hijackthis

Section d'analyse de rapports et de désinfection : malwares en tous genre et autres indésirables. Demandes de nettoyage uniquement. Prise en charge restreinte : équipe spécialisée.

Modérateur: Modérateurs

Règles du forum :arrow: Les désinfections sont prises en charge par un groupe spécifique, tout le monde ne peut pas intervenir pour désinfecter les machines (règles).
:arrow: Les procédures sont sur-mesure, ne faites pas la même chose chez vous (explications).
:arrow: Un topic par machine, chacun crée le sien. ;)

hijackthis

Messagepar angy69 » 16 Avr 2008 13:15

bjr.. j'ai lu un sujet et j'ai essayer Hijackthis.exe mais je c'est pas si tout va bien!! je vous fait un copier coller


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:11:11, on 16/04/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\windows\system\hpsysdrv.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\MarkAny\ContentSafer\MAAgent.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\MSN Messenger\livecall.exe
C:\Documents and Settings\Propriétaire\Bureau\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: ShoppingReport - {100EB1FD-D03E-47FD-81F3-EE91287F9465} - C:\Program Files\ShoppingReport\Bin\2.0.22\ShoppingReport.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [UpdateManager] "c:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [SMSTray] C:\Documents and Settings\Propriétaire\Bureau\KEV1989\MP3\SMSTray.exe
O4 - HKLM\..\Run: [MAAgent] C:\Program Files\MarkAny\ContentSafer\MAAgent.exe
O4 - HKLM\..\Run: [bend logo clock film] C:\Documents and Settings\All Users\Application Data\Frag great bend logo\body team.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [onlinegrey] C:\DOCUME~1\PROPRI~1\APPLIC~1\SLOWWM~1\ONCE PEAK.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Startup: Eurobarre.lnk = C:\Program Files\Eurobarre\eb.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: ShopperReports - Compare product prices - {C5428486-50A0-4a02-9D20-520B59A9F9B2} - C:\Program Files\ShoppingReport\Bin\2.0.22\ShoppingReport.dll (file missing)
O9 - Extra button: ShopperReports - Compare travel rates - {C5428486-50A0-4a02-9D20-520B59A9F9B3} - C:\Program Files\ShoppingReport\Bin\2.0.22\ShoppingReport.dll (file missing)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-U ... E_UNO1.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupda ... 8453593921
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Me ... b56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/Mi ... b56986.cab
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol 120\StarWind\StarWindServiceAE.exe

--
End of file - 8138 bytes

voilà merci de me dire si tout va bien.. :-D
angy69
 
Messages: 15
Inscription: 16 Avr 2008 13:03

Re: hijackthis

Messagepar Falkra » 16 Avr 2008 16:47

Bonjour, attention à ne pas faire Image au lieu de Image... :wink:

Sinon, les réponses arrivent, il suffit d'attendre. ;-)

Lop + une toolbar à première vue, ça ne va pas mal mais il faut s'en débarrasser.

Désactive tes protections résidentes ( Antivirus , ... ) tu les réactiveras ensuite

Télécharge [url="http://eric.71.mespages.googlepages.com/LopSD.exe"]Lop S&D.exe[/url] sur ton bureau

  • Double-clique dessus pour lancer l'installation
  • Puis double-clique sur le raccourci Lop S&D présent sur ton bureau
  • Sélectionne la langue souhaitée, puis choisis l'Option 1 ( Recherche )
  • Patiente jusqu'à la fin du scan
  • Poste le rapport généré ( C:\lopR.txt )

( Si le Bureau ne réapparait pas presse Ctrl + Alt + Suppr , Onglet Fichier , Nouvelle tâche , tape explorer.exe et valide).
Avatar de l’utilisateur
Falkra
Admin libellules.ch
Admin libellules.ch
 
Messages: 24424
Inscription: 30 Jan 2005 13:44
Localisation: 127.0.0.1

Re: hijackthis

Messagepar angy69 » 16 Avr 2008 17:39

-----------------------[ Lop S&D 4.1.1-1 XP/Vista ]---------------------

[ Windows XP (NT 5.1) Build 2600, Service Pack 2 ]
[ USER : Propri‚taire ] [ "C:\Lop SD" ]
[ 16/04/2008 | 18:34:30,15 ] [ PC : ANGY ]
[ MAJ : 15-04-2008 | 20:20 ]

-------------[ Listing des dossiers dans Application Data ]------------

[08/04/2008|21:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\.
[08/04/2008|21:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\..
[01/01/2004|18:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[06/05/2007|11:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Avg7
[04/08/2007|14:02] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Babylon
[12/12/2006|00:15] C:\DOCUME~1\ALLUSE~1\APPLIC~1\BitDefender(2)
[01/01/2004|16:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\desktop.ini
[02/04/2008|18:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Frag great bend logo
[26/03/2008|06:33] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
[06/05/2007|11:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Grisoft
[08/04/2008|21:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\InstallShield
[01/01/2004|18:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\InterVideo
[19/03/2007|23:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kaspersky Lab
[29/10/2007|17:07] C:\DOCUME~1\ALLUSE~1\APPLIC~1\LauncherAccess.dt
[19/03/2007|14:11] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!
[26/10/2007|08:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[01/01/2004|18:58] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Motive
[09/08/2007|21:55] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Nero
[01/01/2004|18:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\QuickTime
[01/01/2004|16:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SBSI
[06/05/2007|11:07] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec
[02/03/2007|09:26] C:\DOCUME~1\ALLUSE~1\APPLIC~1\up inter 64 dumb
[12/12/2006|00:59] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[12/12/2006|02:02] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Live Toolbar



[06/05/2007|19:36] C:\DOCUME~1\DEFAUL~1\APPLIC~1\.
[06/05/2007|19:36] C:\DOCUME~1\DEFAUL~1\APPLIC~1\..
[01/01/2004|16:39] C:\DOCUME~1\DEFAUL~1\APPLIC~1\desktop.ini
[01/01/2004|16:47] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Identities
[01/01/2004|18:28] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Intervideo
[01/01/2004|17:25] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
[01/01/2004|19:26] C:\DOCUME~1\DEFAUL~1\APPLIC~1\SampleView
[01/01/2004|17:28] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Sun
[01/01/2004|23:21] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Symantec



[01/01/2004|16:49] C:\DOCUME~1\LOCALS~1\APPLIC~1\.
[01/01/2004|16:49] C:\DOCUME~1\LOCALS~1\APPLIC~1\..
[06/05/2007|11:14] C:\DOCUME~1\LOCALS~1\APPLIC~1\AVG7
[01/01/2004|16:49] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft

[01/01/2004|16:49] C:\DOCUME~1\NETWOR~1\APPLIC~1\.
[01/01/2004|16:49] C:\DOCUME~1\NETWOR~1\APPLIC~1\..
[01/01/2004|16:49] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft





[03/04/2008|09:44] C:\DOCUME~1\PROPRI~1\APPLIC~1\.
[03/04/2008|09:44] C:\DOCUME~1\PROPRI~1\APPLIC~1\..
[21/04/2007|17:05] C:\DOCUME~1\PROPRI~1\APPLIC~1\.ABC
[05/03/2008|16:57] C:\DOCUME~1\PROPRI~1\APPLIC~1\7z.dll
[05/03/2008|16:55] C:\DOCUME~1\PROPRI~1\APPLIC~1\7z.exe
[10/02/2008|18:16] C:\DOCUME~1\PROPRI~1\APPLIC~1\Adobe
[28/09/2007|15:28] C:\DOCUME~1\PROPRI~1\APPLIC~1\AdobeUM
[09/08/2007|21:58] C:\DOCUME~1\PROPRI~1\APPLIC~1\Ahead
[14/12/2006|00:10] C:\DOCUME~1\PROPRI~1\APPLIC~1\Apple Computer
[12/09/2007|18:46] C:\DOCUME~1\PROPRI~1\APPLIC~1\ATI
[29/03/2008|11:18] C:\DOCUME~1\PROPRI~1\APPLIC~1\AVG7
[04/08/2007|14:02] C:\DOCUME~1\PROPRI~1\APPLIC~1\Babylon
[11/12/2006|19:36] C:\DOCUME~1\PROPRI~1\APPLIC~1\Bitdefender
[21/04/2007|16:54] C:\DOCUME~1\PROPRI~1\APPLIC~1\BitTorrent
[26/10/2007|08:39] C:\DOCUME~1\PROPRI~1\APPLIC~1\DataCast
[01/01/2004|16:39] C:\DOCUME~1\PROPRI~1\APPLIC~1\desktop.ini
[07/05/2007|20:08] C:\DOCUME~1\PROPRI~1\APPLIC~1\Google
[01/08/2007|16:42] C:\DOCUME~1\PROPRI~1\APPLIC~1\Help
[01/01/2004|16:47] C:\DOCUME~1\PROPRI~1\APPLIC~1\Identities
[26/10/2007|08:38] C:\DOCUME~1\PROPRI~1\APPLIC~1\InstallShield
[06/05/2007|10:53] C:\DOCUME~1\PROPRI~1\APPLIC~1\Intervideo
[06/03/2007|18:35] C:\DOCUME~1\PROPRI~1\APPLIC~1\Leadertech
[13/12/2006|23:30] C:\DOCUME~1\PROPRI~1\APPLIC~1\Macromedia
[17/11/2007|22:43] C:\DOCUME~1\PROPRI~1\APPLIC~1\Microsoft
[01/05/2007|21:23] C:\DOCUME~1\PROPRI~1\APPLIC~1\Motive
[11/12/2006|21:02] C:\DOCUME~1\PROPRI~1\APPLIC~1\Mozilla
[04/04/2008|19:40] C:\DOCUME~1\PROPRI~1\APPLIC~1\OpenOffice.org2
[01/01/2004|19:26] C:\DOCUME~1\PROPRI~1\APPLIC~1\SampleView
[04/11/2007|10:46] C:\DOCUME~1\PROPRI~1\APPLIC~1\Samsung
[09/03/2007|19:26] C:\DOCUME~1\PROPRI~1\APPLIC~1\Screenshot Sender
[12/09/2007|16:50] C:\DOCUME~1\PROPRI~1\APPLIC~1\SecuROM
[27/12/2006|14:50] C:\DOCUME~1\PROPRI~1\APPLIC~1\SEGA
[05/03/2008|16:58] C:\DOCUME~1\PROPRI~1\APPLIC~1\serial2.dat
[05/03/2008|16:56] C:\DOCUME~1\PROPRI~1\APPLIC~1\serial2.zip
[04/08/2007|13:36] C:\DOCUME~1\PROPRI~1\APPLIC~1\ShoppingReport
[02/04/2008|14:00] C:\DOCUME~1\PROPRI~1\APPLIC~1\Slow Wma Time
[11/12/2006|18:41] C:\DOCUME~1\PROPRI~1\APPLIC~1\Sonic
[28/10/2007|15:30] C:\DOCUME~1\PROPRI~1\APPLIC~1\Sports Interactive
[01/01/2004|17:28] C:\DOCUME~1\PROPRI~1\APPLIC~1\Sun
[01/01/2004|23:21] C:\DOCUME~1\PROPRI~1\APPLIC~1\Symantec
[11/12/2006|21:03] C:\DOCUME~1\PROPRI~1\APPLIC~1\Talkback
[06/03/2007|18:46] C:\DOCUME~1\PROPRI~1\APPLIC~1\U3
[06/01/2008|01:30] C:\DOCUME~1\PROPRI~1\APPLIC~1\vlc
[09/02/2007|20:43] C:\DOCUME~1\PROPRI~1\APPLIC~1\wunauclt.tbe


----------------[ Tâches planifiées dans C:\WINDOWS\tasks ]---------------

[16/04/2008 18:00][--ah-----] C:\WINDOWS\tasks\B9326FE8870DE134.job
[16/04/2008 17:56][--a------] C:\WINDOWS\tasks\V‚rifier les mises … jour de Windows Live Toolbar.job
[12/02/2004 13:27][-rah-----] C:\WINDOWS\tasks\desktop.ini
[16/04/2008 03:30][--ah-----] C:\WINDOWS\tasks\SA.DAT

---------------[ Listing des dossiers dans C:\Program Files ]--------------

[11/04/2008|16:06] C:\Program Files\.
[11/04/2008|16:06] C:\Program Files\..
[14/04/2008|10:31] C:\Program Files\Ad-aware 6
[09/08/2007|11:47] C:\Program Files\Adobe
[08/04/2008|21:28] C:\Program Files\AGEIA Technologies
[12/09/2007|15:56] C:\Program Files\Alcohol 120
[12/09/2007|18:43] C:\Program Files\ATI Technologies
[04/08/2007|14:02] C:\Program Files\Babylon Pro Setup
[05/03/2008|17:41] C:\Program Files\Boonty
[05/03/2008|17:37] C:\Program Files\BoontyGames
[23/01/2007|21:50] C:\Program Files\Canon
[12/09/2007|16:31] C:\Program Files\CAPCOM
[28/01/2008|14:34] C:\Program Files\Circle Developement
[01/01/2004|18:18] C:\Program Files\Common Files
[17/11/2007|20:52] C:\Program Files\DAEMON Tools
[09/08/2007|21:33] C:\Program Files\DivX
[01/08/2007|15:49] C:\Program Files\DXBall2
[05/06/2007|11:01] C:\Program Files\Easy Internet signup
[05/07/2007|01:23] C:\Program Files\EasyCleaner
[07/04/2008|10:02] C:\Program Files\eMule
[06/05/2007|12:56] C:\Program Files\Eurobarre
[21/09/2007|16:57] C:\Program Files\Eva Cash
[10/04/2008|14:17] C:\Program Files\Evil Under the Sun
[06/03/2007|18:35] C:\Program Files\Executive Software
[08/04/2008|21:20] C:\Program Files\Fichiers communs
[08/04/2008|21:26] C:\Program Files\Focus
[29/03/2008|11:18] C:\Program Files\Google
[16/01/2007|09:56] C:\Program Files\Grisoft
[05/03/2008|16:57] C:\Program Files\inc1.bat
[08/04/2008|21:41] C:\Program Files\InstallShield Installation Information
[09/04/2008|08:17] C:\Program Files\Internet Explorer
[20/01/2008|09:06] C:\Program Files\InterVideo
[26/03/2008|06:33] C:\Program Files\Java
[20/01/2008|09:07] C:\Program Files\Kyodai
[08/04/2008|21:20] C:\Program Files\La nuit des sacrifies
[11/04/2008|16:06] C:\Program Files\Les Sims 2
[02/04/2008|15:55] C:\Program Files\Ludiclub
[26/10/2007|08:39] C:\Program Files\MarkAny
[14/05/2007|16:40] C:\Program Files\messenger
[31/03/2008|10:20] C:\Program Files\Messenger Plus! Live
[12/12/2006|02:15] C:\Program Files\MessengerPlus! 3
[01/01/2004|16:47] C:\Program Files\microsoft frontpage
[06/05/2007|15:22] C:\Program Files\Movie Maker
[16/04/2008|18:24] C:\Program Files\Mozilla Firefox
[01/01/2004|16:43] C:\Program Files\MSN
[08/05/2007|21:34] C:\Program Files\MSN BackUp
[01/01/2004|16:43] C:\Program Files\MSN Gaming Zone
[31/03/2008|10:19] C:\Program Files\MSN Messenger
[10/08/2007|05:40] C:\Program Files\MSXML 4.0
[09/08/2007|21:55] C:\Program Files\Nero
[06/05/2007|15:21] C:\Program Files\NetMeeting
[12/06/2007|21:21] C:\Program Files\NOCD Penumbra Overture crack.exe
[13/12/2006|12:05] C:\Program Files\NUMERICABLE
[04/04/2008|19:43] C:\Program Files\OpenOffice.org 2.4
[14/06/2007|00:17] C:\Program Files\Outlook Express
[05/03/2008|16:55] C:\Program Files\Penumbra Overture crack.exe
[01/01/2004|18:58] C:\Program Files\Presario PC Help
[13/12/2007|13:14] C:\Program Files\Project64 v1.5
[01/01/2004|18:35] C:\Program Files\QuickTime
[06/05/2007|10:50] C:\Program Files\RecordNow!
[04/08/2007|22:25] C:\Program Files\ReflexiveArcade
[16/09/2007|12:46] C:\Program Files\Ricochet Xtreme
[01/01/2004|19:03] C:\Program Files\Services en ligne
[04/08/2007|13:36] C:\Program Files\ShoppingReport
[09/08/2007|21:41] C:\Program Files\SLD Codec Pack
[05/03/2008|16:57] C:\Program Files\sleep.bat
[25/02/2008|08:28] C:\Program Files\Slow Wma Time
[11/12/2006|18:39] C:\Program Files\Sonic
[28/10/2007|15:17] C:\Program Files\Sports Interactive
[25/02/2008|14:50] C:\Program Files\TAROTPRO992
[12/06/2007|21:21] C:\Program Files\temp1.exe
[05/03/2008|16:57] C:\Program Files\temp2.exe
[05/03/2008|16:57] C:\Program Files\temp3.exe
[10/04/2008|14:18] C:\Program Files\The Adventure Company
[01/08/2007|17:29] C:\Program Files\The Bitmap Brothers
[06/05/2007|12:54] C:\Program Files\ToniArts
[06/05/2007|13:37] C:\Program Files\Uninstall Information
[27/12/2006|14:47] C:\Program Files\VID_0E8F&PID_0003
[02/12/2007|18:24] C:\Program Files\VideoLAN
[05/03/2008|16:55] C:\Program Files\Win.All Penumbra Overture crack.exe
[03/06/2007|20:24] C:\Program Files\Windows Live
[12/12/2006|02:03] C:\Program Files\Windows Live Favorites
[12/12/2006|02:03] C:\Program Files\Windows Live Toolbar
[21/01/2007|02:09] C:\Program Files\Windows Media Connect 2
[06/05/2007|16:06] C:\Program Files\Windows Media Player
[06/05/2007|15:21] C:\Program Files\Windows NT
[06/05/2007|11:25] C:\Program Files\WindowsUpdate
[22/02/2007|09:26] C:\Program Files\WinRAR
[01/01/2004|16:47] C:\Program Files\xerox
[11/12/2006|20:41] C:\Program Files\xp-AntiSpy
[04/08/2007|13:41] C:\Program Files\Zapu
[28/10/2007|15:17] C:\Program Files\Zero G Registry

------[ Listing des dossiers dans C:\Program Files\Fichiers communs ]------

[08/04/2008|21:20] C:\Program Files\Fichiers communs\.
[08/04/2008|21:20] C:\Program Files\Fichiers communs\..
[12/12/2006|18:31] C:\Program Files\Fichiers communs\Adobe
[09/08/2007|21:55] C:\Program Files\Fichiers communs\Ahead
[28/12/2006|01:04] C:\Program Files\Fichiers communs\ATI Technologies
[01/06/2007|21:29] C:\Program Files\Fichiers communs\DirectX
[08/04/2008|21:26] C:\Program Files\Fichiers communs\InstallShield
[01/01/2004|17:28] C:\Program Files\Fichiers communs\Java
[01/01/2004|18:18] C:\Program Files\Fichiers communs\Microsoft Shared
[01/01/2004|16:44] C:\Program Files\Fichiers communs\MSSoap
[01/01/2004|16:40] C:\Program Files\Fichiers communs\ODBC
[06/05/2007|19:38] C:\Program Files\Fichiers communs\Services
[16/01/2007|09:41] C:\Program Files\Fichiers communs\Softwin
[11/12/2006|18:40] C:\Program Files\Fichiers communs\Sonic
[01/01/2004|16:40] C:\Program Files\Fichiers communs\SpeechEngines
[06/05/2007|10:50] C:\Program Files\Fichiers communs\SureThing Shared
[14/06/2007|00:17] C:\Program Files\Fichiers communs\System
[08/04/2008|21:28] C:\Program Files\Fichiers communs\Wise Installation Wizard

----------------------[ Recherche avec S_Lop ]---------------------

Aucun fichier / dossier Lop trouvé !

-----------------[ Recherche de Fichiers / Dossiers Lop ]-----------------

C:\DOCUME~1\ALLUSE~1\APPLIC~1\Frag great bend logo
C:\Program Files\Circle Developement
C:\WINDOWS\Tasks\B9326FE8870DE134.job

----------------------[ Verification du Registre ]----------------------

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"bend logo clock film"="C:\\Documents and Settings\\All Users\\Application Data\\Frag great bend logo\\body team.exe"

--------------------[ Verification du fichier Hosts ]---------------------

Fichier Hosts MODIFIE

127.0.0.1 bin.errorprotector.com ## added by CiD
127.0.0.1 br.errorsafe.com ## added by CiD
127.0.0.1 br.winantivirus.com ## added by CiD
127.0.0.1 br.winfixer.com ## added by CiD
127.0.0.1 cdn.drivecleaner.com ## added by CiD
127.0.0.1 cdn.errorsafe.com ## added by CiD
127.0.0.1 cdn.winsoftware.com ## added by CiD
127.0.0.1 de.errorsafe.com ## added by CiD
127.0.0.1 de.winantivirus.com ## added by CiD
127.0.0.1 download.cdn.drivecleaner.com ## added by CiD
127.0.0.1 download.cdn.errorsafe.com ## added by CiD
127.0.0.1 download.cdn.winsoftware.com ## added by CiD
127.0.0.1 download.errorsafe.com ## added by CiD
127.0.0.1 download.systemdoctor.com ## added by CiD
127.0.0.1 download.winantispyware.com ## added by CiD
127.0.0.1 download.windrivecleaner.com ## added by CiD
127.0.0.1 download.winfixer.com ## added by CiD
127.0.0.1 drivecleaner.com ## added by CiD
127.0.0.1 dynamique.drivecleaner.com ## added by CiD
127.0.0.1 errorprotector.com ## added by CiD
127.0.0.1 errorsafe.com ## added by CiD
127.0.0.1 es.winantivirus.com ## added by CiD
127.0.0.1 fr.winantivirus.com ## added by CiD
127.0.0.1 fr.winfixer.com ## added by CiD
127.0.0.1 go.drivecleaner.com ## added by CiD
127.0.0.1 go.errorsafe.com ## added by CiD
127.0.0.1 go.winantispyware.com ## added by CiD
127.0.0.1 go.winantivirus.com ## added by CiD
127.0.0.1 hk.winantivirus.com ## added by CiD
127.0.0.1 instlog.errorsafe.com ## added by CiD
127.0.0.1 instlog.winantivirus.com ## added by CiD
127.0.0.1 instlog.winfixer.com ## added by CiD
127.0.0.1 jsp.drivecleaner.com ## added by CiD
127.0.0.1 kb.errorsafe.com ## added by CiD
127.0.0.1 kb.winantivirus.com ## added by CiD
127.0.0.1 nl.errorsafe.com ## added by CiD
127.0.0.1 se.errorsafe.com ## added by CiD
127.0.0.1 secure.drivecleaner.com ## added by CiD
127.0.0.1 secure.errorsafe.com ## added by CiD
127.0.0.1 secure.winantispam.com ## added by CiD
127.0.0.1 secure.winantispy.com ## added by CiD
127.0.0.1 secure.winantivirus.com ## added by CiD
127.0.0.1 support.winantivirus.com ## added by CiD
127.0.0.1 trial.updates.winsoftware.com ## added by CiD
127.0.0.1 ulog.winantivirus.com ## added by CiD
127.0.0.1 utils.errorsafe.com ## added by CiD
127.0.0.1 utils.winantivirus.com ## added by CiD
127.0.0.1 utils.winfixer.com ## added by CiD
127.0.0.1 winantispyware.com ## added by CiD
127.0.0.1 winantivirus.com ## added by CiD
127.0.0.1 winfixer.com ## added by CiD
127.0.0.1 winfixer2006.com ## added by CiD
127.0.0.1 winsoftware.com ## added by CiD
127.0.0.1 http://www.drivecleaner.com ## added by CiD
127.0.0.1 http://www.errorprotector.com ## added by CiD
127.0.0.1 http://www.errorsafe.com ## added by CiD
127.0.0.1 http://www.systemdoctor.com ## added by CiD
127.0.0.1 http://www.utils.winfixer.com ## added by CiD
127.0.0.1 http://www.win-anti-virus-pro.com ## added by CiD
127.0.0.1 http://www.win-virus-pro.com ## added by CiD
127.0.0.1 http://www.winantispam.com ## added by CiD
127.0.0.1 http://www.winantispy.com ## added by CiD
127.0.0.1 http://www.winantispyware.com ## added by CiD
127.0.0.1 http://www.winantivirus.com ## added by CiD
127.0.0.1 http://www.winantiviruspro.com ## added by CiD
127.0.0.1 http://www.windrivecleaner.com ## added by CiD
127.0.0.1 http://www.windrivesafe.com ## added by CiD
127.0.0.1 http://www.winfixer.com ## added by CiD
127.0.0.1 http://www.winfixer2006.com ## added by CiD
127.0.0.1 http://www.winsoftware.com ## added by CiD

-> 72 ( 70 ## added by CiD )

/!\ 1 Not 127.0.0.1 !!

----------------[ Recherche de fichiers avec Catchme ]-----------------

catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-16 18:35:03
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 0

--------------------[ Recherche d'autres infections ]---------------------

Aucune autre infection trouvée !

/!\ [Fich:49][Doss:22] C:\DOCUME~1\PROPRI~1\LOCALS~1\Temp
/!\ [Fich:41][Doss:0] C:\DOCUME~1\PROPRI~1\Cookies
/!\ [Fich:1756][Doss:11] C:\DOCUME~1\PROPRI~1\LOCALS~1\TEMPOR~1\content.IE5

--------------------[ Fin du rapport a 18:36:43,75 ]----------------------
voilà ce qu'on me dit!!! moi je comprend que dalle lol.. merci..
angy69
 
Messages: 15
Inscription: 16 Avr 2008 13:03

Re: hijackthis

Messagepar Falkra » 16 Avr 2008 17:56

Ok, on nettoie !


Relance Lop S&D

  • Choisis cette fois ci l'Option 2 ( Suppression )
  • Ne ferme pas la fenêtre lors de la suppression !
  • Poste le rapport généré ( C:\lopR.txt )

(Si le Bureau ne réapparaît pas presse Ctrl + Alt + Suppr , Onglet Fichier , Nouvelle tâche , tape explorer.exe et valide)
Avatar de l’utilisateur
Falkra
Admin libellules.ch
Admin libellules.ch
 
Messages: 24424
Inscription: 30 Jan 2005 13:44
Localisation: 127.0.0.1

Re: hijackthis

Messagepar bouldingue » 16 Avr 2008 18:05

Salut Angy.
Si tu veux pas rester trop bête devant tes rapport hijackthis, je te conseille Zeb Help Process, que tu peux télécharger là: zeb-help-process-t26939.html.
Cela te permettra de savoir quels sont les processus normaux et de surveiller plus tard toi même ce qui fonctionne sur ta machine. Sinon les conseils et interventions de Falkra sont toujours efficacces. Il m'a souvent aidé.
Salut.
je suis là pour apprendre et partager.
Avatar de l’utilisateur
bouldingue
Libellulien Junior
Libellulien Junior
 
Messages: 299
Inscription: 31 Juil 2005 22:42
Localisation: France du haut

Re: hijackthis

Messagepar angy69 » 16 Avr 2008 18:53

-----------------------[ Lop S&D 4.1.1-1 XP/Vista ]---------------------

[ Windows XP (NT 5.1) Build 2600, Service Pack 2 ]
[ USER : Propri‚taire ] [ "C:\Lop SD" ]
[ 16/04/2008 | 19:50:08,67 ] [ PC : ANGY ]
[ MAJ : 15-04-2008 | 20:20 ]

\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ SUPPRESSION /////////////////////////////

Supprimé! - C:\WINDOWS\Tasks\B9326FE8870DE134.job
Supprimé! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\Frag great bend logo
Supprimé! - C:\Program Files\Circle Developement
Restauré! - Fichier Hosts

//////////////////////////////////////-\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\


-------------[ Listing des dossiers dans Application Data ]------------

[16/04/2008|19:50] C:\DOCUME~1\ALLUSE~1\APPLIC~1\.
[16/04/2008|19:50] C:\DOCUME~1\ALLUSE~1\APPLIC~1\..
[01/01/2004|18:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[06/05/2007|11:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Avg7
[04/08/2007|14:02] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Babylon
[12/12/2006|00:15] C:\DOCUME~1\ALLUSE~1\APPLIC~1\BitDefender(2)
[01/01/2004|16:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\desktop.ini
[26/03/2008|06:33] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
[06/05/2007|11:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Grisoft
[08/04/2008|21:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\InstallShield
[01/01/2004|18:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\InterVideo
[19/03/2007|23:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kaspersky Lab
[29/10/2007|17:07] C:\DOCUME~1\ALLUSE~1\APPLIC~1\LauncherAccess.dt
[19/03/2007|14:11] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!
[26/10/2007|08:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[01/01/2004|18:58] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Motive
[09/08/2007|21:55] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Nero
[01/01/2004|18:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\QuickTime
[01/01/2004|16:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SBSI
[06/05/2007|11:07] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec
[02/03/2007|09:26] C:\DOCUME~1\ALLUSE~1\APPLIC~1\up inter 64 dumb
[12/12/2006|00:59] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[12/12/2006|02:02] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Live Toolbar



[06/05/2007|19:36] C:\DOCUME~1\DEFAUL~1\APPLIC~1\.
[06/05/2007|19:36] C:\DOCUME~1\DEFAUL~1\APPLIC~1\..
[01/01/2004|16:39] C:\DOCUME~1\DEFAUL~1\APPLIC~1\desktop.ini
[01/01/2004|16:47] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Identities
[01/01/2004|18:28] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Intervideo
[01/01/2004|17:25] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
[01/01/2004|19:26] C:\DOCUME~1\DEFAUL~1\APPLIC~1\SampleView
[01/01/2004|17:28] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Sun
[01/01/2004|23:21] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Symantec



[01/01/2004|16:49] C:\DOCUME~1\LOCALS~1\APPLIC~1\.
[01/01/2004|16:49] C:\DOCUME~1\LOCALS~1\APPLIC~1\..
[06/05/2007|11:14] C:\DOCUME~1\LOCALS~1\APPLIC~1\AVG7
[01/01/2004|16:49] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft

[01/01/2004|16:49] C:\DOCUME~1\NETWOR~1\APPLIC~1\.
[01/01/2004|16:49] C:\DOCUME~1\NETWOR~1\APPLIC~1\..
[01/01/2004|16:49] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft





[03/04/2008|09:44] C:\DOCUME~1\PROPRI~1\APPLIC~1\.
[03/04/2008|09:44] C:\DOCUME~1\PROPRI~1\APPLIC~1\..
[21/04/2007|17:05] C:\DOCUME~1\PROPRI~1\APPLIC~1\.ABC
[05/03/2008|16:57] C:\DOCUME~1\PROPRI~1\APPLIC~1\7z.dll
[05/03/2008|16:55] C:\DOCUME~1\PROPRI~1\APPLIC~1\7z.exe
[10/02/2008|18:16] C:\DOCUME~1\PROPRI~1\APPLIC~1\Adobe
[28/09/2007|15:28] C:\DOCUME~1\PROPRI~1\APPLIC~1\AdobeUM
[09/08/2007|21:58] C:\DOCUME~1\PROPRI~1\APPLIC~1\Ahead
[14/12/2006|00:10] C:\DOCUME~1\PROPRI~1\APPLIC~1\Apple Computer
[12/09/2007|18:46] C:\DOCUME~1\PROPRI~1\APPLIC~1\ATI
[29/03/2008|11:18] C:\DOCUME~1\PROPRI~1\APPLIC~1\AVG7
[04/08/2007|14:02] C:\DOCUME~1\PROPRI~1\APPLIC~1\Babylon
[11/12/2006|19:36] C:\DOCUME~1\PROPRI~1\APPLIC~1\Bitdefender
[21/04/2007|16:54] C:\DOCUME~1\PROPRI~1\APPLIC~1\BitTorrent
[26/10/2007|08:39] C:\DOCUME~1\PROPRI~1\APPLIC~1\DataCast
[01/01/2004|16:39] C:\DOCUME~1\PROPRI~1\APPLIC~1\desktop.ini
[07/05/2007|20:08] C:\DOCUME~1\PROPRI~1\APPLIC~1\Google
[01/08/2007|16:42] C:\DOCUME~1\PROPRI~1\APPLIC~1\Help
[01/01/2004|16:47] C:\DOCUME~1\PROPRI~1\APPLIC~1\Identities
[26/10/2007|08:38] C:\DOCUME~1\PROPRI~1\APPLIC~1\InstallShield
[06/05/2007|10:53] C:\DOCUME~1\PROPRI~1\APPLIC~1\Intervideo
[06/03/2007|18:35] C:\DOCUME~1\PROPRI~1\APPLIC~1\Leadertech
[13/12/2006|23:30] C:\DOCUME~1\PROPRI~1\APPLIC~1\Macromedia
[17/11/2007|22:43] C:\DOCUME~1\PROPRI~1\APPLIC~1\Microsoft
[01/05/2007|21:23] C:\DOCUME~1\PROPRI~1\APPLIC~1\Motive
[11/12/2006|21:02] C:\DOCUME~1\PROPRI~1\APPLIC~1\Mozilla
[04/04/2008|19:40] C:\DOCUME~1\PROPRI~1\APPLIC~1\OpenOffice.org2
[01/01/2004|19:26] C:\DOCUME~1\PROPRI~1\APPLIC~1\SampleView
[04/11/2007|10:46] C:\DOCUME~1\PROPRI~1\APPLIC~1\Samsung
[09/03/2007|19:26] C:\DOCUME~1\PROPRI~1\APPLIC~1\Screenshot Sender
[12/09/2007|16:50] C:\DOCUME~1\PROPRI~1\APPLIC~1\SecuROM
[27/12/2006|14:50] C:\DOCUME~1\PROPRI~1\APPLIC~1\SEGA
[05/03/2008|16:58] C:\DOCUME~1\PROPRI~1\APPLIC~1\serial2.dat
[05/03/2008|16:56] C:\DOCUME~1\PROPRI~1\APPLIC~1\serial2.zip
[04/08/2007|13:36] C:\DOCUME~1\PROPRI~1\APPLIC~1\ShoppingReport
[02/04/2008|14:00] C:\DOCUME~1\PROPRI~1\APPLIC~1\Slow Wma Time
[11/12/2006|18:41] C:\DOCUME~1\PROPRI~1\APPLIC~1\Sonic
[28/10/2007|15:30] C:\DOCUME~1\PROPRI~1\APPLIC~1\Sports Interactive
[01/01/2004|17:28] C:\DOCUME~1\PROPRI~1\APPLIC~1\Sun
[01/01/2004|23:21] C:\DOCUME~1\PROPRI~1\APPLIC~1\Symantec
[11/12/2006|21:03] C:\DOCUME~1\PROPRI~1\APPLIC~1\Talkback
[06/03/2007|18:46] C:\DOCUME~1\PROPRI~1\APPLIC~1\U3
[06/01/2008|01:30] C:\DOCUME~1\PROPRI~1\APPLIC~1\vlc
[09/02/2007|20:43] C:\DOCUME~1\PROPRI~1\APPLIC~1\wunauclt.tbe


----------------[ Tâches planifiées dans C:\WINDOWS\tasks ]---------------

[16/04/2008 18:56][--a------] C:\WINDOWS\tasks\V‚rifier les mises … jour de Windows Live Toolbar.job
[12/02/2004 13:27][-rah-----] C:\WINDOWS\tasks\desktop.ini
[16/04/2008 03:30][--ah-----] C:\WINDOWS\tasks\SA.DAT

---------------[ Listing des dossiers dans C:\Program Files ]--------------

[16/04/2008|19:50] C:\Program Files\.
[16/04/2008|19:50] C:\Program Files\..
[14/04/2008|10:31] C:\Program Files\Ad-aware 6
[09/08/2007|11:47] C:\Program Files\Adobe
[08/04/2008|21:28] C:\Program Files\AGEIA Technologies
[12/09/2007|15:56] C:\Program Files\Alcohol 120
[12/09/2007|18:43] C:\Program Files\ATI Technologies
[04/08/2007|14:02] C:\Program Files\Babylon Pro Setup
[05/03/2008|17:41] C:\Program Files\Boonty
[05/03/2008|17:37] C:\Program Files\BoontyGames
[23/01/2007|21:50] C:\Program Files\Canon
[12/09/2007|16:31] C:\Program Files\CAPCOM
[01/01/2004|18:18] C:\Program Files\Common Files
[17/11/2007|20:52] C:\Program Files\DAEMON Tools
[09/08/2007|21:33] C:\Program Files\DivX
[01/08/2007|15:49] C:\Program Files\DXBall2
[05/06/2007|11:01] C:\Program Files\Easy Internet signup
[05/07/2007|01:23] C:\Program Files\EasyCleaner
[07/04/2008|10:02] C:\Program Files\eMule
[06/05/2007|12:56] C:\Program Files\Eurobarre
[21/09/2007|16:57] C:\Program Files\Eva Cash
[10/04/2008|14:17] C:\Program Files\Evil Under the Sun
[06/03/2007|18:35] C:\Program Files\Executive Software
[08/04/2008|21:20] C:\Program Files\Fichiers communs
[08/04/2008|21:26] C:\Program Files\Focus
[29/03/2008|11:18] C:\Program Files\Google
[16/01/2007|09:56] C:\Program Files\Grisoft
[05/03/2008|16:57] C:\Program Files\inc1.bat
[08/04/2008|21:41] C:\Program Files\InstallShield Installation Information
[09/04/2008|08:17] C:\Program Files\Internet Explorer
[20/01/2008|09:06] C:\Program Files\InterVideo
[26/03/2008|06:33] C:\Program Files\Java
[20/01/2008|09:07] C:\Program Files\Kyodai
[08/04/2008|21:20] C:\Program Files\La nuit des sacrifies
[11/04/2008|16:06] C:\Program Files\Les Sims 2
[02/04/2008|15:55] C:\Program Files\Ludiclub
[26/10/2007|08:39] C:\Program Files\MarkAny
[14/05/2007|16:40] C:\Program Files\messenger
[31/03/2008|10:20] C:\Program Files\Messenger Plus! Live
[12/12/2006|02:15] C:\Program Files\MessengerPlus! 3
[01/01/2004|16:47] C:\Program Files\microsoft frontpage
[06/05/2007|15:22] C:\Program Files\Movie Maker
[16/04/2008|18:54] C:\Program Files\Mozilla Firefox
[01/01/2004|16:43] C:\Program Files\MSN
[08/05/2007|21:34] C:\Program Files\MSN BackUp
[01/01/2004|16:43] C:\Program Files\MSN Gaming Zone
[31/03/2008|10:19] C:\Program Files\MSN Messenger
[10/08/2007|05:40] C:\Program Files\MSXML 4.0
[09/08/2007|21:55] C:\Program Files\Nero
[06/05/2007|15:21] C:\Program Files\NetMeeting
[12/06/2007|21:21] C:\Program Files\NOCD Penumbra Overture crack.exe
[13/12/2006|12:05] C:\Program Files\NUMERICABLE
[04/04/2008|19:43] C:\Program Files\OpenOffice.org 2.4
[14/06/2007|00:17] C:\Program Files\Outlook Express
[05/03/2008|16:55] C:\Program Files\Penumbra Overture crack.exe
[01/01/2004|18:58] C:\Program Files\Presario PC Help
[13/12/2007|13:14] C:\Program Files\Project64 v1.5
[01/01/2004|18:35] C:\Program Files\QuickTime
[06/05/2007|10:50] C:\Program Files\RecordNow!
[04/08/2007|22:25] C:\Program Files\ReflexiveArcade
[16/09/2007|12:46] C:\Program Files\Ricochet Xtreme
[01/01/2004|19:03] C:\Program Files\Services en ligne
[04/08/2007|13:36] C:\Program Files\ShoppingReport
[09/08/2007|21:41] C:\Program Files\SLD Codec Pack
[05/03/2008|16:57] C:\Program Files\sleep.bat
[25/02/2008|08:28] C:\Program Files\Slow Wma Time
[11/12/2006|18:39] C:\Program Files\Sonic
[28/10/2007|15:17] C:\Program Files\Sports Interactive
[25/02/2008|14:50] C:\Program Files\TAROTPRO992
[12/06/2007|21:21] C:\Program Files\temp1.exe
[05/03/2008|16:57] C:\Program Files\temp2.exe
[05/03/2008|16:57] C:\Program Files\temp3.exe
[10/04/2008|14:18] C:\Program Files\The Adventure Company
[01/08/2007|17:29] C:\Program Files\The Bitmap Brothers
[06/05/2007|12:54] C:\Program Files\ToniArts
[06/05/2007|13:37] C:\Program Files\Uninstall Information
[27/12/2006|14:47] C:\Program Files\VID_0E8F&PID_0003
[02/12/2007|18:24] C:\Program Files\VideoLAN
[05/03/2008|16:55] C:\Program Files\Win.All Penumbra Overture crack.exe
[03/06/2007|20:24] C:\Program Files\Windows Live
[12/12/2006|02:03] C:\Program Files\Windows Live Favorites
[12/12/2006|02:03] C:\Program Files\Windows Live Toolbar
[21/01/2007|02:09] C:\Program Files\Windows Media Connect 2
[06/05/2007|16:06] C:\Program Files\Windows Media Player
[06/05/2007|15:21] C:\Program Files\Windows NT
[06/05/2007|11:25] C:\Program Files\WindowsUpdate
[22/02/2007|09:26] C:\Program Files\WinRAR
[01/01/2004|16:47] C:\Program Files\xerox
[11/12/2006|20:41] C:\Program Files\xp-AntiSpy
[04/08/2007|13:41] C:\Program Files\Zapu
[28/10/2007|15:17] C:\Program Files\Zero G Registry

------[ Listing des dossiers dans C:\Program Files\Fichiers communs ]------

[08/04/2008|21:20] C:\Program Files\Fichiers communs\.
[08/04/2008|21:20] C:\Program Files\Fichiers communs\..
[12/12/2006|18:31] C:\Program Files\Fichiers communs\Adobe
[09/08/2007|21:55] C:\Program Files\Fichiers communs\Ahead
[28/12/2006|01:04] C:\Program Files\Fichiers communs\ATI Technologies
[01/06/2007|21:29] C:\Program Files\Fichiers communs\DirectX
[08/04/2008|21:26] C:\Program Files\Fichiers communs\InstallShield
[01/01/2004|17:28] C:\Program Files\Fichiers communs\Java
[01/01/2004|18:18] C:\Program Files\Fichiers communs\Microsoft Shared
[01/01/2004|16:44] C:\Program Files\Fichiers communs\MSSoap
[01/01/2004|16:40] C:\Program Files\Fichiers communs\ODBC
[06/05/2007|19:38] C:\Program Files\Fichiers communs\Services
[16/01/2007|09:41] C:\Program Files\Fichiers communs\Softwin
[11/12/2006|18:40] C:\Program Files\Fichiers communs\Sonic
[01/01/2004|16:40] C:\Program Files\Fichiers communs\SpeechEngines
[06/05/2007|10:50] C:\Program Files\Fichiers communs\SureThing Shared
[14/06/2007|00:17] C:\Program Files\Fichiers communs\System
[08/04/2008|21:28] C:\Program Files\Fichiers communs\Wise Installation Wizard

----------------------[ Recherche avec S_Lop ]---------------------

Aucun fichier / dossier Lop trouvé !

-----------------[ Recherche de Fichiers / Dossiers Lop ]-----------------

Aucun fichier / dossier Lop trouvé !

----------------------[ Verification du Registre ]----------------------

..... OK !

--------------------[ Verification du fichier Hosts ]---------------------

Fichier Hosts PROPRE


----------------[ Recherche de fichiers avec Catchme ]-----------------

catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-16 19:50:41
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 0

--------------------[ Recherche d'autres infections ]---------------------

Aucune autre infection trouvée !

/!\ [Fich:74][Doss:23] C:\DOCUME~1\PROPRI~1\LOCALS~1\Temp
/!\ [Fich:42][Doss:0] C:\DOCUME~1\PROPRI~1\Cookies
/!\ [Fich:1824][Doss:11] C:\DOCUME~1\PROPRI~1\LOCALS~1\TEMPOR~1\content.IE5

--------------------[ Fin du rapport a 19:52:19,43 ]----------------------
voilà c fait!!! tt est normal? merci a tous!!
angy69
 
Messages: 15
Inscription: 16 Avr 2008 13:03

Re: hijackthis

Messagepar Falkra » 16 Avr 2008 20:17

Pour ça, ça va mieux.

Suite :
  • Télécharge BTFix de Bibi26.
  • Dézippe l'archive sur ton Bureau.
  • Ouvre le dossier BTFix.
  • Double clique sur BTFix.exe.
  • Clique sur Rechercher.
  • Un rapport va apparaître, copie/colle-le dans ta prochaine réponse, ne nettoie pas directement, on vérifie d'abord ce qui est listé.
Avatar de l’utilisateur
Falkra
Admin libellules.ch
Admin libellules.ch
 
Messages: 24424
Inscription: 30 Jan 2005 13:44
Localisation: 127.0.0.1

Re: hijackthis

Messagepar angy69 » 17 Avr 2008 07:13

BTFix 1.098 (par bibi26) - 17/04/2008 08:12:02 - Analyse
Lancé depuis C:\Documents and Settings\Propriétaire\Bureau\BTFix\BTFix.exe

---> Fichiers/Dossiers trouvés

- C:\Program Files\ShoppingReport\
- C:\Documents and Settings\Propriétaire\Application Data\ShoppingReport\

---> Analyse terminée le 17/04/2008 08:12:04

voilà!! ensuite que dois-je faire merci
angy69
 
Messages: 15
Inscription: 16 Avr 2008 13:03

Re: hijackthis

Messagepar Falkra » 17 Avr 2008 07:44

Ok, suite :

  • Ouvre BTFix.
  • Clique sur Nettoyer.
  • Un rapport va apparaître, copie/colle-le dans ta prochaine réponse, suivi d'un nouveau rapport Hijackthis.
Avatar de l’utilisateur
Falkra
Admin libellules.ch
Admin libellules.ch
 
Messages: 24424
Inscription: 30 Jan 2005 13:44
Localisation: 127.0.0.1

Re: hijackthis

Messagepar angy69 » 17 Avr 2008 08:15

BTFix 1.098 (par bibi26) - 17/04/2008 09:11:32 - Nettoyage - Mode normal
Lancé depuis C:\Documents and Settings\Propriétaire\Bureau\BTFix\BTFix.exe

---> Fichiers/dossiers supprimés (Première passe)

- Fichiers temporaires effacés
- C:\Program Files\ShoppingReport\Bin\2.0.22\
- C:\Program Files\ShoppingReport\Bin\
- C:\Program Files\ShoppingReport\cs\
- C:\Program Files\ShoppingReport\
- C:\Documents and Settings\Propriétaire\Application Data\ShoppingReport\cs\db\
- C:\Documents and Settings\Propriétaire\Application Data\ShoppingReport\cs\dwld\
- C:\Documents and Settings\Propriétaire\Application Data\ShoppingReport\cs\report\
- C:\Documents and Settings\Propriétaire\Application Data\ShoppingReport\cs\res2\
- C:\Documents and Settings\Propriétaire\Application Data\ShoppingReport\cs\
- C:\Documents and Settings\Propriétaire\Application Data\ShoppingReport\

---> Nettoyage terminé le 17/04/2008 09:11:36
j'ai cliquer sur la 1ere ligne pour pouvoir nettoyer il y avait 2 ligne mais je sais plus se qui etais ecrit!!
apres avoir cliquer j'ai eu le rapport ci dessus, et les 2 lignes ont disparus apres c'est normal?
angy69
 
Messages: 15
Inscription: 16 Avr 2008 13:03

Re: hijackthis

Messagepar Falkra » 17 Avr 2008 08:54

Ca va faire disparaître des lignes dans HijackThis (normal et voulu).
Poste un nouveau rapport HijackThis stp. :-D
Avatar de l’utilisateur
Falkra
Admin libellules.ch
Admin libellules.ch
 
Messages: 24424
Inscription: 30 Jan 2005 13:44
Localisation: 127.0.0.1

Re: hijackthis

Messagepar angy69 » 17 Avr 2008 09:02

ok... et c'est fini la je dois plus rien faire? j'ai installer zeb help process..
mais je comprend rien non + je suis pas douée oui je re connais lol.. existe t-il un modele d'ex? merci beaucoup
angy69
 
Messages: 15
Inscription: 16 Avr 2008 13:03

Re: hijackthis

Messagepar Falkra » 17 Avr 2008 09:16

Je ne sais pas si c'est fini, je dois voir un nouveau rapport.
Relance HijackThis, et fais un nouveau rapport, à poster dans ta prochaine réponse stp. :wink:

@ toute
Avatar de l’utilisateur
Falkra
Admin libellules.ch
Admin libellules.ch
 
Messages: 24424
Inscription: 30 Jan 2005 13:44
Localisation: 127.0.0.1

Re: hijackthis

Messagepar angy69 » 17 Avr 2008 11:02

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:01:40, on 17/04/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\windows\system\hpsysdrv.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\MarkAny\ContentSafer\MAAgent.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\MSN Messenger\livecall.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Propriétaire\Bureau\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [UpdateManager] "c:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [SMSTray] C:\Documents and Settings\Propriétaire\Bureau\KEV1989\MP3\SMSTray.exe
O4 - HKLM\..\Run: [MAAgent] C:\Program Files\MarkAny\ContentSafer\MAAgent.exe
O4 - HKLM\..\Run: [bend logo clock film] C:\Documents and Settings\All Users\Application Data\Frag great bend logo\body team.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [onlinegrey] C:\DOCUME~1\PROPRI~1\APPLIC~1\SLOWWM~1\ONCE PEAK.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Startup: Eurobarre.lnk = C:\Program Files\Eurobarre\eb.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-U ... E_UNO1.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupda ... 8453593921
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Me ... b56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/Mi ... b56986.cab
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol 120\StarWind\StarWindServiceAE.exe

--
End of file - 6589 bytes


voilà j'espere que s'est se que tu me demandais!! lol merci
angy69
 
Messages: 15
Inscription: 16 Avr 2008 13:03

Re: hijackthis

Messagepar Falkra » 17 Avr 2008 18:39

C'était bien ça, impeccable. Il reste des saletés, on va voir si elles sont détectées, si ce n'est aps le cas je ferai remonter 'info au développeur de l'outil (mise à jour rapide et on shootera les fichiers avec).

Désactive tes protections résidentes ( Antivirus , ... ) tu les réactiveras ensuite

Télécharge [url="http://eric.71.mespages.googlepages.com/LopSD.exe"]Lop S&D.exe[/url] sur ton bureau

  • Double-clique dessus pour lancer l'installation
  • Puis double-clique sur le raccourci Lop S&D présent sur ton bureau
  • Sélectionne la langue souhaitée, puis choisis l'Option 1 ( Recherche )
  • Patiente jusqu'à la fin du scan
  • Poste le rapport généré ( C:\lopR.txt )

( Si le Bureau ne réapparait pas presse Ctrl + Alt + Suppr , Onglet Fichier , Nouvelle tâche , tape explorer.exe et valide).
Avatar de l’utilisateur
Falkra
Admin libellules.ch
Admin libellules.ch
 
Messages: 24424
Inscription: 30 Jan 2005 13:44
Localisation: 127.0.0.1

Re: hijackthis

Messagepar angy69 » 18 Avr 2008 06:40

-----------------------[ Lop S&D 4.1.1-1 XP/Vista ]---------------------

[ Windows XP (NT 5.1) Build 2600, Service Pack 2 ]
[ USER : Propri‚taire ] [ "C:\Lop SD" ]
[ 18/04/2008 | 7:35:58,73 ] [ PC : ANGY ]
[ MAJ : 15-04-2008 | 20:20 ]

-------------[ Listing des dossiers dans Application Data ]------------

[16/04/2008|19:50] C:\DOCUME~1\ALLUSE~1\APPLIC~1\.
[16/04/2008|19:50] C:\DOCUME~1\ALLUSE~1\APPLIC~1\..
[01/01/2004|18:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[06/05/2007|11:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Avg7
[04/08/2007|14:02] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Babylon
[12/12/2006|00:15] C:\DOCUME~1\ALLUSE~1\APPLIC~1\BitDefender(2)
[01/01/2004|16:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\desktop.ini
[26/03/2008|06:33] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
[06/05/2007|11:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Grisoft
[08/04/2008|21:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\InstallShield
[01/01/2004|18:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\InterVideo
[19/03/2007|23:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kaspersky Lab
[29/10/2007|17:07] C:\DOCUME~1\ALLUSE~1\APPLIC~1\LauncherAccess.dt
[19/03/2007|14:11] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!
[26/10/2007|08:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[01/01/2004|18:58] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Motive
[09/08/2007|21:55] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Nero
[01/01/2004|18:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\QuickTime
[01/01/2004|16:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SBSI
[06/05/2007|11:07] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec
[02/03/2007|09:26] C:\DOCUME~1\ALLUSE~1\APPLIC~1\up inter 64 dumb
[12/12/2006|00:59] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[12/12/2006|02:02] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Live Toolbar



[06/05/2007|19:36] C:\DOCUME~1\DEFAUL~1\APPLIC~1\.
[06/05/2007|19:36] C:\DOCUME~1\DEFAUL~1\APPLIC~1\..
[01/01/2004|16:39] C:\DOCUME~1\DEFAUL~1\APPLIC~1\desktop.ini
[01/01/2004|16:47] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Identities
[01/01/2004|18:28] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Intervideo
[01/01/2004|17:25] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
[01/01/2004|19:26] C:\DOCUME~1\DEFAUL~1\APPLIC~1\SampleView
[01/01/2004|17:28] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Sun
[01/01/2004|23:21] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Symantec



[01/01/2004|16:49] C:\DOCUME~1\LOCALS~1\APPLIC~1\.
[01/01/2004|16:49] C:\DOCUME~1\LOCALS~1\APPLIC~1\..
[06/05/2007|11:14] C:\DOCUME~1\LOCALS~1\APPLIC~1\AVG7
[01/01/2004|16:49] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft

[01/01/2004|16:49] C:\DOCUME~1\NETWOR~1\APPLIC~1\.
[01/01/2004|16:49] C:\DOCUME~1\NETWOR~1\APPLIC~1\..
[01/01/2004|16:49] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft






[17/04/2008|09:11] C:\DOCUME~1\PROPRI~1\APPLIC~1\.
[17/04/2008|09:11] C:\DOCUME~1\PROPRI~1\APPLIC~1\..
[21/04/2007|17:05] C:\DOCUME~1\PROPRI~1\APPLIC~1\.ABC
[05/03/2008|16:57] C:\DOCUME~1\PROPRI~1\APPLIC~1\7z.dll
[05/03/2008|16:55] C:\DOCUME~1\PROPRI~1\APPLIC~1\7z.exe
[10/02/2008|18:16] C:\DOCUME~1\PROPRI~1\APPLIC~1\Adobe
[28/09/2007|15:28] C:\DOCUME~1\PROPRI~1\APPLIC~1\AdobeUM
[09/08/2007|21:58] C:\DOCUME~1\PROPRI~1\APPLIC~1\Ahead
[14/12/2006|00:10] C:\DOCUME~1\PROPRI~1\APPLIC~1\Apple Computer
[12/09/2007|18:46] C:\DOCUME~1\PROPRI~1\APPLIC~1\ATI
[29/03/2008|11:18] C:\DOCUME~1\PROPRI~1\APPLIC~1\AVG7
[04/08/2007|14:02] C:\DOCUME~1\PROPRI~1\APPLIC~1\Babylon
[11/12/2006|19:36] C:\DOCUME~1\PROPRI~1\APPLIC~1\Bitdefender
[21/04/2007|16:54] C:\DOCUME~1\PROPRI~1\APPLIC~1\BitTorrent
[26/10/2007|08:39] C:\DOCUME~1\PROPRI~1\APPLIC~1\DataCast
[01/01/2004|16:39] C:\DOCUME~1\PROPRI~1\APPLIC~1\desktop.ini
[07/05/2007|20:08] C:\DOCUME~1\PROPRI~1\APPLIC~1\Google
[01/08/2007|16:42] C:\DOCUME~1\PROPRI~1\APPLIC~1\Help
[01/01/2004|16:47] C:\DOCUME~1\PROPRI~1\APPLIC~1\Identities
[26/10/2007|08:38] C:\DOCUME~1\PROPRI~1\APPLIC~1\InstallShield
[06/05/2007|10:53] C:\DOCUME~1\PROPRI~1\APPLIC~1\Intervideo
[06/03/2007|18:35] C:\DOCUME~1\PROPRI~1\APPLIC~1\Leadertech
[13/12/2006|23:30] C:\DOCUME~1\PROPRI~1\APPLIC~1\Macromedia
[17/11/2007|22:43] C:\DOCUME~1\PROPRI~1\APPLIC~1\Microsoft
[01/05/2007|21:23] C:\DOCUME~1\PROPRI~1\APPLIC~1\Motive
[11/12/2006|21:02] C:\DOCUME~1\PROPRI~1\APPLIC~1\Mozilla
[04/04/2008|19:40] C:\DOCUME~1\PROPRI~1\APPLIC~1\OpenOffice.org2
[01/01/2004|19:26] C:\DOCUME~1\PROPRI~1\APPLIC~1\SampleView
[04/11/2007|10:46] C:\DOCUME~1\PROPRI~1\APPLIC~1\Samsung
[09/03/2007|19:26] C:\DOCUME~1\PROPRI~1\APPLIC~1\Screenshot Sender
[12/09/2007|16:50] C:\DOCUME~1\PROPRI~1\APPLIC~1\SecuROM
[27/12/2006|14:50] C:\DOCUME~1\PROPRI~1\APPLIC~1\SEGA
[05/03/2008|16:58] C:\DOCUME~1\PROPRI~1\APPLIC~1\serial2.dat
[05/03/2008|16:56] C:\DOCUME~1\PROPRI~1\APPLIC~1\serial2.zip
[02/04/2008|14:00] C:\DOCUME~1\PROPRI~1\APPLIC~1\Slow Wma Time
[11/12/2006|18:41] C:\DOCUME~1\PROPRI~1\APPLIC~1\Sonic
[28/10/2007|15:30] C:\DOCUME~1\PROPRI~1\APPLIC~1\Sports Interactive
[01/01/2004|17:28] C:\DOCUME~1\PROPRI~1\APPLIC~1\Sun
[01/01/2004|23:21] C:\DOCUME~1\PROPRI~1\APPLIC~1\Symantec
[11/12/2006|21:03] C:\DOCUME~1\PROPRI~1\APPLIC~1\Talkback
[06/03/2007|18:46] C:\DOCUME~1\PROPRI~1\APPLIC~1\U3
[06/01/2008|01:30] C:\DOCUME~1\PROPRI~1\APPLIC~1\vlc
[09/02/2007|20:43] C:\DOCUME~1\PROPRI~1\APPLIC~1\wunauclt.tbe


----------------[ Tâches planifiées dans C:\WINDOWS\tasks ]---------------

[17/04/2008 23:56][--a------] C:\WINDOWS\tasks\V‚rifier les mises … jour de Windows Live Toolbar.job
[12/02/2004 13:27][-rah-----] C:\WINDOWS\tasks\desktop.ini
[18/04/2008 07:30][--ah-----] C:\WINDOWS\tasks\SA.DAT

---------------[ Listing des dossiers dans C:\Program Files ]--------------

[17/04/2008|09:11] C:\Program Files\.
[17/04/2008|09:11] C:\Program Files\..
[14/04/2008|10:31] C:\Program Files\Ad-aware 6
[09/08/2007|11:47] C:\Program Files\Adobe
[08/04/2008|21:28] C:\Program Files\AGEIA Technologies
[12/09/2007|15:56] C:\Program Files\Alcohol 120
[12/09/2007|18:43] C:\Program Files\ATI Technologies
[04/08/2007|14:02] C:\Program Files\Babylon Pro Setup
[05/03/2008|17:41] C:\Program Files\Boonty
[05/03/2008|17:37] C:\Program Files\BoontyGames
[23/01/2007|21:50] C:\Program Files\Canon
[12/09/2007|16:31] C:\Program Files\CAPCOM
[01/01/2004|18:18] C:\Program Files\Common Files
[17/11/2007|20:52] C:\Program Files\DAEMON Tools
[09/08/2007|21:33] C:\Program Files\DivX
[01/08/2007|15:49] C:\Program Files\DXBall2
[05/06/2007|11:01] C:\Program Files\Easy Internet signup
[05/07/2007|01:23] C:\Program Files\EasyCleaner
[07/04/2008|10:02] C:\Program Files\eMule
[06/05/2007|12:56] C:\Program Files\Eurobarre
[21/09/2007|16:57] C:\Program Files\Eva Cash
[10/04/2008|14:17] C:\Program Files\Evil Under the Sun
[06/03/2007|18:35] C:\Program Files\Executive Software
[16/04/2008|20:00] C:\Program Files\Fichiers communs
[08/04/2008|21:26] C:\Program Files\Focus
[29/03/2008|11:18] C:\Program Files\Google
[16/01/2007|09:56] C:\Program Files\Grisoft
[05/03/2008|16:57] C:\Program Files\inc1.bat
[08/04/2008|21:41] C:\Program Files\InstallShield Installation Information
[09/04/2008|08:17] C:\Program Files\Internet Explorer
[20/01/2008|09:06] C:\Program Files\InterVideo
[26/03/2008|06:33] C:\Program Files\Java
[20/01/2008|09:07] C:\Program Files\Kyodai
[08/04/2008|21:20] C:\Program Files\La nuit des sacrifies
[11/04/2008|16:06] C:\Program Files\Les Sims 2
[02/04/2008|15:55] C:\Program Files\Ludiclub
[26/10/2007|08:39] C:\Program Files\MarkAny
[14/05/2007|16:40] C:\Program Files\messenger
[31/03/2008|10:20] C:\Program Files\Messenger Plus! Live
[12/12/2006|02:15] C:\Program Files\MessengerPlus! 3
[01/01/2004|16:47] C:\Program Files\microsoft frontpage
[06/05/2007|15:22] C:\Program Files\Movie Maker
[17/04/2008|23:49] C:\Program Files\Mozilla Firefox
[01/01/2004|16:43] C:\Program Files\MSN
[08/05/2007|21:34] C:\Program Files\MSN BackUp
[01/01/2004|16:43] C:\Program Files\MSN Gaming Zone
[31/03/2008|10:19] C:\Program Files\MSN Messenger
[10/08/2007|05:40] C:\Program Files\MSXML 4.0
[09/08/2007|21:55] C:\Program Files\Nero
[06/05/2007|15:21] C:\Program Files\NetMeeting
[12/06/2007|21:21] C:\Program Files\NOCD Penumbra Overture crack.exe
[13/12/2006|12:05] C:\Program Files\NUMERICABLE
[04/04/2008|19:43] C:\Program Files\OpenOffice.org 2.4
[14/06/2007|00:17] C:\Program Files\Outlook Express
[05/03/2008|16:55] C:\Program Files\Penumbra Overture crack.exe
[01/01/2004|18:58] C:\Program Files\Presario PC Help
[13/12/2007|13:14] C:\Program Files\Project64 v1.5
[01/01/2004|18:35] C:\Program Files\QuickTime
[06/05/2007|10:50] C:\Program Files\RecordNow!
[04/08/2007|22:25] C:\Program Files\ReflexiveArcade
[16/09/2007|12:46] C:\Program Files\Ricochet Xtreme
[01/01/2004|19:03] C:\Program Files\Services en ligne
[09/08/2007|21:41] C:\Program Files\SLD Codec Pack
[05/03/2008|16:57] C:\Program Files\sleep.bat
[25/02/2008|08:28] C:\Program Files\Slow Wma Time
[11/12/2006|18:39] C:\Program Files\Sonic
[28/10/2007|15:17] C:\Program Files\Sports Interactive
[25/02/2008|14:50] C:\Program Files\TAROTPRO992
[12/06/2007|21:21] C:\Program Files\temp1.exe
[05/03/2008|16:57] C:\Program Files\temp2.exe
[05/03/2008|16:57] C:\Program Files\temp3.exe
[10/04/2008|14:18] C:\Program Files\The Adventure Company
[01/08/2007|17:29] C:\Program Files\The Bitmap Brothers
[06/05/2007|12:54] C:\Program Files\ToniArts
[06/05/2007|13:37] C:\Program Files\Uninstall Information
[27/12/2006|14:47] C:\Program Files\VID_0E8F&PID_0003
[02/12/2007|18:24] C:\Program Files\VideoLAN
[05/03/2008|16:55] C:\Program Files\Win.All Penumbra Overture crack.exe
[03/06/2007|20:24] C:\Program Files\Windows Live
[12/12/2006|02:03] C:\Program Files\Windows Live Favorites
[12/12/2006|02:03] C:\Program Files\Windows Live Toolbar
[21/01/2007|02:09] C:\Program Files\Windows Media Connect 2
[06/05/2007|16:06] C:\Program Files\Windows Media Player
[06/05/2007|15:21] C:\Program Files\Windows NT
[06/05/2007|11:25] C:\Program Files\WindowsUpdate
[22/02/2007|09:26] C:\Program Files\WinRAR
[01/01/2004|16:47] C:\Program Files\xerox
[11/12/2006|20:41] C:\Program Files\xp-AntiSpy
[04/08/2007|13:41] C:\Program Files\Zapu
[16/04/2008|20:07] C:\Program Files\ZebHelpProcess 2
[28/10/2007|15:17] C:\Program Files\Zero G Registry

------[ Listing des dossiers dans C:\Program Files\Fichiers communs ]------

[16/04/2008|20:00] C:\Program Files\Fichiers communs\.
[16/04/2008|20:00] C:\Program Files\Fichiers communs\..
[12/12/2006|18:31] C:\Program Files\Fichiers communs\Adobe
[09/08/2007|21:55] C:\Program Files\Fichiers communs\Ahead
[28/12/2006|01:04] C:\Program Files\Fichiers communs\ATI Technologies
[16/04/2008|20:00] C:\Program Files\Fichiers communs\Borland Shared
[01/06/2007|21:29] C:\Program Files\Fichiers communs\DirectX
[08/04/2008|21:26] C:\Program Files\Fichiers communs\InstallShield
[01/01/2004|17:28] C:\Program Files\Fichiers communs\Java
[01/01/2004|18:18] C:\Program Files\Fichiers communs\Microsoft Shared
[01/01/2004|16:44] C:\Program Files\Fichiers communs\MSSoap
[01/01/2004|16:40] C:\Program Files\Fichiers communs\ODBC
[06/05/2007|19:38] C:\Program Files\Fichiers communs\Services
[16/01/2007|09:41] C:\Program Files\Fichiers communs\Softwin
[11/12/2006|18:40] C:\Program Files\Fichiers communs\Sonic
[01/01/2004|16:40] C:\Program Files\Fichiers communs\SpeechEngines
[06/05/2007|10:50] C:\Program Files\Fichiers communs\SureThing Shared
[14/06/2007|00:17] C:\Program Files\Fichiers communs\System
[08/04/2008|21:28] C:\Program Files\Fichiers communs\Wise Installation Wizard

----------------------[ Recherche avec S_Lop ]---------------------

Aucun fichier / dossier Lop trouvé !

-----------------[ Recherche de Fichiers / Dossiers Lop ]-----------------

Aucun fichier / dossier Lop trouvé !

----------------------[ Verification du Registre ]----------------------

..... OK !

--------------------[ Verification du fichier Hosts ]---------------------

Fichier Hosts PROPRE


----------------[ Recherche de fichiers avec Catchme ]-----------------

catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-18 07:36:32
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 0

--------------------[ Recherche d'autres infections ]---------------------

Aucune autre infection trouvée !

/!\ [Fich:125][Doss:4] C:\DOCUME~1\PROPRI~1\LOCALS~1\Temp
/!\ [Fich:48][Doss:0] C:\DOCUME~1\PROPRI~1\Cookies
/!\ [Fich:2107][Doss:11] C:\DOCUME~1\PROPRI~1\LOCALS~1\TEMPOR~1\content.IE5

--------------------[ Fin du rapport a 7:38:28,90 ]----------------------

voilà!!! mais on l'avais dejà fait ça!! c'est normal de le refaire?
angy69
 
Messages: 15
Inscription: 16 Avr 2008 13:03

Re: hijackthis

Messagepar angy69 » 18 Avr 2008 08:45

et dans tout cela où son les erreurs? qui y'a t'il de suspect? c'est pour mieux comprendre. merci
angy69
 
Messages: 15
Inscription: 16 Avr 2008 13:03

Re: hijackthis

Messagepar Falkra » 18 Avr 2008 22:12

Ok, poste un nouveau rapport HijackThis stp. tout n'a pas forcément été détecté par l'outil, si ce n'est pas le cas, on fera remonter des données au développeur pour améliorer les détections.
On le saura en voyant le prochain rapport.

@ toute
Avatar de l’utilisateur
Falkra
Admin libellules.ch
Admin libellules.ch
 
Messages: 24424
Inscription: 30 Jan 2005 13:44
Localisation: 127.0.0.1

Re: hijackthis

Messagepar angy69 » 19 Avr 2008 06:22

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 07:21:56, on 19/04/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\windows\system\hpsysdrv.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\MarkAny\ContentSafer\MAAgent.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Eurobarre\eb.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\MSN Messenger\livecall.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Documents and Settings\Propriétaire\Bureau\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [UpdateManager] "c:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [SMSTray] C:\Documents and Settings\Propriétaire\Bureau\KEV1989\MP3\SMSTray.exe
O4 - HKLM\..\Run: [MAAgent] C:\Program Files\MarkAny\ContentSafer\MAAgent.exe
O4 - HKLM\..\Run: [bend logo clock film] C:\Documents and Settings\All Users\Application Data\Frag great bend logo\body team.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [onlinegrey] C:\DOCUME~1\PROPRI~1\APPLIC~1\SLOWWM~1\ONCE PEAK.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Startup: Eurobarre.lnk = C:\Program Files\Eurobarre\eb.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-U ... E_UNO1.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupda ... 8453593921
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Me ... b56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/Mi ... b56986.cab
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol 120\StarWind\StarWindServiceAE.exe

--
End of file - 6624 bytes

voilà merci..
angy69
 
Messages: 15
Inscription: 16 Avr 2008 13:03

Re: hijackthis

Messagepar Falkra » 19 Avr 2008 07:34

Ils y sont encore, l'outil devrait les trouver dans sa version 4.1.1-3 (l'actuelle)

** Désinstalle ta version de Lop S&D (par le raccourci du menu démarrer).
** Télécharge la nouvelle ici : http://eric.71.mespages.googlepages.com/LopSD.exe
** Installe cette version et refais un rapport avec l'option 1, à poster après stp. :-D
Avatar de l’utilisateur
Falkra
Admin libellules.ch
Admin libellules.ch
 
Messages: 24424
Inscription: 30 Jan 2005 13:44
Localisation: 127.0.0.1

Suivante

Retourner vers Désinfections et demandes d'analyse

Qui est en ligne

Utilisateurs parcourant ce forum: Aucun utilisateur enregistré et 5 invités