Derniers tutoriels :
Sondage :
Publicité
Derniers articles :
![]() |
[RESOLU]Infecté par Trojan TratBHO - Version imprimable +- Forums d'entraide informatique - Les forums de PCW (http://forum.pcinfo-web.com) +-- Forum : Forum Informatique (/forumdisplay.php?fid=39) +--- Forum : Sécurité Informatique (/forumdisplay.php?fid=2) +--- Discussion : [RESOLU]Infecté par Trojan TratBHO (/showthread.php?tid=2091) |
[RESOLU]Infecté par Trojan TratBHO - Alex1-1 - 13-02-2008 21:52 PM Bonsoir a tous, depuis 3 jours, Avast arrete pas de s'affolercar j'ai un Trojan TratBHO . A chaque fois je le met en quarrentaine, mais rien a faire, il revient . En plus, presuqe toute les heures j'ai une fenettre internet explorer avec 10 onglets qui m'affiche des sites s'ouvrent . Je suis sous Windows Vista Edition Familial Premium . Voila le rapport Hijackthis : Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 22:35:41, on 13/02/2008 Platform: Windows Vista (WinNT 6.00.1904) MSIE: Internet Explorer v7.00 (7.00.6000.16575) Boot mode: Normal Running processes: C:\Windows\System32\smss.exe C:\Windows\system32\csrss.exe C:\Windows\system32\wininit.exe C:\Windows\system32\csrss.exe C:\Windows\system32\services.exe C:\Windows\system32\lsass.exe C:\Windows\system32\lsm.exe C:\Windows\system32\winlogon.exe C:\Windows\system32\svchost.exe C:\Windows\system32\svchost.exe C:\Windows\System32\svchost.exe C:\Windows\system32\Ati2evxx.exe C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe C:\Windows\system32\svchost.exe C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe C:\Windows\system32\svchost.exe C:\Windows\system32\Ati2evxx.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe C:\Acer\Empowering Technology\ePerformance\MemCheck.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Windows\system32\svchost.exe C:\Program Files\CyberLink\Shared Files\RichVideo.exe C:\Program Files\Spyware Doctor\svcntaux.exe C:\Program Files\Spyware Doctor\swdsvc.exe C:\Windows\system32\Dwm.exe C:\Windows\system32\taskeng.exe C:\Windows\Explorer.EXE C:\Program Files\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe C:\Windows\system32\svchost.exe C:\Program Files\Spyware Doctor\SDTrayApp.exe C:\Windows\System32\svchost.exe C:\Windows\system32\SearchIndexer.exe C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe C:\Windows\system32\WUDFHost.exe C:\Program Files\Windows Defender\MSASCui.exe C:\Windows\RtHDVCpl.exe C:\Acer\Empowering Technology\SysMonitor.exe C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe C:\Windows\tsnpstd3.exe C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe C:\Program Files\Alwil Software\Avast4\ashDisp.exe C:\Windows\vsnpstd3.exe C:\Program Files\ScanSoft\OmniPageSE4.0\OpWareSE4.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Windows\ehome\ehtray.exe C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe C:\Program Files\Macrogaming\SweetIM\SweetIM.exe C:\Windows\System32\mobsync.exe C:\Windows\System32\rundll32.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\Windows\system32\taskeng.exe C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE C:\Windows\ehome\ehmsas.exe C:\Windows\system32\wbem\unsecapp.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\taskeng.exe C:\Users\eric\Desktop\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://fr.rd.yahoo.com/customize/y [...] .yahoo.com R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.fr.acer.yahoo.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://fr.fr.acer.yahoo.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.fr.acer.yahoo.com R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.rd.yahoo.com/customize/y [...] .yahoo.com R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file) R3 - URLSearchHook: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll (file missing) O1 - Hosts: ::1 localhost O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe O4 - HKLM\..\Run: [Acer Empowering Technology Monitor] C:\Acer\Empowering Technology\SysMonitor.exe O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe O4 - HKLM\..\Run: [WarReg_PopUp] C:\Acer\WR_PopUp\WarReg_PopUp.exe O4 - HKLM\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe O4 - HKLM\..\Run: [Apanel] C:\ACERSW\config\NewSetApanel.cmd O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe" O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [tsnpstd3] C:\Windows\tsnpstd3.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [snpstd3] C:\Windows\vsnpstd3.exe O4 - HKLM\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe" O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun O4 - HKCU\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden O4 - HKCU\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe O4 - HKCU\..\Run: [VoipBuster] "C:\Program Files\VoipBuster.com\VoipBuster\VoipBuster.exe" -nosplash -minimized O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 52\axcmd.exe" /automount O4 - HKCU\..\Run: [MSServer] rundll32.exe C:\Users\eric\AppData\Local\Temp\geeed.dll,#1 O4 - HKCU\..\Run: [cmds] rundll32.exe C:\Users\eric\AppData\Local\Temp\vtsqn.dll,c O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL') O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL') O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU') O4 - HKUS\S-1-5-18\..\Run: [] (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [] (User 'Default user') O4 - Startup: IMVU.lnk = ? O4 - Global Startup: Empowering Technology Launcher.lnk = ? O4 - Global Startup: PCM Media Sharing.lnk = C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Users\eric\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing) O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O13 - Gopher Prefix: O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-F [...] E_UNO1.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/bina [...] b56649.cab O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/bina [...] b57213.cab O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/bina [...] b56907.cab O16 - DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} (GoPetsWeb Control) - https://secure.gopetslive.com/dev/GoPetsWeb.cab O23 - Service: Acer HomeMedia Connect Service - CyberLink - C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe O23 - Service: ePerformance Service (AcerMemUsageCheckService) - Unknown owner - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing) O23 - Service: eDSService.exe (eDataSecurity Service) - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe -- End of file - 12196 bytes Voila Bonne soirée - Troll - 13-02-2008 21:58 PM Salut à toi Alex1-1, Bienvenue sur PCInfo-Web, si tu souhaites te présenter, passe par la section "présentations" ![]() Effectues cette procédure, ensuite poste nous le rapport de ewido/antispyware (après désinfection). Voilà voilou ![]() - Alex1-1 - 14-02-2008 13:10 PM Aie, sa ma tout niké ! New Scan HijackThis : Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 14:07:35, on 14/02/2008 Platform: Windows Vista (WinNT 6.00.1904) MSIE: Internet Explorer v7.00 (7.00.6000.16609) Boot mode: Normal Running processes: C:\Windows\System32\smss.exe C:\Windows\system32\csrss.exe C:\Windows\system32\wininit.exe C:\Windows\system32\csrss.exe C:\Windows\system32\services.exe C:\Windows\system32\lsass.exe C:\Windows\system32\lsm.exe C:\Windows\system32\winlogon.exe C:\Windows\system32\svchost.exe C:\Windows\system32\svchost.exe C:\Windows\System32\svchost.exe C:\Windows\system32\Ati2evxx.exe C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe C:\Windows\system32\svchost.exe C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe C:\Windows\system32\Ati2evxx.exe C:\Windows\system32\svchost.exe C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe C:\Acer\Empowering Technology\ePerformance\MemCheck.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Windows\system32\svchost.exe C:\Program Files\CyberLink\Shared Files\RichVideo.exe C:\Program Files\Spyware Doctor\svcntaux.exe C:\Program Files\Spyware Doctor\swdsvc.exe C:\Program Files\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe C:\Windows\system32\svchost.exe C:\Windows\System32\svchost.exe C:\Windows\system32\SearchIndexer.exe C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe C:\Windows\system32\WUDFHost.exe C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\RtHDVCpl.exe C:\Acer\Empowering Technology\SysMonitor.exe C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe C:\Program Files\Spyware Doctor\SDTrayApp.exe C:\Windows\tsnpstd3.exe C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe C:\Program Files\Alwil Software\Avast4\ashDisp.exe C:\Windows\system32\wbem\unsecapp.exe C:\Windows\vsnpstd3.exe C:\Program Files\Macrogaming\SweetIM\SweetIM.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files\ScanSoft\OmniPageSE4.0\OpWareSE4.exe C:\Windows\ehome\ehtray.exe C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe C:\Windows\System32\rundll32.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\Windows\System32\rundll32.exe C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe C:\Program Files\Windows Defender\MSASCui.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Windows\ehome\ehmsas.exe C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE C:\Program Files\Mozilla Firefox\firefox.exe C:\Windows\explorer.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\taskeng.exe C:\Users\eric\Desktop\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://fr.rd.yahoo.com/customize/ycomp/defaults/sp/*http://fr.yahoo.com R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.fr.acer.yahoo.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://fr.fr.acer.yahoo.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.fr.acer.yahoo.com R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.rd.yahoo.com/customize/ycomp/defaults/su/*http://fr.yahoo.com R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file) R3 - URLSearchHook: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll (file missing) O1 - Hosts: ::1 localhost O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe O4 - HKLM\..\Run: [Acer Empowering Technology Monitor] C:\Acer\Empowering Technology\SysMonitor.exe O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe O4 - HKLM\..\Run: [WarReg_PopUp] C:\Acer\WR_PopUp\WarReg_PopUp.exe O4 - HKLM\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe O4 - HKLM\..\Run: [Apanel] C:\ACERSW\config\NewSetApanel.cmd O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe" O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [tsnpstd3] C:\Windows\tsnpstd3.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [snpstd3] C:\Windows\vsnpstd3.exe O4 - HKLM\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe" O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun O4 - HKCU\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden O4 - HKCU\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe O4 - HKCU\..\Run: [VoipBuster] "C:\Program Files\VoipBuster.com\VoipBuster\VoipBuster.exe" -nosplash -minimized O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 52\axcmd.exe" /automount O4 - HKCU\..\Run: [MSServer] rundll32.exe C:\Users\eric\AppData\Local\Temp\xxwvt.dll,#1 O4 - HKCU\..\Run: [cmds] rundll32.exe C:\Users\eric\AppData\Local\Temp\hggff.dll,c O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe O4 - HKCU\..\Run: [MS Juan] rundll32 "C:\Users\eric\AppData\Local\Temp\ymvmbngp.dll",run O4 - HKCU\..\Run: [e4d7fbc0] rundll32.exe "C:\Users\eric\AppData\Local\Temp\ijbylucb.dll",b O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL') O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL') O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU') O4 - HKUS\S-1-5-18\..\Run: [] (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [] (User 'Default user') O4 - Startup: IMVU.lnk = ? O4 - Global Startup: Empowering Technology Launcher.lnk = ? O4 - Global Startup: PCM Media Sharing.lnk = C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Users\eric\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing) O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O13 - Gopher Prefix: O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab57213.cab O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab O16 - DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} (GoPetsWeb Control) - https://secure.gopetslive.com/dev/GoPetsWeb.cab O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe O23 - Service: Acer HomeMedia Connect Service - CyberLink - C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe O23 - Service: ePerformance Service (AcerMemUsageCheckService) - Unknown owner - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing) O23 - Service: eDSService.exe (eDataSecurity Service) - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe -- End of file - 12801 bytes Alors, j'ai télécharger les autres, mais Ewido n'est pas compatible Vista, alors j'ai pris AVG anti-pyware (qui est crée pas la meme société), voici le log : --------------------------------------------------------- AVG Anti-Spyware - Rapport d'analyse --------------------------------------------------------- + Créé à: 00:46:51 14/02/2008 + Résultat de l'analyse: :mozilla.184:C:\Users\aurelie\AppData\Roaming\Mozilla\Firefox\Profiles\cwq649m7.default\cookies.txt -> TrackingCookie.2o7 : Aucune action entreprise. C:\Users\aurelie\AppData\Roaming\Microsoft\Windows\Cookies\aurelie@2o7[2].txt -> TrackingCookie.2o7 : Aucune action entreprise. :mozilla.130:C:\Users\aurelie\AppData\Roaming\Mozilla\Firefox\Profiles\cwq649m7.default\cookies.txt -> TrackingCookie.Adbrite : Aucune action entreprise. :mozilla.131:C:\Users\aurelie\AppData\Roaming\Mozilla\Firefox\Profiles\cwq649m7.default\cookies.txt -> TrackingCookie.Adbrite : Aucune action entreprise. :mozilla.132:C:\Users\aurelie\AppData\Roaming\Mozilla\Firefox\Profiles\cwq649m7.default\cookies.txt -> TrackingCookie.Adbrite : Aucune action entreprise. :mozilla.133:C:\Users\aurelie\AppData\Roaming\Mozilla\Firefox\Profiles\cwq649m7.default\cookies.txt -> TrackingCookie.Adbrite : Aucune action entreprise. :mozilla.134:C:\Users\aurelie\AppData\Roaming\Mozilla\Firefox\Profiles\cwq649m7.default\cookies.txt -> TrackingCookie.Adbrite : Aucune action entreprise. :mozilla.191:C:\Users\aurelie\AppData\Roaming\Mozilla\Firefox\Profiles\cwq649m7.default\cookies.txt -> TrackingCookie.Adtech : Aucune action entreprise. :mozilla.192:C:\Users\aurelie\AppData\Roaming\Mozilla\Firefox\Profiles\cwq649m7.default\cookies.txt -> TrackingCookie.Adtech : Aucune action entreprise. :mozilla.193:C:\Users\aurelie\AppData\Roaming\Mozilla\Firefox\Profiles\cwq649m7.default\cookies.txt -> TrackingCookie.Advertising : Aucune action entreprise. :mozilla.194:C:\Users\aurelie\AppData\Roaming\Mozilla\Firefox\Profiles\cwq649m7.default\cookies.txt -> TrackingCookie.Advertising : Aucune action entreprise. :mozilla.195:C:\Users\aurelie\AppData\Roaming\Mozilla\Firefox\Profiles\cwq649m7.default\cookies.txt -> TrackingCookie.Advertising : Aucune action entreprise. :mozilla.196:C:\Users\aurelie\AppData\Roaming\Mozilla\Firefox\Profiles\cwq649m7.default\cookies.txt -> TrackingCookie.Advertising : Aucune action entreprise. C:\Users\aurelie\AppData\Roaming\Microsoft\Windows\Cookies\Low\aurelie@atdmt[1].txt -> TrackingCookie.Atdmt : Aucune action entreprise. C:\Users\aurelie\AppData\Roaming\Microsoft\Windows\Cookies\aurelie@atdmt[2].txt -> TrackingCookie.Atdmt : Aucune action entreprise. C:\Users\aurelie\AppData\Roaming\Microsoft\Windows\Cookies\Low\aurelie@bluestreak[2].txt -> TrackingCookie.Bluestreak : Aucune action entreprise. C:\Users\aurelie\AppData\Roaming\Microsoft\Windows\Cookies\Low\aurelie@doubleclick[2].txt -> TrackingCookie.Doubleclick : Aucune action entreprise. C:\Users\aurelie\AppData\Roaming\Microsoft\Windows\Cookies\aurelie@doubleclick[1].txt -> TrackingCookie.Doubleclick : Aucune action entreprise. :mozilla.22:C:\Users\aurelie\AppData\Roaming\Mozilla\Firefox\Profiles\cwq649m7.default\cookies.txt -> TrackingCookie.Estat : Aucune action entreprise. :mozilla.92:C:\Users\aurelie\AppData\Roaming\Mozilla\Firefox\Profiles\cwq649m7.default\cookies.txt -> TrackingCookie.Euroclick : Aucune action entreprise. :mozilla.93:C:\Users\aurelie\AppData\Roaming\Mozilla\Firefox\Profiles\cwq649m7.default\cookies.txt -> TrackingCookie.Euroclick : Aucune action entreprise. :mozilla.94:C:\Users\aurelie\AppData\Roaming\Mozilla\Firefox\Profiles\cwq649m7.default\cookies.txt -> TrackingCookie.Euroclick : Aucune action entreprise. :mozilla.95:C:\Users\aurelie\AppData\Roaming\Mozilla\Firefox\Profiles\cwq649m7.default\cookies.txt -> TrackingCookie.Euroclick : Aucune action entreprise. :mozilla.96:C:\Users\aurelie\AppData\Roaming\Mozilla\Firefox\Profiles\cwq649m7.default\cookies.txt -> TrackingCookie.Euroclick : Aucune action entreprise. :mozilla.97:C:\Users\aurelie\AppData\Roaming\Mozilla\Firefox\Profiles\cwq649m7.default\cookies.txt -> TrackingCookie.Euroclick : Aucune action entreprise. C:\Users\aurelie\AppData\Roaming\Microsoft\Windows\Cookies\Low\aurelie@mediaplex[1].txt -> TrackingCookie.Mediaplex : Aucune action entreprise. :mozilla.28:C:\Users\aurelie\AppData\Roaming\Mozilla\Firefox\Profiles\cwq649m7.default\cookies.txt -> TrackingCookie.Overture : Aucune action entreprise. :mozilla.144:C:\Users\aurelie\AppData\Roaming\Mozilla\Firefox\Profiles\cwq649m7.default\cookies.txt -> TrackingCookie.Realmedia : Aucune action entreprise. :mozilla.145:C:\Users\aurelie\AppData\Roaming\Mozilla\Firefox\Profiles\cwq649m7.default\cookies.txt -> TrackingCookie.Realmedia : Aucune action entreprise. :mozilla.188:C:\Users\aurelie\AppData\Roaming\Mozilla\Firefox\Profiles\cwq649m7.default\cookies.txt -> TrackingCookie.Revsci : Aucune action entreprise. :mozilla.190:C:\Users\aurelie\AppData\Roaming\Mozilla\Firefox\Profiles\cwq649m7.default\cookies.txt -> TrackingCookie.Revsci : Aucune action entreprise. :mozilla.171:C:\Users\aurelie\AppData\Roaming\Mozilla\Firefox\Profiles\cwq649m7.default\cookies.txt -> TrackingCookie.Serving-sys : Aucune action entreprise. :mozilla.172:C:\Users\aurelie\AppData\Roaming\Mozilla\Firefox\Profiles\cwq649m7.default\cookies.txt -> TrackingCookie.Serving-sys : Aucune action entreprise. :mozilla.173:C:\Users\aurelie\AppData\Roaming\Mozilla\Firefox\Profiles\cwq649m7.default\cookies.txt -> TrackingCookie.Serving-sys : Aucune action entreprise. :mozilla.174:C:\Users\aurelie\AppData\Roaming\Mozilla\Firefox\Profiles\cwq649m7.default\cookies.txt -> TrackingCookie.Serving-sys : Aucune action entreprise. :mozilla.175:C:\Users\aurelie\AppData\Roaming\Mozilla\Firefox\Profiles\cwq649m7.default\cookies.txt -> TrackingCookie.Serving-sys : Aucune action entreprise. :mozilla.176:C:\Users\aurelie\AppData\Roaming\Mozilla\Firefox\Profiles\cwq649m7.default\cookies.txt -> TrackingCookie.Serving-sys : Aucune action entreprise. :mozilla.177:C:\Users\aurelie\AppData\Roaming\Mozilla\Firefox\Profiles\cwq649m7.default\cookies.txt -> TrackingCookie.Serving-sys : Aucune action entreprise. C:\Users\aurelie\AppData\Roaming\Microsoft\Windows\Cookies\aurelie@bs.serving-sys[2].txt -> TrackingCookie.Serving-sys : Aucune action entreprise. C:\Users\aurelie\AppData\Roaming\Microsoft\Windows\Cookies\aurelie@serving-sys[2].txt -> TrackingCookie.Serving-sys : Aucune action entreprise. :mozilla.73:C:\Users\aurelie\AppData\Roaming\Mozilla\Firefox\Profiles\cwq649m7.default\cookies.txt -> TrackingCookie.Smartadserver : Aucune action entreprise. :mozilla.74:C:\Users\aurelie\AppData\Roaming\Mozilla\Firefox\Profiles\cwq649m7.default\cookies.txt -> TrackingCookie.Smartadserver : Aucune action entreprise. :mozilla.75:C:\Users\aurelie\AppData\Roaming\Mozilla\Firefox\Profiles\cwq649m7.default\cookies.txt -> TrackingCookie.Smartadserver : Aucune action entreprise. C:\Users\aurelie\AppData\Roaming\Microsoft\Windows\Cookies\aurelie@smartadserver[1].txt -> TrackingCookie.Smartadserver : Aucune action entreprise. :mozilla.169:C:\Users\aurelie\AppData\Roaming\Mozilla\Firefox\Profiles\cwq649m7.default\cookies.txt -> TrackingCookie.Weborama : Aucune action entreprise. :mozilla.170:C:\Users\aurelie\AppData\Roaming\Mozilla\Firefox\Profiles\cwq649m7.default\cookies.txt -> TrackingCookie.Weborama : Aucune action entreprise. C:\Users\aurelie\AppData\Roaming\Microsoft\Windows\Cookies\aurelie@weborama[1].txt -> TrackingCookie.Weborama : Aucune action entreprise. :mozilla.79:C:\Users\aurelie\AppData\Roaming\Mozilla\Firefox\Profiles\cwq649m7.default\cookies.txt -> TrackingCookie.Yieldmanager : Aucune action entreprise. :mozilla.80:C:\Users\aurelie\AppData\Roaming\Mozilla\Firefox\Profiles\cwq649m7.default\cookies.txt -> TrackingCookie.Yieldmanager : Aucune action entreprise. :mozilla.81:C:\Users\aurelie\AppData\Roaming\Mozilla\Firefox\Profiles\cwq649m7.default\cookies.txt -> TrackingCookie.Yieldmanager : Aucune action entreprise. :mozilla.82:C:\Users\aurelie\AppData\Roaming\Mozilla\Firefox\Profiles\cwq649m7.default\cookies.txt -> TrackingCookie.Yieldmanager : Aucune action entreprise. Fin du rapport Maintenant, des que je veux remettre les retaurations, des que je veux acceder a mes documents etc ... (tout ce qu'utilise l'explorateur windows) , Explorer.exe reboot et ducoup impossible d'y acceder ... Comment faire ? - Zarnergun - 14-02-2008 16:44 PM Salut, Les no names ne servent a rien ca : O4 - HKCU\..\Run: [MSServer] rundll32.exe C:\Users\eric\AppData\Local\Temp\xxwvt.dll,#1 et ca : O4 - HKCU\..\Run: [cmds] rundll32.exe C:\Users\eric\AppData\Local\Temp\hggff.dll,c et ca : O4 - HKCU\..\Run: [e4d7fbc0] rundll32.exe "C:\Users\eric\AppData\Local\Temp\ijbylucb.dll",b et ca : O4 - HKCU\..\Run: [MS Juan] rundll32 "C:\Users\eric\AppData\Local\Temp\ymvmbngp.dll",run C'est bizarre Et ca je connais pas : O16 - DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} (GoPetsWeb Control) - https://secure.gopetslive.com/dev/GoPetsWeb.cab - Bilifly - 14-02-2008 20:47 PM Bonsoir à vous et bienvenue Alex1-1 Commençons par le commencement Redémarres ton ordi Lances CCleaner Sur la gauche clic sur "Outils" Puis clic sur "Sauver le texte" Tu enregistres le fichier texte sur ton bureau en lui donnant un nom Puis envois son contenu dans ta prochaine réponse, afin de virer les logiciels pourris A suivre - -Sh4D0w- - 24-02-2008 16:12 PM tout c'est arrangé ? je peux le lock ou pas ? - Bilifly - 24-02-2008 16:40 PM Bonsoir à vous Il n'y a aucune nouvelle, Up ? Pourquoi veux-tu le locker ? ![]() [RESOLU]Infecté par Trojan TratBHO - -Sh4D0w- - 24-02-2008 17:30 PM enfin marquer résolu dsl je m'étais trompé une habitude d'autres forums ![]() |