Bonjour
provenant de virus MSN J'Ai Qui Envoie à mes contacts Liens pour voir des photos des, en plus ça genere UNE Fenêtre lieu au http://gllod.com de Google!
J'Ai Télécharge hitjackthis et VOICI le rapport:
Logfile de Trend Micro HijackThis v2.0.2
Scan saved at 11:01:51, le 03/04/2010
Plate-forme: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
processus en cours:
C: \ windows \ System32 \ smss.exe
C: \ windows \ system32 \ winlogon.exe
C: \ windows \ system32 \ services.exe
C: \ windows \ system32 \ lsass.exe
C: \ windows \ system32 \ Ati2evxx.exe
C: \ windows \ system32 \ svchost.exe
C: \ windows \ System32 \ svchost.exe
C: \ windows \ system32 \ spoolsv.exe
C: \ Program Files \ Avira \ AntiVir Desktop \ sched.exe
C: \ Program Files \ Avira \ AntiVir Desktop \ avguard.exe
C: \ Program Files \ Java \ jre6 \ bin \ jqs.exe
C: \ windows \ system32 \ svchost.exe
C: \ windows \ system32 \ Ati2evxx.exe
C: \ windows \ explorer.exe
C: \ WINDOWS \ System32 \ spool \ drivers \ w32x86 \ 3 \ E_FATIADE.EXE
C: \ windows \ system32 \ rundll32.exe
C: \ Program Files \ AMT Media Manager \ AMTDeviceService.exe
C: \ Program Files \ Avira \ AntiVir Desktop \ avgnt.exe
C: \ Program Files \ Fichiers Communs \ Java \ Java Update \ jusched.exe
C: \ windows \ RTHDCPL.EXE
C: \ Program Files \ ATI Technologies \ ATI.ACE \ MOM.exe \ Core-Static
C: \ Program Files \ Messenger \ msmsgs.exe
C: \ windows \ system32 \ ctfmon.exe
C: \ Program Files \ Windows Live \ Messenger \ msnmsgr.exe
C: \ Program Files \ ATI Technologies \ ATI.ACE \ Core-Static \ ccc.exe
C: \ Program Files \ Windows Live Contacts \ \ wlcomm.exe
C: \ Program Files \ Internet Explorer iexplore.exe \
C: \ Program Files \ Internet Explorer iexplore.exe \
C: \ Program Files \ Fichiers Communs \ Java \ Java Update \ jucheck.exe
C: \ Program Files \ Trend Micro \ HijackThis \ HijackThis.exe
R0 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main, Start Page = http://www.google.fr/
R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - Software \ HKCU \ Toolbar \ Microsoft \ Internet Explorer, LinksFolderName = Liens
URLSearchHook R3 -: myBabylon anglais Toolbar - (b2e293ee-fd7e-4c71-A714-5f4750d8d7b7) - C: \ Program Files \ tbmyBa.dll \ myBabylon_English
O2 - BHO: AcroIEHelperStub - (18DF081C-E8AD-4283-A596-FA578C2EBDC3) - C: \ Program Files \ Fichiers Communs \ Adobe \ Acrobat \ ActiveX \ AcroIEHelperShim.dll
O2 - BHO: (no name) - (5C255C8A-E604-49b4-9D64-90988571CECB) - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - (9030D464-4C02-4ABF-8ECC-5164760863C6) - C: \ Program Files \ Fichiers Communs \ Microsoft Shared \ Windows Live \ WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - (AA58ED58-01DD-4d91-8333-CF10577473F7) - C: \ Program Files \ Google \ Google Toolbar \ GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - (AF69DE43-7D58-4638-B6FA-CE66B5AD205D) - C: \ Program Files \ Google \ GoogleToolbarNotifier \ 5.5.4723.1820 \ swg.dll
BHO O2 -: myBabylon anglais Toolbar - (b2e293ee-fd7e-4c71-A714-5f4750d8d7b7) - C: \ Program Files \ tbmyBa.dll \ myBabylon_English
O2 - BHO: Java (TM) Plug-In 2 SSV Helper - (DBC80044-A445-435B-BC74-9C25C1C588A9) - C: \ Program Files \ Java \ jre6 \ bin \ jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - (E7E6F031-17CE-4C07-BC86-EABFE594F69C) - C: \ Program Files \ Java \ jre6 \ lib \ deploy \ JQS \ ie \ jqs_plugin.dll
O3 - Toolbar: barre d'outils Google - (2318C2B1-4965-11D4-9B18-009027A5CD4F) - C: \ Program Files \ Google \ Google Toolbar \ GoogleToolbar_32.dll
O3 - Toolbar: barre d'outils myBabylon anglais - (b2e293ee-fd7e-4c71-A714-5f4750d8d7b7) - C: \ Program Files \ tbmyBa.dll \ myBabylon_English
O4 - HKLM \ .. \ Run: [Google Quick Search Box] "C: \ Program Files \ Google \ Quick Search Box \ GoogleQuickSearchBox.exe" / autorun
O4 - HKLM \ .. \ Run: [EPSON Stylus DX4800 Series] C: \ WINDOWS \ System32 \ spool \ drivers \ w32x86 \ 3 \ E_FATIADE.EXE / P26 "EPSON Stylus DX4800 Series" / O6 "USB001" / M "Stylus DX4800 "
O4 - HKLM \ .. \ Run: [NeroCheck] C: \ WINDOWS \ system32 \ NeroCheck.exe
O4 - HKLM \ .. \ Run: [BluetoothAuthenticationAgent] bthprops.cpl rundll32.exe, BluetoothAuthenticationAgent
O4 - HKLM \ .. \ Run:] AMTDeviceService ["C: \ Program Files \ AMT Media Manager \ AMTDeviceService.exe"
O4 - HKLM \ .. \ Run:] avgnt ["C: \ Program Files \ Avira \ AntiVir Desktop \ avgnt.exe" / min
O4 - HKLM \ .. \ Run: [Adobe] Lanceur de vitesse "C: \ Program Files \ Adobe \ Reader 9.0 \ Reader Reader_sl.exe \"
O4 - HKLM \ .. \ Run: [Adobe ARM] "C: \ Program Files \ Fichiers Communs \ Adobe \ ARM \ 1.0 \ AdobeARM.exe"
O4 - HKLM \ .. \ Run: [SunJavaUpdateSched] "C: \ Program Files \ Fichiers Communs \ Java \ Java Update \ jusched.exe"
O4 - HKLM \ .. \ Run: [] StartCCC "C: \ Program Files \ ATI Technologies \ ATI.ACE \ CLIStart.exe Core-Static \" MSRun
O4 - HKLM \ .. \ Run: [RTHDCPL.EXE] RTHDCPL
O4 - HKLM \ .. \ Run: [ALCMTR.EXE] Alcmtr
O4 - HKLM \ .. \ Run: [Firewall Administration] C: \ windows \ infocard.exe
O4 - HKCU \ .. \ Run: [msmsgs] "C: \ Program Files \ msmsgs.exe \ Messenger" / background
O4 - HKCU \ .. \ Run: [ctfmon.exe] C: \ windows \ system32 \ ctfmon.exe
O4 - HKCU \ .. \ Run: [Firewall Administration] C: \ windows \ infocard.exe
O4 - HKCU \ .. \ Run: [mise à jour Shockwave] C: \ WINDOWS \ system32 \ Adobe \ Shockwave 11 \ SwHelper_1150596.exe-Mise à jour -1150596 - "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0 ; GTB6;. NET CLR 1.1.4322;. NET CLR 2.0.50727; InfoPath.2;. NET CLR 3.0.4506.2152;. NET CLR 3.5.30729) "-" http://www.blogg.org/blog- 78820-themes-shemale_gros_seins-238463.html "
O4 - HKUS \ S-1-5-18 \ .. \ Run: [CTFMON.EXE] C: \ WINDOWS \ system32 \ CTFMON.EXE (User 'SYSTEM')
O4 - HKUS \. DEFAULT \ .. \ Run: [CTFMON.EXE] C: \ WINDOWS \ system32 \ CTFMON.EXE (User 'utilisateur par défaut ")
O4 - Global Startup: Windows Live Messenger. Lnk = C: \ Program Files \ Windows Live \ Messenger \ msnmsgr.exe
O8 - Extra context menu item: E & Xporter vers Microsoft Excel - res: / / C: \ PROGRA ~ 1 \ MICROS ~ 2 \ Office12 \ EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki ... - Res: / / C: \ Program Files \ Google \ Google Toolbar \ GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html \ Component
O9 - Extra button: (no name) - (85d1f590-48f4-11d9-9669-0800200c9a66) - C: \ windows \ bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - (85d1f590-48f4-11d9-9669-0800200c9a66) - C: \ windows \ bdoscandel.exe
O9 - Extra button: Recherche - (92780B25-18CC-41C8-B9BE-3C9C571A8263) - C: \ PROGRA ~ 1 \ MICROS ~ 2 \ Office12 \ REFIEBAR.DLL
O9 - Extra button: (no name) - (e2e2dd38-d088-4134-82b7-f2ba38496583) - C: \ windows \ Network Diagnostic \ xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @ xpsp3res.dll, -20001 - (e2e2dd38-d088-4134-82b7-f2ba38496583) - C: \ windows \ Network Diagnostic \ xpnetdiag.exe
O9 - Extra button: Messenger - (FB5F1910-F110-11D2-BB9E-00C04F795683) - C: \ Program Files \ Messenger \ msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - (FB5F1910-F110-11D2-BB9E-00C04F795683) - C: \ Program Files \ Messenger \ msmsgs.exe
O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
O16 - DPF: (215B8138-A3CF-44C5-803f-8226143CFC0A) (Trend Micro ActiveX Scan Agent 6.6) - http://ushousecall02.trendmicro.com/... cabine
O16 - DPF: (2EDF75C0-5ABD-49f9-BAB6-220476A32034) (System Requirements Lab) - http://intel-drv-cdn.systemrequirementslab.com/multi/bin/sysreqlab_srlx.cab
O16 - DPF: (5D86DDB5-BDF9-441B-9E9E-D4730F4EE499) (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O16 - DPF: (5ED80217-570B-BF44-4DA9-BE107C0EC166) (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase8942.cab
O16 - DPF: (6E32070A-766D-879C-4EE6-DC1FA91D2FC3) (MUWebControl classe) - http://update.microsoft.com/...
O16 - DPF: (6F15128C-E66A-490C-B848-5000B5ABEEAC) (HP Download Manager) - https: / / h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: (7530BFB8-7293-4D34-9923-61A11451AFC5) - http://download.eset.com/special/eos/OnlineScanner.cab
O16 - DPF: (867E13F2-7F31-44FB-AC97-CD38E0DC46EF) (contrôle de Ma-Config) - http://www.ma-config.com/plugins/MaConfig_4_0_1_3.cab
O16 - DPF: (E2883E8F-472f-9522-4FB0-AC9BF37916A7) (get_atlcom classe) - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C: \ Program Files \ Avira \ AntiVir Desktop \ sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C: \ Program Files \ Avira \ AntiVir Desktop \ avguard.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc - C: \ windows \ system32 \ Ati2evxx.exe
O23 - Service: ATI Smart - Unknown propriétaire - C: \ WINDOWS \ system32 \ ati2sgag.exe
O23 - Service: Service de mise à jour Google (gupdate) (gupdate) - Google Inc - C: \ Program Files \ Google \ Update \ GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C: \ Program Files \ Google \ Common \ Google Updater \ GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc - C: \ Program Files \ Java \ jre6 \ bin \ jqs.exe
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C: \ Program Files \ maconfservice.exe \ ma-config.com
-
End of file - 9182 bytes
Merci de m'aider svp Pour la suite sur J'Ai vu post Autre ONU télécharger Fallait qu'il OTM et MBAM CE Que J'Ai FAIT MAIS je ne sais s'ils SONT DANS Pas conseillés lun. CAS J'attends Votre aide
<Config> Windows XP / Internet Explorer 8.0 </ config>

User : Propriétaire (Administrateurs) # CLARISSE-D6457C
Update on 18/03/2010 by El Desaparecido , C_XX & Chimay8
Start at: 12:28:35 | 03/04/2010
Website : http://pagesperso-orange.fr/NosTools/index.html
Contact : FindyKill.Contact@gmail.com
Intel(R) Pentium(R) 4 CPU 2.93GHz
Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
Internet Explorer 8.0.6001.18702
Windows Firewall Status : Enabled
AV : AntiVir Desktop 9.0.1.32 [ Enabled | Updated ]
C:\ -> Disque fixe local # 232,88 Go (180,99 Go free) # NTFS
D:\ -> Disque amovible
E:\ -> Disque amovible
F:\ -> Disque amovible
G:\ -> Disque amovible
H:\ -> Disque CD-ROM
I:\ -> Disque amovible # 7,55 Go (6,18 Go free) [KINGSTON] # FAT32
L:\ -> Disque fixe local # 465,65 Go (60,61 Go free) [STOREX] # FAT32
################## | Elements infectieux |
C:\windows\infocard.exe
C:\WINDOWS\infocard.exe
################## | Registre |
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Firewall Administrating"
[HKLM\Software\Microsoft\Windows\CurrentVersion\Run] "Firewall Administrating"
[HKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY_SSHNAS]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoDrives"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoDrives"
################## | Mountpoints2 |
HKCU\..\..\Explorer\MountPoints2\{b95738bf-b359-11de-abad-00142acaf309}
Shell\AutoRun\command =D:\start.exe
################## | Vaccin |
(!) Cet ordinateur n'est pas vacciné !
################## | ! Fin du rapport # UsbFix V6.100 ! |