Aller au contenu

Kinoa

Membres
  • Compteur de contenus

    8
  • Inscription

  • Dernière visite

Tout ce qui a été posté par Kinoa

  1. Bonsoir, Excuse-moi pour le retard, mais le ciel nous tombe sur la tête depuis 2 jours et je crains plus les micro-coupures que les virus !!! Je n'ai pas trouvé les 2 fichiers que tu me signales sur mon micro ( même en regardant les cachés ). J'ai donc fait uniquement la maj de MBAM suivi d'une recherche complète et un HiJack dont voici les 2 logs. Pour l'instant le PC semble fonctionner normalement Merci encore et @+ MBAM Malwarebytes' Anti-Malware 1.30 Version de la base de données: 1358 Windows 5.1.2600 Service Pack 3 03/11/2008 22:57:58 mbam-log-2008-11-03 (22-57-58).txt Type de recherche: Examen complet (C:\|D:\|) Eléments examinés: 85761 Temps écoulé: 40 minute(s), 42 second(s) Processus mémoire infecté(s): 0 Module(s) mémoire infecté(s): 0 Clé(s) du Registre infectée(s): 0 Valeur(s) du Registre infectée(s): 0 Elément(s) de données du Registre infecté(s): 0 Dossier(s) infecté(s): 0 Fichier(s) infecté(s): 0 Processus mémoire infecté(s): (Aucun élément nuisible détecté) Module(s) mémoire infecté(s): (Aucun élément nuisible détecté) Clé(s) du Registre infectée(s): (Aucun élément nuisible détecté) Valeur(s) du Registre infectée(s): (Aucun élément nuisible détecté) Elément(s) de données du Registre infecté(s): (Aucun élément nuisible détecté) Dossier(s) infecté(s): (Aucun élément nuisible détecté) Fichier(s) infecté(s): (Aucun élément nuisible détecté) HiJack Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 23:03:51, on 03/11/2008 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16735) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\ATKKBService.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Network Associates\Common Framework\FrameworkService.exe C:\Program Files\Network Associates\VirusScan\Mcshield.exe C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe C:\Program Files\Microsoft LifeCam\MSCamS32.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\vVX1000.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\SpeedFan\speedfan.exe C:\WINDOWS\system32\wbem\wmiapsrv.exe C:\Program Files\HiJackThis\HiJackThis.exe C:\WINDOWS\system32\wuauclt.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe" O4 - HKLM\..\Run: [VX1000] C:\WINDOWS\vVX1000.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Startup: SpeedFan.lnk = C:\Program Files\SpeedFan\speedfan.exe O4 - Global Startup: Blue eye Calibration.lnk = C:\Program Files\LaCie blue eye Pro\Tools\CLCalibrationLoader.exe O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe -- End of file - 4793 bytes
  2. OK Il ne me reste plus qu'à t'envoyer un grand merci pour ta disponibilité et ton efficacité @+
  3. Re, Effectivement JAVA n'avait pas la dernière version ( c'était la 6.7 ) La mise à jour est maintenant faite en 6.10. et j'ai passé JavaRa Par contre si je peux encore abuser un peu de ton temps.... A quoi sert exactement JAVA dans tout ça ? Quand tu me dis d'installer PSI et de faire une analyse par semaine, cela remplace mon antivirus ( Mc AFEE ) ? @+
  4. Ne t'inquiète pas pour le retard, j'ai profité du scan de Kapersky, pour manger un bout. J'espère quand même que tu prends le temps de manger !!! Je n'arrivais pas à supprimer le fichier dexplore.exe, le système disait qu'il était en mode lecture seul ou utilisé. Je suis passé en Mode sans échec, et là j'ai pu le supprimer. @+
  5. Suite de l'aventure... @+ JAVA JavaRa 1.11 Removal Log. Report follows after line. ------------------------------------ The JavaRa removal process was started on Sat Nov 01 19:26:19 2008 Found and removed: C:\Program Files\Java\jre1.5.0 Found and removed: Software\JavaSoft\Java2D\1.5.0 Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} Found and removed: SOFTWARE\Classes\Installer\Features\8A0F842331866D117AB7000B0D510000 Found and removed: SOFTWARE\Classes\Installer\Products\8A0F842331866D117AB7000B0D510000 Found and removed: SOFTWARE\Classes\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D510000 Found and removed: SOFTWARE\Classes\JavaPlugin.150 Found and removed: SOFTWARE\Classes\JavaWebStart.isInstalled.1.5.0.0 Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.5.0 Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.5 Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.5.0 Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACBB9B2318A96D117A58000B0D510000 Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F842331866D117AB7000B0D510000 Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3248F0A8-6813-11D6-A77B-00B0D0150000} Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.5.0 Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA} Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.5.0\ Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1 Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_02 Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_03 Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_04 Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2 Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2.0_01 Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBB} ------------------------------------ Finished reporting. KASPERSKY -------------------------------------------------------------------------------- KASPERSKY ONLINE SCANNER 7 REPORT Saturday, November 1, 2008 Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600) Kaspersky Online Scanner 7 version: 7.0.25.0 Program database last update: Saturday, November 01, 2008 16:31:35 Records in database: 1366340 -------------------------------------------------------------------------------- Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - My Computer: A:\ C:\ D:\ E:\ F:\ Scan statistics: Files scanned: 51535 Threat name: 1 Infected objects: 1 Suspicious objects: 0 Duration of the scan: 00:35:41 File name / Threat name / Threats count C:\Documents and Settings\SerMi\Application Data\ѕуmbols\dеxplore.exe Infected: not-a-virus:AdWare.Win32.PurityScan.jw 1 The selected area was scanned.
  6. Cette fois, j'ai pris le bon bouton Répondre !!! Voilà les 3 logs demandées ( apparamment il y a toujours les lignes bizarres 02BHO noname ) @+ LOPSD --------------------\\ Lop S&D 4.2.4-9b XP/Vista Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 3 X86-based PC ( Multiprocessor Free : Intel® Pentium® 4 CPU 3.00GHz ) BIOS : BIOS Date: 10/30/05 16:09:25 Ver: 08.00.10 USER : SerMi ( Administrator ) BOOT : Normal boot A:\ (USB) C:\ (Local Disk) - NTFS - Total:37 Go (Free:29 Go) D:\ (Local Disk) - NTFS - Total:195 Go (Free:76 Go) E:\ (CD or DVD) F:\ (CD or DVD) "C:\Lop SD" ( MAJ : 01-11-2008|04:15 ) Option : [2] ( 01/11/2008|17:58 ) \\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ --------------------\\ Listing des dossiers dans APPLIC~1 [26/05/2006|17:08] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe [04/04/2006|20:26] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ahead [01/04/2008|17:57] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Desktop Pictures [14/09/2008|20:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\EnterNHelp [28/10/2008|16:53] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Malwarebytes [27/06/2008|16:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft [30/03/2006|21:22] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Network Associates [12/09/2006|19:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\nView_Profiles [01/09/2007|18:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Skyline [01/11/2008|12:23] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy [14/09/2008|20:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SystemConfiguration [14/09/2008|20:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Track Settings [14/09/2008|20:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ultima_T15 [30/03/2006|21:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage [01/06/2008|15:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller [30/03/2006|19:52] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft [30/03/2006|19:52] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft [30/03/2006|19:52] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft [28/12/2007|21:43] C:\DOCUME~1\SerMi\APPLIC~1\Adobe [04/04/2006|20:44] C:\DOCUME~1\SerMi\APPLIC~1\Ahead [04/10/2008|14:01] C:\DOCUME~1\SerMi\APPLIC~1\Canon [18/08/2006|17:38] C:\DOCUME~1\SerMi\APPLIC~1\Help [30/03/2006|20:01] C:\DOCUME~1\SerMi\APPLIC~1\Identities [30/03/2006|20:09] C:\DOCUME~1\SerMi\APPLIC~1\InterTrust [12/04/2006|17:18] C:\DOCUME~1\SerMi\APPLIC~1\Macromedia [28/10/2008|16:53] C:\DOCUME~1\SerMi\APPLIC~1\Malwarebytes [31/08/2008|16:32] C:\DOCUME~1\SerMi\APPLIC~1\Microsoft [28/08/2008|18:23] C:\DOCUME~1\SerMi\APPLIC~1\Mozilla [14/09/2008|20:12] C:\DOCUME~1\SerMi\APPLIC~1\Nikon [10/04/2006|18:14] C:\DOCUME~1\SerMi\APPLIC~1\Sun [04/02/2007|12:32] C:\DOCUME~1\SerMi\APPLIC~1\Teleca [28/10/2008|17:57] C:\DOCUME~1\SerMi\APPLIC~1\??mbols --------------------\\ Tâches planifiées dans C:\WINDOWS\tasks [01/11/2008 15:54][--ah-----] C:\WINDOWS\tasks\SA.DAT [05/08/2004 13:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini --------------------\\ Listing des dossiers dans C:\Program Files [26/05/2006|17:14] C:\Program Files\Adobe [24/05/2006|20:58] C:\Program Files\Ahead [30/03/2006|20:14] C:\Program Files\ASUSTeK [31/03/2006|16:34] C:\Program Files\Canon [28/10/2008|19:43] C:\Program Files\CCleaner [30/03/2006|19:50] C:\Program Files\ComPlus Applications [28/10/2008|18:32] C:\Program Files\Fichiers communs [28/10/2006|19:44] C:\Program Files\Free Audio Pack [01/11/2008|16:22] C:\Program Files\HiJackThis [31/03/2006|16:35] C:\Program Files\InstallShield Installation Information [30/03/2006|20:05] C:\Program Files\Intel [15/10/2008|20:55] C:\Program Files\Internet Explorer [30/03/2006|19:54] C:\Program Files\Java [14/04/2008|21:08] C:\Program Files\LaCie blue eye Pro [01/11/2008|11:19] C:\Program Files\Malwarebytes' Anti-Malware [30/03/2006|20:07] C:\Program Files\Marvell [27/09/2008|20:36] C:\Program Files\Messenger [30/03/2006|19:55] C:\Program Files\microsoft frontpage [30/03/2006|20:20] C:\Program Files\Microsoft IntelliPoint [01/06/2008|16:13] C:\Program Files\Microsoft LifeCam [03/04/2006|17:00] C:\Program Files\Microsoft Money [27/09/2008|20:32] C:\Program Files\Movie Maker [01/11/2008|16:21] C:\Program Files\Mozilla Firefox [01/06/2008|15:56] C:\Program Files\MSN [30/03/2006|19:50] C:\Program Files\MSN Gaming Zone [19/11/2006|13:03] C:\Program Files\MSXML 4.0 [27/09/2008|20:30] C:\Program Files\NetMeeting [30/03/2006|21:22] C:\Program Files\Network Associates [14/09/2008|20:10] C:\Program Files\Nikon [30/03/2006|19:50] C:\Program Files\Online Services [27/09/2008|20:30] C:\Program Files\Outlook Express [07/10/2006|10:10] C:\Program Files\Pochette Express 2 [24/05/2006|20:28] C:\Program Files\QuickZip4 [30/03/2006|20:06] C:\Program Files\Realtek [30/03/2006|19:51] C:\Program Files\Services en ligne [01/09/2007|18:36] C:\Program Files\Skyline [26/05/2006|16:56] C:\Program Files\Smart Projects [01/11/2008|15:55] C:\Program Files\SpeedFan [30/03/2006|20:01] C:\Program Files\Uninstall Information [01/06/2008|15:34] C:\Program Files\Windows Live [16/12/2006|11:03] C:\Program Files\Windows Media Connect 2 [27/09/2008|20:30] C:\Program Files\Windows Media Player [27/09/2008|20:30] C:\Program Files\Windows NT [30/03/2006|19:51] C:\Program Files\WindowsUpdate [30/03/2006|19:55] C:\Program Files\xerox --------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs [26/05/2006|17:12] C:\Program Files\Fichiers communs\Adobe [26/05/2006|17:11] C:\Program Files\Fichiers communs\Adobe Systems Shared [24/05/2006|20:58] C:\Program Files\Fichiers communs\Ahead [30/03/2006|21:22] C:\Program Files\Fichiers communs\Cisco Systems [30/03/2006|20:13] C:\Program Files\Fichiers communs\InstallShield [30/03/2006|19:54] C:\Program Files\Fichiers communs\Java [01/06/2008|15:29] C:\Program Files\Fichiers communs\Microsoft Shared [30/03/2006|19:51] C:\Program Files\Fichiers communs\MSSoap [30/03/2006|21:22] C:\Program Files\Fichiers communs\Network Associates [14/09/2008|20:10] C:\Program Files\Fichiers communs\Nikon [30/03/2006|20:59] C:\Program Files\Fichiers communs\ODBC [30/03/2006|19:51] C:\Program Files\Fichiers communs\Services [30/03/2006|20:59] C:\Program Files\Fichiers communs\SpeechEngines [27/09/2008|20:30] C:\Program Files\Fichiers communs\System [04/02/2007|22:12] C:\Program Files\Fichiers communs\Teleca Shared [01/06/2008|15:34] C:\Program Files\Fichiers communs\WindowsLiveInstaller --------------------\\ Process ( 30 Processes ) ... OK ! --------------------\\ Recherche avec S_Lop Aucun fichier / dossier Lop trouvé ! --------------------\\ Recherche de Fichiers / Dossiers Lop Aucun fichier / dossier Lop trouvé ! --------------------\\ Verification du Registre ..... OK ! --------------------\\ Verification du fichier Hosts Fichier Hosts PROPRE --------------------\\ Recherche de fichiers avec Catchme catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-11-01 18:00:22 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden files ... scan completed successfully hidden processes: 0 hidden files: 0 --------------------\\ Recherche d'autres infections Aucune autre infection trouvée ! [F:171][D:16]-> C:\DOCUME~1\SerMi\LOCALS~1\Temp [F:28][D:0]-> C:\DOCUME~1\SerMi\Cookies [F:151][D:4]-> C:\DOCUME~1\SerMi\LOCALS~1\TEMPOR~1\content.IE5 1 - "C:\Lop SD\LopR_1.txt" - 01/11/2008|17:39 - Option : [1] 2 - "C:\Lop SD\LopR_2.txt" - 01/11/2008|18:00 - Option : [2] --------------------\\ Fin du rapport a 18:00:50 MALWAREBYTES Malwarebytes' Anti-Malware 1.30 Version de la base de données: 1349 Windows 5.1.2600 Service Pack 3 01/11/2008 18:36:49 mbam-log-2008-11-01 (18-36-49).txt Type de recherche: Examen complet (C:\|D:\|) Eléments examinés: 86570 Temps écoulé: 34 minute(s), 5 second(s) Processus mémoire infecté(s): 0 Module(s) mémoire infecté(s): 0 Clé(s) du Registre infectée(s): 0 Valeur(s) du Registre infectée(s): 0 Elément(s) de données du Registre infecté(s): 0 Dossier(s) infecté(s): 0 Fichier(s) infecté(s): 0 Processus mémoire infecté(s): (Aucun élément nuisible détecté) Module(s) mémoire infecté(s): (Aucun élément nuisible détecté) Clé(s) du Registre infectée(s): (Aucun élément nuisible détecté) Valeur(s) du Registre infectée(s): (Aucun élément nuisible détecté) Elément(s) de données du Registre infecté(s): (Aucun élément nuisible détecté) Dossier(s) infecté(s): (Aucun élément nuisible détecté) Fichier(s) infecté(s): (Aucun élément nuisible détecté) HiJack Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 18:37:20, on 01/11/2008 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16735) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\ATKKBService.exe C:\Program Files\Network Associates\Common Framework\FrameworkService.exe C:\Program Files\Network Associates\VirusScan\Mcshield.exe C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe C:\WINDOWS\vVX1000.exe C:\Program Files\Microsoft LifeCam\MSCamS32.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\svchost.exe C:\Documents and Settings\SerMi\Application Data\??mbols\d?xplore.exe C:\Program Files\SpeedFan\speedfan.exe C:\Program Files\HiJackThis\HiJackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx O2 - BHO: (no name) - {C26CFF9E-05D5-43B8-8886-E093702D2324} - (no file) O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file) O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe" O4 - HKLM\..\Run: [VX1000] C:\WINDOWS\vVX1000.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [Lkn] "C:\Documents and Settings\SerMi\Application Data\??mbols\d?xplore.exe" O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Startup: SpeedFan.lnk = C:\Program Files\SpeedFan\speedfan.exe O4 - Global Startup: Blue eye Calibration.lnk = C:\Program Files\LaCie blue eye Pro\Tools\CLCalibrationLoader.exe O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O20 - AppInit_DLLs: jedwjk.dll qlhymo.dll O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe -- End of file - 4732 bytes
  7. Bonsoir et merci de t'intéresser à mon cas, Voilà la log @+ --------------------\\ Lop S&D 4.2.4-9b XP/Vista Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 3 X86-based PC ( Multiprocessor Free : Intel® Pentium® 4 CPU 3.00GHz ) BIOS : BIOS Date: 10/30/05 16:09:25 Ver: 08.00.10 USER : SerMi ( Administrator ) BOOT : Normal boot A:\ (USB) C:\ (Local Disk) - NTFS - Total:37 Go (Free:29 Go) D:\ (Local Disk) - NTFS - Total:195 Go (Free:76 Go) E:\ (CD or DVD) F:\ (CD or DVD) "C:\Lop SD" ( MAJ : 01-11-2008|04:15 ) Option : [1] ( 01/11/2008|17:37 ) --------------------\\ Listing des dossiers dans APPLIC~1 [26/05/2006|17:08] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe [04/04/2006|20:26] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ahead [01/04/2008|17:57] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Desktop Pictures [14/09/2008|20:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\EnterNHelp [28/10/2008|16:53] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Malwarebytes [27/06/2008|16:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft [30/03/2006|21:22] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Network Associates [12/09/2006|19:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\nView_Profiles [01/09/2007|18:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Skyline [01/11/2008|12:23] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy [14/09/2008|20:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SystemConfiguration [14/09/2008|20:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Track Settings [14/09/2008|20:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ultima_T15 [30/03/2006|21:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage [01/06/2008|15:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller [30/03/2006|19:52] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft [30/03/2006|19:52] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft [30/03/2006|19:52] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft [28/12/2007|21:43] C:\DOCUME~1\SerMi\APPLIC~1\Adobe [04/04/2006|20:44] C:\DOCUME~1\SerMi\APPLIC~1\Ahead [04/10/2008|14:01] C:\DOCUME~1\SerMi\APPLIC~1\Canon [18/08/2006|17:38] C:\DOCUME~1\SerMi\APPLIC~1\Help [30/03/2006|20:01] C:\DOCUME~1\SerMi\APPLIC~1\Identities [30/03/2006|20:09] C:\DOCUME~1\SerMi\APPLIC~1\InterTrust [12/04/2006|17:18] C:\DOCUME~1\SerMi\APPLIC~1\Macromedia [28/10/2008|16:53] C:\DOCUME~1\SerMi\APPLIC~1\Malwarebytes [31/08/2008|16:32] C:\DOCUME~1\SerMi\APPLIC~1\Microsoft [28/08/2008|18:23] C:\DOCUME~1\SerMi\APPLIC~1\Mozilla [14/09/2008|20:12] C:\DOCUME~1\SerMi\APPLIC~1\Nikon [10/04/2006|18:14] C:\DOCUME~1\SerMi\APPLIC~1\Sun [04/02/2007|12:32] C:\DOCUME~1\SerMi\APPLIC~1\Teleca [28/10/2008|17:57] C:\DOCUME~1\SerMi\APPLIC~1\??mbols --------------------\\ Tâches planifiées dans C:\WINDOWS\tasks [01/11/2008 15:54][--ah-----] C:\WINDOWS\tasks\SA.DAT [05/08/2004 13:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini --------------------\\ Listing des dossiers dans C:\Program Files [26/05/2006|17:14] C:\Program Files\Adobe [24/05/2006|20:58] C:\Program Files\Ahead [30/03/2006|20:14] C:\Program Files\ASUSTeK [31/03/2006|16:34] C:\Program Files\Canon [28/10/2008|19:43] C:\Program Files\CCleaner [30/03/2006|19:50] C:\Program Files\ComPlus Applications [28/10/2008|18:32] C:\Program Files\Fichiers communs [28/10/2006|19:44] C:\Program Files\Free Audio Pack [01/11/2008|16:22] C:\Program Files\HiJackThis [31/03/2006|16:35] C:\Program Files\InstallShield Installation Information [30/03/2006|20:05] C:\Program Files\Intel [15/10/2008|20:55] C:\Program Files\Internet Explorer [30/03/2006|19:54] C:\Program Files\Java [14/04/2008|21:08] C:\Program Files\LaCie blue eye Pro [01/11/2008|11:19] C:\Program Files\Malwarebytes' Anti-Malware [30/03/2006|20:07] C:\Program Files\Marvell [27/09/2008|20:36] C:\Program Files\Messenger [30/03/2006|19:55] C:\Program Files\microsoft frontpage [30/03/2006|20:20] C:\Program Files\Microsoft IntelliPoint [01/06/2008|16:13] C:\Program Files\Microsoft LifeCam [03/04/2006|17:00] C:\Program Files\Microsoft Money [27/09/2008|20:32] C:\Program Files\Movie Maker [01/11/2008|16:21] C:\Program Files\Mozilla Firefox [01/06/2008|15:56] C:\Program Files\MSN [30/03/2006|19:50] C:\Program Files\MSN Gaming Zone [19/11/2006|13:03] C:\Program Files\MSXML 4.0 [27/09/2008|20:30] C:\Program Files\NetMeeting [30/03/2006|21:22] C:\Program Files\Network Associates [14/09/2008|20:10] C:\Program Files\Nikon [30/03/2006|19:50] C:\Program Files\Online Services [27/09/2008|20:30] C:\Program Files\Outlook Express [07/10/2006|10:10] C:\Program Files\Pochette Express 2 [24/05/2006|20:28] C:\Program Files\QuickZip4 [30/03/2006|20:06] C:\Program Files\Realtek [30/03/2006|19:51] C:\Program Files\Services en ligne [01/09/2007|18:36] C:\Program Files\Skyline [26/05/2006|16:56] C:\Program Files\Smart Projects [01/11/2008|15:55] C:\Program Files\SpeedFan [30/03/2006|20:01] C:\Program Files\Uninstall Information [01/06/2008|15:34] C:\Program Files\Windows Live [16/12/2006|11:03] C:\Program Files\Windows Media Connect 2 [27/09/2008|20:30] C:\Program Files\Windows Media Player [27/09/2008|20:30] C:\Program Files\Windows NT [30/03/2006|19:51] C:\Program Files\WindowsUpdate [30/03/2006|19:55] C:\Program Files\xerox --------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs [26/05/2006|17:12] C:\Program Files\Fichiers communs\Adobe [26/05/2006|17:11] C:\Program Files\Fichiers communs\Adobe Systems Shared [24/05/2006|20:58] C:\Program Files\Fichiers communs\Ahead [30/03/2006|21:22] C:\Program Files\Fichiers communs\Cisco Systems [30/03/2006|20:13] C:\Program Files\Fichiers communs\InstallShield [30/03/2006|19:54] C:\Program Files\Fichiers communs\Java [01/06/2008|15:29] C:\Program Files\Fichiers communs\Microsoft Shared [30/03/2006|19:51] C:\Program Files\Fichiers communs\MSSoap [30/03/2006|21:22] C:\Program Files\Fichiers communs\Network Associates [14/09/2008|20:10] C:\Program Files\Fichiers communs\Nikon [30/03/2006|20:59] C:\Program Files\Fichiers communs\ODBC [30/03/2006|19:51] C:\Program Files\Fichiers communs\Services [30/03/2006|20:59] C:\Program Files\Fichiers communs\SpeechEngines [27/09/2008|20:30] C:\Program Files\Fichiers communs\System [04/02/2007|22:12] C:\Program Files\Fichiers communs\Teleca Shared [01/06/2008|15:34] C:\Program Files\Fichiers communs\WindowsLiveInstaller --------------------\\ Process ( 30 Processes ) ... OK ! --------------------\\ Recherche avec S_Lop Aucun fichier / dossier Lop trouvé ! --------------------\\ Recherche de Fichiers / Dossiers Lop Aucun fichier / dossier Lop trouvé ! --------------------\\ Verification du Registre ..... OK ! --------------------\\ Verification du fichier Hosts Fichier Hosts PROPRE --------------------\\ Recherche de fichiers avec Catchme catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-11-01 17:38:34 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden files ... scan completed successfully hidden processes: 0 hidden files: 0 --------------------\\ Recherche d'autres infections Aucune autre infection trouvée ! [F:172][D:17]-> C:\DOCUME~1\SerMi\LOCALS~1\Temp [F:28][D:0]-> C:\DOCUME~1\SerMi\Cookies [F:123][D:4]-> C:\DOCUME~1\SerMi\LOCALS~1\TEMPOR~1\content.IE5 1 - "C:\Lop SD\LopR_1.txt" - 01/11/2008|17:39 - Option : [1] --------------------\\ Fin du rapport a 17:39:02
  8. Bonjour, Après une récupération hasardeuse d'un .exe ( je sais que ce n'est pas à faire, la preuve !!!) , j'ai des icônes qui apparaissent sur mon bureau, une page web qui apparait à intervalle régulier ( toujours la même ) et un ralentissement du PC. Après avoir lu quelques pages de votre forum, j'ai appliqué à la lettre votre procédure de "pré-nettoyage-d-un-pc-infecté". AntiVir a détecté quelques virus qu'il a semble t'il éradiqués J'avais auparavant passé Malwarebytes qui avait aussi détecté et "corrigés" quelques anomalies. Les problèmes sont toujours là, c'est pour cela que je vous soumets la log d'HiJack suivante ( avec des lignes suspectes, mais je n'en sais pas assez ). Merci par avance pour votre aide La log d'HiJack donne les résultats suivants : Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 16:05:09, on 01/11/2008 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16735) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\ATKKBService.exe C:\Program Files\Network Associates\Common Framework\FrameworkService.exe C:\Program Files\Network Associates\VirusScan\Mcshield.exe C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe C:\WINDOWS\vVX1000.exe C:\Program Files\Microsoft LifeCam\MSCamS32.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\svchost.exe C:\Documents and Settings\SerMi\Application Data\??mbols\d?xplore.exe C:\Program Files\SpeedFan\speedfan.exe C:\Program Files\HiJackThis\HiJackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx O2 - BHO: (no name) - {C26CFF9E-05D5-43B8-8886-E093702D2324} - (no file) O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file) O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe" O4 - HKLM\..\Run: [VX1000] C:\WINDOWS\vVX1000.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [Lkn] "C:\Documents and Settings\SerMi\Application Data\??mbols\d?xplore.exe" O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Startup: SpeedFan.lnk = C:\Program Files\SpeedFan\speedfan.exe O4 - Global Startup: Blue eye Calibration.lnk = C:\Program Files\LaCie blue eye Pro\Tools\CLCalibrationLoader.exe O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O20 - AppInit_DLLs: jedwjk.dll qlhymo.dll O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe -- End of file - 4732 bytes
×
×
  • Créer...