txt (ID = 3447) 9:37: Found Spy Cookie: statcounter cookie 9:37: thomas@realmedia[1].txt (ID = 3235) 9:37: Found Spy Cookie: realmedia cookie 9:37: thomas@msnportal.112.2o7[1].txt (ID = 1958) 9:37: Found Spy Cookie: 2o7.net cookie 9:37: thomas@metriweb[1].txt (ID = 2992) 9:37: Found Spy Cookie: metriweb.be cookie 9:37: thomas@bluestreak[2].txt (ID = 2314) 9:37: Found Spy Cookie: bluestreak cookie 9:37: thomas@247realmedia[2].txt (ID = 1953) 9:37: Found Spy Cookie: 247realmedia cookie 9:37: Starting Cookie Sweep 9:37: Registry Sweep Complete, Elapsed Time:00:01:11 9:37: HKU\S-1-5-18\software\microsoft\internet explorer\extensions\cmdmapping\ || {686c970f-1d7d-4469-85d1-4b35763b56cc} (ID = 146456) 9:37: HKU\S-1-5-21-1844237615-2139871995-682003330-1004\software\microsoft\internet explorer\extensions\cmdmapping\ || {686c970f-1d7d-4469-85d1-4b35763b56cc} (ID = 146456) 9:37: Found Adware: websearch toolbar 9:37: HKLM\software\classes\typelib\{dfcda823-80c5-4f55-b328-7efd4afbd9a0}\ (ID = 1193558) 9:37: HKLM\software\classes\clsid\{d7abe914-b8cf-4602-9145-6bdaaeda21aa}\ (ID = 1193512) 9:37: HKLM\software\classes\ad-protect.server.1\ (ID = 1193450) 9:37: HKLM\software\classes\ad-protect.server\ (ID = 1193444) 9:37: HKCR\typelib\{dfcda823-80c5-4f55-b328-7efd4afbd9a0}\ (ID = 1193408) 9:37: HKCR\clsid\{d7abe914-b8cf-4602-9145-6bdaaeda21aa}\ (ID = 1193326) 9:37: HKCR\ad-protect.server.1\ (ID = 1193264) 9:37: HKCR\ad-protect.server\ (ID = 1193258) 9:37: Found Adware: spy-shield 9:37: HKLM\software\microsoft\code store database\distribution units\{33331111-1111-1111-1111-611111193457}\ (ID = 141760) 9:37: Found Adware: sicro dialer 9:37: HKLM\software\microsoft\code store database\distribution units\{33331111-1111-1111-1111-611111193458}\ (ID = 135094) 9:37: Found Adware: mirar webband 9:37: HKLM\software\microsoft\windows\currentversion\shellserviceobjectdelayload\ || systemcheck2 (ID = 129814) 9:37: Found Adware: logih adware 9:37: HKLM\software\microsoft\windows\currentversion\run\ || iexplore.exe (ID = 126410) 9:37: Found Adware: fastlook hijacker 9:37: Memory Sweep Complete, Elapsed Time: 00:00:00 9:37: Starting Registry Sweep 9:36: Starting Memory Sweep 9:36: Warning: Files are not scanned for viruses because AV engine failed to load. 9:36: Sweep initiated using definitions version 836 9:36: Spy Sweeper 5.2.3.2138 started 9:36: | Start of Session, samedi 13 janvier 2007 | ******** 9:36: | End of Session, samedi 13 janvier 2007 | 9:35: Program Version 5.2.3.2138 Using Spyware Definitions 836 9:35: Warning: Virus definitions files are invalid, please update your virus definitions. 220 9:20: The Internet Communication shield has blocked access to: TRY.STARWARE.COM 9:20: The Internet Communication shield has blocked access to: TRY.STARWARE.COM 9:18: Access to Hosts file blocked for E:\PROGRAM FILES\GRISOFT\AVG ANTI-SPYWARE 7.5\AVGAS.EXE Operation: File Access Target: Source: E:\PROGRAM FILES\KASPERSKY LAB\KASPERSKY INTERNET SECURITY 6.0\AVP.EXE 9:14: Tamper Detection Keylogger: Off BHO Shield: On IE Security Shield: On Alternate Data Stream (ADS) Execution Shield: On Startup Shield: On Common Ad Sites: Off Hosts File Shield: On Internet Communication Shield: On ActiveX Shield: On Windows Messenger Service Shield: On IE Favorites Shield: On Spy Installation Shield: On Memory Shield: On IE Hijack Shield: On IE Tracking Cookies Shield: Off 9:14: Shield States 9:13: Spyware Definitions: 836 9:13: Warning: Virus definitions files are invalid, please update your virus definitions. 220 9:12: Spy Sweeper 5.2.3.2138 started 22:09: Access to Hosts file allowed for E:\PROGRAM FILES\GRISOFT\AVG ANTI-SPYWARE 7.5\AVGAS.EXE 21:08: Access to Hosts file allowed for E:\PROGRAM FILES\GRISOFT\AVG ANTI-SPYWARE 7.5\AVGAS.EXE 20:08: Access to Hosts file allowed for E:\PROGRAM FILES\GRISOFT\AVG ANTI-SPYWARE 7.5\AVGAS.EXE Keylogger: Off BHO Shield: On IE Security Shield: On Alternate Data Stream (ADS) Execution Shield: On Startup Shield: On Common Ad Sites: Off Hosts File Shield: On Internet Communication Shield: On ActiveX Shield: On Windows Messenger Service Shield: On IE Favorites Shield: On Spy Installation Shield: On Memory Shield: On IE Hijack Shield: On IE Tracking Cookies Shield: Off 19:08: Shield States 19:03: Spyware Definitions: 816 19:03: Warning: Virus definitions files are invalid, please update your virus definitions. 220 19:02: Spy Sweeper 5.2.3.2138 started 19:02: Spy Sweeper 5.2.3.2138 started 19:02: | Start of Session, vendredi 12 janvier 2007 | ******** Ensuite le rapport HijackThis: Logfile of HijackThis v1.99.1 Scan saved at 21:49:12, on 13/01/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.5730.0011) Running processes: E:\WINDOWS\System32\smss.exe E:\WINDOWS\system32\winlogon.exe E:\WINDOWS\system32\services.exe E:\WINDOWS\system32\lsass.exe E:\WINDOWS\system32\Ati2evxx.exe E:\WINDOWS\system32\svchost.exe E:\WINDOWS\System32\svchost.exe E:\WINDOWS\system32\spoolsv.exe E:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe E:\Program Files\F-Secure\fswsclds.exe E:\WINDOWS\system32\HPZipm12.exe E:\Program Files\Analog Devices\SoundMAX\SMAgent.exe E:\WINDOWS\System32\svchost.exe E:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe E:\WINDOWS\system32\Ati2evxx.exe E:\WINDOWS\Explorer.EXE E:\WINDOWS\System32\LVCOMSX.EXE E:\Program Files\Logitech\Video\LogiTray.exe E:\WINDOWS\system32\rundll32.exe E:\Program Files\QuickTime\qttask.exe E:\Program Files\Java\jre1.5.0_06\bin\jusched.exe E:\WINDOWS\system32\rundll32.exe E:\Program Files\Anti-Blaxx\Anti-Blaxx.exe E:\Program Files\DAEMON Tools\daemon.exe E:\Program Files\HP\HP Software Update\HPWuSchd2.exe E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe E:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe E:\WINDOWS\system32\NotifyPhoneBook.exe E:\Program Files\Logitech\Video\FxSvr2.exe E:\WINDOWS\system32\ctfmon.exe E:\Program Files\Messenger\msmsgs.exe E:\Program Files\MSN Messenger\MsnMsgr.Exe E:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe E:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe E:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe E:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe E:\Program Files\Internet Explorer\iexplore.exe E:\DOCUME~1\thomas\LOCALS~1\Temp\OnlineScanner\Anti-Virus\fsgk32.exe E:\DOCUME~1\thomas\LOCALS~1\Temp\OnlineScanner\Anti-Virus\fssm32.exe E:\Documents and Settings\thomas\Bureau\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens F2 - REG:system.ini: UserInit=userinit.exe O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - E:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - E:\Program Files\Windows Live Toolbar\msntb.dll O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - E:\Program Files\Windows Live Toolbar\msntb.dll O4 - HKLM\..\Run: [LVCOMSX] E:\WINDOWS\System32\LVCOMSX.EXE O4 - HKLM\..\Run: [LogitechVideoRepair] "E:\Program Files\Logitech\Video\ISStart.exe" O4 - HKLM\..\Run: [LogitechVideoTray] "E:\Program Files\Logitech\Video\LogiTray.exe" O4 - HKLM\..\Run: [AME_CSA] rundll32 amecsa.cpl,RUN_DLL O4 - HKLM\..\Run: [QuickTime Task] "E:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [sunJavaUpdateSched] "E:\Program Files\Java\jre1.5.0_06\bin\jusched.exe" O4 - HKLM\..\Run: [NeroFilterCheck] E:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [hpfsched] E:\WINDOWS\hpfsched.exe O4 - HKLM\..\Run: [bluetoothAuthenticationAgent] "rundll32.exe" bthprops.cpl,,BluetoothAuthenticationAgent O4 - HKLM\..\Run: [Anti-Blaxx Manager] "E:\Program Files\Anti-Blaxx\Anti-Blaxx.exe" O4 - HKLM\..\Run: [DAEMON Tools] "E:\Program Files\DAEMON Tools\daemon.exe" -lang 1033 O4 - HKLM\..\Run: [HP Software Update] "E:\Program Files\HP\HP Software Update\HPWuSchd2.exe" O4 - HKLM\..\Run: [kis] "E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe" O4 - HKLM\..\Run: [update] E:\Program Files\AntiVir PersonalEdition Classic\preupd.exe /CALLSCHEDULER /DM="0" /CALLSCHEDULER O4 - HKLM\..\Run: [!AVG Anti-Spyware] "E:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized O4 - HKLM\..\Run: [spySweeper] "E:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray O4 - HKCU\..\Run: [CTFMON.EXE] E:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MSMSGS] "E:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "E:\Program Files\Logitech\Video\ManifestEngine.exe" boot O4 - HKCU\..\Run: [MsnMsgr] "E:\Program Files\MSN Messenger\MsnMsgr.Exe" /background O4 - Global Startup: Démarrage rapide du logiciel HP Image Zone.lnk = E:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe O4 - Global Startup: HP Digital Imaging Monitor.lnk = E:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = E:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O8 - Extra context menu item: &Windows Live Search - res://E:\Program Files\Windows Live Toolbar\msntb.dll/search.htm O8 - Extra context menu item: Ajouter à Kaspersky Anti-Banner - E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\\ie_banner_deny.htm O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra button: Antivirus Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\scieplugin.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe O11 - Options group: [iNTERNATIONAL] International* O16 - DPF: {24311111-1111-1121-1111-111191113457} - file://c:\eied_s7.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co...b?1114527428817 O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2005102...all/xscan53.cab O16 - DPF: {9D190AE6-C81E-4039-8061-978EBAD10073} (F-Secure Online Scanner 3.0) - http://support.f-secure.com/ols/fscax.cab O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmesse...pdownloader.cab O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/hpdj/fr/check/qdiagh.cab?326 O17 - HKLM\System\CCS\Services\Tcpip\..\{F913E87C-5C08-4413-8A9C-0CCA75AD489E}: NameServer = 194.119.228.67 193.74.208.135 O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "E:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O20 - AppInit_DLLs: E:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll O20 - Winlogon Notify: klogon - E:\WINDOWS\system32\klogon.dll O20 - Winlogon Notify: WgaLogon - E:\WINDOWS\SYSTEM32\WgaLogon.dll O20 - Winlogon Notify: WRNotifier - E:\WINDOWS\SYSTEM32\WRLogonNTF.dll O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - E:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - E:\WINDOWS\system32\ati2sgag.exe O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - E:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe O23 - Service: Kaspersky Internet Security 6.0 (AVP) - Unknown owner - E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe" -r (file missing) O23 - Service: F-Secure Windows Security Center Legacy Detection Service (Fswsclds) - F-Secure Corporation - E:\Program Files\F-Secure\fswsclds.exe O23 - Service: Pml Driver HPZ12 - HP - E:\WINDOWS\system32\HPZipm12.exe O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - E:\Program Files\Analog Devices\SoundMAX\SMAgent.exe O23 - Service: Moteur Webroot Spy Sweeper (WebrootSpySweeperService) - Webroot Software, Inc. - E:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe Et celui exécuter en ligne: -
Encore Virus W32.Myzorfk
ikki2 a répondu à un(e) sujet de ikki2 dans Analyses et éradication malwares
Je vais effectué cette démarche mais avant tout, je voulais te dire que j'avais desinstallé AntiVir avec le gestionnaire Ajout/Supprimer programme et supprimé certain fichiers .EXE avec le gestionnaire de tâches; donc je ne vois pas ce que je peux faire de plus pour le désinstaller correctement! Si tu peux m'aider d'avantage..... -
Encore Virus W32.Myzorfk
ikki2 a répondu à un(e) sujet de ikki2 dans Analyses et éradication malwares
Salut, voici le rapport Smitfraudfix: SmitFraudFix v2.132 Rapport fait à 23:31:28,12, mar. 09/01/2007 Executé à partir de E:\Program Files\SmitfraudFix OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT Le type du système de fichiers est NTFS Fix executé en mode sans echec »»»»»»»»»»»»»»»»»»»»»»»» Avant SmitFraudFix !!!Attention, les clés qui suivent ne sont pas forcément infectées!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] "{b59f3ba4-98da-4b5f-8a2d-7b56fb11140b}"="buprestidae" [HKEY_CLASSES_ROOT\CLSID\{b59f3ba4-98da-4b5f-8a2d-7b56fb11140b}\InProcServer32] @="E:\WINDOWS\system32\cthkpcv.dll" [HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{b59f3ba4-98da-4b5f-8a2d-7b56fb11140b}\InProcServer32] @="E:\WINDOWS\system32\cthkpcv.dll" »»»»»»»»»»»»»»»»»»»»»»»» Arret des processus »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix GenericRenosFix by S!Ri E:\WINDOWS\system32\cthkpcv.dll -> Hoax.Win32.Renos.gen.i E:\WINDOWS\system32\cthkpcv.dll -> Deleted »»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés E:\DOCUME~1\ALLUSE~1\Bureau\Online Security Guide.url supprimé E:\DOCUME~1\ALLUSE~1\Bureau\Security Troubleshooting.url supprimé E:\DOCUME~1\thomas\Favoris\Online Security Test.url supprimé E:\DOCUME~1\ALLUSE~1\MENUDM~1\Online Security Guide.url supprimé E:\DOCUME~1\ALLUSE~1\MENUDM~1\Security Troubleshooting.url supprimé E:\Program Files\strCodec\ supprimé E:\Program Files\Video ActiveX Object\ supprimé »»»»»»»»»»»»»»»»»»»»»»»» Suppression Fichiers Temporaires »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System !!!Attention, les clés qui suivent ne sont pas forcément infectées!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] "System"="" »»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre Nettoyage terminé. »»»»»»»»»»»»»»»»»»»»»»»» Après SmitFraudFix !!!Attention, les clés qui suivent ne sont pas forcément infectées!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll »»»»»»»»»»»»»»»»»»»»»»»» Fin Ensuite le nouveau rapport HijackThis Logfile of HijackThis v1.99.1 Scan saved at 18:10:08, on 10/01/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.5730.0011) Running processes: E:\WINDOWS\System32\smss.exe E:\WINDOWS\system32\winlogon.exe E:\WINDOWS\system32\services.exe E:\WINDOWS\system32\lsass.exe E:\WINDOWS\system32\Ati2evxx.exe E:\WINDOWS\system32\svchost.exe E:\WINDOWS\System32\svchost.exe E:\WINDOWS\system32\spoolsv.exe E:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe E:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe E:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe E:\Program Files\F-Secure\fswsclds.exe E:\Program Files\Analog Devices\SoundMAX\SMAgent.exe E:\WINDOWS\System32\svchost.exe E:\WINDOWS\system32\Ati2evxx.exe E:\WINDOWS\Explorer.EXE E:\WINDOWS\System32\LVCOMSX.EXE E:\Program Files\Logitech\Video\LogiTray.exe E:\WINDOWS\system32\rundll32.exe E:\Program Files\QuickTime\qttask.exe E:\WINDOWS\system32\NotifyPhoneBook.exe E:\Program Files\Java\jre1.5.0_06\bin\jusched.exe E:\WINDOWS\system32\rundll32.exe E:\Program Files\Anti-Blaxx\Anti-Blaxx.exe E:\Program Files\DAEMON Tools\daemon.exe E:\WINDOWS\system32\ctfmon.exe E:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe E:\Program Files\HP\HP Software Update\HPWuSchd2.exe E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe E:\PROGRA~1\Grisoft\AVG7\avgcc.exe E:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe E:\Program Files\Messenger\msmsgs.exe E:\Program Files\Logitech\Video\FxSvr2.exe E:\PROGRA~1\Grisoft\AVG7\avgw.exe E:\Program Files\MSN Messenger\MsnMsgr.Exe E:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe E:\Program Files\ArcSoft\TotalMedia\TM Monitor.exe E:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe E:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe E:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe E:\Program Files\Internet Explorer\iexplore.exe E:\Documents and Settings\thomas\Bureau\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens F2 - REG:system.ini: UserInit=userinit.exe O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - E:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - E:\Program Files\Windows Live Toolbar\msntb.dll O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - E:\Program Files\Windows Live Toolbar\msntb.dll O4 - HKLM\..\Run: [LVCOMSX] E:\WINDOWS\System32\LVCOMSX.EXE O4 - HKLM\..\Run: [LogitechVideoRepair] E:\Program Files\Logitech\Video\ISStart.exe O4 - HKLM\..\Run: [LogitechVideoTray] E:\Program Files\Logitech\Video\LogiTray.exe O4 - HKLM\..\Run: [AME_CSA] rundll32 amecsa.cpl,RUN_DLL O4 - HKLM\..\Run: [QuickTime Task] "E:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [iexplore.exe] E:\Program Files\Internet Explorer\iexplore.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] E:\Program Files\Java\jre1.5.0_06\bin\jusched.exe O4 - HKLM\..\Run: [NeroFilterCheck] E:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [hpfsched] E:\WINDOWS\hpfsched.exe O4 - HKLM\..\Run: [bluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent O4 - HKLM\..\Run: [Anti-Blaxx Manager] E:\Program Files\Anti-Blaxx\Anti-Blaxx.exe O4 - HKLM\..\Run: [DAEMON Tools] "E:\Program Files\DAEMON Tools\daemon.exe" -lang 1033 O4 - HKLM\..\Run: [ATIPTA] "E:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" O4 - HKLM\..\Run: [HP Software Update] E:\Program Files\HP\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [kis] "E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe" O4 - HKLM\..\Run: [AVG7_CC] E:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP O4 - HKLM\..\Run: [update] E:\Program Files\AntiVir PersonalEdition Classic\preupd.exe /CALLSCHEDULER /DM="0" /CALLSCHEDULER O4 - HKLM\..\Run: [!AVG Anti-Spyware] "E:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized O4 - HKCU\..\Run: [CTFMON.EXE] E:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MSMSGS] "E:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "E:\Program Files\Logitech\Video\ManifestEngine.exe" boot O4 - HKCU\..\Run: [MsnMsgr] "E:\Program Files\MSN Messenger\MsnMsgr.Exe" /background O4 - Global Startup: Démarrage rapide du logiciel HP Image Zone.lnk = E:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe O4 - Global Startup: HP Digital Imaging Monitor.lnk = E:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = E:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: TM Monitor.lnk = E:\Program Files\ArcSoft\TotalMedia\TM Monitor.exe O8 - Extra context menu item: &Windows Live Search - res://E:\Program Files\Windows Live Toolbar\msntb.dll/search.htm O8 - Extra context menu item: Ajouter à Kaspersky Anti-Banner - E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\\ie_banner_deny.htm O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra button: Antivirus Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\scieplugin.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe O11 - Options group: [iNTERNATIONAL] International* O16 - DPF: {24311111-1111-1121-1111-111191113457} - file://c:\eied_s7.cab O16 - DPF: {33331111-1111-1111-1111-611111193457} - file://c:\ex.cab O16 - DPF: {33331111-1111-1111-1111-611111193458} - file://c:\ex.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co...b?1114527428817 O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2005102...all/xscan53.cab O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmesse...pdownloader.cab O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/hpdj/fr/check/qdiagh.cab?326 O17 - HKLM\System\CCS\Services\Tcpip\..\{F913E87C-5C08-4413-8A9C-0CCA75AD489E}: NameServer = 194.119.228.67 193.74.208.135 O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "E:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O20 - AppInit_DLLs: E:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll O20 - Winlogon Notify: klogon - E:\WINDOWS\system32\klogon.dll O20 - Winlogon Notify: WgaLogon - E:\WINDOWS\SYSTEM32\WgaLogon.dll O21 - SSODL: SystemCheck2 - {54645654-2225-4455-44A1-9F4543D34545} - (no file) O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - E:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - E:\WINDOWS\system32\ati2sgag.exe O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - E:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - E:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - E:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe O23 - Service: Kaspersky Internet Security 6.0 (AVP) - Unknown owner - E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe" -r (file missing) O23 - Service: F-Secure Windows Security Center Legacy Detection Service (Fswsclds) - F-Secure Corporation - E:\Program Files\F-Secure\fswsclds.exe O23 - Service: Pml Driver HPZ12 - HP - E:\WINDOWS\system32\HPZipm12.exe O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - E:\Program Files\Analog Devices\SoundMAX\SMAgent.exe Et pour finir le rapport AVG Anti Spyware: --------------------------------------------------------- AVG Anti-Spyware - Rapport d'analyse --------------------------------------------------------- + Créé à: 17:53:52 10/01/2007 + Résultat de l'analyse: HKU\S-1-5-21-1844237615-2139871995-682003330-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0D045BAA-4BD3-4C94-BE8B-21536BD6BD9F} -> Adware.Generic : Ignoré. HKU\S-1-5-21-1844237615-2139871995-682003330-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{67982BB7-0F95-44C5-92DC-E3AF3DC19D6D} -> Adware.Generic : Ignoré. E:\System Volume Information\_restore{DB4C3F3F-9E46-49D2-A57A-CEA2FD691FDD}\RP321\A0443601.exe -> Adware.MalwareWiped : Ignoré. E:\System Volume Information\_restore{DB4C3F3F-9E46-49D2-A57A-CEA2FD691FDD}\RP322\A0443688.exe -> Adware.MalwareWiped : Ignoré. E:\Program Files\DAEMON Tools\SetupDTSB.exe -> Adware.SaveNow : Ignoré. E:\System Volume Information\_restore{DB4C3F3F-9E46-49D2-A57A-CEA2FD691FDD}\RP280\A0430818.exe -> Adware.SaveNow : Ignoré. HKU\S-1-5-21-1844237615-2139871995-682003330-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1F6FE2C2-6040-4645-9053-7F689AFFE176} -> Adware.VirusBlast : Ignoré. E:\System Volume Information\_restore{DB4C3F3F-9E46-49D2-A57A-CEA2FD691FDD}\RP323\A0443922.dll -> Adware.WorldSecurityOnline : Ignoré. HKLM\SOFTWARE\Classes\CLSID\{daa873d4-958c-453c-81ca-3fe6f3676a87} -> Downloader.Fugif : Nettoyé et sauvegardé (mise en quarantaine). E:\System Volume Information\_restore{DB4C3F3F-9E46-49D2-A57A-CEA2FD691FDD}\RP323\A0443927.exe -> Downloader.Zlob.bfj : Nettoyé et sauvegardé (mise en quarantaine). E:\System Volume Information\_restore{DB4C3F3F-9E46-49D2-A57A-CEA2FD691FDD}\RP323\A0443930.exe -> Not-A-Virus.Hoax.Win32.Renos.fo : Ignoré. Fin du rapport Voila, le problème de la connexion internet est résolu!! Merci bcps!!! Je me pose néanmoins une question, mon pc rame bcps! Dois je garder AVG comme anti-virus ou mon KasperskyInternet Security 6.0? Encore une fois merci de votre aide! -
Encore Virus W32.Myzorfk
ikki2 a répondu à un(e) sujet de ikki2 dans Analyses et éradication malwares
Voici le rapport de smitfraudfix: SmitFraudFix v2.132 Rapport fait à 20:07:47,04, mar. 09/01/2007 Executé à partir de E:\Program Files\SmitfraudFix OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT Le type du système de fichiers est NTFS Fix executé en mode normal »»»»»»»»»»»»»»»»»»»»»»»» E:\ »»»»»»»»»»»»»»»»»»»»»»»» E:\WINDOWS »»»»»»»»»»»»»»»»»»»»»»»» E:\WINDOWS\system »»»»»»»»»»»»»»»»»»»»»»»» E:\WINDOWS\Web »»»»»»»»»»»»»»»»»»»»»»»» E:\WINDOWS\system32 E:\WINDOWS\system32\cthkpcv.dll PRESENT ! »»»»»»»»»»»»»»»»»»»»»»»» E:\Documents and Settings\thomas »»»»»»»»»»»»»»»»»»»»»»»» E:\Documents and Settings\thomas\Application Data »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer E:\DOCUME~1\ALLUSE~1\MENUDM~1\Online Security Guide.url PRESENT ! E:\DOCUME~1\ALLUSE~1\MENUDM~1\Security Troubleshooting.url PRESENT ! »»»»»»»»»»»»»»»»»»»»»»»» E:\DOCUME~1\thomas\Favoris E:\DOCUME~1\thomas\Favoris\Online Security Test.url PRESENT ! »»»»»»»»»»»»»»»»»»»»»»»» Bureau E:\DOCUME~1\ALLUSE~1\Bureau\Online Security Guide.url PRESENT ! E:\DOCUME~1\ALLUSE~1\Bureau\Security Troubleshooting.url PRESENT ! »»»»»»»»»»»»»»»»»»»»»»»» E:\Program Files E:\Program Files\strCodec\ PRESENT ! E:\Program Files\Video ActiveX Object\ PRESENT ! »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0] "Source"="About:Home" "SubscribedURL"="About:Home" "FriendlyName"="Ma page d'accueil" »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler !!!Attention, les clés qui suivent ne sont pas forcément infectées!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] "{b59f3ba4-98da-4b5f-8a2d-7b56fb11140b}"="buprestidae" [HKEY_CLASSES_ROOT\CLSID\{b59f3ba4-98da-4b5f-8a2d-7b56fb11140b}\InProcServer32] @="E:\WINDOWS\system32\cthkpcv.dll" [HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{b59f3ba4-98da-4b5f-8a2d-7b56fb11140b}\InProcServer32] @="E:\WINDOWS\system32\cthkpcv.dll" »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs !!!Attention, les clés qui suivent ne sont pas forcément infectées!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="E:\\PROGRA~1\\KASPER~1\\KASPER~1.0\\adialhk.dll" »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System !!!Attention, les clés qui suivent ne sont pas forcément infectées!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] "System"="" »»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32 »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll »»»»»»»»»»»»»»»»»»»»»»»» Fin -
Bonjour a tous et bonne année 2007, étant nouveau sur ce site, après de nb heures de lecture, j'ai tout essaye pour me debarasser de ce virus mais en vain. Alors voila j'ai suivi la procédure de pré-nettoyage de MégaTaupe expliquée sur ce site. Après la dernière étape, voici mon rapport HijackThis: Logfile of HijackThis v1.99.1 Scan saved at 18:26:46, on 9/01/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.5730.0011) Running processes: E:\WINDOWS\System32\smss.exe E:\WINDOWS\system32\winlogon.exe E:\WINDOWS\system32\services.exe E:\WINDOWS\system32\lsass.exe E:\WINDOWS\system32\Ati2evxx.exe E:\WINDOWS\system32\svchost.exe E:\WINDOWS\System32\svchost.exe E:\WINDOWS\system32\spoolsv.exe E:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe E:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe E:\Program Files\F-Secure\fswsclds.exe E:\WINDOWS\system32\Ati2evxx.exe E:\Program Files\Analog Devices\SoundMAX\SMAgent.exe E:\WINDOWS\System32\svchost.exe E:\WINDOWS\Explorer.EXE E:\Program Files\Video ActiveX Object\isamonitor.exe E:\WINDOWS\System32\LVCOMSX.EXE E:\Program Files\Logitech\Video\LogiTray.exe E:\Program Files\Video ActiveX Object\isamini.exe E:\WINDOWS\system32\rundll32.exe E:\Program Files\QuickTime\qttask.exe E:\Program Files\Java\jre1.5.0_06\bin\jusched.exe E:\WINDOWS\system32\NotifyPhoneBook.exe E:\WINDOWS\system32\rundll32.exe E:\Program Files\Anti-Blaxx\Anti-Blaxx.exe E:\WINDOWS\system32\ctfmon.exe E:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe E:\Program Files\HP\HP Software Update\HPWuSchd2.exe E:\PROGRA~1\Grisoft\AVG7\avgcc.exe E:\Program Files\Messenger\msmsgs.exe E:\Program Files\Logitech\Video\FxSvr2.exe E:\Program Files\MSN Messenger\MsnMsgr.Exe E:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe E:\Program Files\ArcSoft\TotalMedia\TM Monitor.exe E:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe E:\WINDOWS\system32\wuauclt.exe E:\WINDOWS\system32\wscntfy.exe E:\Documents and Settings\thomas\Bureau\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.be/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens F2 - REG:system.ini: UserInit=userinit.exe O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {67982BB7-0F95-44C5-92DC-E3AF3DC19D6D} - E:\Program Files\Video ActiveX Object\isaddon.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - E:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - E:\Program Files\Windows Live Toolbar\msntb.dll O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - E:\Program Files\Windows Live Toolbar\msntb.dll O3 - Toolbar: Protection Bar - {0D045BAA-4BD3-4C94-BE8B-21536BD6BD9F} - E:\Program Files\Video ActiveX Object\iesplugin.dll (file missing) O4 - HKLM\..\Run: [LVCOMSX] E:\WINDOWS\System32\LVCOMSX.EXE O4 - HKLM\..\Run: [LogitechVideoRepair] E:\Program Files\Logitech\Video\ISStart.exe O4 - HKLM\..\Run: [LogitechVideoTray] E:\Program Files\Logitech\Video\LogiTray.exe O4 - HKLM\..\Run: [AME_CSA] rundll32 amecsa.cpl,RUN_DLL O4 - HKLM\..\Run: [QuickTime Task] "E:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [iexplore.exe] E:\Program Files\Internet Explorer\iexplore.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] E:\Program Files\Java\jre1.5.0_06\bin\jusched.exe O4 - HKLM\..\Run: [NeroFilterCheck] E:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [hpfsched] E:\WINDOWS\hpfsched.exe O4 - HKLM\..\Run: [bluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent O4 - HKLM\..\Run: [Anti-Blaxx Manager] E:\Program Files\Anti-Blaxx\Anti-Blaxx.exe O4 - HKLM\..\Run: [DAEMON Tools] "E:\Program Files\DAEMON Tools\daemon.exe" -lang 1033 O4 - HKLM\..\Run: [ATIPTA] "E:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" O4 - HKLM\..\Run: [HP Software Update] E:\Program Files\HP\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [kis] "E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe" O4 - HKLM\..\Run: [AVG7_CC] E:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP O4 - HKLM\..\Run: [update] E:\Program Files\AntiVir PersonalEdition Classic\preupd.exe /CALLSCHEDULER /DM="0" /CALLSCHEDULER O4 - HKCU\..\Run: [CTFMON.EXE] E:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MSMSGS] "E:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "E:\Program Files\Logitech\Video\ManifestEngine.exe" boot O4 - HKCU\..\Run: [MsnMsgr] "E:\Program Files\MSN Messenger\MsnMsgr.Exe" /background O4 - Global Startup: Démarrage rapide du logiciel HP Image Zone.lnk = E:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe O4 - Global Startup: HP Digital Imaging Monitor.lnk = E:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = E:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: TM Monitor.lnk = E:\Program Files\ArcSoft\TotalMedia\TM Monitor.exe O8 - Extra context menu item: &Windows Live Search - res://E:\Program Files\Windows Live Toolbar\msntb.dll/search.htm O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra button: Antivirus Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\scieplugin.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe O11 - Options group: [iNTERNATIONAL] International* O16 - DPF: {24311111-1111-1121-1111-111191113457} - file://c:\eied_s7.cab O16 - DPF: {33331111-1111-1111-1111-611111193457} - file://c:\ex.cab O16 - DPF: {33331111-1111-1111-1111-611111193458} - file://c:\ex.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co...b?1114527428817 O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2005102...all/xscan53.cab O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmesse...pdownloader.cab O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/hpdj/fr/check/qdiagh.cab?326 O17 - HKLM\System\CCS\Services\Tcpip\..\{F913E87C-5C08-4413-8A9C-0CCA75AD489E}: NameServer = 194.119.228.67 193.74.208.135 O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "E:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O20 - AppInit_DLLs: E:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll O20 - Winlogon Notify: klogon - E:\WINDOWS\system32\klogon.dll O20 - Winlogon Notify: WgaLogon - E:\WINDOWS\SYSTEM32\WgaLogon.dll O21 - SSODL: SystemCheck2 - {54645654-2225-4455-44A1-9F4543D34545} - (no file) O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - E:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - E:\WINDOWS\system32\ati2sgag.exe O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - E:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - E:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe O23 - Service: Kaspersky Internet Security 6.0 (AVP) - Unknown owner - E:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe" -r (file missing) O23 - Service: F-Secure Windows Security Center Legacy Detection Service (Fswsclds) - F-Secure Corporation - E:\Program Files\F-Secure\fswsclds.exe O23 - Service: Pml Driver HPZ12 - HP - E:\WINDOWS\system32\HPZipm12.exe O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - E:\Program Files\Analog Devices\SoundMAX\SMAgent.exe