Pub intempestive CiD et infection

Résolu/Fermé
ChtiteFleur Messages postés 158 Date d'inscription samedi 10 mai 2008 Statut Membre Dernière intervention 24 octobre 2011 - 6 oct. 2008 à 11:20
jlpjlp Messages postés 51580 Date d'inscription vendredi 18 mai 2007 Statut Contributeur sécurité Dernière intervention 3 mai 2022 - 6 oct. 2008 à 14:12
Bonjour à tous !


Alors voilà, j'ai depuis quelques jours des publicités intempestives qui s'ouvrent avec Internet Explorer, toujours avec "CiD" en début de nom de fenêtre.
J'ai fait un scan, et il se trouve que j'ai des registery locations infectés (23 exactement).
De plus j'ai constaté la présence de WDC.exe dans les processus.

Bref ! J'ai besoin d'un bon nettoyage, mais je ne sais pas trop comment procéder.
J'ai déjà fait un scan avec SpyBot et CCleaner, sans succès.

Voici le rapport Hijack :

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:19:32, on 06/10/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16711)
Boot mode: Normal

Running processes:
C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\AsGHost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\Program Files\ATKOSD2\ATKOSD2.exe
C:\Program Files\ASUS\ATK Media\DMedia.exe
C:\Program Files\P4P\P4P.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Synaptics\SynTP\SynAsus.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\ASUS\ASUS Live Update\ALU.exe
C:\Program Files\ASUS\SmartLogon\sensorsrv.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\conime.exe
C:\Program Files\PrevxCSI\prevxcsi.exe
C:\Windows\system32\Taskmgr.exe
C:\Program Files\Internet Explorer\IEUser.exe
C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Laurent\Downloads\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://actus.sfr.fr
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://actus.sfr.fr
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www2.iesearch.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.asus.com/fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://actus.sfr.fr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = https://actus.sfr.fr
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: ContributeBHO Class - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ASUS Security Protect Manager - {DF21F1DB-80C6-11D3-9483-B03D0EC10000} - C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\ItIEAddIn.dll
O3 - Toolbar: Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [ATKOSD2] "C:\Program Files\ATKOSD2\ATKOSD2.exe"
O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files\ASUS\ATK Media\DMEDIA.EXE
O4 - HKLM\..\Run: [ChkMail] C:\Program Files\ChkMail\ChkMail\ChkMail.exe
O4 - HKLM\..\Run: [CognizanceTS] rundll32.exe C:\PROGRA~1\ASUSSE~1\ASUSSE~1\Bin\ASTSVCC.dll,RegisterModule
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [PowerForPhone] "C:\Program Files\P4P\P4P.exe"
O4 - HKLM\..\Run: [ASUS Screen Saver Protector] C:\Windows\ASScrPro.exe
O4 - HKLM\..\Run: [ASUS Camera ScreenSaver] C:\Windows\ASScrProlog.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
O4 - HKLM\..\RunServices: [SSDPSRV] C:\Windows\system32\ssdpsrv.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Users\Laurent\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [BaitBlue] "C:\ProgramData\Tool Log Log.j418ul"
O4 - HKCU\..\Run: [WIPE MORE DART AMEN] "C:\ProgramData\Lite Grey Support.ymbgvjo"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [Uniblue SpyEraser] "C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe" -m
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: PDFCreator.lnk = C:\Program Files\PDFCreator\PDFCreator.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O20 - AppInit_DLLs: APSHook.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files\ATK Hotkey\ASLDRSrv.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - Unknown owner - C:\Program Files\ATKGFNEX\GFNEXSrv.exe
O23 - Service: Autodesk Licensing Service - Autodesk, Inc. - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: CSIScanner - Prevx - C:\Program Files\PrevxCSI\prevxcsi.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: spmgr - Unknown owner - C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
O23 - Service: wampapache - Apache Software Foundation - c:\wamp\www\bin\apache\apache2.2.8\bin\httpd.exe
O23 - Service: wampmysqld - Unknown owner - c:\wamp\www\bin\mysql\mysql5.0.51b\bin\mysqld-nt.exe

End of file - 9875 bytes
A voir également:

18 réponses

ChtiteFleur Messages postés 158 Date d'inscription samedi 10 mai 2008 Statut Membre Dernière intervention 24 octobre 2011
6 oct. 2008 à 12:04
OK merci, j'ai viré une grosse partie des fichiers (ceux dont je suis sûre de non-utilité).


Voilà le rapport :


--------------------\\ Lop S&D 4.2.4-5 XP/Vista

Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6000 )
X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 Duo CPU T8100 @ 2.10GHz )
BIOS : Default System BIOS
USER : Laurent ( Administrator )
BOOT : Normal boot
Antivirus : Avira AntiVir PersonalEdition 8.0.1.27 (Activated)
C:\ (Local Disk) - NTFS - Total : 116 Go Free : 43 Go
D:\ (Local Disk) - NTFS - Total : 116 Go Free : 116 Go
E:\ (Local Disk) - NTFS - Total : 108 Go Free : 84 Go
F:\ (Local Disk) - NTFS - Total : 116 Go Free : 69 Go
G:\ (CD or DVD)
H:\ (CD or DVD)
I:\ (CD or DVD)

"C:\Lop SD" ( MAJ : 02-10-2008|23:42 )
Option : [2] ( 06/10/2008|12:01 )

[ UAC => 1 ]


\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ SUPPRESSION

Supprime! - C:\Users\Laurent\AppData\Roaming\MICROS~1\Windows\Cookies\laurent@adopt.euroclick[1].txt
Supprime! - C:\Program Files\WinZix
-
[ Fichier Hosts ] .. Restaure!

\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\


--------------------\\ Listing des dossiers dans Local

[21/08/2008|16:53] C:\Users\Laurent\AppData\Local\Adobe
[20/06/2008|13:53] C:\Users\Laurent\AppData\Local\Ahead
[19/06/2008|21:35] C:\Users\Laurent\AppData\Local\Application Data
[19/06/2008|22:34] C:\Users\Laurent\AppData\Local\ASUS
[19/06/2008|21:49] C:\Users\Laurent\AppData\Local\ATI
[20/06/2008|19:57] C:\Users\Laurent\AppData\Local\Autodesk
[05/10/2008|19:01] C:\Users\Laurent\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[26/08/2008|14:30] C:\Users\Laurent\AppData\Local\DNA
[23/08/2008|17:41] C:\Users\Laurent\AppData\Local\Downloaded Installations
[24/08/2008|11:35] C:\Users\Laurent\AppData\Local\GDIPFONTCACHEV1.DAT
[19/06/2008|21:35] C:\Users\Laurent\AppData\Local\Historique
[06/10/2008|00:04] C:\Users\Laurent\AppData\Local\IconCache.db
[26/08/2008|00:23] C:\Users\Laurent\AppData\Local\LogMeIn
[08/08/2008|16:52] C:\Users\Laurent\AppData\Local\Microsoft
[28/06/2008|17:29] C:\Users\Laurent\AppData\Local\Microsoft Games
[22/07/2008|13:30] C:\Users\Laurent\AppData\Local\Microsoft Help
[21/06/2008|16:57] C:\Users\Laurent\AppData\Local\Mozilla
[06/10/2008|12:01] C:\Users\Laurent\AppData\Local\Temp
[19/06/2008|21:35] C:\Users\Laurent\AppData\Local\Temporary Internet Files
[21/06/2008|17:22] C:\Users\Laurent\AppData\Local\VirtualStore
[23/08/2008|16:40] C:\Users\Laurent\AppData\Local\Wyzo

--------------------\\ Tâches planifiées dans C:\Windows\tasks

[06/10/2008 11:16][--a------] C:\Windows\tasks\Uniblue SpyEraser.job
[05/10/2008 22:19][--ah-----] C:\Windows\tasks\User_Feed_Synchronization-{B70EE645-63D9-4088-8BA6-B6993209A7A4}.job
[29/09/2008 20:00][--a------] C:\Windows\tasks\Norton Internet Security - Analyse systŠme complŠte - Laurent.job
[06/10/2008 10:39][--ah-----] C:\Windows\tasks\SA.DAT
[06/10/2008 00:04][--a------] C:\Windows\tasks\SCHEDLGU.TXT

--------------------\\ Listing des dossiers dans C:\ProgramData

[24/04/2008|04:42] C:\ProgramData\{623D32E9-0C62-4453-AD44-98B31F52A5E1}
[21/08/2008|16:52] C:\ProgramData\Adobe
[24/07/2008|16:33] C:\ProgramData\Adobe Systems
[19/06/2008|21:37] C:\ProgramData\Ahead
[21/08/2008|16:56] C:\ProgramData\ALM
[02/11/2006|15:02] C:\ProgramData\Application Data
[19/06/2008|22:34] C:\ProgramData\ASUS
[24/04/2008|07:24] C:\ProgramData\ATI
[21/07/2008|13:43] C:\ProgramData\Autodesk
[20/06/2008|15:48] C:\ProgramData\Avira
[02/11/2006|15:02] C:\ProgramData\Desktop
[02/11/2006|15:02] C:\ProgramData\Documents
[02/11/2006|15:02] C:\ProgramData\Favorites
[23/07/2008|14:07] C:\ProgramData\FLEXnet
[20/06/2008|13:53] C:\ProgramData\LightScribe
[26/08/2008|00:23] C:\ProgramData\LogMeIn
[23/08/2008|18:13] C:\ProgramData\Malwarebytes
[31/08/2008|21:02] C:\ProgramData\Microsoft
[11/09/2008|09:57] C:\ProgramData\Microsoft Help
[19/06/2008|21:37] C:\ProgramData\Nero
[21/06/2008|12:00] C:\ProgramData\ntuser.pol
[16/07/2008|21:55] C:\ProgramData\Office Genuine Advantage
[24/04/2008|07:13] C:\ProgramData\P4G
[23/08/2008|17:42] C:\ProgramData\Pinnacle
[23/08/2008|17:46] C:\ProgramData\Pinnacle VideoSpin
[06/10/2008|10:51] C:\ProgramData\PrevxCSI
[01/10/2008|18:22] C:\ProgramData\Spybot - Search & Destroy
[02/11/2006|15:02] C:\ProgramData\Start Menu
[23/07/2008|22:30] C:\ProgramData\TEMP
[02/11/2006|15:02] C:\ProgramData\Templates
[06/10/2008|11:02] C:\ProgramData\Uniblue
[23/08/2008|17:44] C:\ProgramData\VideoSpin
[25/06/2008|13:35] C:\ProgramData\WLInstaller

--------------------\\ Listing des dossiers dans C:\Program Files

[24/04/2008|04:42] C:\Program Files\Activation Assistant for the 2007 Microsoft Office suites
[23/08/2008|13:06] C:\Program Files\Adobe
[27/08/2008|15:50] C:\Program Files\ASUS
[24/04/2008|07:07] C:\Program Files\ASUS Security Center
[24/04/2008|06:43] C:\Program Files\ATI
[24/04/2008|06:44] C:\Program Files\ATI Technologies
[24/04/2008|06:49] C:\Program Files\ATK Hotkey
[24/04/2008|06:50] C:\Program Files\ATKGFNEX
[24/04/2008|06:51] C:\Program Files\ATKOSD2
[20/06/2008|19:51] C:\Program Files\Autodesk
[20/06/2008|15:48] C:\Program Files\Avira
[26/08/2008|14:30] C:\Program Files\BitTorrent
[21/08/2008|16:49] C:\Program Files\Bonjour
[21/07/2008|17:24] C:\Program Files\Bullfrog
[12/08/2008|16:03] C:\Program Files\Canon
[20/06/2008|15:35] C:\Program Files\CCleaner
[24/04/2008|07:06] C:\Program Files\ChkMail
[23/08/2008|17:56] C:\Program Files\Common Files
[24/04/2008|07:22] C:\Program Files\CSR
[29/06/2008|23:45] C:\Program Files\DAEMON Tools Lite
[24/04/2008|07:02] C:\Program Files\DIFX
[26/08/2008|14:30] C:\Program Files\DNA
[09/09/2008|14:30] C:\Program Files\EA GAMES
[16/08/2008|17:32] C:\Program Files\EphPod
[24/04/2008|07:06] C:\Program Files\Fingerprint Sensor
[17/07/2008|20:56] C:\Program Files\IKEA HomePlanner
[24/04/2008|07:22] C:\Program Files\InstallShield Installation Information
[24/04/2008|06:33] C:\Program Files\Intel
[16/08/2008|19:32] C:\Program Files\Internet Explorer
[23/08/2008|16:42] C:\Program Files\IrfanView
[23/07/2008|22:12] C:\Program Files\Java
[16/07/2008|13:13] C:\Program Files\LaBoiteACouleurs
[28/09/2008|21:06] C:\Program Files\LimeWire
[27/08/2008|00:23] C:\Program Files\LogMeIn
[23/08/2008|18:13] C:\Program Files\Malwarebytes' Anti-Malware
[12/08/2008|14:09] C:\Program Files\Microsoft Games
[24/04/2008|04:41] C:\Program Files\Microsoft Office
[24/04/2008|04:41] C:\Program Files\Microsoft Visual Studio
[31/08/2008|21:00] C:\Program Files\Microsoft Visual Studio 8
[24/04/2008|04:41] C:\Program Files\Microsoft Works
[24/04/2008|04:40] C:\Program Files\Microsoft.NET
[24/04/2008|04:30] C:\Program Files\Motorola
[18/04/2007|11:24] C:\Program Files\Movie Maker
[02/10/2008|18:12] C:\Program Files\Mozilla Firefox
[31/08/2008|21:03] C:\Program Files\MSBuild
[02/11/2006|14:37] C:\Program Files\MSN
[18/04/2007|10:43] C:\Program Files\MSXML 4.0
[19/06/2008|21:37] C:\Program Files\Nero
[20/06/2008|00:25] C:\Program Files\Neuf
[23/06/2008|23:38] C:\Program Files\NewTek
[02/07/2008|15:14] C:\Program Files\Notepad++
[24/04/2008|07:13] C:\Program Files\P4G
[24/04/2008|07:19] C:\Program Files\P4P
[21/07/2008|15:36] C:\Program Files\PDFCreator
[24/04/2008|07:13] C:\Program Files\Power4Gear eXtreme
[06/10/2008|10:48] C:\Program Files\PrevxCSI
[24/04/2008|06:47] C:\Program Files\Realtek
[02/11/2006|14:37] C:\Program Files\Reference Assemblies
[01/10/2008|18:27] C:\Program Files\Spybot - Search & Destroy
[01/10/2008|18:31] C:\Program Files\SpywareBlaster
[24/04/2008|07:17] C:\Program Files\Synaptics
[06/10/2008|11:02] C:\Program Files\Uniblue
[02/11/2006|15:01] C:\Program Files\Uninstall Information
[20/06/2008|19:09] C:\Program Files\VLC
[24/04/2008|06:28] C:\Program Files\Windows Calendar
[18/04/2007|11:24] C:\Program Files\Windows Collaboration
[24/04/2008|06:28] C:\Program Files\Windows Defender
[18/04/2007|11:24] C:\Program Files\Windows Journal
[25/06/2008|13:39] C:\Program Files\Windows Live
[16/08/2008|12:44] C:\Program Files\Windows Mail
[24/04/2008|06:28] C:\Program Files\Windows Media Player
[02/11/2006|14:37] C:\Program Files\Windows NT
[18/04/2007|11:24] C:\Program Files\Windows Photo Gallery
[24/04/2008|06:28] C:\Program Files\Windows Sidebar
[20/06/2008|19:08] C:\Program Files\WinRAR
[24/04/2008|06:56] C:\Program Files\Wireless Console 2

--------------------\\ Listing des dossiers dans C:\Program Files\Common Files

[21/08/2008|16:57] C:\Program Files\Common Files\Adobe
[24/07/2008|16:26] C:\Program Files\Common Files\Adobe Systems Shared
[19/06/2008|21:37] C:\Program Files\Common Files\Ahead
[21/07/2008|13:43] C:\Program Files\Common Files\Autodesk Shared
[12/08/2008|16:03] C:\Program Files\Common Files\Canon
[24/04/2008|04:41] C:\Program Files\Common Files\DESIGNER
[24/04/2008|06:54] C:\Program Files\Common Files\InstallShield
[23/07/2008|22:11] C:\Program Files\Common Files\Java
[19/06/2008|21:38] C:\Program Files\Common Files\LightScribe
[21/08/2008|16:45] C:\Program Files\Common Files\Macrovision Shared
[31/08/2008|21:03] C:\Program Files\Common Files\microsoft shared
[02/11/2006|13:18] C:\Program Files\Common Files\Services
[02/11/2006|13:18] C:\Program Files\Common Files\SpeechEngines
[20/06/2008|15:42] C:\Program Files\Common Files\Symantec Shared
[24/04/2008|06:28] C:\Program Files\Common Files\System
[24/06/2008|10:46] C:\Program Files\Common Files\WindowsLiveInstaller
[17/07/2008|20:56] C:\Program Files\Common Files\Wise Installation Wizard

--------------------\\ Process

( 81 Processes )

... OK !

--------------------\\ Recherche avec S_Lop

Aucun fichier / dossier Lop trouvé !

--------------------\\ Recherche de Fichiers / Dossiers Lop

Aucun fichier / dossier Lop trouvé !

--------------------\\ Verification du Registre

..... OK !

--------------------\\ Verification du fichier Hosts

Fichier Hosts PROPRE


--------------------\\ Recherche de fichiers avec Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-06 12:02:00
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden files ...
C:\Users\Laurent\AppData\Local\Microsoft\Windows\GameExplorer\{DFEF49D9-FC95-4301-99B9-2FB91C6ABA06}\PlayTasks\1\Les Sims™ 2 : Boit@Look.lnk 1246 bytes hidden from API
scan completed successfully
hidden processes: 0
hidden files: 11

--------------------\\ Recherche d'autres infections


Aucune autre infection trouvée !

[F:10][D:6]-> C:\Users\Laurent\AppData\Local\Temp
[F:28][D:1]-> C:\Users\Laurent\AppData\Roaming\MICROS~1\Windows\Cookies
[F:358][D:4]-> C:\Users\Laurent\AppData\Local\MICROS~1\Windows\TEMPOR~1\content.IE5
[F:28][D:2]-> C:\$Recycle.Bin

1 - "C:\Lop SD\LopR_1.txt" - 06/10/2008|11:39 - Option : [1]
2 - "C:\Lop SD\LopR_2.txt" - 06/10/2008|12:03 - Option : [2]

--------------------\\ Fin du rapport a 12:03:31
[ UAC => 1 ]
1
Bonjour

Les Pop Up CiD vienne d'un logiciel que tu a toi meme installer :)

msn plus sponso par CiD

pour regler ton probleme des popup CiD je te conseil daller dans Ajout/Suppression de Programme et de desinstaller MSN Plus! Live et Sponsor

Un tuto avait ete creer a ce sujet : http://www.commentcamarche.net/faq/sujet 5996 comment bloquer les fenetres cid#1ere methode de desinfection suppression manuelle

:)
0
non il supprimera seulement l'infection

les fichier citer plus haut par freelog et qu'il te conseil de supprimer ne reste qu'un conseil.
Ce sont des fichiers ou il existe une forte probabiliter d'infection.


Eizn
0
jlpjlp Messages postés 51580 Date d'inscription vendredi 18 mai 2007 Statut Contributeur sécurité Dernière intervention 3 mai 2022 5 040
6 oct. 2008 à 11:24
slt,


tu télécharge Lop S&D.exe sur ton Bureau.https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/LopSD.exe?attachauth=ANoY7co3ntqUavpZ3q1BG-h4pc13vqDZmhcNeEPChtsyrgAykRbhE8bZzhk979EfQD4AgwtQUHCaQ7ZQwNYMo3_0kA8htAspckDJtu2K5t6J9z6dLW4fpZyH4FpFL1tVMBZ8H-KnN7afZ5vt-WxZRpnynk-a0XmV_Y0C0q6DxGEDKie1TnPT7gFoZnoCnspzBmbW6ZzxA4fNr3oEDlbelNZON-LjF8nOmQ%3D%3D&attredirects=2

* Double-clique dessus pour lancer l'installation
* Puis double-clique sur le raccourci Lop S&D présent sur ton Bureau
* Séléctionne la langue souhaitée , puis choisis l'option 1 (Recherche)
* Patiente jusqu'à la fin du scan
* Poste le rapport généré (C:\lopR.txt)
-1

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
freelog Messages postés 2052 Date d'inscription vendredi 12 octobre 2007 Statut Membre Dernière intervention 16 avril 2011 130
6 oct. 2008 à 11:32
http://www.commentcamarche.net/faq/sujet 2490 popups ouverture de fenetres internet publicitaires pop up
-1
jlpjlp Messages postés 51580 Date d'inscription vendredi 18 mai 2007 Statut Contributeur sécurité Dernière intervention 3 mai 2022 5 040
6 oct. 2008 à 11:36
slt a tous l'infection est ici:

O4 - HKCU\..\Run: [BaitBlue] "C:\ProgramData\Tool Log Log.j418ul"
O4 - HKCU\..\Run: [WIPE MORE DART AMEN] "C:\ProgramData\Lite Grey Support.ymbgvjo"




et lop sd va la trouvér et on la virera
-1
ChtiteFleur Messages postés 158 Date d'inscription samedi 10 mai 2008 Statut Membre Dernière intervention 24 octobre 2011
6 oct. 2008 à 11:42
jlpjlp, voilà le rapport Lop S&D :


--------------------\\ Lop S&D 4.2.4-5 XP/Vista

Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6000 )
X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 Duo CPU T8100 @ 2.10GHz )
BIOS : Default System BIOS
USER : Laurent ( Administrator )
BOOT : Normal boot
Antivirus : Avira AntiVir PersonalEdition 8.0.1.27 (Activated)
C:\ (Local Disk) - NTFS - Total : 116 Go Free : 41 Go
D:\ (Local Disk) - NTFS - Total : 116 Go Free : 116 Go
E:\ (Local Disk) - NTFS - Total : 108 Go Free : 84 Go
F:\ (Local Disk) - NTFS - Total : 116 Go Free : 69 Go
G:\ (CD or DVD)
H:\ (CD or DVD)
I:\ (CD or DVD)

"C:\Lop SD" ( MAJ : 02-10-2008|23:42 )
Option : [1] ( 06/10/2008|11:37 )

[ UAC => 1 ]

--------------------\\ Listing des dossiers dans Local

[21/08/2008|16:53] C:\Users\Laurent\AppData\Local\Adobe
[20/06/2008|13:53] C:\Users\Laurent\AppData\Local\Ahead
[19/06/2008|21:35] C:\Users\Laurent\AppData\Local\Application Data
[19/06/2008|22:34] C:\Users\Laurent\AppData\Local\ASUS
[19/06/2008|21:49] C:\Users\Laurent\AppData\Local\ATI
[20/06/2008|19:57] C:\Users\Laurent\AppData\Local\Autodesk
[05/10/2008|19:01] C:\Users\Laurent\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[26/08/2008|14:30] C:\Users\Laurent\AppData\Local\DNA
[23/08/2008|17:41] C:\Users\Laurent\AppData\Local\Downloaded Installations
[24/08/2008|11:35] C:\Users\Laurent\AppData\Local\GDIPFONTCACHEV1.DAT
[19/06/2008|21:35] C:\Users\Laurent\AppData\Local\Historique
[06/10/2008|00:04] C:\Users\Laurent\AppData\Local\IconCache.db
[26/08/2008|00:23] C:\Users\Laurent\AppData\Local\LogMeIn
[08/08/2008|16:52] C:\Users\Laurent\AppData\Local\Microsoft
[28/06/2008|17:29] C:\Users\Laurent\AppData\Local\Microsoft Games
[22/07/2008|13:30] C:\Users\Laurent\AppData\Local\Microsoft Help
[21/06/2008|16:57] C:\Users\Laurent\AppData\Local\Mozilla
[06/10/2008|11:36] C:\Users\Laurent\AppData\Local\Temp
[19/06/2008|21:35] C:\Users\Laurent\AppData\Local\Temporary Internet Files
[21/06/2008|17:22] C:\Users\Laurent\AppData\Local\VirtualStore
[23/08/2008|16:40] C:\Users\Laurent\AppData\Local\Wyzo

--------------------\\ Tâches planifiées dans C:\Windows\tasks

[06/10/2008 11:16][--a------] C:\Windows\tasks\Uniblue SpyEraser.job
[05/10/2008 22:19][--ah-----] C:\Windows\tasks\User_Feed_Synchronization-{B70EE645-63D9-4088-8BA6-B6993209A7A4}.job
[29/09/2008 20:00][--a------] C:\Windows\tasks\Norton Internet Security - Analyse systŠme complŠte - Laurent.job
[06/10/2008 10:39][--ah-----] C:\Windows\tasks\SA.DAT
[06/10/2008 00:04][--a------] C:\Windows\tasks\SCHEDLGU.TXT

--------------------\\ Listing des dossiers dans C:\ProgramData

[24/04/2008|04:42] C:\ProgramData\{623D32E9-0C62-4453-AD44-98B31F52A5E1}
[21/08/2008|16:52] C:\ProgramData\Adobe
[24/07/2008|16:33] C:\ProgramData\Adobe Systems
[19/06/2008|21:37] C:\ProgramData\Ahead
[21/08/2008|16:56] C:\ProgramData\ALM
[02/11/2006|15:02] C:\ProgramData\Application Data
[19/06/2008|22:34] C:\ProgramData\ASUS
[24/04/2008|07:24] C:\ProgramData\ATI
[21/07/2008|13:43] C:\ProgramData\Autodesk
[20/06/2008|15:48] C:\ProgramData\Avira
[02/11/2006|15:02] C:\ProgramData\Desktop
[02/11/2006|15:02] C:\ProgramData\Documents
[02/11/2006|15:02] C:\ProgramData\Favorites
[23/07/2008|14:07] C:\ProgramData\FLEXnet
[29/09/2008|09:45] C:\ProgramData\Heart kind download
[20/06/2008|13:53] C:\ProgramData\LightScribe
[29/09/2008|09:45] C:\ProgramData\Lite Grey Support.ymbgvjo
[26/08/2008|00:23] C:\ProgramData\LogMeIn
[23/08/2008|18:13] C:\ProgramData\Malwarebytes
[31/08/2008|21:02] C:\ProgramData\Microsoft
[11/09/2008|09:57] C:\ProgramData\Microsoft Help
[19/06/2008|21:37] C:\ProgramData\Nero
[21/06/2008|12:00] C:\ProgramData\ntuser.pol
[16/07/2008|21:55] C:\ProgramData\Office Genuine Advantage
[24/04/2008|07:13] C:\ProgramData\P4G
[23/08/2008|17:42] C:\ProgramData\Pinnacle
[23/08/2008|17:46] C:\ProgramData\Pinnacle VideoSpin
[06/10/2008|10:51] C:\ProgramData\PrevxCSI
[29/09/2008|09:45] C:\ProgramData\Slow eggs wipe more
[01/10/2008|18:22] C:\ProgramData\Spybot - Search & Destroy
[02/11/2006|15:02] C:\ProgramData\Start Menu
[23/07/2008|22:30] C:\ProgramData\TEMP
[02/11/2006|15:02] C:\ProgramData\Templates
[29/09/2008|09:44] C:\ProgramData\Tool Log Log.0ehtkw
[29/09/2008|09:44] C:\ProgramData\Tool Log Log.j418ul
[06/10/2008|11:02] C:\ProgramData\Uniblue
[23/08/2008|17:44] C:\ProgramData\VideoSpin
[25/06/2008|13:35] C:\ProgramData\WLInstaller

--------------------\\ Listing des dossiers dans C:\Program Files

[24/04/2008|04:42] C:\Program Files\Activation Assistant for the 2007 Microsoft Office suites
[23/08/2008|13:06] C:\Program Files\Adobe
[27/08/2008|15:50] C:\Program Files\ASUS
[24/04/2008|07:07] C:\Program Files\ASUS Security Center
[24/04/2008|06:43] C:\Program Files\ATI
[24/04/2008|06:44] C:\Program Files\ATI Technologies
[24/04/2008|06:49] C:\Program Files\ATK Hotkey
[24/04/2008|06:50] C:\Program Files\ATKGFNEX
[24/04/2008|06:51] C:\Program Files\ATKOSD2
[20/06/2008|19:51] C:\Program Files\Autodesk
[20/06/2008|15:48] C:\Program Files\Avira
[26/08/2008|14:30] C:\Program Files\BitTorrent
[21/08/2008|16:49] C:\Program Files\Bonjour
[21/07/2008|17:24] C:\Program Files\Bullfrog
[12/08/2008|16:03] C:\Program Files\Canon
[20/06/2008|15:35] C:\Program Files\CCleaner
[24/04/2008|07:06] C:\Program Files\ChkMail
[23/08/2008|17:56] C:\Program Files\Common Files
[24/04/2008|07:22] C:\Program Files\CSR
[29/06/2008|23:45] C:\Program Files\DAEMON Tools Lite
[24/04/2008|07:02] C:\Program Files\DIFX
[26/08/2008|14:30] C:\Program Files\DNA
[09/09/2008|14:30] C:\Program Files\EA GAMES
[16/08/2008|17:32] C:\Program Files\EphPod
[24/04/2008|07:06] C:\Program Files\Fingerprint Sensor
[17/07/2008|20:56] C:\Program Files\IKEA HomePlanner
[24/04/2008|07:22] C:\Program Files\InstallShield Installation Information
[24/04/2008|06:33] C:\Program Files\Intel
[16/08/2008|19:32] C:\Program Files\Internet Explorer
[23/08/2008|16:42] C:\Program Files\IrfanView
[23/07/2008|22:12] C:\Program Files\Java
[16/07/2008|13:13] C:\Program Files\LaBoiteACouleurs
[28/09/2008|21:06] C:\Program Files\LimeWire
[27/08/2008|00:23] C:\Program Files\LogMeIn
[23/08/2008|18:13] C:\Program Files\Malwarebytes' Anti-Malware
[12/08/2008|14:09] C:\Program Files\Microsoft Games
[24/04/2008|04:41] C:\Program Files\Microsoft Office
[24/04/2008|04:41] C:\Program Files\Microsoft Visual Studio
[31/08/2008|21:00] C:\Program Files\Microsoft Visual Studio 8
[24/04/2008|04:41] C:\Program Files\Microsoft Works
[24/04/2008|04:40] C:\Program Files\Microsoft.NET
[24/04/2008|04:30] C:\Program Files\Motorola
[18/04/2007|11:24] C:\Program Files\Movie Maker
[02/10/2008|18:12] C:\Program Files\Mozilla Firefox
[31/08/2008|21:03] C:\Program Files\MSBuild
[02/11/2006|14:37] C:\Program Files\MSN
[18/04/2007|10:43] C:\Program Files\MSXML 4.0
[19/06/2008|21:37] C:\Program Files\Nero
[20/06/2008|00:25] C:\Program Files\Neuf
[23/06/2008|23:38] C:\Program Files\NewTek
[02/07/2008|15:14] C:\Program Files\Notepad++
[24/04/2008|07:13] C:\Program Files\P4G
[24/04/2008|07:19] C:\Program Files\P4P
[21/07/2008|15:36] C:\Program Files\PDFCreator
[24/04/2008|07:13] C:\Program Files\Power4Gear eXtreme
[06/10/2008|10:48] C:\Program Files\PrevxCSI
[24/04/2008|06:47] C:\Program Files\Realtek
[02/11/2006|14:37] C:\Program Files\Reference Assemblies
[01/10/2008|18:27] C:\Program Files\Spybot - Search & Destroy
[01/10/2008|18:31] C:\Program Files\SpywareBlaster
[24/04/2008|07:17] C:\Program Files\Synaptics
[06/10/2008|11:02] C:\Program Files\Uniblue
[02/11/2006|15:01] C:\Program Files\Uninstall Information
[20/06/2008|19:09] C:\Program Files\VLC
[24/04/2008|06:28] C:\Program Files\Windows Calendar
[18/04/2007|11:24] C:\Program Files\Windows Collaboration
[24/04/2008|06:28] C:\Program Files\Windows Defender
[18/04/2007|11:24] C:\Program Files\Windows Journal
[25/06/2008|13:39] C:\Program Files\Windows Live
[16/08/2008|12:44] C:\Program Files\Windows Mail
[24/04/2008|06:28] C:\Program Files\Windows Media Player
[02/11/2006|14:37] C:\Program Files\Windows NT
[18/04/2007|11:24] C:\Program Files\Windows Photo Gallery
[24/04/2008|06:28] C:\Program Files\Windows Sidebar
[20/06/2008|19:08] C:\Program Files\WinRAR
[29/09/2008|09:43] C:\Program Files\WinZix
[24/04/2008|06:56] C:\Program Files\Wireless Console 2

--------------------\\ Listing des dossiers dans C:\Program Files\Common Files

[21/08/2008|16:57] C:\Program Files\Common Files\Adobe
[24/07/2008|16:26] C:\Program Files\Common Files\Adobe Systems Shared
[19/06/2008|21:37] C:\Program Files\Common Files\Ahead
[21/07/2008|13:43] C:\Program Files\Common Files\Autodesk Shared
[12/08/2008|16:03] C:\Program Files\Common Files\Canon
[24/04/2008|04:41] C:\Program Files\Common Files\DESIGNER
[24/04/2008|06:54] C:\Program Files\Common Files\InstallShield
[23/07/2008|22:11] C:\Program Files\Common Files\Java
[19/06/2008|21:38] C:\Program Files\Common Files\LightScribe
[21/08/2008|16:45] C:\Program Files\Common Files\Macrovision Shared
[31/08/2008|21:03] C:\Program Files\Common Files\microsoft shared
[02/11/2006|13:18] C:\Program Files\Common Files\Services
[02/11/2006|13:18] C:\Program Files\Common Files\SpeechEngines
[20/06/2008|15:42] C:\Program Files\Common Files\Symantec Shared
[24/04/2008|06:28] C:\Program Files\Common Files\System
[24/06/2008|10:46] C:\Program Files\Common Files\WindowsLiveInstaller
[17/07/2008|20:56] C:\Program Files\Common Files\Wise Installation Wizard

--------------------\\ Process

( 85 Processes )

iexplore.exe ~ [PID:3396]
iexplore.exe ~ [PID:3404]

--------------------\\ Recherche avec S_Lop

C:\ProgramData\Tool Log Log.0ehtkw
C:\ProgramData\Tool Log Log.j418ul
C:\ProgramData\Lite Grey Support.ymbgvjo

--------------------\\ Recherche de Fichiers / Dossiers Lop

C:\Program Files\WinZix
C:\Users\Laurent\AppData\Roaming\MICROS~1\Windows\Cookies\laurent@adopt.euroclick[1].txt

--------------------\\ Verification du Registre

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BaitBlue"="\"C:\\ProgramData\\Tool Log Log.j418ul\""
"WIPE MORE DART AMEN"="\"C:\\ProgramData\\Lite Grey Support.ymbgvjo\""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

--------------------\\ Verification du fichier Hosts

Fichier Hosts PROPRE


--------------------\\ Recherche de fichiers avec Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-06 11:38:15
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden files ...
C:\Users\Laurent\AppData\Local\Microsoft\Windows\GameExplorer\{DFEF49D9-FC95-4301-99B9-2FB91C6ABA06}\PlayTasks\1\Les Sims™ 2 : Boit@Look.lnk 1246 bytes hidden from API
scan completed successfully
hidden processes: 0
hidden files: 11

--------------------\\ Recherche d'autres infections

--------------------\\ Cracks & Keygens ..

C:\Users\Laurent\AppData\Roaming\BitTorrent\FIFA 09 [PC-GAME][MULTi5][Crack + serial][TNTvillage org].torrent
C:\Users\Laurent\AppData\Roaming\BitTorrent\The Sims 2 Apartment Life + Crack 2008.iso.torrent
C:\Users\Laurent\Documents\LimeWire\Saved\crack sims_2.exe
C:\Users\Laurent\Documents\LimeWire\Saved\Pc Game The Sims 2 (Crack ) .rar
C:\Users\Laurent\Documents\LimeWire\Saved\speed edit keygen.zip
C:\Users\Laurent\Documents\LimeWire\Saved\The_Sims_2_French_Crack.rar


[F:9][D:5]-> C:\Users\Laurent\AppData\Local\Temp
[F:29][D:1]-> C:\Users\Laurent\AppData\Roaming\MICROS~1\Windows\Cookies
[F:358][D:4]-> C:\Users\Laurent\AppData\Local\MICROS~1\Windows\TEMPOR~1\content.IE5
[F:2][D:2]-> C:\$Recycle.Bin

1 - "C:\Lop SD\LopR_1.txt" - 06/10/2008|11:39 - Option : [1]

--------------------\\ Fin du rapport a 11:39:48
[ UAC => 1 ]


Eizn
, merci pour la précision, je comprends le truc. Mais ça doit provenir d'un autre logiciel que MSN, parce que je n'ai que Windows Live Messenger. Je n'ai pas trouvé dans les programmes à désinstaller quoi que ce soit de MSN. Mais c'est bon à savoir ! Surtout si c'est mon frangin qui l'installe dans mon dos !


freelog, merci aussi pour le lien. Je vais y jeter un grand coup d'oeil :) .
-1
jlpjlp Messages postés 51580 Date d'inscription vendredi 18 mai 2007 Statut Contributeur sécurité Dernière intervention 3 mai 2022 5 040
6 oct. 2008 à 11:47
ok l'infection a été trouvée


il serait preferable de virer ces cracks:

C:\Users\Laurent\AppData\Roaming\BitTorrent\FIFA 09 [PC-GAME][MULTi5][Crack + serial][TNTvillage org].torrent
C:\Users\Laurent\AppData\Roaming\BitTorrent\The Sims 2 Apartment Life + Crack 2008.iso.torrent
C:\Users\Laurent\Documents\LimeWire\Saved\crack sims_2.exe
C:\Users\Laurent\Documents\LimeWire\Saved\Pc Game The Sims 2 (Crack ) .rar
C:\Users\Laurent\Documents\LimeWire\Saved\speed edit keygen.zip
C:\Users\Laurent\Documents\LimeWire\Saved\The_Sims_2_French_Crack.rar









refais lop sd


* Choisis cette fois ci l'Option 2 (Suppression)
* Ne ferme pas la fenêtre lors de la suppression !
* Poste le rapport généré (C:\lopR.txt)


_________________

recolle ensuite un nouveau rapport hijakchits et dis si encore des pubs CID.....
-1
freelog Messages postés 2052 Date d'inscription vendredi 12 octobre 2007 Statut Membre Dernière intervention 16 avril 2011 130
6 oct. 2008 à 11:50
fais gaffe avec limewire c'est bourré de virus
essaye plutôt les torrents
-1
ChtiteFleur Messages postés 158 Date d'inscription samedi 10 mai 2008 Statut Membre Dernière intervention 24 octobre 2011
6 oct. 2008 à 11:50
L'option 2 "suppression" va virer les fichiers que tu as cités ci-dessus ? En fait le PC n'est pas à moi, je bosse juste dessus quand le proprio n'en a pas besoin. Je ne voudrais pas faire une bourde :) !
-1
jlpjlp Messages postés 51580 Date d'inscription vendredi 18 mai 2007 Statut Contributeur sécurité Dernière intervention 3 mai 2022 5 040
6 oct. 2008 à 11:58
bon alors laisse les il le fera si besoin

et passe a

refais lop sd
qui ne virera que les infections responsables de CId et laissera les cracks

* Choisis cette fois ci l'Option 2 (Suppression)
* Ne ferme pas la fenêtre lors de la suppression !
* Poste le rapport généré (C:\lopR.txt)
-1
jlpjlp Messages postés 51580 Date d'inscription vendredi 18 mai 2007 Statut Contributeur sécurité Dernière intervention 3 mai 2022 5 040
6 oct. 2008 à 12:06
ok cela devrait etre bon:

recolle ensuite un nouveau rapport hijakchits et dis si encore des pubs CID.....
-1
ChtiteFleur Messages postés 158 Date d'inscription samedi 10 mai 2008 Statut Membre Dernière intervention 24 octobre 2011
6 oct. 2008 à 12:09
Pour l'instant pas de pubs intempestives. Mais ça se passe parfois comme ça. De grands laps de temps sans, et plusieurs tout à coup. C'est très énervant.


Le rapport Hijack :

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:08:26, on 06/10/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16711)
Boot mode: Normal

Running processes:
C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\AsGHost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\Program Files\ATKOSD2\ATKOSD2.exe
C:\Program Files\ASUS\ATK Media\DMedia.exe
C:\Program Files\P4P\P4P.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Synaptics\SynTP\SynAsus.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\ASUS\ASUS Live Update\ALU.exe
C:\Program Files\ASUS\SmartLogon\sensorsrv.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\conime.exe
C:\Program Files\PrevxCSI\prevxcsi.exe
C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe
C:\Windows\system32\cmd.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Users\Laurent\Downloads\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://actus.sfr.fr
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://actus.sfr.fr
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www2.iesearch.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.asus.com/fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://actus.sfr.fr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = https://actus.sfr.fr
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: ContributeBHO Class - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ASUS Security Protect Manager - {DF21F1DB-80C6-11D3-9483-B03D0EC10000} - C:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\ItIEAddIn.dll
O3 - Toolbar: Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [ATKOSD2] "C:\Program Files\ATKOSD2\ATKOSD2.exe"
O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files\ASUS\ATK Media\DMEDIA.EXE
O4 - HKLM\..\Run: [ChkMail] C:\Program Files\ChkMail\ChkMail\ChkMail.exe
O4 - HKLM\..\Run: [CognizanceTS] rundll32.exe C:\PROGRA~1\ASUSSE~1\ASUSSE~1\Bin\ASTSVCC.dll,RegisterModule
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [PowerForPhone] "C:\Program Files\P4P\P4P.exe"
O4 - HKLM\..\Run: [ASUS Screen Saver Protector] C:\Windows\ASScrPro.exe
O4 - HKLM\..\Run: [ASUS Camera ScreenSaver] C:\Windows\ASScrProlog.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
O4 - HKLM\..\RunServices: [SSDPSRV] C:\Windows\system32\ssdpsrv.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Users\Laurent\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [Uniblue SpyEraser] "C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe" -m
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: PDFCreator.lnk = C:\Program Files\PDFCreator\PDFCreator.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O20 - AppInit_DLLs: APSHook.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files\ATK Hotkey\ASLDRSrv.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - Unknown owner - C:\Program Files\ATKGFNEX\GFNEXSrv.exe
O23 - Service: Autodesk Licensing Service - Autodesk, Inc. - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: CSIScanner - Prevx - C:\Program Files\PrevxCSI\prevxcsi.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: spmgr - Unknown owner - C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
O23 - Service: wampapache - Apache Software Foundation - c:\wamp\www\bin\apache\apache2.2.8\bin\httpd.exe
O23 - Service: wampmysqld - Unknown owner - c:\wamp\www\bin\mysql\mysql5.0.51b\bin\mysqld-nt.exe

End of file - 9539 bytes
-1
jlpjlp Messages postés 51580 Date d'inscription vendredi 18 mai 2007 Statut Contributeur sécurité Dernière intervention 3 mai 2022 5 040
6 oct. 2008 à 12:11
ok tu ne devrait plus avoir de pubs

tu peux virer lopsd et hijakchits


fais un scan avec antivir que tu as pour voir si aucune autre infection

si des infections sont trouvées colle le rapport

sinon et si plus de pub c'est bon pour toi
-1
ChtiteFleur Messages postés 158 Date d'inscription samedi 10 mai 2008 Statut Membre Dernière intervention 24 octobre 2011
6 oct. 2008 à 12:19
Pour l'isntant j'ai une alerte, en faisant le scan avec Antivir, concernant le fichier :
C:\$RECYCLE.BIN\S-1-5-21-836168442-498619839-1718942187-1000\$R0ITXKD.rar
Je "delete" ?
-1
jlpjlp Messages postés 51580 Date d'inscription vendredi 18 mai 2007 Statut Contributeur sécurité Dernière intervention 3 mai 2022 5 040
6 oct. 2008 à 12:35
oui

cela correspond a la poubelle que tu n'as pas du virée
, vide la corbeille par la suite
-1
ChtiteFleur Messages postés 158 Date d'inscription samedi 10 mai 2008 Statut Membre Dernière intervention 24 octobre 2011
6 oct. 2008 à 13:59
Bon ben j'ai fini le scan avec Antivir, et ça m'a l'air bon :) .
Je coche mon problème comme résolu ;) !
Encore merci !
-1
jlpjlp Messages postés 51580 Date d'inscription vendredi 18 mai 2007 Statut Contributeur sécurité Dernière intervention 3 mai 2022 5 040
6 oct. 2008 à 14:12
ok bonne suite
-1