Aller au contenu

Fede.leg

Membres
  • Compteur de contenus

    2
  • Inscription

  • Dernière visite

Messages posté(e)s par Fede.leg

  1. Bonjours a tous, je tente de résoudre mes X problèmes informatique et voici le plus gros.

    Grand néophyte dans le domaine de la sécurité je m'en remet à votre analyse.

    Si je me rappelle bien le problème est apparu après le téléchargement d'un faux fichier .mp3,

    que j'ai activé croyant lire un fichier audio, sur le logiciel Limewire.

     

    Symptômes :

    Depuis cet instant, mon ordinateur me fait apparaitre l'écran bleu d'erreur

    dés lors que mes périphériques réseaux sont activent. En cherchant un peu sur des forums,

    j'ai cru comprendre qu'il s'agissait d'un problème lié à un changement d'adresse DNS,

    d'où les conflits vis à vis des périphériques réseaux mais peut être pas du tout.

     

    Depuis deux jours mon ordinateur arrive a se connecter à internet sans trop de conflit, l'ecran bleu

    m'est apparu seulement deux fois sinon pas de problème, bizarre.

    Mais depuis que j'arrive a me connecter à internet j'ai découvert d'autres problèmes,

    impossible de mettre à jours mon antivirus (mcafee) et idem pour les mises a jours windows.

    De plus j'ai essayé de me connecter à Hamachi et peer2me, logiciel qui permettent de créer

    un VPN (virtual private network), impossible. J'ai tendance à penser que tout ceci est lié à

    un probleme de DNS. A vous de m'eclairer.

     

    Technique :

     

    + Sans grande importance je pense mais voici le code d'erreur de l'ecran bleu :

    *** STOP: 0x00008E (0x000005, 0x910B2CFE, 0xB209B048, 0x00000000)

     

    + Mon analyse Mcafee détecte un nombre important de fichier particulier, comme :

    generic.rootkit.d!rootkit

    generic.dx

     

    + De plus je vous poste mon analyse Hijackthis et smitfraudfix.

     

     

     

    Hijackthis :

     

    Logfile of Trend Micro HijackThis v2.0.2

    Scan saved at 19:18:44, on 12/08/2009

    Platform: Windows Vista SP1 (WinNT 6.00.1905)

    MSIE: Internet Explorer v7.00 (7.00.6001.18000)

    Boot mode: Normal

     

    Running processes:

    C:\Windows\system32\taskeng.exe

    C:\Windows\system32\Dwm.exe

    C:\Windows\Explorer.EXE

    C:\Program Files\Dell\DellDock\DellDock.exe

    C:\Windows\system32\conime.exe

    c:\PROGRA~1\mcafee.com\agent\mcagent.exe

    C:\Program Files\Windows Defender\MSASCui.exe

    C:\Program Files\DellTPad\Apoint.exe

    C:\Windows\OEM02Mon.exe

    C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe

    C:\Program Files\Dell\MediaDirect\PCMService.exe

    C:\Program Files\Dell Support Center\bin\sprtcmd.exe

    C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe

    C:\Program Files\Java\jre6\bin\jusched.exe

    C:\Program Files\RKFree\rkfree.exe

    C:\Windows\System32\rundll32.exe

    C:\Windows\System32\rundll32.exe

    C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe

    C:\Program Files\Protector Suite QL\psqltray.exe

    C:\Windows\ehome\ehtray.exe

    C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe

    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

    C:\Program Files\DAEMON Tools Lite\daemon.exe

    C:\Program Files\Skype\Phone\Skype.exe

    C:\Windows\System32\2bnt0sta.exe

    C:\Program Files\Peer2Me\Peer2Me.exe

    C:\Program Files\Windows Media Player\wmpnscfg.exe

    C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe

    C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe

    C:\Program Files\Dell\QuickSet\quickset.exe

    C:\Windows\ehome\ehmsas.exe

    C:\Program Files\DellTPad\ApMsgFwd.exe

    C:\Program Files\DellTPad\HidFind.exe

    C:\Program Files\DellTPad\Apntex.exe

    C:\Program Files\Skype\Plugin Manager\skypePM.exe

    c:\PROGRA~1\mcafee\msc\mcuimgr.exe

    C:\Windows\system32\wuauclt.exe

    C:\Program Files\Mozilla Firefox\firefox.exe

    C:\Program Files\Skype\Toolbars\Shared\SkypeNames.exe

    C:\Program Files\Mozilla Thunderbird\thunderbird.exe

    C:\PROGRA~1\mcafee\msc\mcshell.exe

    C:\Program Files\Adobe\Photoshop 7.0\Photoshop.exe

    C:\Windows\notepad.exe

    C:\Windows\system32\SearchFilterHost.exe

    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

     

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.fr/ig/dell?hl=fr&cli...amp;ibd=5081205

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

    F2 - REG:system.ini: UserInit=userinit.exe

    O1 - Hosts: ::1 localhost

    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

    O2 - BHO: McAntiPhishingBHO - {377C180E-6F0E-4D4C-980F-F45BD3D40CF4} - c:\PROGRA~1\mcafee\msk\mcapbho.dll

    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

    O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll

    O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptsn.dll

    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll

    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll

    O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll

    O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll

    O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

    O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll

    O3 - Toolbar: Veoh Web Player Video Finder - {0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - C:\Program Files\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll

    O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide

    O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe

    O4 - HKLM\..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe

    O4 - HKLM\..\Run: [PSQLLauncher] "C:\Program Files\Protector Suite QL\launcher.exe" /startup

    O4 - HKLM\..\Run: [iAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"

    O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"

    O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey

    O4 - HKLM\..\Run: [dellsupportcenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter

    O4 - HKLM\..\Run: [WD Drive Manager] C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe

    O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"

    O4 - HKLM\..\Run: [rkfree] "C:\Program Files\RKFree\rkfree.exe" /b

    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit

    O4 - HKLM\..\Run: [NVHotkey] rundll32.exe C:\Windows\system32\nvHotkey.dll,Start

    O4 - HKLM\..\Run: [ContentTransferWMDetector.exe] C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe

    O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe

    O4 - HKCU\..\Run: [iSUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup

    O4 - HKCU\..\Run: [iSUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start

    O4 - HKCU\..\Run: [iSUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler

    O4 - HKCU\..\Run: [sUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

    O4 - HKCU\..\Run: [RGSC] C:\Program Files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe /silent

    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

    O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun

    O4 - HKCU\..\Run: [skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized

    O4 - HKCU\..\Run: [2bnt0sta.exe] C:\Windows\system32\2bnt0sta.exe

    O4 - HKCU\..\Run: [WiniShield] C:\Program Files\WiniShield Software\WiniShield\WiniShield.exe -min

    O4 - HKCU\..\Run: [Peer2Me] "C:\Program Files\Peer2Me\Peer2Me.exe"

    O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe

    O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')

    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')

    O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')

    O4 - Startup: Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe

    O4 - Global Startup: BTTray.lnk = ?

    O4 - Global Startup: Nikon Monitor.lnk = C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe

    O4 - Global Startup: QuickSet.lnk = C:\Program Files\Dell\QuickSet\quickset.exe

    O8 - Extra context menu item: Envoyer au périphérique &Bluetooth... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm

    O8 - Extra context menu item: Envoyer l'&image au périphérique Bluetooth... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm

    O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm

    O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm

    O13 - Gopher Prefix:

    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.112.39,85.255.112.40

    O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.112.39,85.255.112.40

    O17 - HKLM\System\CS3\Services\Tcpip\Parameters: NameServer = 85.255.112.39,85.255.112.40

    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.112.39,85.255.112.40

    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL

    O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL

    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

    O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll

    O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\system32\aestsrv.exe

    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

    O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

    O23 - Service: Dock Login Service (DockLoginService) - Stardock Corporation - C:\Program Files\Dell\DellDock\DockLogin.exe

    O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe

    O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

    O23 - Service: Google Desktop Manager 5.8.809.23506 (GoogleDesktopManager-092308-165331) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe

    O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe

    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

    O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe

    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

    O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

    O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe

    O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe

    O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe

    O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe

    O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\McShield.exe

    O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe

    O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe

    O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe

    O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe

    O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe

    O23 - Service: SupportSoft Sprocket Service (DellSupportCenter) (sprtsvc_DellSupportCenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe

    O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\system32\STacSV.exe

    O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe

    O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe

    O23 - Service: WD Drive Manager Service (WDBtnMgrSvc.exe) - WDC - C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe

     

    --

    End of file - 12837 bytes

     

     

    Smitfraudfix :

     

     

    SmitFraudFix v2.423

     

    Scan done at 19:15:44,54, 12/08/2009

    Run from C:\Program Files\Mozilla Firefox\SmitfraudFix

    OS: Microsoft Windows [version 6.0.6001] - Windows_NT

    The filesystem type is NTFS

    Fix run in normal mode

     

    »»»»»»»»»»»»»»»»»»»»»»»» Process

     

    C:\Windows\system32\csrss.exe

    C:\Windows\system32\wininit.exe

    C:\Windows\system32\csrss.exe

    C:\Windows\system32\services.exe

    C:\Windows\system32\lsass.exe

    C:\Windows\system32\lsm.exe

    C:\Windows\system32\svchost.exe

    C:\Windows\system32\nvvsvc.exe

    C:\Windows\system32\svchost.exe

    C:\Windows\System32\svchost.exe

    C:\Windows\System32\svchost.exe

    C:\Windows\System32\svchost.exe

    C:\Windows\system32\svchost.exe

    C:\Windows\system32\winlogon.exe

    C:\Windows\system32\SLsvc.exe

    C:\Windows\system32\svchost.exe

    C:\Program Files\Dell\DellDock\DockLogin.exe

    C:\Windows\system32\svchost.exe

    C:\Windows\system32\WLANExt.exe

    C:\Windows\System32\spoolsv.exe

    C:\Windows\system32\svchost.exe

    C:\Windows\system32\rundll32.exe

    C:\Program Files\Protector Suite QL\upeksvr.exe

    C:\Windows\system32\taskeng.exe

    C:\Windows\system32\Dwm.exe

    C:\Windows\Explorer.EXE

    C:\Program Files\Dell\DellDock\DellDock.exe

    C:\Windows\system32\aestsrv.exe

    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

    C:\Program Files\Bonjour\mDNSResponder.exe

    C:\Windows\system32\svchost.exe

    C:\Program Files\Intel\Wireless\Bin\EvtEng.exe

    C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe

    c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe

    C:\Program Files\McAfee\VirusScan\McShield.exe

    C:\Windows\system32\conime.exe

    C:\Program Files\McAfee\MPF\MPFSrv.exe

    C:\Program Files\McAfee\MSK\MskSrver.exe

    C:\Windows\system32\svchost.exe

    C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe

    C:\Windows\system32\STacSV.exe

    C:\Windows\system32\svchost.exe

    C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe

    C:\Windows\System32\svchost.exe

    C:\Windows\system32\SearchIndexer.exe

    C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe

    C:\Windows\System32\alg.exe

    c:\PROGRA~1\mcafee.com\agent\mcagent.exe

    C:\Program Files\Windows Defender\MSASCui.exe

    C:\Program Files\DellTPad\Apoint.exe

    C:\Windows\OEM02Mon.exe

    C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe

    C:\Program Files\Dell\MediaDirect\PCMService.exe

    C:\Program Files\Dell Support Center\bin\sprtcmd.exe

    C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe

    C:\Program Files\Java\jre6\bin\jusched.exe

    C:\Program Files\RKFree\rkfree.exe

    C:\Windows\System32\rundll32.exe

    C:\Windows\System32\rundll32.exe

    C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe

    C:\Program Files\Protector Suite QL\psqltray.exe

    C:\Windows\ehome\ehtray.exe

    C:\Windows\system32\taskeng.exe

    C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe

    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

    C:\Program Files\DAEMON Tools Lite\daemon.exe

    C:\Program Files\Skype\Phone\Skype.exe

    C:\Windows\System32\2bnt0sta.exe

    C:\Program Files\Peer2Me\Peer2Me.exe

    C:\Program Files\Windows Media Player\wmpnscfg.exe

    C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe

    C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe

    C:\Program Files\Dell\QuickSet\quickset.exe

    C:\Windows\ehome\ehmsas.exe

    C:\Windows\system32\wbem\wmiprvse.exe

    C:\Program Files\Windows Media Player\wmpnetwk.exe

    C:\Program Files\DellTPad\ApMsgFwd.exe

    C:\Program Files\DellTPad\HidFind.exe

    C:\Program Files\DellTPad\Apntex.exe

    C:\Program Files\Skype\Plugin Manager\skypePM.exe

    C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe

    C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe

    c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe

    C:\Program Files\Dell Support Center\bin\sprtsvc.exe

    c:\PROGRA~1\mcafee\msc\mcuimgr.exe

    C:\Windows\system32\WUDFHost.exe

    C:\Windows\system32\wuauclt.exe

    C:\Program Files\Mozilla Firefox\firefox.exe

    C:\Program Files\Skype\Toolbars\Shared\SkypeNames.exe

    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    C:\Windows\system32\NOTEPAD.EXE

    C:\Program Files\Mozilla Thunderbird\thunderbird.exe

    C:\PROGRA~1\mcafee\msc\mcshell.exe

    C:\Program Files\Common Files\McAfee\Core\mchost.exe

    C:\Program Files\Adobe\Photoshop 7.0\Photoshop.exe

    C:\Windows\system32\SearchProtocolHost.exe

    C:\Windows\system32\SearchFilterHost.exe

    C:\Program Files\Mozilla Firefox\SmitfraudFix\Policies.exe

    C:\Windows\system32\cmd.exe

    C:\Windows\system32\wbem\wmiprvse.exe

     

    »»»»»»»»»»»»»»»»»»»»»»»» hosts

     

     

    »»»»»»»»»»»»»»»»»»»»»»»» C:\

     

     

    »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows

     

     

    »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system

     

     

    »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\Web

     

     

    »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32

     

     

    »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32\LogFiles

     

     

    »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\Fred

     

     

    »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\Fred\AppData\Local\Temp

     

     

    »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\Fred\Application Data

     

     

    »»»»»»»»»»»»»»»»»»»»»»»» Start Menu

     

     

    »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\Fred\FAVORI~1

     

     

    »»»»»»»»»»»»»»»»»»»»»»»» Desktop

     

     

    »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

     

     

    »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys

     

     

    »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

     

     

     

    »»»»»»»»»»»»»»»»»»»»»»»» o4Patch

    !!!Attention, following keys are not inevitably infected!!!

     

    o4Patch

    Credits: Malware Analysis & Diagnostic

    Code: S!Ri

     

     

     

    »»»»»»»»»»»»»»»»»»»»»»»» IEDFix

    !!!Attention, following keys are not inevitably infected!!!

     

    IEDFix

    Credits: Malware Analysis & Diagnostic

    Code: S!Ri

     

     

     

    »»»»»»»»»»»»»»»»»»»»»»»» Agent.OMZ.Fix

    !!!Attention, following keys are not inevitably infected!!!

     

    Agent.OMZ.Fix

    Credits: Malware Analysis & Diagnostic

    Code: S!Ri

     

     

    »»»»»»»»»»»»»»»»»»»»»»»» VACFix

    !!!Attention, following keys are not inevitably infected!!!

     

    VACFix

    Credits: Malware Analysis & Diagnostic

    Code: S!Ri

     

     

    »»»»»»»»»»»»»»»»»»»»»»»» 404Fix

    !!!Attention, following keys are not inevitably infected!!!

     

    404Fix

    Credits: Malware Analysis & Diagnostic

    Code: S!Ri

     

     

    »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler

    !!!Attention, following keys are not inevitably infected!!!

     

    SrchSTS.exe by S!Ri

    Search SharedTaskScheduler's .dll

     

     

    »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs

    !!!Attention, following keys are not inevitably infected!!!

     

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]

    "AppInit_DLLs"="C:\\PROGRA~1\\Google\\GOOGLE~3\\GOEC62~1.DLL"

    "LoadAppInit_DLLs"=dword:00000001

     

     

    »»»»»»»»»»»»»»»»»»»»»»»» Winlogon

    !!!Attention, following keys are not inevitably infected!!!

     

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]

    "Userinit"="userinit.exe"

     

    »»»»»»»»»»»»»»»»»»»»»»»» RK

     

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]

     

     

    C:\Windows\system32\drivers\opdxvpjuqqpr.sys detected !

    use a Rootkit scanner

     

    C:\Windows\system32\opdxmeimdmcq.dll detected !

    use a Rootkit scanner

     

     

     

    »»»»»»»»»»»»»»»»»»»»»»»» DNS

     

    Description: Intel® Wireless WiFi Link 4965AGN

    DNS Server Search Order: 192.168.2.1

     

    HKLM\SYSTEM\CCS\Services\Tcpip\..\{D9B3F7AE-3A58-4F92-BED0-C4B258F5823D}: DhcpNameServer=192.168.2.1

    HKLM\SYSTEM\CS2\Services\Tcpip\..\{D9B3F7AE-3A58-4F92-BED0-C4B258F5823D}: DhcpNameServer=192.168.2.1

    HKLM\SYSTEM\CS3\Services\Tcpip\..\{D9B3F7AE-3A58-4F92-BED0-C4B258F5823D}: DhcpNameServer=192.168.2.1

    HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1

    HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: NameServer=85.255.112.39,85.255.112.40

    HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: NameServer=85.255.112.39,85.255.112.40

    HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1

    HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: NameServer=85.255.112.39,85.255.112.40

    HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1

    HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: NameServer=85.255.112.39,85.255.112.40

     

     

    »»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection

     

     

    »»»»»»»»»»»»»»»»»»»»»»»» End

     

     

    Voila. J'èspère avoir étais assé clair.

    Merci pour vos lumières.

  2. Bonjours a tous.

     

    Je commence le nettoyage de mon ordinateur infecté jusqu'à

    l'os. Une première pour moi qui prenais l'habitude d'un formatage

    tout les X mois. Première étape, s'occuper de la pub qui s'affiche

    sur mon écran sous différentes formes sans compter les redirections

    sur mon navigateur et les ralentissements. Tout ceci est apparu suite

    à l'installation du logiciel de sécurité Winishield.

     

    J'ai effectué un scan avec Hijackthis puis avec Smitfraudfix que voici :

     

    Hijackthis :

     

    Logfile of Trend Micro HijackThis v2.0.2

    Scan saved at 19:18:44, on 12/08/2009

    Platform: Windows Vista SP1 (WinNT 6.00.1905)

    MSIE: Internet Explorer v7.00 (7.00.6001.18000)

    Boot mode: Normal

     

    Running processes:

    C:\Windows\system32\taskeng.exe

    C:\Windows\system32\Dwm.exe

    C:\Windows\Explorer.EXE

    C:\Program Files\Dell\DellDock\DellDock.exe

    C:\Windows\system32\conime.exe

    c:\PROGRA~1\mcafee.com\agent\mcagent.exe

    C:\Program Files\Windows Defender\MSASCui.exe

    C:\Program Files\DellTPad\Apoint.exe

    C:\Windows\OEM02Mon.exe

    C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe

    C:\Program Files\Dell\MediaDirect\PCMService.exe

    C:\Program Files\Dell Support Center\bin\sprtcmd.exe

    C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe

    C:\Program Files\Java\jre6\bin\jusched.exe

    C:\Program Files\RKFree\rkfree.exe

    C:\Windows\System32\rundll32.exe

    C:\Windows\System32\rundll32.exe

    C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe

    C:\Program Files\Protector Suite QL\psqltray.exe

    C:\Windows\ehome\ehtray.exe

    C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe

    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

    C:\Program Files\DAEMON Tools Lite\daemon.exe

    C:\Program Files\Skype\Phone\Skype.exe

    C:\Windows\System32\2bnt0sta.exe

    C:\Program Files\Peer2Me\Peer2Me.exe

    C:\Program Files\Windows Media Player\wmpnscfg.exe

    C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe

    C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe

    C:\Program Files\Dell\QuickSet\quickset.exe

    C:\Windows\ehome\ehmsas.exe

    C:\Program Files\DellTPad\ApMsgFwd.exe

    C:\Program Files\DellTPad\HidFind.exe

    C:\Program Files\DellTPad\Apntex.exe

    C:\Program Files\Skype\Plugin Manager\skypePM.exe

    c:\PROGRA~1\mcafee\msc\mcuimgr.exe

    C:\Windows\system32\wuauclt.exe

    C:\Program Files\Mozilla Firefox\firefox.exe

    C:\Program Files\Skype\Toolbars\Shared\SkypeNames.exe

    C:\Program Files\Mozilla Thunderbird\thunderbird.exe

    C:\PROGRA~1\mcafee\msc\mcshell.exe

    C:\Program Files\Adobe\Photoshop 7.0\Photoshop.exe

    C:\Windows\notepad.exe

    C:\Windows\system32\SearchFilterHost.exe

    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

     

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.fr/ig/dell?hl=fr&cli...fr&ibd(...)

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

    F2 - REG:system.ini: UserInit=userinit.exe

    O1 - Hosts: ::1 localhost

    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

    O2 - BHO: McAntiPhishingBHO - {377C180E-6F0E-4D4C-980F-F45BD3D40CF4} - c:\PROGRA~1\mcafee\msk\mcapbho.dll

    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

    O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll

    O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptsn.dll

    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll

    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll

    O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll

    O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll

    O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

    O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll

    O3 - Toolbar: Veoh Web Player Video Finder - {0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - C:\Program Files\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll

    O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide

    O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe

    O4 - HKLM\..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe

    O4 - HKLM\..\Run: [PSQLLauncher] "C:\Program Files\Protector Suite QL\launcher.exe" /startup

    O4 - HKLM\..\Run: [iAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"

    O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"

    O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey

    O4 - HKLM\..\Run: [dellsupportcenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter

    O4 - HKLM\..\Run: [WD Drive Manager] C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe

    O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"

    O4 - HKLM\..\Run: [rkfree] "C:\Program Files\RKFree\rkfree.exe" /b

    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit

    O4 - HKLM\..\Run: [NVHotkey] rundll32.exe C:\Windows\system32\nvHotkey.dll,Start

    O4 - HKLM\..\Run: [ContentTransferWMDetector.exe] C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe

    O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe

    O4 - HKCU\..\Run: [iSUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup

    O4 - HKCU\..\Run: [iSUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start

    O4 - HKCU\..\Run: [iSUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler

    O4 - HKCU\..\Run: [sUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

    O4 - HKCU\..\Run: [RGSC] C:\Program Files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe /silent

    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

    O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun

    O4 - HKCU\..\Run: [skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized

    O4 - HKCU\..\Run: [2bnt0sta.exe] C:\Windows\system32\2bnt0sta.exe

    O4 - HKCU\..\Run: [WiniShield] C:\Program Files\WiniShield Software\WiniShield\WiniShield.exe -min

    O4 - HKCU\..\Run: [Peer2Me] "C:\Program Files\Peer2Me\Peer2Me.exe"

    O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe

    O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')

    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')

    O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')

    O4 - Startup: Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe

    O4 - Global Startup: BTTray.lnk = ?

    O4 - Global Startup: Nikon Monitor.lnk = C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe

    O4 - Global Startup: QuickSet.lnk = C:\Program Files\Dell\QuickSet\quickset.exe

    O8 - Extra context menu item: Envoyer au périphérique &Bluetooth... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm

    O8 - Extra context menu item: Envoyer l'ℑ au périphérique Bluetooth... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm

    O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm

    O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm

    O13 - Gopher Prefix:

    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.112.39,85.255.112.40

    O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.112.39,85.255.112.40

    O17 - HKLM\System\CS3\Services\Tcpip\Parameters: NameServer = 85.255.112.39,85.255.112.40

    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.112.39,85.255.112.40

    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL

    O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL

    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

    O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll

    O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\system32\aestsrv.exe

    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

    O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

    O23 - Service: Dock Login Service (DockLoginService) - Stardock Corporation - C:\Program Files\Dell\DellDock\DockLogin.exe

    O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe

    O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

    O23 - Service: Google Desktop Manager 5.8.809.23506 (GoogleDesktopManager-092308-165331) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe

    O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe

    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

    O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe

    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

    O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

    O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe

    O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe

    O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe

    O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe

    O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\McShield.exe

    O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe

    O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe

    O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe

    O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe

    O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe

    O23 - Service: SupportSoft Sprocket Service (DellSupportCenter) (sprtsvc_DellSupportCenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe

    O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\system32\STacSV.exe

    O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe

    O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe

    O23 - Service: WD Drive Manager Service (WDBtnMgrSvc.exe) - WDC - C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe

     

    --

    End of file - 12837 bytes

     

     

     

     

    Smitfraudfix :

     

    SmitFraudFix v2.423

     

    Scan done at 19:15:44,54, 12/08/2009

    Run from C:\Program Files\Mozilla Firefox\SmitfraudFix

    OS: Microsoft Windows [version 6.0.6001] - Windows_NT

    The filesystem type is NTFS

    Fix run in normal mode

     

    »»»»»»»»»»»»»»»»»»»»»»»» Process

     

    C:\Windows\system32\csrss.exe

    C:\Windows\system32\wininit.exe

    C:\Windows\system32\csrss.exe

    C:\Windows\system32\services.exe

    C:\Windows\system32\lsass.exe

    C:\Windows\system32\lsm.exe

    C:\Windows\system32\svchost.exe

    C:\Windows\system32\nvvsvc.exe

    C:\Windows\system32\svchost.exe

    C:\Windows\System32\svchost.exe

    C:\Windows\System32\svchost.exe

    C:\Windows\System32\svchost.exe

    C:\Windows\system32\svchost.exe

    C:\Windows\system32\winlogon.exe

    C:\Windows\system32\SLsvc.exe

    C:\Windows\system32\svchost.exe

    C:\Program Files\Dell\DellDock\DockLogin.exe

    C:\Windows\system32\svchost.exe

    C:\Windows\system32\WLANExt.exe

    C:\Windows\System32\spoolsv.exe

    C:\Windows\system32\svchost.exe

    C:\Windows\system32\rundll32.exe

    C:\Program Files\Protector Suite QL\upeksvr.exe

    C:\Windows\system32\taskeng.exe

    C:\Windows\system32\Dwm.exe

    C:\Windows\Explorer.EXE

    C:\Program Files\Dell\DellDock\DellDock.exe

    C:\Windows\system32\aestsrv.exe

    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

    C:\Program Files\Bonjour\mDNSResponder.exe

    C:\Windows\system32\svchost.exe

    C:\Program Files\Intel\Wireless\Bin\EvtEng.exe

    C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe

    c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe

    C:\Program Files\McAfee\VirusScan\McShield.exe

    C:\Windows\system32\conime.exe

    C:\Program Files\McAfee\MPF\MPFSrv.exe

    C:\Program Files\McAfee\MSK\MskSrver.exe

    C:\Windows\system32\svchost.exe

    C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe

    C:\Windows\system32\STacSV.exe

    C:\Windows\system32\svchost.exe

    C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe

    C:\Windows\System32\svchost.exe

    C:\Windows\system32\SearchIndexer.exe

    C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe

    C:\Windows\System32\alg.exe

    c:\PROGRA~1\mcafee.com\agent\mcagent.exe

    C:\Program Files\Windows Defender\MSASCui.exe

    C:\Program Files\DellTPad\Apoint.exe

    C:\Windows\OEM02Mon.exe

    C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe

    C:\Program Files\Dell\MediaDirect\PCMService.exe

    C:\Program Files\Dell Support Center\bin\sprtcmd.exe

    C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe

    C:\Program Files\Java\jre6\bin\jusched.exe

    C:\Program Files\RKFree\rkfree.exe

    C:\Windows\System32\rundll32.exe

    C:\Windows\System32\rundll32.exe

    C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe

    C:\Program Files\Protector Suite QL\psqltray.exe

    C:\Windows\ehome\ehtray.exe

    C:\Windows\system32\taskeng.exe

    C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe

    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

    C:\Program Files\DAEMON Tools Lite\daemon.exe

    C:\Program Files\Skype\Phone\Skype.exe

    C:\Windows\System32\2bnt0sta.exe

    C:\Program Files\Peer2Me\Peer2Me.exe

    C:\Program Files\Windows Media Player\wmpnscfg.exe

    C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe

    C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe

    C:\Program Files\Dell\QuickSet\quickset.exe

    C:\Windows\ehome\ehmsas.exe

    C:\Windows\system32\wbem\wmiprvse.exe

    C:\Program Files\Windows Media Player\wmpnetwk.exe

    C:\Program Files\DellTPad\ApMsgFwd.exe

    C:\Program Files\DellTPad\HidFind.exe

    C:\Program Files\DellTPad\Apntex.exe

    C:\Program Files\Skype\Plugin Manager\skypePM.exe

    C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe

    C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe

    c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe

    C:\Program Files\Dell Support Center\bin\sprtsvc.exe

    c:\PROGRA~1\mcafee\msc\mcuimgr.exe

    C:\Windows\system32\WUDFHost.exe

    C:\Windows\system32\wuauclt.exe

    C:\Program Files\Mozilla Firefox\firefox.exe

    C:\Program Files\Skype\Toolbars\Shared\SkypeNames.exe

    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    C:\Windows\system32\NOTEPAD.EXE

    C:\Program Files\Mozilla Thunderbird\thunderbird.exe

    C:\PROGRA~1\mcafee\msc\mcshell.exe

    C:\Program Files\Common Files\McAfee\Core\mchost.exe

    C:\Program Files\Adobe\Photoshop 7.0\Photoshop.exe

    C:\Windows\system32\SearchProtocolHost.exe

    C:\Windows\system32\SearchFilterHost.exe

    C:\Program Files\Mozilla Firefox\SmitfraudFix\Policies.exe

    C:\Windows\system32\cmd.exe

    C:\Windows\system32\wbem\wmiprvse.exe

     

    »»»»»»»»»»»»»»»»»»»»»»»» hosts

     

     

    »»»»»»»»»»»»»»»»»»»»»»»» C:\

     

     

    »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows

     

     

    »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system

     

     

    »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\Web

     

     

    »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32

     

     

    »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32\LogFiles

     

     

    »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\Fred

     

     

    »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\Fred\AppData\Local\Temp

     

     

    »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\Fred\Application Data

     

     

    »»»»»»»»»»»»»»»»»»»»»»»» Start Menu

     

     

    »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\Fred\FAVORI~1

     

     

    »»»»»»»»»»»»»»»»»»»»»»»» Desktop

     

     

    »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

     

     

    »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys

     

     

    »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

     

     

     

    »»»»»»»»»»»»»»»»»»»»»»»» o4Patch

    !!!Attention, following keys are not inevitably infected!!!

     

    o4Patch

    Credits: Malware Analysis & Diagnostic

    Code: S!Ri

     

     

     

    »»»»»»»»»»»»»»»»»»»»»»»» IEDFix

    !!!Attention, following keys are not inevitably infected!!!

     

    IEDFix

    Credits: Malware Analysis & Diagnostic

    Code: S!Ri

     

     

     

    »»»»»»»»»»»»»»»»»»»»»»»» Agent.OMZ.Fix

    !!!Attention, following keys are not inevitably infected!!!

     

    Agent.OMZ.Fix

    Credits: Malware Analysis & Diagnostic

    Code: S!Ri

     

     

    »»»»»»»»»»»»»»»»»»»»»»»» VACFix

    !!!Attention, following keys are not inevitably infected!!!

     

    VACFix

    Credits: Malware Analysis & Diagnostic

    Code: S!Ri

     

     

    »»»»»»»»»»»»»»»»»»»»»»»» 404Fix

    !!!Attention, following keys are not inevitably infected!!!

     

    404Fix

    Credits: Malware Analysis & Diagnostic

    Code: S!Ri

     

     

    »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler

    !!!Attention, following keys are not inevitably infected!!!

     

    SrchSTS.exe by S!Ri

    Search SharedTaskScheduler's .dll

     

     

    »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs

    !!!Attention, following keys are not inevitably infected!!!

     

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]

    "AppInit_DLLs"="C:\\PROGRA~1\\Google\\GOOGLE~3\\GOEC62~1.DLL"

    "LoadAppInit_DLLs"=dword:00000001

     

     

    »»»»»»»»»»»»»»»»»»»»»»»» Winlogon

    !!!Attention, following keys are not inevitably infected!!!

     

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]

    "Userinit"="userinit.exe"

     

    »»»»»»»»»»»»»»»»»»»»»»»» RK

     

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]

     

     

    C:\Windows\system32\drivers\opdxvpjuqqpr.sys detected !

    use a Rootkit scanner

     

    C:\Windows\system32\opdxmeimdmcq.dll detected !

    use a Rootkit scanner

     

     

     

    »»»»»»»»»»»»»»»»»»»»»»»» DNS

     

    Description: Intel® Wireless WiFi Link 4965AGN

    DNS Server Search Order: 192.168.2.1

     

    HKLM\SYSTEM\CCS\Services\Tcpip\..\{D9B3F7AE-3A58-4F92-BED0-C4B258F5823D}: DhcpNameServer=192.168.2.1

    HKLM\SYSTEM\CS2\Services\Tcpip\..\{D9B3F7AE-3A58-4F92-BED0-C4B258F5823D}: DhcpNameServer=192.168.2.1

    HKLM\SYSTEM\CS3\Services\Tcpip\..\{D9B3F7AE-3A58-4F92-BED0-C4B258F5823D}: DhcpNameServer=192.168.2.1

    HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1

    HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: NameServer=85.255.112.39,85.255.112.40

    HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: NameServer=85.255.112.39,85.255.112.40

    HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1

    HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: NameServer=85.255.112.39,85.255.112.40

    HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1

    HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: NameServer=85.255.112.39,85.255.112.40

     

     

    »»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection

     

     

    »»»»»»»»»»»»»»»»»»»»»»»» End

     

     

    Merci pour votre aide.

×
×
  • Créer...