nouveau rapport de hidjackthis2 installé dans un dossier crée à la racine c:
Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 21:27:35, on 04/06/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
D:\Program Files\
AntiVir PersonalEdition Classic\avguard.exe
D:\Program Files\
AntiVir PersonalEdition Classic\sched.exe
D:\Program Files\Comodo\CBOClean\BOCORE.exe
C:\Program Files\Comodo\Firewall\cmdagent.exe
C:\Program Files\Kerio\
Personal Firewall\persfw.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Comodo\Firewall\CPF.exe
D:\Program Files\
AntiVir PersonalEdition Classic\avgnt.exe
D:\Program Files\Eraser\eraser.exe
C:\HJT\HiJackThis_v2.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://www.google.fr
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.files-ftp.com/~unicorni/phpBB2/index.php
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.free.fr:3128
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\Comodo\Firewall\CPF.exe" /background
O4 - HKLM\..\Run: [avgnt] "D:\Program Files\
AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [Eraser] D:\Program Files\Eraser\eraser.exe -hide
O4 - Startup: MRU-Blaster Scheduler.lnk = D:\Program Files\MRU-Blaster\scheduler.exe
O4 - Startup: MRU-Blaster Silent Clean.lnk = D:\Program Files\MRU-Blaster\mrublaster.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.files-ftp.com/~unicorni/phpBB2/index.php
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.microsoft.com/windowsupda ... 6470726972
O17 - HKLM\System\CCS\Services\Tcpip\..\{EC6A3F84-F497-481C-8FE7-C1054EFAF642}: NameServer = 208.67.222.222,208.67.220.200
O22 - SharedTaskScheduler: Pré-chargeur Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Démon de cache des catégories de composant - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service:
AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) -
Avira GmbH - D:\Program Files\
AntiVir PersonalEdition Classic\sched.exe
O23 - Service:
AntiVir PersonalEdition Classic Guard (AntiVirService) -
Avira GmbH - D:\Program Files\
AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: BOCore - COMODO - D:\Program Files\Comodo\CBOClean\BOCORE.exe
O23 - Service: BTC - Unknown owner - C:\DOCUME~1\xavier\LOCALS~1\Temp\BTC.exe (file missing)
O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Program Files\Comodo\Firewall\cmdagent.exe
O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - Unknown owner - C:\WINDOWS\System32\dmadmin.exe
O23 - Service: EKQY - Unknown owner - C:\DOCUME~1\xavier\LOCALS~1\Temp\EKQY.exe (file missing)
O23 - Service: Journal des événements (Eventlog) - Unknown owner - C:\WINDOWS\system32\services.exe
O23 - Service: FPAFTFGLT - Unknown owner - C:\DOCUME~1\xavier\LOCALS~1\Temp\FPAFTFGLT.exe (file missing)
O23 - Service: HMPQXTXBB - Unknown owner - C:\DOCUME~1\xavier\LOCALS~1\Temp\HMPQXTXBB.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Service COM de gravure de CD IMAPI (ImapiService) - Unknown owner - C:\WINDOWS\system32\imapi.exe
O23 - Service: Kerio
Personal Firewall (PersFw) - Kerio Technologies - C:\Program Files\Kerio\
Personal Firewall\persfw.exe
O23 - Service: Plug-and-Play (PlugPlay) - Unknown owner - C:\WINDOWS\system32\services.exe
O23 - Service: Gestionnaire de session d'aide sur le Bureau à distance (RDSessMgr) - Unknown owner - C:\WINDOWS\system32\sessmgr.exe
O23 - Service: Carte à puce (SCardSvr) - Unknown owner - C:\WINDOWS\System32\SCardSvr.exe
O23 - Service: SUTIE - Unknown owner - C:\DOCUME~1\xavier\LOCALS~1\Temp\SUTIE.exe (file missing)
O23 - Service: Journaux et alertes de performance (SysmonLog) - Unknown owner - C:\WINDOWS\system32\smlogsvc.exe
O23 - Service: Cliché instantané de volume (VSS) - Unknown owner - C:\WINDOWS\System32\vssvc.exe
O23 - Service: Carte de performance WMI (WmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\wmiapsrv.exe
--
End of file - 5218 bytes
2/ Pour les Parfeux j'ai desactivé Kerio.
3/ nouveau rapport de scan Spybot :
--- Report generated: 2007-06-04 23:04 ---
E-MusicA: Réglages (Valeur du registre, fixed)
HKEY_USERS\S-1-5-21-329068152-854245398-941058211-1003\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\{686C970F-1D7D-4469-85D1-4B35763B56CC}
MS Office 9.0: Recently used files (59 files) (Répertoire, fixed)
C:\Documents and Settings\xavier\Application Data\Microsoft\Office\Récents\
Log: Activity: SchedLgU.Txt (Sauver le fichier, fixing failed)
C:\WINDOWS\SchedLgU.Txt
Internet Explorer: User agent (Modification du registre, fixed)
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent!=Mozilla/4.0 (compatible; MSIE; Win32)
Internet Explorer: User agent (Modification du registre, fixed)
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent!=Mozilla/4.0 (compatible; MSIE; Win32)
Internet Explorer: User agent (Modification du registre, fixed)
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent!=Mozilla/4.0 (compatible; MSIE; Win32)
Internet Explorer: User agent (Modification du registre, fixed)
HKEY_USERS\S-1-5-21-329068152-854245398-941058211-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent!=Mozilla/4.0 (compatible; MSIE; Win32)
Internet Explorer: User agent (Modification du registre, fixed)
HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent!=Mozilla/4.0 (compatible; MSIE; Win32)
MS Media Player: Client ID (Modification du registre, fixed)
HKEY_USERS\S-1-5-19\Software\Microsoft\MediaPlayer\Player\Settings\Client ID!=
MS Media Player: Client ID (Modification du registre, fixed)
HKEY_USERS\S-1-5-20\Software\Microsoft\MediaPlayer\Player\Settings\Client ID!=
MS Media Player: Anonymous ID (Modification du registre, fixed)
HKEY_USERS\S-1-5-21-329068152-854245398-941058211-1003\Software\Microsoft\MediaPlayer\Preferences\SendUserGUID!=B=0
MS Office 9.0: Internet history (Valeur du registre, fixed)
HKEY_USERS\S-1-5-21-329068152-854245398-941058211-1003\Software\Microsoft\Office\9.0\Common\Internet\LocationOfComponents
MS Office 9.0: Access recent file (1 fichiers) (Clé du registre, fixed)
HKEY_USERS\S-1-5-21-329068152-854245398-941058211-1003\Software\Microsoft\Office\9.0\Access\Settings
MS Office 9.0 (Word): Recently used file list (Valeur du registre, fixed)
HKEY_USERS\S-1-5-21-329068152-854245398-941058211-1003\Software\Microsoft\Office\9.0\Word\Data\Settings
MS Search Assistant: Typed search terms history (Clé du registre, fixed)
HKEY_USERS\S-1-5-21-329068152-854245398-941058211-1003\Software\Microsoft\Search Assistant\ACMru
MS Windows Backup 5.0: Last created backup set (Modification du registre, fixed)
HKEY_USERS\S-1-5-21-329068152-854245398-941058211-1003\Software\Microsoft\Ntbackup\Hardware\Logical Disk File!=
Windows: Drivers installation paths (Modification du registre, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\Installation Sources!=
Windows.OpenWith: Open with list - .CSS extension (2 fichiers) (Clé du registre, fixed)
HKEY_USERS\S-1-5-21-329068152-854245398-941058211-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.CSS\OpenWithList
Windows Explorer: Recent wallpaper list (44 fichiers) (Clé du registre, fixed)
HKEY_USERS\S-1-5-21-329068152-854245398-941058211-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Wallpaper\MRU
Windows Explorer: Recent file global history (Clé du registre, fixed)
HKEY_USERS\S-1-5-21-329068152-854245398-941058211-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs
Windows Media SDK: Computer name (Modification du registre, fixed)
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows Media\WMSDK\General\ComputerName!=ComputerName
Windows Media SDK: Computer name (Modification du registre, fixed)
HKEY_USERS\S-1-5-21-329068152-854245398-941058211-1003\Software\Microsoft\Windows Media\WMSDK\General\ComputerName!=ComputerName
Windows Media SDK: Computer name (Modification du registre, fixed)
HKEY_USERS\S-1-5-18\Software\Microsoft\Windows Media\WMSDK\General\ComputerName!=ComputerName
Windows Media SDK: Unique ID (Modification du registre, fixed)
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows Media\WMSDK\General\UniqueID!={00000000-0000-0000-0000-000000000000}
Windows Media SDK: Unique ID (Modification du registre, fixed)
HKEY_USERS\S-1-5-21-329068152-854245398-941058211-1003\Software\Microsoft\Windows Media\WMSDK\General\UniqueID!={00000000-0000-0000-0000-000000000000}
Windows Media SDK: Unique ID (Modification du registre, fixed)
HKEY_USERS\S-1-5-18\Software\Microsoft\Windows Media\WMSDK\General\UniqueID!={00000000-0000-0000-0000-000000000000}
Windows Media SDK: Volume serial number (Valeur du registre, fixed)
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows Media\WMSDK\General\VolumeSerialNumber
Windows Media SDK: Volume serial number (Valeur du registre, fixed)
HKEY_USERS\S-1-5-21-329068152-854245398-941058211-1003\Software\Microsoft\Windows Media\WMSDK\General\VolumeSerialNumber
Windows Media SDK: Volume serial number (Valeur du registre, fixed)
HKEY_USERS\S-1-5-18\Software\Microsoft\Windows Media\WMSDK\General\VolumeSerialNumber
--- Spybot - Search & Destroy version: 1.4 (build: 20050523) ---
2005-05-31 blindman.exe (1.0.0.1)
2005-05-31 SpybotSD.exe (1.4.0.3)
2005-05-31 TeaTimer.exe (1.4.0.2)
2007-06-02 unins000.exe (51.41.0.0)
2005-05-31 Update.exe (1.4.0.0)
2007-05-23 advcheck.dll (1.5.3.0)
2005-05-31 aports.dll (2.1.0.0)
2005-05-31 borlndmm.dll (7.0.4.453)
2005-05-31 delphimm.dll (7.0.4.453)
2005-05-31 SDHelper.dll (1.4.0.0)
2007-01-02 Tools.dll (2.0.1.0)
2005-05-31 UnzDll.dll (1.73.1.1)
2005-05-31 ZipDll.dll (1.73.2.0)
2007-05-30 Includes\Cookies.sbi (*)
2007-05-30 Includes\Dialer.sbi (*)
2007-05-30 Includes\DialerC.sbi (*)
2007-05-30 Includes\Hijackers.sbi (*)
2007-05-30 Includes\HijackersC.sbi (*)
2006-10-27 Includes\Keyloggers.sbi (*)
2007-05-30 Includes\KeyloggersC.sbi (*)
2007-05-30 Includes\Malware.sbi (*)
2007-05-30 Includes\MalwareC.sbi (*)
2007-03-21 Includes\PUPS.sbi (*)
2007-05-30 Includes\PUPSC.sbi (*)
2007-05-30 Includes\Revision.sbi (*)
2007-05-30 Includes\Security.sbi (*)
2007-05-30 Includes\SecurityC.sbi (*)
2007-05-30 Includes\Spybots.sbi (*)
2007-05-30 Includes\SpybotsC.sbi (*)
2005-02-17 Includes\Tracks.uti (*)
2007-05-16 Includes\Trojans.sbi (*)
2007-05-30 Includes\TrojansC.sbi (*)
nouveau rapport et supression des spywares infectés : (active X acrobat impossible à suprimer alors que j'ai suprimé acrobat)
--- Report generated: 2007-06-04 23:04 ---
E-MusicA: Réglages (Valeur du registre, fixed)
HKEY_USERS\S-1-5-21-329068152-854245398-941058211-1003\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\{686C970F-1D7D-4469-85D1-4B35763B56CC}
MS Office 9.0: Recently used files (59 files) (Répertoire, fixed)
C:\Documents and Settings\xavier\Application Data\Microsoft\Office\Récents\
Log: Activity: SchedLgU.Txt (Sauver le fichier, fixing failed)
C:\WINDOWS\SchedLgU.Txt
Internet Explorer: User agent (Modification du registre, fixed)
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent!=Mozilla/4.0 (compatible; MSIE; Win32)
Internet Explorer: User agent (Modification du registre, fixed)
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent!=Mozilla/4.0 (compatible; MSIE; Win32)
Internet Explorer: User agent (Modification du registre, fixed)
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent!=Mozilla/4.0 (compatible; MSIE; Win32)
Internet Explorer: User agent (Modification du registre, fixed)
HKEY_USERS\S-1-5-21-329068152-854245398-941058211-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent!=Mozilla/4.0 (compatible; MSIE; Win32)
Internet Explorer: User agent (Modification du registre, fixed)
HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent!=Mozilla/4.0 (compatible; MSIE; Win32)
MS Media Player: Client ID (Modification du registre, fixed)
HKEY_USERS\S-1-5-19\Software\Microsoft\MediaPlayer\Player\Settings\Client ID!=
MS Media Player: Client ID (Modification du registre, fixed)
HKEY_USERS\S-1-5-20\Software\Microsoft\MediaPlayer\Player\Settings\Client ID!=
MS Media Player: Anonymous ID (Modification du registre, fixed)
HKEY_USERS\S-1-5-21-329068152-854245398-941058211-1003\Software\Microsoft\MediaPlayer\Preferences\SendUserGUID!=B=0
MS Office 9.0: Internet history (Valeur du registre, fixed)
HKEY_USERS\S-1-5-21-329068152-854245398-941058211-1003\Software\Microsoft\Office\9.0\Common\Internet\LocationOfComponents
MS Office 9.0: Access recent file (1 fichiers) (Clé du registre, fixed)
HKEY_USERS\S-1-5-21-329068152-854245398-941058211-1003\Software\Microsoft\Office\9.0\Access\Settings
MS Office 9.0 (Word): Recently used file list (Valeur du registre, fixed)
HKEY_USERS\S-1-5-21-329068152-854245398-941058211-1003\Software\Microsoft\Office\9.0\Word\Data\Settings
MS Search Assistant: Typed search terms history (Clé du registre, fixed)
HKEY_USERS\S-1-5-21-329068152-854245398-941058211-1003\Software\Microsoft\Search Assistant\ACMru
MS Windows Backup 5.0: Last created backup set (Modification du registre, fixed)
HKEY_USERS\S-1-5-21-329068152-854245398-941058211-1003\Software\Microsoft\Ntbackup\Hardware\Logical Disk File!=
Windows: Drivers installation paths (Modification du registre, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\Installation Sources!=
Windows.OpenWith: Open with list - .CSS extension (2 fichiers) (Clé du registre, fixed)
HKEY_USERS\S-1-5-21-329068152-854245398-941058211-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.CSS\OpenWithList
Windows Explorer: Recent wallpaper list (44 fichiers) (Clé du registre, fixed)
HKEY_USERS\S-1-5-21-329068152-854245398-941058211-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Wallpaper\MRU
Windows Explorer: Recent file global history (Clé du registre, fixed)
HKEY_USERS\S-1-5-21-329068152-854245398-941058211-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs
Windows Media SDK: Computer name (Modification du registre, fixed)
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows Media\WMSDK\General\ComputerName!=ComputerName
Windows Media SDK: Computer name (Modification du registre, fixed)
HKEY_USERS\S-1-5-21-329068152-854245398-941058211-1003\Software\Microsoft\Windows Media\WMSDK\General\ComputerName!=ComputerName
Windows Media SDK: Computer name (Modification du registre, fixed)
HKEY_USERS\S-1-5-18\Software\Microsoft\Windows Media\WMSDK\General\ComputerName!=ComputerName
Windows Media SDK: Unique ID (Modification du registre, fixed)
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows Media\WMSDK\General\UniqueID!={00000000-0000-0000-0000-000000000000}
Windows Media SDK: Unique ID (Modification du registre, fixed)
HKEY_USERS\S-1-5-21-329068152-854245398-941058211-1003\Software\Microsoft\Windows Media\WMSDK\General\UniqueID!={00000000-0000-0000-0000-000000000000}
Windows Media SDK: Unique ID (Modification du registre, fixed)
HKEY_USERS\S-1-5-18\Software\Microsoft\Windows Media\WMSDK\General\UniqueID!={00000000-0000-0000-0000-000000000000}
Windows Media SDK: Volume serial number (Valeur du registre, fixed)
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows Media\WMSDK\General\VolumeSerialNumber
Windows Media SDK: Volume serial number (Valeur du registre, fixed)
HKEY_USERS\S-1-5-21-329068152-854245398-941058211-1003\Software\Microsoft\Windows Media\WMSDK\General\VolumeSerialNumber
Windows Media SDK: Volume serial number (Valeur du registre, fixed)
HKEY_USERS\S-1-5-18\Software\Microsoft\Windows Media\WMSDK\General\VolumeSerialNumber
--- Spybot - Search & Destroy version: 1.4 (build: 20050523) ---
2005-05-31 blindman.exe (1.0.0.1)
2005-05-31 SpybotSD.exe (1.4.0.3)
2005-05-31 TeaTimer.exe (1.4.0.2)
2007-06-02 unins000.exe (51.41.0.0)
2005-05-31 Update.exe (1.4.0.0)
2007-05-23 advcheck.dll (1.5.3.0)
2005-05-31 aports.dll (2.1.0.0)
2005-05-31 borlndmm.dll (7.0.4.453)
2005-05-31 delphimm.dll (7.0.4.453)
2005-05-31 SDHelper.dll (1.4.0.0)
2007-01-02 Tools.dll (2.0.1.0)
2005-05-31 UnzDll.dll (1.73.1.1)
2005-05-31 ZipDll.dll (1.73.2.0)
2007-05-30 Includes\Cookies.sbi (*)
2007-05-30 Includes\Dialer.sbi (*)
2007-05-30 Includes\DialerC.sbi (*)
2007-05-30 Includes\Hijackers.sbi (*)
2007-05-30 Includes\HijackersC.sbi (*)
2006-10-27 Includes\Keyloggers.sbi (*)
2007-05-30 Includes\KeyloggersC.sbi (*)
2007-05-30 Includes\Malware.sbi (*)
2007-05-30 Includes\MalwareC.sbi (*)
2007-03-21 Includes\PUPS.sbi (*)
2007-05-30 Includes\PUPSC.sbi (*)
2007-05-30 Includes\Revision.sbi (*)
2007-05-30 Includes\Security.sbi (*)
2007-05-30 Includes\SecurityC.sbi (*)
2007-05-30 Includes\Spybots.sbi (*)
2007-05-30 Includes\SpybotsC.sbi (*)
2005-02-17 Includes\Tracks.uti (*)
2007-05-16 Includes\Trojans.sbi (*)
2007-05-30 Includes\TrojansC.sbi (*)
4/ pour mon autre PC windows 2000
j'ai pas eu le temps de vérifier pour une description précise
de l'image que j'avais mis à la corbeille
MAis c'était photo petit format
c'était un couple qu baisait
photo trafiqué je crois un peu d'ailleur
Mais mainteant j''ai une coupure brusque du P4 windows 2000
avc un BIP continu je crois que c'est le processeur.
en fait j'interveti les cables claviers et couris + écran que je asse d'un pc à l'autre et pendat le sacna je sui salle voir
pour essayer de remettre un peu d'ordre come réinstaller le firewal mais j'ai pas eu le temps
/5 bien vu la 2ème DNS n'était pas ok.
le 1er octet à prirori est le meme pour les 2 DNS