Chargement en cours...
Connexion au forum informatique de Sur-la-Toile
La discussion « Bonjour je crois que je suis bien infécté ! help me ! » se trouve dans le forum « Virus, troyens, etc... »
Statut de la discussion » Bonjour je crois que je suis bien infécté ! help me ! « ( normale)

Bonjour je crois que je suis bien infécté ! help me !

Le 19-06-2007 à 20:30 #

Bonjour,

bon je vous raconte ce qui m'arrive ;)
je pense avoir pas mal de virus, trojan etc.
bon j'ai passé mcaffee, ad-aware, avg anti-spyware.

il y a 5 seconde j'ai arreté l'execution de mDNSResponder.exe qui etait dans C:\Program Files\Bonjour ( dossier & fichier non supprimer actuellement )

sinon voici le log, merci à vous ;
Code:
  1.   Logfile of HijackThis v1.99.1
  2.   Scan saved at 20:19:14, on 19/06/2007
  3.   Platform: Windows XP SP2 (WinNT 5.01.2600)
  4.   MSIE: Internet Explorer v7.00 (7.00.6000.16473)
  5.   
  6.   Running processes:
  7.   C:\WINDOWS\System32\smss.exe
  8.   C:\WINDOWS\system32\winlogon.exe
  9.   C:\WINDOWS\system32\services.exe
  10.   C:\WINDOWS\system32\lsass.exe
  11.   C:\WINDOWS\system32\svchost.exe
  12.   C:\WINDOWS\System32\svchost.exe
  13.   C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
  14.   C:\WINDOWS\Explorer.EXE
  15.   C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
  16.   C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
  17.   C:\WINDOWS\system32\spoolsv.exe
  18.   C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
  19.   C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
  20.   C:\Program Files\Fichiers communs\Creative Labs Shared\Service\CreativeLicensing.exe
  21.   C:\WINDOWS\system32\CTsvcCDA.exe
  22.   C:\Program Files\Dell Network Assistant\hnm_svc.exe
  23.   C:\Program Files\Fichiers communs\McAfee\HackerWatch\HWAPI.exe
  24.   C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
  25.   c:\program files\fichiers communs\mcafee\mna\mcnasvc.exe
  26.   C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
  27.   C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
  28.   c:\PROGRA~1\FICHIE~1\mcafee\mcproxy\mcproxy.exe
  29.   c:\PROGRA~1\FICHIE~1\mcafee\redirsvc\redirsvc.exe
  30.   C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
  31.   C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
  32.   C:\Program Files\McAfee\MPF\MPFSrv.exe
  33.   C:\PROGRA~1\McAfee\MPS\mps.exe
  34.   C:\Program Files\McAfee\MSK\MskSrver.exe
  35.   C:\WINDOWS\system32\nvsvc32.exe
  36.   C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
  37.   C:\Program Files\McAfee\MPS\mpsevh.exe
  38.   c:\PROGRA~1\mcafee.com\agent\mcagent.exe
  39.   C:\WINDOWS\system32\rundll32.exe
  40.   C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
  41.   C:\WINDOWS\stsystra.exe
  42.   C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
  43.   C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
  44.   C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
  45.   C:\WINDOWS\system32\Rundll32.exe
  46.   C:\Program Files\McAfee\MSK\MskAgent.exe
  47.   C:\WINDOWS\system32\dla\tfswctrl.exe
  48.   C:\DOCUME~1\Wu\LOCALS~1\Temp\clclean.0001
  49.   C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
  50.   C:\Program Files\Dell\MediaDirect\PCMService.exe
  51.   C:\Program Files\Corel\Corel Snapfire Plus\Corel Photo Downloader.exe
  52.   C:\WINDOWS\system32\kmw_run.exe
  53.   C:\Documents and Settings\All Users\Application Data\udinajkv.exe
  54.   C:\WINDOWS\system32\scchk32.exe
  55.   C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
  56.   C:\WINDOWS\system32\KMW_SHOW.EXE
  57.   C:\WINDOWS\system32\svchost.exe
  58.   C:\Program Files\Creative\MediaSource5\CTDetctu.exe
  59.   C:\PROGRA~1\Mozilla Firefox\firefox.exe
  60.   C:\WINDOWS\system32\ctfmon.exe
  61.   C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
  62.   C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
  63.   C:\WINDOWS\System32\svchost.exe
  64.   C:\Documents and Settings\Wu\Bureau\hijackthis_199\HijackThis.exe
  65.   
  66.   R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.fr/ig/dell?hl=fr&client=dell-row&channel=fr&ibd=0070525
  67.   R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://files.myopera.com/Rodrigoosilva/files/index.htm
  68.   R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
  69.   R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
  70.   R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
  71.   R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
  72.   R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.fr/ig/dell?hl=fr&client=dell-row&channel=fr&ibd=0070525
  73.   R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
  74.   R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
  75.   O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
  76.   O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
  77.   O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
  78.   O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptcl.dll
  79.   O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
  80.   O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
  81.   O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
  82.   O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
  83.   O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
  84.   O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
  85.   O4 - HKLM\..\Run: [NVHotkey] rundll32.exe nvHotkey.dll,Start
  86.   O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
  87.   O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
  88.   O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
  89.   O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
  90.   O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
  91.   O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe /r
  92.   O4 - HKLM\..\Run: [MBMon] Rundll32 CTMBHA.DLL,MBMon
  93.   O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
  94.   O4 - HKLM\..\Run: [VoiceCenter] "C:\Program Files\Creative\VoiceCenter\AndreaVC.exe" /tray
  95.   O4 - HKLM\..\Run: [MskAgentexe] C:\Program Files\McAfee\MSK\MskAgent.exe
  96.   O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
  97.   O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
  98.   O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
  99.   O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"
  100.   O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Snapfire Plus\Corel Photo Downloader.exe
  101.   O4 - HKLM\..\Run: [kmw_run.exe] kmw_run.exe
  102.   O4 - HKLM\..\Run: [udinajkv.exe] C:\Documents and Settings\All Users\Application Data\udinajkv.exe
  103.   O4 - HKLM\..\Run: [SC2] C:\WINDOWS\system32\scchk32.exe
  104.   O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
  105.   O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe
  106.   O4 - HKCU\..\Run: [SetDefaultMIDI] MIDIDef.exe
  107.   O4 - HKCU\..\Run: [Creative Detector U] "C:\Program Files\Creative\MediaSource5\CTDetctu.exe" /R
  108.   O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
  109.   O4 - Global Startup: BTTray.lnk = ?
  110.   O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
  111.   O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
  112.   O8 - Extra context menu item: Envoyer au périphérique &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
  113.   O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
  114.   O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
  115.   O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
  116.   O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
  117.   O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
  118.   O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
  119.   O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
  120.   O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
  121.   O11 - Options group: [INTERNATIONAL] International*
  122.   O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2005111401/housecall.trendmicro.com/housecall/xscan53.cab
  123.   O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
  124.   O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Fichiers communs\Microsoft Shared\Help\hxds.dll
  125.   O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
  126.   O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\FICHIE~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
  127.   O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
  128.   O20 - Winlogon Notify: winhdn32 - winhdn32.dll (file missing)
  129.   O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
  130.   O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
  131.   O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
  132.   O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
  133.   O23 - Service: Creative Labs Licensing Service - Creative Labs - C:\Program Files\Fichiers communs\Creative Labs Shared\Service\CreativeLicensing.exe
  134.   O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
  135.   O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\FICHIE~1\McAfee\EmProxy\emproxy.exe
  136.   O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
  137.   O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
  138.   O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
  139.   O23 - Service: Advanced Networking Service (hnmsvc) - SingleClick Systems - C:\Program Files\Dell Network Assistant\hnm_svc.exe
  140.   O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Fichiers communs\McAfee\HackerWatch\HWAPI.exe
  141.   O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
  142.   O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
  143.   O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\fichiers communs\mcafee\mna\mcnasvc.exe
  144.   O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
  145.   O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
  146.   O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\FICHIE~1\mcafee\mcproxy\mcproxy.exe
  147.   O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\FICHIE~1\mcafee\redirsvc\redirsvc.exe
  148.   O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
  149.   O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
  150.   O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
  151.   O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
  152.   O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
  153.   O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
  154.   O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
  155.   O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
  156.   O23 - Service: wampapache - Unknown owner - C:\Program Files\server\wamp\apache2\bin\httpd.exe" -k runservice (file missing)
  157.   O23 - Service: wampmysqld - Unknown owner - C:\Program Files\server\wamp\mysql\bin\mysqld-nt.exe" "--defaults-file=C:\Program Files\server\wamp\mysql\my.ini" wampmysqld (file missing)
  158.   O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel(R) Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe




    Ajout du 19-06-2007 à 20:34:

    je me suis fais aussi avoir par l'ultimate fixer, ouui j'ai cliquer et lancer le logiciel, mais j'ai arreté au milieux quand meme . (l'onglet en bas, proposant de l'installer est toujour present ).

    j'ai xp si ca peut aidé ;)

    merci encore de m'aider :P plz, je vous en conjure aidé moi. merci

    Le 19-06-2007 à 20:46 #

    salut,


    il n'est pas mauvais à part des entrées inconnu, prends ton log et fais un copier coller sur le lien suivant et tu verras Lien @+

    Le 19-06-2007 à 21:03 #

    salut,
    télécharge SmitfraudFix
    SmitfraudFix.zip
    deconnectes toi du net
    dezip le dossier (extraire tout)
    Ouvre le dossier SmitfraudFix double clic sur SmitfraudFix.cmd
    valide l'option 1
    Copie/colle le contenu du rapport ici

    a+

    Le 19-06-2007 à 21:17 #

    merci à vous :

    fred :

    Code:
    1.   SmitFraudFix v2.195
    2.   
    3.   Rapport fait à 21:16:18,84, 19/06/2007
    4.   Executé à partir de C:\Documents and Settings\Wu\Bureau\SmitfraudFix\SmitfraudFix
    5.   OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
    6.   Le type du système de fichiers est NTFS
    7.   Fix executé en mode normal
    8.   
    9.   »»»»»»»»»»»»»»»»»»»»»»»» Process
    10.   
    11.   C:\WINDOWS\System32\smss.exe
    12.   C:\WINDOWS\system32\winlogon.exe
    13.   C:\WINDOWS\system32\services.exe
    14.   C:\WINDOWS\system32\lsass.exe
    15.   C:\WINDOWS\system32\svchost.exe
    16.   C:\WINDOWS\System32\svchost.exe
    17.   C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    18.   C:\WINDOWS\Explorer.EXE
    19.   C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    20.   C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
    21.   C:\WINDOWS\system32\spoolsv.exe
    22.   C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    23.   C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
    24.   C:\Program Files\Fichiers communs\Creative Labs Shared\Service\CreativeLicensing.exe
    25.   C:\WINDOWS\system32\CTsvcCDA.exe
    26.   C:\Program Files\Dell Network Assistant\hnm_svc.exe
    27.   C:\Program Files\Fichiers communs\McAfee\HackerWatch\HWAPI.exe
    28.   C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
    29.   c:\program files\fichiers communs\mcafee\mna\mcnasvc.exe
    30.   C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
    31.   C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
    32.   c:\PROGRA~1\FICHIE~1\mcafee\mcproxy\mcproxy.exe
    33.   c:\PROGRA~1\FICHIE~1\mcafee\redirsvc\redirsvc.exe
    34.   C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
    35.   C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
    36.   C:\Program Files\McAfee\MPF\MPFSrv.exe
    37.   C:\PROGRA~1\McAfee\MPS\mps.exe
    38.   C:\Program Files\McAfee\MSK\MskSrver.exe
    39.   C:\WINDOWS\system32\nvsvc32.exe
    40.   C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    41.   C:\Program Files\McAfee\MPS\mpsevh.exe
    42.   c:\PROGRA~1\mcafee.com\agent\mcagent.exe
    43.   C:\WINDOWS\system32\rundll32.exe
    44.   C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
    45.   C:\WINDOWS\stsystra.exe
    46.   C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    47.   C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
    48.   C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
    49.   C:\WINDOWS\system32\Rundll32.exe
    50.   C:\Program Files\McAfee\MSK\MskAgent.exe
    51.   C:\WINDOWS\system32\dla\tfswctrl.exe
    52.   C:\DOCUME~1\Wu\LOCALS~1\Temp\clclean.0001
    53.   C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
    54.   C:\Program Files\Dell\MediaDirect\PCMService.exe
    55.   C:\Program Files\Corel\Corel Snapfire Plus\Corel Photo Downloader.exe
    56.   C:\WINDOWS\system32\kmw_run.exe
    57.   C:\Documents and Settings\All Users\Application Data\udinajkv.exe
    58.   C:\WINDOWS\system32\scchk32.exe
    59.   C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
    60.   C:\WINDOWS\system32\KMW_SHOW.EXE
    61.   C:\WINDOWS\system32\svchost.exe
    62.   C:\Program Files\Creative\MediaSource5\CTDetctu.exe
    63.   C:\PROGRA~1\Mozilla Firefox\firefox.exe
    64.   C:\WINDOWS\system32\ctfmon.exe
    65.   C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
    66.   C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
    67.   C:\WINDOWS\System32\svchost.exe
    68.   C:\Program Files\MSN Messenger\msnmsgr.exe
    69.   C:\Program Files\MSN Messenger\usnsvc.exe
    70.   C:\Program Files\mIRC\mirc.exe
    71.   C:\Program Files-ZipzFM.exe
    72.   c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe
    73.   C:\WINDOWS\system32\cmd.exe
    74.   
    75.   »»»»»»»»»»»»»»»»»»»»»»»» hosts
    76.   
    77.   
    78.   »»»»»»»»»»»»»»»»»»»»»»»» C:\
    79.   
    80.   
    81.   »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS
    82.   
    83.   
    84.   »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system
    85.   
    86.   
    87.   »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web
    88.   
    89.   
    90.   »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32
    91.   
    92.   
    93.   »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles
    94.   
    95.   
    96.   »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Wu
    97.   
    98.   
    99.   »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Wu\Application Data
    100.   
    101.   
    102.   »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer
    103.   
    104.   
    105.   »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Wu\Favoris
    106.   
    107.   
    108.   »»»»»»»»»»»»»»»»»»»»»»»» Bureau
    109.   
    110.   
    111.   »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files
    112.   
    113.   
    114.   »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues
    115.   
    116.   
    117.   »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau
    118.   
    119.   [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components[code]
      SmitFraudFix v2.195

      Rapport fait à 21:16:18,84, 19/06/2007
      Executé à partir de C:\Documents and Settings\Wu\Bureau\SmitfraudFix\SmitfraudFix
      OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
      Le type du système de fichiers est NTFS
      Fix executé en mode normal

      »»»»»»»»»»»»»»»»»»»»»»»» Process

      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
      C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
      C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
      C:\Program Files\Fichiers communs\Creative Labs Shared\Service\CreativeLicensing.exe
      C:\WINDOWS\system32\CTsvcCDA.exe
      C:\Program Files\Dell Network Assistant\hnm_svc.exe
      C:\Program Files\Fichiers communs\McAfee\HackerWatch\HWAPI.exe
      C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
      c:\program files\fichiers communs\mcafee\mna\mcnasvc.exe
      C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
      C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
      c:\PROGRA~1\FICHIE~1\mcafee\mcproxy\mcproxy.exe
      c:\PROGRA~1\FICHIE~1\mcafee\redirsvc\redirsvc.exe
      C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
      C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
      C:\Program Files\McAfee\MPF\MPFSrv.exe
      C:\PROGRA~1\McAfee\MPS\mps.exe
      C:\Program Files\McAfee\MSK\MskSrver.exe
      C:\WINDOWS\system32\nvsvc32.exe
      C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
      C:\Program Files\McAfee\MPS\mpsevh.exe
      c:\PROGRA~1\mcafee.com\agent\mcagent.exe
      C:\WINDOWS\system32\rundll32.exe
      C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
      C:\WINDOWS\stsystra.exe
      C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
      C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
      C:\WINDOWS\system32\Rundll32.exe
      C:\Program Files\McAfee\MSK\MskAgent.exe
      C:\WINDOWS\system32\dla\tfswctrl.exe
      C:\DOCUME~1\Wu\LOCALS~1\Temp\clclean.0001
      C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
      C:\Program Files\Dell\MediaDirect\PCMService.exe
      C:\Program Files\Corel\Corel Snapfire Plus\Corel Photo Downloader.exe
      C:\WINDOWS\system32\kmw_run.exe
      C:\Documents and Settings\All Users\Application Data\udinajkv.exe
      C:\WINDOWS\system32\scchk32.exe
      C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
      C:\WINDOWS\system32\KMW_SHOW.EXE
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Creative\MediaSource5\CTDetctu.exe
      C:\PROGRA~1\Mozilla Firefox\firefox.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
      C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\MSN Messenger\msnmsgr.exe
      C:\Program Files\MSN Messenger\usnsvc.exe
      C:\Program Files\mIRC\mirc.exe
      C:\Program Files\7-Zip\7zFM.exe
      c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe
      C:\WINDOWS\system32\cmd.exe

      »»»»»»»»»»»»»»»»»»»»»»»» hosts


      »»»»»»»»»»»»»»»»»»»»»»»» C:\


      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS


      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system


      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web


      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32


      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles


      »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Wu


      »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Wu\Application Data


      »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer


      »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Wu\Favoris


      »»»»»»»»»»»»»»»»»»»»»»»» Bureau


      »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files


      »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues


      »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

      [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
      "Source"="About:Home"
      "SubscribedURL"="About:Home"
      "FriendlyName"="Ma page d'accueil"


      »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      SrchSTS.exe by S!Ri
      Search SharedTaskScheduler's .dll


      »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
      "AppInit_DLLs"=""


      »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
      "System"=""


      »»»»»»»»»»»»»»»»»»»»»»»» Rustock



      »»»»»»»»»»»»»»»»»»»»»»»» DNS

      Description: Intel(R) PRO/Wireless 3945ABG Network Connection - Miniport d'ordonnancement de paquets
      DNS Server Search Order: 192.168.1.1

      HKLM\SYSTEM\CCS\Services\Tcpip\..\{E3BBE7A0-790C-4B8F-9018-55E7B1A46372}: DhcpNameServer=192.168.1.1
      HKLM\SYSTEM\CS1\Services\Tcpip\..\{E3BBE7A0-790C-4B8F-9018-55E7B1A46372}: DhcpNameServer=192.168.1.1
      HKLM\SYSTEM\CS3\Services\Tcpip\..\{E3BBE7A0-790C-4B8F-9018-55E7B1A46372}: DhcpNameServer=192.168.1.1
      HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
      HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
      HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1


      »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll


      »»»»»»»»»»»»»»»»»»»»»»»» Fin


      [/code]]
    120.   "Source"="About:Home"
    121.   "SubscribedURL"="About:Home"
    122.   "FriendlyName"="Ma page d'accueil"
    123.   
    124.   
    125.   »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
    126.   !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
    127.   
    128.   SrchSTS.exe by S!Ri
    129.   Search SharedTaskScheduler's .dll
    130.   
    131.   
    132.   »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
    133.   !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
    134.   
    135.   [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
    136.   "AppInit_DLLs"=""
    137.   
    138.   
    139.   »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
    140.   !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
    141.   
    142.   [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
    143.   "System"=""
    144.   
    145.   
    146.   »»»»»»»»»»»»»»»»»»»»»»»» Rustock
    147.   
    148.   
    149.   
    150.   »»»»»»»»»»»»»»»»»»»»»»»» DNS
    151.   
    152.   Description: Intel(R) PRO/Wireless 3945ABG Network Connection - Miniport d'ordonnancement de paquets
    153.   DNS Server Search Order: 192.168.1.1
    154.   
    155.   HKLM\SYSTEM\CCS\Services\Tcpip\..\{E3BBE7A0-790C-4B8F-9018-55E7B1A46372}: DhcpNameServer=192.168.1.1
    156.   HKLM\SYSTEM\CS1\Services\Tcpip\..\{E3BBE7A0-790C-4B8F-9018-55E7B1A46372}: DhcpNameServer=192.168.1.1
    157.   HKLM\SYSTEM\CS3\Services\Tcpip\..\{E3BBE7A0-790C-4B8F-9018-55E7B1A46372}: DhcpNameServer=192.168.1.1
    158.   HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
    159.   HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
    160.   HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
    161.   
    162.   
    163.   »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll
    164.   
    165.   
    166.   »»»»»»»»»»»»»»»»»»»»»»»» Fin

      Le 20-06-2007 à 10:01 #

      relancer hijack

      cocher ces ligns et clic ensuite sur fix checked

      O4 - HKLM\..\Run: [udinajkv.exe] C:\Documents and Settings\All Users\Application Data\udinajkv.exe
      O4 - HKLM\..\Run: [SC2] C:\WINDOWS\system32\scchk32.exe
      O20 - Winlogon Notify: winhdn32 - winhdn32.dll (file missing)
      -----------
      Télécharger sur le bureau

      OTMoveIt.exe
      = Copier ce texte en gras
      C:\Documents and Settings\All Users\Application Data\udinajkv.exe
      C:\WINDOWS\system32\scchk32.exe

      = Double-clic sur OTMoveIt.exe
      = Dans le cadre de Gauche ==> clic-droit ==> coller
      = Clic MoveIt!
      = si redémarrage demandé==> Clic : YES
      = Un rapport dans ==> C:\_OTMoveIt\MovedFiles\date du jour à copier/coller dans la réponse

      Le 20-06-2007 à 12:33 #

      voila le rapport :
      Code:
      1.   C:\Documents and Settings\All Users\Application Data\udinajkv.exe moved successfully.
      2.   C:\WINDOWS\system32\scchk32.exe moved successfully.
      3.   
      4.   Created on 06/20/2007 12:30:49


        sinon le rapport de HijackThis.exe apres les consignes éffectué :
        Code:
        1.   Logfile of HijackThis v1.99.1
        2.   Scan saved at 12:33:04, on 20/06/2007
        3.   Platform: Windows XP SP2 (WinNT 5.01.2600)
        4.   MSIE: Internet Explorer v7.00 (7.00.6000.16473)
        5.   
        6.   Running processes:
        7.   C:\WINDOWS\System32\smss.exe
        8.   C:\WINDOWS\system32\winlogon.exe
        9.   C:\WINDOWS\system32\services.exe
        10.   C:\WINDOWS\system32\lsass.exe
        11.   C:\WINDOWS\system32\svchost.exe
        12.   C:\WINDOWS\System32\svchost.exe
        13.   C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
        14.   C:\WINDOWS\Explorer.EXE
        15.   C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
        16.   C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
        17.   C:\WINDOWS\system32\spoolsv.exe
        18.   C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
        19.   C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
        20.   C:\Program Files\Fichiers communs\Creative Labs Shared\Service\CreativeLicensing.exe
        21.   C:\WINDOWS\system32\CTsvcCDA.exe
        22.   C:\Program Files\Dell Network Assistant\hnm_svc.exe
        23.   C:\Program Files\Fichiers communs\McAfee\HackerWatch\HWAPI.exe
        24.   C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
        25.   c:\program files\fichiers communs\mcafee\mna\mcnasvc.exe
        26.   C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
        27.   C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
        28.   c:\PROGRA~1\FICHIE~1\mcafee\mcproxy\mcproxy.exe
        29.   c:\PROGRA~1\FICHIE~1\mcafee\redirsvc\redirsvc.exe
        30.   C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
        31.   C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
        32.   C:\Program Files\McAfee\MPF\MPFSrv.exe
        33.   C:\PROGRA~1\McAfee\MPS\mps.exe
        34.   C:\Program Files\McAfee\MSK\MskSrver.exe
        35.   C:\WINDOWS\system32\nvsvc32.exe
        36.   C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
        37.   C:\Program Files\McAfee\MPS\mpsevh.exe
        38.   c:\PROGRA~1\mcafee.com\agent\mcagent.exe
        39.   C:\WINDOWS\system32\rundll32.exe
        40.   C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
        41.   C:\WINDOWS\stsystra.exe
        42.   C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
        43.   C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
        44.   C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
        45.   C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe
        46.   C:\WINDOWS\system32\Rundll32.exe
        47.   C:\Program Files\McAfee\MSK\MskAgent.exe
        48.   C:\WINDOWS\system32\dla\tfswctrl.exe
        49.   C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
        50.   C:\Program Files\Dell\MediaDirect\PCMService.exe
        51.   C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
        52.   C:\Program Files\Corel\Corel Snapfire Plus\Corel Photo Downloader.exe
        53.   C:\DOCUME~1\Wu\LOCALS~1\Temp\clclean.0001
        54.   C:\WINDOWS\system32\kmw_run.exe
        55.   C:\WINDOWS\system32\svchost.exe
        56.   C:\WINDOWS\system32\KMW_SHOW.EXE
        57.   C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
        58.   C:\Program Files\Creative\MediaSource5\CTDetctu.exe
        59.   C:\WINDOWS\System32\svchost.exe
        60.   C:\WINDOWS\system32\ctfmon.exe
        61.   C:\Program Files\Messenger\msmsgs.exe
        62.   C:\Program Files\MSN Messenger\msnmsgr.exe
        63.   C:\Program Files\Mozilla Thunderbird\thunderbird.exe
        64.   C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
        65.   C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
        66.   C:\Program Files\MSN Messenger\usnsvc.exe
        67.   C:\PROGRA~1\Mozilla Firefox\firefox.exe
        68.   C:\Documents and Settings\Wu\Bureau\hijackthis_199\HijackThis.exe
        69.   
        70.   R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.fr/ig/dell?hl=fr&client=dell-row&channel=fr&ibd=0070525
        71.   R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://files.myopera.com/Rodrigoosilva/files/index.htm
        72.   R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
        73.   R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
        74.   R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
        75.   R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
        76.   R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.fr/ig/dell?hl=fr&client=dell-row&channel=fr&ibd=0070525
        77.   R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
        78.   R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
        79.   O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
        80.   O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
        81.   O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
        82.   O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptcl.dll
        83.   O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
        84.   O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
        85.   O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
        86.   O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
        87.   O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
        88.   O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
        89.   O4 - HKLM\..\Run: [NVHotkey] rundll32.exe nvHotkey.dll,Start
        90.   O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
        91.   O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
        92.   O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
        93.   O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
        94.   O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
        95.   O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe /r
        96.   O4 - HKLM\..\Run: [MBMon] Rundll32 CTMBHA.DLL,MBMon
        97.   O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
        98.   O4 - HKLM\..\Run: [VoiceCenter] "C:\Program Files\Creative\VoiceCenter\AndreaVC.exe" /tray
        99.   O4 - HKLM\..\Run: [MskAgentexe] C:\Program Files\McAfee\MSK\MskAgent.exe
        100.   O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
        101.   O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
        102.   O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
        103.   O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"
        104.   O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Snapfire Plus\Corel Photo Downloader.exe
        105.   O4 - HKLM\..\Run: [kmw_run.exe] kmw_run.exe
        106.   O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
        107.   O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe
        108.   O4 - HKCU\..\Run: [SetDefaultMIDI] MIDIDef.exe
        109.   O4 - HKCU\..\Run: [Creative Detector U] "C:\Program Files\Creative\MediaSource5\CTDetctu.exe" /R
        110.   O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
        111.   O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
        112.   O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
        113.   O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Fichiers communs\Adobe\Updater5\AdobeUpdater.exe
        114.   O4 - Global Startup: BTTray.lnk = ?
        115.   O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
        116.   O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
        117.   O8 - Extra context menu item: Envoyer au périphérique &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
        118.   O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
        119.   O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
        120.   O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
        121.   O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
        122.   O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
        123.   O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        124.   O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        125.   O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
        126.   O11 - Options group: [INTERNATIONAL] International*
        127.   O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2005111401/housecall.trendmicro.com/housecall/xscan53.cab
        128.   O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
        129.   O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Fichiers communs\Microsoft Shared\Help\hxds.dll
        130.   O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
        131.   O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\FICHIE~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
        132.   O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
        133.   O20 - Winlogon Notify: winhdn32 - winhdn32.dll (file missing)
        134.   O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
        135.   O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
        136.   O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Unknown owner - C:\Program Files\Bonjour\mDNSResponder.exe (file missing)
        137.   O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
        138.   O23 - Service: Creative Labs Licensing Service - Creative Labs - C:\Program Files\Fichiers communs\Creative Labs Shared\Service\CreativeLicensing.exe
        139.   O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
        140.   O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\FICHIE~1\McAfee\EmProxy\emproxy.exe
        141.   O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
        142.   O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
        143.   O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        144.   O23 - Service: Advanced Networking Service (hnmsvc) - SingleClick Systems - C:\Program Files\Dell Network Assistant\hnm_svc.exe
        145.   O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Fichiers communs\McAfee\HackerWatch\HWAPI.exe
        146.   O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
        147.   O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
        148.   O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\fichiers communs\mcafee\mna\mcnasvc.exe
        149.   O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
        150.   O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
        151.   O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\FICHIE~1\mcafee\mcproxy\mcproxy.exe
        152.   O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\FICHIE~1\mcafee\redirsvc\redirsvc.exe
        153.   O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
        154.   O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
        155.   O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
        156.   O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
        157.   O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
        158.   O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
        159.   O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
        160.   O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
        161.   O23 - Service: wampapache - Unknown owner - C:\Program Files\server\wamp\apache2\bin\httpd.exe" -k runservice (file missing)
        162.   O23 - Service: wampmysqld - Unknown owner - C:\Program Files\server\wamp\mysql\bin\mysqld-nt.exe" "--defaults-file=C:\Program Files\server\wamp\mysql\my.ini" wampmysqld (file missing)
        163.   O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel(R) Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe




          Ajout du 20-06-2007 à 12:35:

          merci beaucoup sinon ;)

          Le 20-06-2007 à 13:43 #

          supprime Smitfraudfix ( tu n'avais pas d'infection smitfraud ) et son rapport

          -------
          pour C:\Program Files\Bonjour si tu as un Itune , c'est ok
          bien que tu puisses arrêter ce service.

          » Liste des Forums » Virus, troyens, etc...

          Sujets Connexes

          Arakien & WéWé


          Forums

          Navigation


          Publicité

          Connectés

          Il y a actuellement 449 visiteurs et 18 toiliens en ligne, ainsi que 13 connectés sur le tchat.

          Recherche

          Annonces


          Sauf mention contraire, le contenu du blog et du forum est sous licence Creative Commons By-Sa. Vous avez le droit de le reproduire à condition de citer l'auteur, de faire un lien vers la page d'origine, et de partager vos travaux dérivés selon les mêmes conditions.

          Conditions d'utilisation -

          Partenaires: [Informatique Multimédia] [Portail du Maroc] [Actualité High Tech]
          [Tutoriaux Photoshop] [éligibilité ADSL] [Astuces Windows]

          Page générée en 213 millisecondes sur WWW1.