Bonsoir a tous !!
Je vient vous demandez une petite aide car depuis deux jours j'ai une fenetre jaune a coté de l'heure qui me dit :
Your pc is infected j'ai bien chercher dans le forum j'ai trouvé des reponse mais aucune ma aidé !!
J'ai passé adward, spybot, cleanup, ccleaner, ewido, et spyware doctor
ALors le seul qui a reussi a me trouver et virer ce virus c'est spyware doctor mais malheusement quand j'ai redemarrer l'ordi la fenetre est revenu et ca m'installe spywarestrike 2.5 automatiquement !!
Je sais plus Quoi faire alors je vous demande votre aide voici mes differents rapport avec les log !!
AVEC SPYWARE DOCTOR
Infection Name Location Risk
SpywareStrike HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\SpywareStrike.exe Elevated
SpywareStrike HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\SpywareStrike.exe## Elevated
SpywareStrike HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SpywareStrike Elevated
SpywareStrike HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SpywareStrike## Elevated
SpywareStrike HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SpywareStrike##DisplayName Elevated
SpywareStrike HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SpywareStrike##UninstallString Elevated
SpywareStrike HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SpywareStrike##DisplayIcon Elevated
SpywareStrike HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SpywareStrike##DisplayVersion Elevated
SpywareStrike HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SpywareStrike##NSIS:StartMenuDir Elevated
SpywareStrike HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SpywareStrike##URLInfoAbout Elevated
SpywareStrike HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SpywareStrike##Publisher Elevated
SpywareStrike HKLM\SOFTWARE\SpywareStrike Elevated
SpywareStrike HKLM\SOFTWARE\SpywareStrike## Elevated
SpywareStrike HKLM\SOFTWARE\SpywareStrike##ref Elevated
Tracking Cookie(s) C:\Documents and Settings\mike\Cookies\mike@xiti[1].txt Medium
Tracking Cookie(s) C:\Documents and Settings\mike\Cookies\mike@tradedoubler[1].txt Medium
Advertising C:\Documents and Settings\mike\Cookies\mike@www.smartadserver[2].txt Low
Tracking Cookie(s) C:\Documents and Settings\mike\Cookies\mike@247realmedia[1].txt Medium
Tracking Cookie(s) C:\Documents and Settings\mike\Cookies\mike@bluestreak[2].txt Medium
SpywareStrike C:\Documents and Settings\mike\Application Data\Microsoft\Internet Explorer\Quick Launch\SpywareStrike 2.5.lnk Elevated
SpywareStrike C:\Documents and Settings\mike\Bureau\SpywareStrike.lnk Elevated
SpywareStrike C:\Documents and Settings\mike\Menu D魡rrer\Programmes\SpywareStrike Elevated
SpywareStrike C:\Documents and Settings\mike\Menu D魡rrer\Programmes\SpywareStrike\SpywareStrike 2.5 Website.lnk Elevated
SpywareStrike C:\Documents and Settings\mike\Menu D魡rrer\Programmes\SpywareStrike\SpywareStrike 2.5.lnk Elevated
SpywareStrike C:\Documents and Settings\mike\Menu D魡rrer\Programmes\SpywareStrike\Uninstall SpywareStrike 2.5.lnk Elevated
SpywareStrike C:\Documents and Settings\mike\Menu D魡rrer\SpywareStrike 2.5.lnk Elevated
SpywareStrike C:\Program Files\SpywareStrike Elevated
SpywareStrike C:\Program Files\SpywareStrike\Lang Elevated
SpywareStrike C:\Program Files\SpywareStrike\Lang\English.ini Elevated
SpywareStrike C:\Program Files\SpywareStrike\msvcp71.dll Elevated
SpywareStrike C:\Program Files\SpywareStrike\msvcr71.dll Elevated
SpywareStrike C:\Program Files\SpywareStrike\Quarantine Elevated
SpywareStrike C:\Program Files\SpywareStrike\signatures.ref Elevated
SpywareStrike C:\Program Files\SpywareStrike\SpywareStrike.exe Elevated
SpywareStrike C:\Program Files\SpywareStrike\SpywareStrike.url Elevated
SpywareStrike C:\Program Files\SpywareStrike\uninst.exe Elevated
AVEC HIJACKTHIS
Logfile of HijackThis v1.99.1
Scan saved at 21:40:49, on 23/01/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\mike\Bureau\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O4 - HKLM\..\Run: [Soltek] C:\WINDOWS\System32\autorun.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [KAVPersonal50] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe" /minimize
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: Yahoo! Dominoes - http://download.games.yahoo.com/games/clients/y/dot8_x.cab
O16 - DPF: Yahoo! Fleet - http://download.games.yahoo.com/games/clients/y/fltt3_x.cab
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1137382720037
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{AF155C6A-0279-4B80-BCDB-D658554628D1}: NameServer = 212.27.54.252,212.27.39.1
O20 - AppInit_DLLs: MsgPlusLoader.dll
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: kavsvc - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
Aidez moi svppppp looool
