bonjour,
je ne peux pas changer les mots de passe, je ne le connais pas c'est mon patron qui les a.
ci-dessous le log dds
AV: Symantec AntiVirus Corporate Edition *On-access scanning enabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\ADELIWS\Adelrun\Win32\mwdaemon.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\ADELIWS\Adelrun\Win32\MWBOOT.EXE
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\Explorer.EXE
c:\har\sys\xmu.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\sistray.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\IdLog\Client\Obj\MENUG.exe
C:\Program Files\IdLog\Client\Obj\UTMG01.exe
C:\Program Files\Fichiers communs\Adobe\Updater6\Adobe_Updater.exe
C:\Program Files\IdLog\Client\Obj\VE100X.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\audrey.esnault\Local Settings\Temporary Internet Files\Content.IE5\JIU9FY02\dds[1].scr
============== Pseudo HJT Report ===============
uStart Page =
hxxp://www.google.fr/uSearch Page =
hxxp://www.google.comuWindow Title = Windows Internet Explorer
uSearchAssistant =
hxxp://www.google.com/ieuSearchURL,(Default) =
hxxp://www.google.com/search?q=%s
mSearchAssistant =
hxxp://www.google.com/ieBHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\fichiers communs\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar1.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.4.4525.1752\swg.dll
BHO: PDFCreator Toolbar Helper: {c451c08a-ec37-45df-aaad-18b51ab5e837} - c:\program files\pdfcreator toolbar\v3.0.0.0\PDFCreator_Toolbar.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar1.dll
TB: PDFCreator Toolbar: {31cf9ebe-5755-4a1d-ac25-2834d952d9b4} - c:\program files\pdfcreator toolbar\v3.0.0.0\PDFCreator_Toolbar.dll
uRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
mRun: [SoundMan] SOUNDMAN.EXE
mRun: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
mRun: [ccApp] "c:\program files\fichiers communs\symantec shared\ccApp.exe"
mRun: [vptray] c:\progra~1\symant~1\VPTray.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\fichiers communs\adobe\arm\1.0\AdobeARM.exe"
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
StartupFolder: c:\docume~1\audrey~1.esn\menudm~1\progra~1\dmarra~1\openof~1.lnk - c:\program files\openoffice.org 3\program\quickstart.exe
StartupFolder: c:\docume~1\alluse~1\menudm~1\progra~1\dmarra~1\majidlog.lnk - \\serveur\idm$\installidlog\MajIdLog.bat
StartupFolder: c:\docume~1\alluse~1\menudm~1\progra~1\dmarra~1\utilit~1.lnk - c:\windows\system32\sistray.exe
StartupFolder: c:\docume~1\alluse~1\menudm~1\progra~1\dmarra~1\winzip~1.lnk - c:\program files\winzip\WZQKPICK.EXE
uPolicies-explorer: HonorAutoRunSetting = 0 (0x0)
mPolicies-explorer: NoDisconnect = 1 (0x1)
mPolicies-explorer: HonorAutoRunSetting = 0 (0x0)
IE: E&xporter vers Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} -
hxxp://download.macromedia.com/pub/shoc ... tor/sw.cabDPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} -
hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cabDPF: {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA} -
hxxp://java.sun.com/update/1.5.0/jinsta ... s-i586.cabDPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} -
hxxp://java.sun.com/update/1.5.0/jinsta ... s-i586.cabDPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} -
hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cabDPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} -
hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cabDPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} -
hxxp://download.macromedia.com/pub/shoc ... wflash.cabDPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} -
hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cabNotify: NavLogon - c:\windows\system32\NavLogon.dll
Hosts: 127.0.0.1
www.spywareinfo.com============= SERVICES / DRIVERS ===============
R1 SAVRT;SAVRT;c:\program files\symantec antivirus\savrt.sys [2005-2-4 324232]
R1 SAVRTPEL;SAVRTPEL;c:\program files\symantec antivirus\Savrtpel.sys [2005-2-4 53896]
R2 AdeliaDaemon;Adelia - Middleware;c:\adeliws\adelrun\win32\mwdaemon.exe [2006-1-19 28737]
R2 ccEvtMgr;Symantec Event Manager;c:\program files\fichiers communs\symantec shared\ccEvtMgr.exe [2005-4-18 185968]
R2 ccSetMgr;Symantec Settings Manager;c:\program files\fichiers communs\symantec shared\ccSetMgr.exe [2005-4-18 161392]
R2 MLPTDR_N;MLPTDR_N;c:\windows\system32\MLPTDR_N.SYS [2005-9-23 18848]
R2 SavRoam;SAVRoam;c:\program files\symantec antivirus\SavRoam.exe [2005-5-9 127584]
R2 Symantec AntiVirus;Symantec AntiVirus;c:\program files\symantec antivirus\Rtvscan.exe [2005-5-9 1724512]
R2 xmu;Divalto XMU Version 5.4;c:\har\sys\xmu.exe [2006-4-26 356352]
R2 xservices;Divalto services Diva version 5;c:\har\sys\xservices.exe [2006-4-26 81920]
R3 NAVENG;NAVENG;c:\progra~1\fichie~1\symant~1\virusd~1\20100314.003\naveng.sys [2010-3-15 84912]
R3 NAVEX15;NAVEX15;c:\progra~1\fichie~1\symant~1\virusd~1\20100314.003\navex15.sys [2010-3-15 1324720]
S3 ccPwdSvc;Symantec Password Validation;c:\program files\fichiers communs\symantec shared\ccPwdSvc.exe [2005-4-18 83568]
=============== Created Last 30 ================
2010-03-10 13:59:34 0 ----a-w- c:\windows\vpc32.INI
2010-03-10 07:52:35 3558912 ------w- c:\windows\system32\dllcache\moviemk.exe
2010-03-08 08:42:53 2451 ----a-w- C:\UsbFix_Upload_Me_BARRAL-TRAITEUR.zip
2010-03-08 08:39:46 0 d-sha-r- C:\autorun.inf
2010-03-05 16:40:49 0 d-----w- C:\UsbFix
2010-03-05 15:37:18 0 d-----w- c:\program files\Navilog1
2010-03-05 08:36:57 0 d-----w- c:\docume~1\audrey~1.esn\applic~1\Malwarebytes
2010-03-05 08:36:50 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-05 08:36:48 0 d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2010-03-05 08:36:47 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-03-05 08:36:47 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-03-04 10:15:26 0 d-----w- c:\program files\Spybot - Search & Destroy
2010-03-04 10:15:26 0 d-----w- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
==================== Find3M ====================
2009-12-31 16:50:03 353792 ------w- c:\windows\system32\dllcache\srv.sys
2009-12-21 19:07:01 916480 ----a-w- c:\windows\system32\wininet.dll
2009-12-21 19:07:01 916480 ------w- c:\windows\system32\dllcache\wininet.dll
2009-12-21 19:07:01 12800 ------w- c:\windows\system32\dllcache\xpshims.dll
2009-12-21 19:07:01 1208832 ------w- c:\windows\system32\dllcache\urlmon.dll
2009-12-21 19:07:00 5942784 ------w- c:\windows\system32\dllcache\mshtml.dll
2009-12-21 19:07:00 206848 ------w- c:\windows\system32\dllcache\occache.dll
2009-12-21 19:06:58 594432 ------w- c:\windows\system32\dllcache\msfeeds.dll
2009-12-21 19:06:58 55296 ------w- c:\windows\system32\dllcache\msfeedsbs.dll
2009-12-21 19:06:58 25600 ------w- c:\windows\system32\dllcache\jsproxy.dll
2009-12-21 19:06:57 1985536 ------w- c:\windows\system32\dllcache\iertutil.dll
2009-12-21 19:06:56 246272 ------w- c:\windows\system32\dllcache\ieproxy.dll
2009-12-21 19:06:56 184320 ------w- c:\windows\system32\dllcache\iepeers.dll
2009-12-21 19:06:56 11070464 ------w- c:\windows\system32\dllcache\ieframe.dll
2009-12-21 19:06:52 387584 ------w- c:\windows\system32\dllcache\iedkcs32.dll
2009-12-21 13:20:15 173056 ------w- c:\windows\system32\dllcache\ie4uinit.exe
2009-12-17 07:41:32 347648 ----a-w- c:\windows\system32\mspaint.exe
2009-12-17 07:41:32 347648 ------w- c:\windows\system32\dllcache\mspaint.exe
============= FINISH: 14:57:29,75 ===============