Se connecter / S'enregistrer
Votre question

Problème de virus wow

Tags :
  • Windows
  • Sécurité
Dernière réponse : dans Sécurité et virus
26 Septembre 2009 20:14:28

bonjour, l'attaque sur mon PC est énorme!!! Je crois que j'ai déjà vu pire, mais je suis en doutes, tellement je suis choqué de la santé de cet ordinateur hahaha

Pour commencé, voilà mon rapport HijackThis suivi du rapport d'AntiMalware.




HijackThis

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:12:18, on 27/9/2552
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.20661)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Premium\sched.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Avira\AntiVir PersonalEdition Premium\avesvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\FolderSize\FolderSizeSvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\VistaDrive\VistaDrive.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\Program Files\Visual+\PowerMenu\PowerMenu.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Avira\AntiVir PersonalEdition Premium\avgnt.exe
C:\Program Files\Creative\Shared Files\CAMTRAY.EXE
C:\WINDOWS\vVX1000.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\LClock\LClock.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\WINDOWS\system32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Java\jre6\bin\jucheck.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Administrator\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource=10&ctid=CT210247...
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://login.live.com/ppsecure/sha1auth.srf?lc=1054
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: PHPNukeFR Toolbar - {258fe8b8-a13c-4b91-9a0c-c2d3cab8b990} - C:\Program Files\PHPNukeFR\tbPHP0.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: PHPNukeFR Toolbar - {258fe8b8-a13c-4b91-9a0c-c2d3cab8b990} - C:\Program Files\PHPNukeFR\tbPHP0.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: PHPNukeFR Toolbar - {258fe8b8-a13c-4b91-9a0c-c2d3cab8b990} - C:\Program Files\PHPNukeFR\tbPHP0.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [VistaDrive] C:\WINDOWS\VistaDrive\VistaDrive.exe
O4 - HKLM\..\Run: [PowerMenu] C:\Program Files\Visual+\PowerMenu\PowerMenu.exe
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Premium\avgnt.exe" /min
O4 - HKLM\..\Run: [Creative WebCam Tray] C:\Program Files\Creative\Shared Files\CAMTRAY.EXE
O4 - HKLM\..\Run: [VX1000] C:\WINDOWS\vVX1000.exe
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "E:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [LClock] C:\Program Files\LClock\LClock.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [flawmore] C:\DOCUME~1\ADMINI~1\APPLIC~1\FLAGLI~1\bibthis.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [LClock] C:\Program Files\LClock\LClock.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'Default user')
O4 - Startup: OpenOffice.org 3.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-US/a-UNO1/GAME_UNO1.ca...
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPACl...
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab569...
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Avira AntiVir Premium MailGuard (AntiVirMailService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\avmailc.exe
O23 - Service: Avira AntiVir Premium Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\sched.exe
O23 - Service: Avira AntiVir Premium Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\avguard.exe
O23 - Service: Avira AntiVir Premium WebGuard (antivirwebservice) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\AVWEBGRD.EXE
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Avira AntiVir Premium MailGuard helper service (AVEService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\avesvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: Folder Size (FolderSize) - Brio - C:\Program Files\FolderSize\FolderSizeSvc.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

--
End of file - 9479 bytes







Malwarebytes' Anti-Malware

Malwarebytes' Anti-Malware 1.41
Version de la base de donn้es: 2860
Windows 5.1.2600 Service Pack 2

27/9/2552 13:21:40
mbam-log-2009-09-27 (13-21-39).txt

Type de recherche: Examen complet (C:\|E:\|F:\|)
El้ments examin้s: 153182
Temps ้coul้: 34 minute(s), 39 second(s)

Processus m้moire infect้(s): 0
Module(s) m้moire infect้(s): 0
Cl้(s) du Registre infect้e(s): 0
Valeur(s) du Registre infect้e(s): 2
El้ment(s) de donn้es du Registre infect้(s): 4
Dossier(s) infect้(s): 0
Fichier(s) infect้(s): 2

Processus m้moire infect้(s):
(Aucun ้l้ment nuisible d้tect้)

Module(s) m้moire infect้(s):
(Aucun ้l้ment nuisible d้tect้)

Cl้(s) du Registre infect้e(s):
(Aucun ้l้ment nuisible d้tect้)

Valeur(s) du Registre infect้e(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\ForceClassicControlPanel (Hijack.ControlPanelStyle) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Base frag grid bows (Trojan.Agent) -> Quarantined and deleted successfully.

El้ment(s) de donn้es du Registre infect้(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSMHelp (Hijack.Help) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Dossier(s) infect้(s):
(Aucun ้l้ment nuisible d้tect้)

Fichier(s) infect้(s):
C:\WINDOWS\system32\TCPLimit.exe (Malware.Tool) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Cast ping base frag\Creative Close.exe (Trojan.Agent) -> Delete on reboot.



thank you very much ! :D 

Autres pages sur : probleme virus wow

a c 267 8 Sécurité
a b 9 Windows
26 Septembre 2009 20:33:52

Bonjour,

  • Télécharge Lop S&D sur ton Bureau.
  • Double-clique dessus pour lancer l'installation.
  • Puis double-clique sur le raccourci Lop S&D présent sur ton Bureau.
    (Sous Vista, il faut cliquer droit sur le raccourci Lop S&D et choisir Exécuter en tant qu'administrateur)
  • Sélectionne la langue souhaitée, puis choisis l'option 1 (Recherche) .
  • Patiente jusqu'à la fin du scan.
  • Poste le rapport généré (C:\lopR.txt).
    26 Septembre 2009 20:52:09


    --------------------\\ Lop S&D 4.2.5-0 XP/Vista

    Microsoft Windows XP Professional ( v5.1.2600 ) Service Pack 2
    X86-based PC ( Uniprocessor Free : AMD Turion(tm) 64 Mobile Technology MK-36 )
    BIOS : Ver 1.00PARTTBL
    USER : Administrator ( Administrator )
    BOOT : Normal boot
    Antivirus : ESET NOD32 Antivirus 3.0 3.0 (Activated)
    C:\ (Local Disk) - NTFS - Total:48 Go (Free:32 Go)
    D:\ (CD or DVD)
    E:\ (Local Disk) - NTFS - Total:62 Go (Free:62 Go)
    F:\ (USB) - FAT - Total:1932 Mo (Free:0 Go)

    "C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
    Option : [1] ( Sun 09/27/2009|20:47 )

    --------------------\\ Listing des dossiers dans APPLIC~1

    [11/09/2008|02:01] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Adobe
    [05/31/2009|06:31] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Apple Computer
    [09/10/2008|08:32] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> BSplayer
    [08/25/2008|10:43] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> BSplayer Pro
    [05/15/2008|07:57] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Creative
    [06/26/2009|08:43] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> dvdcss
    [09/10/2009|12:58] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Flag Link
    [06/13/2009|07:46] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> HP
    [05/14/2008|02:56] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Identities
    [11/02/2008|01:15] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> ImgBurn
    [08/08/2009|03:39] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> InstallShield
    [05/15/2008|07:53] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> InterTrust
    [08/08/2009|03:41] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> LG Electronics
    [05/14/2008|06:23] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Macromedia
    [09/27/2009|12:16] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Malwarebytes
    [09/27/2008|09:27] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Media Player Classic
    [05/14/2008|06:01] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Microsoft
    [05/14/2008|03:04] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Mozilla
    [05/12/2009|10:16] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> OpenOffice.org
    [02/11/2009|09:41] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Real
    [07/12/2008|04:08] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> SecuROM
    [08/22/2008|04:09] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Sibelius Software
    [09/21/2009|04:37] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Skype
    [09/21/2009|02:38] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> skypePM
    [05/30/2008|04:44] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Sun
    [05/14/2008|03:04] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Talkback
    [05/14/2008|03:12] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> uTorrent
    [05/30/2009|10:09] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> vlc
    [05/14/2008|03:30] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> WinRAR

    [01/31/2009|10:22] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> {3276BE95_AF08_429F_A64F_CA64CB79BCF6}
    [05/14/2008|02:53] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Adobe
    [05/26/2008|10:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Apple
    [05/26/2008|10:24] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Apple Computer
    [05/14/2008|05:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Avira
    [09/27/2009|01:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Cast ping base frag
    [05/14/2008|02:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> ESET
    [06/13/2009|07:11] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> HP
    [09/27/2009|12:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Malwarebytes
    [09/01/2008|06:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Messenger Plus!
    [07/04/2008|11:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Microsoft
    [08/19/2008|09:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Skype
    [05/14/2008|02:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Windows Genuine Advantage

    [05/14/2008|02:42] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Microsoft

    [06/13/2009|07:11] C:\DOCUME~1\LOCALS~1\APPLIC~1\<DIR> HP
    [05/14/2008|02:48] C:\DOCUME~1\LOCALS~1\APPLIC~1\<DIR> Microsoft

    [05/14/2008|02:48] C:\DOCUME~1\NETWOR~1\APPLIC~1\<DIR> Microsoft

    --------------------\\ Tโches planifi้es dans C:\WINDOWS\tasks

    [09/27/2009 08:00 PM][--ah-----] C:\WINDOWS\tasks\A8ECBE18918B3250.job
    [08/08/2009 09:59 AM][--a------] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
    [05/18/2008 01:10 PM][--ah-----] C:\WINDOWS\tasks\Microsoft_Hardware_Launch_setup_exe.job
    [09/27/2009 01:25 PM][--ah-----] C:\WINDOWS\tasks\SA.DAT
    [02/28/2008 12:38 AM][-r-h-----] C:\WINDOWS\tasks\desktop.ini

    ( A8ECBE18918B3250.job )=( c:\docume~1\admini~1\applic~1\flagli~1\BagsWmaDefy.exe )

    --------------------\\ Listing des dossiers dans C:\Program Files

    [05/14/2008|02:46] C:\Program Files\<DIR> 7-Zip
    [05/15/2008|07:53] C:\Program Files\<DIR> Adobe
    [05/14/2008|02:46] C:\Program Files\<DIR> Alky for Applications
    [07/03/2008|01:55] C:\Program Files\<DIR> AMT
    [11/18/2008|07:14] C:\Program Files\<DIR> Apple Software Update
    [05/14/2008|05:51] C:\Program Files\<DIR> Avira
    [05/28/2008|09:26] C:\Program Files\<DIR> AviSynth 2.5
    [01/31/2009|10:03] C:\Program Files\<DIR> Bonjour
    [12/19/2008|09:51] C:\Program Files\<DIR> BS.Player ControlBar
    [05/14/2008|02:53] C:\Program Files\<DIR> CD-DVD
    [08/20/2008|09:04] C:\Program Files\<DIR> Circle Developement
    [05/14/2008|02:54] C:\Program Files\<DIR> Combined Community Codec Pack
    [05/26/2008|10:21] C:\Program Files\<DIR> Common Files
    [05/14/2008|02:37] C:\Program Files\<DIR> ComPlus Applications
    [01/02/2009|03:17] C:\Program Files\<DIR> Conduit
    [05/15/2008|06:27] C:\Program Files\<DIR> CONEXANT
    [05/14/2008|02:54] C:\Program Files\<DIR> CPE17
    [05/18/2008|12:42] C:\Program Files\<DIR> Creative
    [01/17/2009|09:09] C:\Program Files\<DIR> DivX
    [06/18/2009|09:40] C:\Program Files\<DIR> EA GAMES
    [05/29/2008|05:59] C:\Program Files\<DIR> eRightSoft
    [05/14/2008|02:54] C:\Program Files\<DIR> ESET
    [09/10/2009|12:56] C:\Program Files\<DIR> Flag Link
    [05/14/2008|02:54] C:\Program Files\<DIR> FolderSize
    [05/14/2008|02:36] C:\Program Files\<DIR> HashTab Shell Extension
    [06/13/2009|06:53] C:\Program Files\<DIR> Hewlett-Packard
    [08/07/2009|05:05] C:\Program Files\<DIR> HORRE
    [06/13/2009|07:09] C:\Program Files\<DIR> HP
    [05/14/2008|02:54] C:\Program Files\<DIR> ImgBurn
    [08/08/2009|07:34] C:\Program Files\<DIR> InstallShield Installation Information
    [05/14/2008|02:51] C:\Program Files\<DIR> Internet Explorer
    [01/31/2009|10:22] C:\Program Files\<DIR> iPod
    [01/31/2009|10:22] C:\Program Files\<DIR> iTunes
    [05/12/2009|10:07] C:\Program Files\<DIR> Java
    [05/12/2009|10:08] C:\Program Files\<DIR> JRE
    [05/14/2008|02:37] C:\Program Files\<DIR> LClock
    [08/08/2009|11:30] C:\Program Files\<DIR> LG Electronics
    [08/20/2009|01:02] C:\Program Files\<DIR> LG PC Suite II
    [08/19/2009|09:41] C:\Program Files\<DIR> LGInternetKit
    [08/05/2009|10:14] C:\Program Files\<DIR> Messenger Plus! Live
    [04/13/2009|12:48] C:\Program Files\<DIR> Microsoft Games
    [05/18/2008|01:15] C:\Program Files\<DIR> Microsoft LifeCam
    [05/14/2008|02:36] C:\Program Files\<DIR> Microsoft PowerToys
    [05/14/2008|02:39] C:\Program Files\<DIR> Movie Maker
    [09/27/2009|08:45] C:\Program Files\<DIR> Mozilla Firefox
    [05/14/2008|02:36] C:\Program Files\<DIR> MSN Gaming Zone
    [05/14/2008|02:39] C:\Program Files\<DIR> NetMeeting
    [05/14/2008|02:40] C:\Program Files\<DIR> Online Services
    [05/12/2009|10:08] C:\Program Files\<DIR> OpenOffice.org 3
    [05/14/2008|02:39] C:\Program Files\<DIR> Outlook Express
    [03/09/2009|06:01] C:\Program Files\<DIR> PHPNukeFR
    [01/31/2009|10:19] C:\Program Files\<DIR> QuickTime
    [05/14/2008|04:28] C:\Program Files\<DIR> Realtek
    [08/22/2008|04:08] C:\Program Files\<DIR> Sibelius Software
    [08/19/2008|09:00] C:\Program Files\<DIR> Skype
    [05/14/2008|02:54] C:\Program Files\<DIR> The KMPlayer
    [05/14/2008|02:56] C:\Program Files\<DIR> Uninstall Information
    [05/14/2008|02:36] C:\Program Files\<DIR> Unlocker
    [05/14/2008|03:07] C:\Program Files\<DIR> uTorrent
    [05/12/2009|07:03] C:\Program Files\<DIR> VideoLAN
    [05/14/2008|02:36] C:\Program Files\<DIR> Visual+
    [05/14/2008|02:46] C:\Program Files\<DIR> VisualTaskTips
    [08/25/2008|10:42] C:\Program Files\<DIR> Webteh
    [05/14/2008|02:55] C:\Program Files\<DIR> Windows Live
    [05/14/2008|02:36] C:\Program Files\<DIR> Windows Media Connect 2
    [05/18/2008|12:59] C:\Program Files\<DIR> Windows Media Player
    [05/14/2008|02:35] C:\Program Files\<DIR> Windows NT
    [05/14/2008|02:52] C:\Program Files\<DIR> Windows Sidebar
    [05/14/2008|02:40] C:\Program Files\<DIR> WindowsUpdate
    [05/14/2008|02:56] C:\Program Files\<DIR> WinRAR

    --------------------\\ Listing des dossiers dans C:\Program Files\Common Files

    [05/14/2008|02:53] C:\Program Files\Common Files\<DIR> Adobe
    [01/31/2009|10:18] C:\Program Files\Common Files\<DIR> Apple
    [06/13/2009|06:52] C:\Program Files\Common Files\<DIR> Hewlett-Packard
    [06/13/2009|07:09] C:\Program Files\Common Files\<DIR> HP
    [05/15/2008|07:50] C:\Program Files\Common Files\<DIR> InstallShield
    [05/14/2008|02:51] C:\Program Files\Common Files\<DIR> Java
    [05/14/2008|02:57] C:\Program Files\Common Files\<DIR> Microsoft Shared
    [05/14/2008|02:39] C:\Program Files\Common Files\<DIR> MSSoap
    [05/14/2008|09:28] C:\Program Files\Common Files\<DIR> ODBC
    [05/14/2008|02:39] C:\Program Files\Common Files\<DIR> Services
    [08/19/2008|09:00] C:\Program Files\Common Files\<DIR> Skype
    [05/14/2008|09:28] C:\Program Files\Common Files\<DIR> SpeechEngines
    [05/14/2008|02:38] C:\Program Files\Common Files\<DIR> System

    --------------------\\ Process

    ( 39 Processes )

    ... OK !

    --------------------\\ Recherche avec S_Lop

    C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\bis10CF.exe

    --------------------\\ Recherche de Fichiers / Dossiers Lop

    C:\DOCUME~1\ALLUSE~1\APPLIC~1\Cast ping base frag
    C:\DOCUME~1\ALLUSE~1\APPLIC~1\Cast ping base frag\Creative Close.dat
    C:\DOCUME~1\ADMINI~1\APPLIC~1\flagli~1
    C:\DOCUME~1\ADMINI~1\APPLIC~1\flagli~1\Axis Skip For Plus.exe
    C:\DOCUME~1\ADMINI~1\APPLIC~1\flagli~1\BagsWmaDefy.exe
    C:\DOCUME~1\ADMINI~1\APPLIC~1\flagli~1\bibthis.exe
    C:\DOCUME~1\ADMINI~1\APPLIC~1\flagli~1\bweslneg.exe
    C:\DOCUME~1\ADMINI~1\APPLIC~1\flagli~1\cjbrkhiy.exe
    C:\DOCUME~1\ADMINI~1\APPLIC~1\flagli~1\fvnbgefh.exe
    C:\DOCUME~1\ADMINI~1\APPLIC~1\flagli~1\fztchjqo.exe
    C:\DOCUME~1\ADMINI~1\APPLIC~1\flagli~1\hgetsrte.exe
    C:\DOCUME~1\ADMINI~1\APPLIC~1\flagli~1\iknknjvk.exe
    C:\DOCUME~1\ADMINI~1\APPLIC~1\flagli~1\lsahjrnb.exe
    C:\DOCUME~1\ADMINI~1\APPLIC~1\flagli~1\mfhuhxzf.exe
    C:\DOCUME~1\ADMINI~1\APPLIC~1\flagli~1\nscgfawe.exe
    C:\DOCUME~1\ADMINI~1\APPLIC~1\flagli~1\nzbxhkaa.exe
    C:\DOCUME~1\ADMINI~1\APPLIC~1\flagli~1\oyzgpwqp.exe
    C:\DOCUME~1\ADMINI~1\APPLIC~1\flagli~1\qelmpkch.exe
    C:\DOCUME~1\ADMINI~1\APPLIC~1\flagli~1\rnggluwd.exe
    C:\DOCUME~1\ADMINI~1\APPLIC~1\flagli~1\scqzsfwv.exe
    C:\DOCUME~1\ADMINI~1\APPLIC~1\flagli~1\sepbzotr.exe
    C:\DOCUME~1\ADMINI~1\APPLIC~1\flagli~1\slzwsyqn.exe
    C:\DOCUME~1\ADMINI~1\APPLIC~1\flagli~1\wmrerxxr.exe
    C:\Program Files\flagli~1
    C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsl125.tmp
    C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsl126.tmp
    C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\sta13.exe
    C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\sta14EB.exe
    C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\sta187.exe
    C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\sta1BD.exe
    C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\sta1D8.exe
    C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\sta220.exe
    C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\sta29.exe
    C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\sta2A3.exe
    C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\sta5D.exe
    C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\sta6F.exe
    C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\sta71.exe
    C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\sta9D.exe
    C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\staF6.exe
    C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\staFB.exe
    C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\status.txt
    C:\Program Files\Circle Developement
    C:\Program Files\Circle Developement\Uninstall.exe
    C:\DOCUME~1\ADMINI~1\Cookies\administrator@advertstream[2].txt
    C:\DOCUME~1\ADMINI~1\Cookies\administrator@adserver5[1].txt
    C:\DOCUME~1\ADMINI~1\Cookies\administrator@www.adserver5[2].txt
    C:\DOCUME~1\ADMINI~1\Cookies\administrator@advertising[2].txt
    C:\DOCUME~1\ADMINI~1\Cookies\administrator@bigpoint[2].txt
    C:\DOCUME~1\ADMINI~1\Cookies\administrator@fr.darkorbit.bigpoint[1].txt
    C:\DOCUME~1\ADMINI~1\Cookies\administrator@fr.seafight.bigpoint[2].txt
    C:\DOCUME~1\ADMINI~1\Cookies\administrator@fr1.seafight.bigpoint[1].txt
    C:\DOCUME~1\ADMINI~1\Cookies\administrator@thepimps.bigpoint[2].txt
    C:\DOCUME~1\ADMINI~1\Cookies\administrator@banner.cotedazurpalace[2].txt
    C:\DOCUME~1\ADMINI~1\Cookies\administrator@cotedazurpalace[2].txt
    C:\DOCUME~1\ADMINI~1\Cookies\administrator@serve.cotedazurpalace[2].txt
    C:\DOCUME~1\ADMINI~1\Cookies\administrator@www.cotedazurpalace[1].txt
    C:\DOCUME~1\ADMINI~1\Cookies\administrator@adopt.euroclick[1].txt
    C:\DOCUME~1\ADMINI~1\Cookies\administrator@fr.pacificpoker[1].txt
    C:\DOCUME~1\ADMINI~1\Cookies\administrator@pacificpoker[2].txt
    C:\DOCUME~1\ADMINI~1\Cookies\administrator@partypoker[1].txt
    C:\DOCUME~1\ADMINI~1\Cookies\administrator@fr.seafight.bigpoint[2].txt
    C:\DOCUME~1\ADMINI~1\Cookies\administrator@fr1.seafight.bigpoint[1].txt
    C:\DOCUME~1\ADMINI~1\Cookies\administrator@www.lop[2].txt
    C:\DOCUME~1\ADMINI~1\Cookies\administrator@888[2].txt
    C:\WINDOWS\Tasks\A8ECBE18918B3250.job

    --------------------\\ Verification du Registre

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "flawmore"="C:\\DOCUME~1\\ADMINI~1\\APPLIC~1\\FLAGLI~1\\bibthis.exe"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

    --------------------\\ Verification du fichier Hosts

    Fichier Hosts PROPRE


    --------------------\\ Recherche de fichiers avec Catchme

    catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-09-27 20:48:27
    Windows 5.1.2600 Service Pack 2 NTFS
    scanning hidden processes ...
    scanning hidden files ...
    scan completed successfully
    hidden processes: 0
    hidden files: 23

    --------------------\\ Recherche d'autres infections


    Aucune autre infection trouv้e !

    [F:5416][D:121]-> C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp
    [F:492][D:0]-> C:\DOCUME~1\ADMINI~1\Cookies
    [F:1526][D:21]-> C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMPOR~1\content.IE5

    1 - "C:\Lop SD\LopR_1.txt" - Sun 09/27/2009|20:50 - Option : [1]

    --------------------\\ Fin du rapport a 20:50:29
    Contenus similaires
    a c 267 8 Sécurité
    a b 9 Windows
    26 Septembre 2009 20:54:52

    Infection Lop/Swizzor détectée.

  • Relance Lop S&D.
    (Sous Vista, il faut cliquer droit sur le raccourci Lop S&D et choisir Exécuter en tant qu'administrateur)
  • Choisis cette fois-ci l'option 2 (Suppression).
  • Ne ferme pas la fenêtre lors de la suppression !
  • Poste le rapport généré (C:\lopR.txt).

    (Si le Bureau ne réapparaît pas, presse Ctrl+Alt+Suppr, Onglet Fichier, Nouvelle tâche, tape explorer.exe et valide)
    26 Septembre 2009 21:53:38


    --------------------\\ Lop S&D 4.2.5-0 XP/Vista

    Microsoft Windows XP Professional ( v5.1.2600 ) Service Pack 2
    X86-based PC ( Uniprocessor Free : AMD Turion(tm) 64 Mobile Technology MK-36 )
    BIOS : Ver 1.00PARTTBL
    USER : Administrator ( Administrator )
    BOOT : Normal boot
    Antivirus : ESET NOD32 Antivirus 3.0 3.0 (Activated)
    C:\ (Local Disk) - NTFS - Total:48 Go (Free:32 Go)
    D:\ (CD or DVD)
    E:\ (Local Disk) - NTFS - Total:62 Go (Free:62 Go)
    F:\ (USB) - FAT - Total:1932 Mo (Free:0 Go)

    "C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
    Option : [2] ( Sun 09/27/2009|21:44 )


    \\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ SUPPRESSION

    Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\Cast ping base frag\Creative Close.dat
    Supprime! - C:\DOCUME~1\ADMINI~1\APPLIC~1\flagli~1\Axis Skip For Plus.exe
    Supprime! - C:\DOCUME~1\ADMINI~1\APPLIC~1\flagli~1\BagsWmaDefy.exe
    Supprime! - C:\DOCUME~1\ADMINI~1\APPLIC~1\flagli~1\bibthis.exe
    Supprime! - C:\DOCUME~1\ADMINI~1\APPLIC~1\flagli~1\bweslneg.exe
    Supprime! - C:\DOCUME~1\ADMINI~1\APPLIC~1\flagli~1\cjbrkhiy.exe
    Supprime! - C:\DOCUME~1\ADMINI~1\APPLIC~1\flagli~1\fvnbgefh.exe
    Supprime! - C:\DOCUME~1\ADMINI~1\APPLIC~1\flagli~1\fztchjqo.exe
    Supprime! - C:\DOCUME~1\ADMINI~1\APPLIC~1\flagli~1\hgetsrte.exe
    Supprime! - C:\DOCUME~1\ADMINI~1\APPLIC~1\flagli~1\iknknjvk.exe
    Supprime! - C:\DOCUME~1\ADMINI~1\APPLIC~1\flagli~1\lsahjrnb.exe
    Supprime! - C:\DOCUME~1\ADMINI~1\APPLIC~1\flagli~1\mfhuhxzf.exe
    Supprime! - C:\DOCUME~1\ADMINI~1\APPLIC~1\flagli~1\nscgfawe.exe
    Supprime! - C:\DOCUME~1\ADMINI~1\APPLIC~1\flagli~1\nzbxhkaa.exe
    Supprime! - C:\DOCUME~1\ADMINI~1\APPLIC~1\flagli~1\oyzgpwqp.exe
    Supprime! - C:\DOCUME~1\ADMINI~1\APPLIC~1\flagli~1\qelmpkch.exe
    Supprime! - C:\DOCUME~1\ADMINI~1\APPLIC~1\flagli~1\rnggluwd.exe
    Supprime! - C:\DOCUME~1\ADMINI~1\APPLIC~1\flagli~1\scqzsfwv.exe
    Supprime! - C:\DOCUME~1\ADMINI~1\APPLIC~1\flagli~1\sepbzotr.exe
    Supprime! - C:\DOCUME~1\ADMINI~1\APPLIC~1\flagli~1\slzwsyqn.exe
    Supprime! - C:\DOCUME~1\ADMINI~1\APPLIC~1\flagli~1\wmrerxxr.exe
    Supprime! - C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsl125.tmp
    Supprime! - C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\nsl126.tmp
    Supprime! - C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\sta13.exe
    Supprime! - C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\sta14EB.exe
    Supprime! - C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\sta187.exe
    Supprime! - C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\sta1BD.exe
    Supprime! - C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\sta1D8.exe
    Supprime! - C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\sta220.exe
    Supprime! - C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\sta29.exe
    Supprime! - C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\sta2A3.exe
    Supprime! - C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\sta5D.exe
    Supprime! - C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\sta6F.exe
    Supprime! - C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\sta71.exe
    Supprime! - C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\sta9D.exe
    Supprime! - C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\staF6.exe
    Supprime! - C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\staFB.exe
    Supprime! - C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\status.txt
    Supprime! - C:\Program Files\Circle Developement\Uninstall.exe
    Supprime! - C:\DOCUME~1\ADMINI~1\Cookies\administrator@advertstream[2].txt
    Supprime! - C:\DOCUME~1\ADMINI~1\Cookies\administrator@adserver5[1].txt
    Supprime! - C:\DOCUME~1\ADMINI~1\Cookies\administrator@www.adserver5[2].txt
    Supprime! - C:\DOCUME~1\ADMINI~1\Cookies\administrator@advertising[2].txt
    Supprime! - C:\DOCUME~1\ADMINI~1\Cookies\administrator@bigpoint[2].txt
    Supprime! - C:\DOCUME~1\ADMINI~1\Cookies\administrator@fr.darkorbit.bigpoint[1].txt
    Supprime! - C:\DOCUME~1\ADMINI~1\Cookies\administrator@fr.seafight.bigpoint[2].txt
    Supprime! - C:\DOCUME~1\ADMINI~1\Cookies\administrator@fr1.seafight.bigpoint[1].txt
    Supprime! - C:\DOCUME~1\ADMINI~1\Cookies\administrator@thepimps.bigpoint[2].txt
    Supprime! - C:\DOCUME~1\ADMINI~1\Cookies\administrator@banner.cotedazurpalace[2].txt
    Supprime! - C:\DOCUME~1\ADMINI~1\Cookies\administrator@cotedazurpalace[2].txt
    Supprime! - C:\DOCUME~1\ADMINI~1\Cookies\administrator@serve.cotedazurpalace[2].txt
    Supprime! - C:\DOCUME~1\ADMINI~1\Cookies\administrator@www.cotedazurpalace[1].txt
    Supprime! - C:\DOCUME~1\ADMINI~1\Cookies\administrator@adopt.euroclick[1].txt
    Supprime! - C:\DOCUME~1\ADMINI~1\Cookies\administrator@fr.pacificpoker[1].txt
    Supprime! - C:\DOCUME~1\ADMINI~1\Cookies\administrator@pacificpoker[2].txt
    Supprime! - C:\DOCUME~1\ADMINI~1\Cookies\administrator@partypoker[1].txt
    Supprime! - C:\DOCUME~1\ADMINI~1\Cookies\administrator@www.lop[2].txt
    Supprime! - C:\DOCUME~1\ADMINI~1\Cookies\administrator@888[2].txt
    Supprime! - C:\WINDOWS\Tasks\A8ECBE18918B3250.job
    Supprime! - C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\bis10CF.exe
    Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\Cast ping base frag
    Supprime! - C:\DOCUME~1\ADMINI~1\APPLIC~1\flagli~1
    Supprime! - C:\Program Files\flagli~1
    Supprime! - C:\Program Files\Circle Developement
    -
    [ Fichier Hosts ] .. Restaure!

    \\\\\\\\\\\\\\\\\\\\\\\\\\\\\\


    --------------------\\ Listing des dossiers dans APPLIC~1

    [11/09/2008|02:01] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Adobe
    [05/31/2009|06:31] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Apple Computer
    [09/10/2008|08:32] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> BSplayer
    [08/25/2008|10:43] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> BSplayer Pro
    [05/15/2008|07:57] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Creative
    [06/26/2009|08:43] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> dvdcss
    [06/13/2009|07:46] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> HP
    [05/14/2008|02:56] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Identities
    [11/02/2008|01:15] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> ImgBurn
    [08/08/2009|03:39] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> InstallShield
    [05/15/2008|07:53] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> InterTrust
    [08/08/2009|03:41] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> LG Electronics
    [05/14/2008|06:23] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Macromedia
    [09/27/2009|12:16] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Malwarebytes
    [09/27/2008|09:27] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Media Player Classic
    [05/14/2008|06:01] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Microsoft
    [05/14/2008|03:04] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Mozilla
    [05/12/2009|10:16] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> OpenOffice.org
    [02/11/2009|09:41] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Real
    [07/12/2008|04:08] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> SecuROM
    [08/22/2008|04:09] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Sibelius Software
    [09/21/2009|04:37] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Skype
    [09/21/2009|02:38] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> skypePM
    [05/30/2008|04:44] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Sun
    [05/14/2008|03:04] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> Talkback
    [05/14/2008|03:12] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> uTorrent
    [05/30/2009|10:09] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> vlc
    [05/14/2008|03:30] C:\DOCUME~1\ADMINI~1\APPLIC~1\<DIR> WinRAR

    [01/31/2009|10:22] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> {3276BE95_AF08_429F_A64F_CA64CB79BCF6}
    [05/14/2008|02:53] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Adobe
    [05/26/2008|10:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Apple
    [05/26/2008|10:24] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Apple Computer
    [05/14/2008|05:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Avira
    [05/14/2008|02:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> ESET
    [06/13/2009|07:11] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> HP
    [09/27/2009|12:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Malwarebytes
    [09/01/2008|06:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Messenger Plus!
    [07/04/2008|11:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Microsoft
    [08/19/2008|09:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Skype
    [05/14/2008|02:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Windows Genuine Advantage

    [05/14/2008|02:42] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Microsoft

    [06/13/2009|07:11] C:\DOCUME~1\LOCALS~1\APPLIC~1\<DIR> HP
    [05/14/2008|02:48] C:\DOCUME~1\LOCALS~1\APPLIC~1\<DIR> Microsoft

    [05/14/2008|02:48] C:\DOCUME~1\NETWOR~1\APPLIC~1\<DIR> Microsoft

    --------------------\\ Tโches planifi้es dans C:\WINDOWS\tasks

    [08/08/2009 09:59 AM][--a------] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
    [05/18/2008 01:10 PM][--ah-----] C:\WINDOWS\tasks\Microsoft_Hardware_Launch_setup_exe.job
    [09/27/2009 01:25 PM][--ah-----] C:\WINDOWS\tasks\SA.DAT
    [02/28/2008 12:38 AM][-r-h-----] C:\WINDOWS\tasks\desktop.ini

    --------------------\\ Listing des dossiers dans C:\Program Files

    [05/14/2008|02:46] C:\Program Files\<DIR> 7-Zip
    [05/15/2008|07:53] C:\Program Files\<DIR> Adobe
    [05/14/2008|02:46] C:\Program Files\<DIR> Alky for Applications
    [07/03/2008|01:55] C:\Program Files\<DIR> AMT
    [11/18/2008|07:14] C:\Program Files\<DIR> Apple Software Update
    [05/14/2008|05:51] C:\Program Files\<DIR> Avira
    [05/28/2008|09:26] C:\Program Files\<DIR> AviSynth 2.5
    [01/31/2009|10:03] C:\Program Files\<DIR> Bonjour
    [12/19/2008|09:51] C:\Program Files\<DIR> BS.Player ControlBar
    [05/14/2008|02:53] C:\Program Files\<DIR> CD-DVD
    [05/14/2008|02:54] C:\Program Files\<DIR> Combined Community Codec Pack
    [05/26/2008|10:21] C:\Program Files\<DIR> Common Files
    [05/14/2008|02:37] C:\Program Files\<DIR> ComPlus Applications
    [01/02/2009|03:17] C:\Program Files\<DIR> Conduit
    [05/15/2008|06:27] C:\Program Files\<DIR> CONEXANT
    [05/14/2008|02:54] C:\Program Files\<DIR> CPE17
    [05/18/2008|12:42] C:\Program Files\<DIR> Creative
    [01/17/2009|09:09] C:\Program Files\<DIR> DivX
    [06/18/2009|09:40] C:\Program Files\<DIR> EA GAMES
    [05/29/2008|05:59] C:\Program Files\<DIR> eRightSoft
    [05/14/2008|02:54] C:\Program Files\<DIR> ESET
    [05/14/2008|02:54] C:\Program Files\<DIR> FolderSize
    [05/14/2008|02:36] C:\Program Files\<DIR> HashTab Shell Extension
    [06/13/2009|06:53] C:\Program Files\<DIR> Hewlett-Packard
    [08/07/2009|05:05] C:\Program Files\<DIR> HORRE
    [06/13/2009|07:09] C:\Program Files\<DIR> HP
    [05/14/2008|02:54] C:\Program Files\<DIR> ImgBurn
    [08/08/2009|07:34] C:\Program Files\<DIR> InstallShield Installation Information
    [05/14/2008|02:51] C:\Program Files\<DIR> Internet Explorer
    [01/31/2009|10:22] C:\Program Files\<DIR> iPod
    [01/31/2009|10:22] C:\Program Files\<DIR> iTunes
    [05/12/2009|10:07] C:\Program Files\<DIR> Java
    [05/12/2009|10:08] C:\Program Files\<DIR> JRE
    [05/14/2008|02:37] C:\Program Files\<DIR> LClock
    [08/08/2009|11:30] C:\Program Files\<DIR> LG Electronics
    [08/20/2009|01:02] C:\Program Files\<DIR> LG PC Suite II
    [08/19/2009|09:41] C:\Program Files\<DIR> LGInternetKit
    [08/05/2009|10:14] C:\Program Files\<DIR> Messenger Plus! Live
    [04/13/2009|12:48] C:\Program Files\<DIR> Microsoft Games
    [05/18/2008|01:15] C:\Program Files\<DIR> Microsoft LifeCam
    [05/14/2008|02:36] C:\Program Files\<DIR> Microsoft PowerToys
    [05/14/2008|02:39] C:\Program Files\<DIR> Movie Maker
    [09/27/2009|09:43] C:\Program Files\<DIR> Mozilla Firefox
    [05/14/2008|02:36] C:\Program Files\<DIR> MSN Gaming Zone
    [05/14/2008|02:39] C:\Program Files\<DIR> NetMeeting
    [05/14/2008|02:40] C:\Program Files\<DIR> Online Services
    [05/12/2009|10:08] C:\Program Files\<DIR> OpenOffice.org 3
    [05/14/2008|02:39] C:\Program Files\<DIR> Outlook Express
    [03/09/2009|06:01] C:\Program Files\<DIR> PHPNukeFR
    [01/31/2009|10:19] C:\Program Files\<DIR> QuickTime
    [05/14/2008|04:28] C:\Program Files\<DIR> Realtek
    [08/22/2008|04:08] C:\Program Files\<DIR> Sibelius Software
    [08/19/2008|09:00] C:\Program Files\<DIR> Skype
    [05/14/2008|02:54] C:\Program Files\<DIR> The KMPlayer
    [05/14/2008|02:56] C:\Program Files\<DIR> Uninstall Information
    [05/14/2008|02:36] C:\Program Files\<DIR> Unlocker
    [05/14/2008|03:07] C:\Program Files\<DIR> uTorrent
    [05/12/2009|07:03] C:\Program Files\<DIR> VideoLAN
    [05/14/2008|02:36] C:\Program Files\<DIR> Visual+
    [05/14/2008|02:46] C:\Program Files\<DIR> VisualTaskTips
    [08/25/2008|10:42] C:\Program Files\<DIR> Webteh
    [05/14/2008|02:55] C:\Program Files\<DIR> Windows Live
    [05/14/2008|02:36] C:\Program Files\<DIR> Windows Media Connect 2
    [05/18/2008|12:59] C:\Program Files\<DIR> Windows Media Player
    [05/14/2008|02:35] C:\Program Files\<DIR> Windows NT
    [05/14/2008|02:52] C:\Program Files\<DIR> Windows Sidebar
    [05/14/2008|02:40] C:\Program Files\<DIR> WindowsUpdate
    [05/14/2008|02:56] C:\Program Files\<DIR> WinRAR

    --------------------\\ Listing des dossiers dans C:\Program Files\Common Files

    [05/14/2008|02:53] C:\Program Files\Common Files\<DIR> Adobe
    [01/31/2009|10:18] C:\Program Files\Common Files\<DIR> Apple
    [06/13/2009|06:52] C:\Program Files\Common Files\<DIR> Hewlett-Packard
    [06/13/2009|07:09] C:\Program Files\Common Files\<DIR> HP
    [05/15/2008|07:50] C:\Program Files\Common Files\<DIR> InstallShield
    [05/14/2008|02:51] C:\Program Files\Common Files\<DIR> Java
    [05/14/2008|02:57] C:\Program Files\Common Files\<DIR> Microsoft Shared
    [05/14/2008|02:39] C:\Program Files\Common Files\<DIR> MSSoap
    [05/14/2008|09:28] C:\Program Files\Common Files\<DIR> ODBC
    [05/14/2008|02:39] C:\Program Files\Common Files\<DIR> Services
    [08/19/2008|09:00] C:\Program Files\Common Files\<DIR> Skype
    [05/14/2008|09:28] C:\Program Files\Common Files\<DIR> SpeechEngines
    [05/14/2008|02:38] C:\Program Files\Common Files\<DIR> System

    --------------------\\ Process

    ( 38 Processes )

    ... OK !

    --------------------\\ Recherche avec S_Lop

    Aucun fichier / dossier Lop trouv้ !

    --------------------\\ Recherche de Fichiers / Dossiers Lop

    Aucun fichier / dossier Lop trouv้ !

    --------------------\\ Verification du Registre

    ..... OK !

    --------------------\\ Verification du fichier Hosts

    Fichier Hosts PROPRE


    --------------------\\ Recherche de fichiers avec Catchme

    catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-09-27 21:45:59
    Windows 5.1.2600 Service Pack 2 NTFS
    scanning hidden processes ...
    scanning hidden files ...
    scan completed successfully
    hidden processes: 0
    hidden files: 23

    --------------------\\ Recherche d'autres infections


    Aucune autre infection trouv้e !

    [F:5399][D:121]-> C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp
    [F:473][D:0]-> C:\DOCUME~1\ADMINI~1\Cookies
    [F:1526][D:21]-> C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMPOR~1\content.IE5

    1 - "C:\Lop SD\LopR_1.txt" - Sun 09/27/2009|20:50 - Option : [1]
    2 - "C:\Lop SD\LopR_2.txt" - Sun 09/27/2009|21:47 - Option : [2]

    --------------------\\ Fin du rapport a 21:47:29
    a c 267 8 Sécurité
    a b 9 Windows
    27 Septembre 2009 00:30:00

    Bien.

  • Relance MBAM, va dans Quarantaine et supprime tout.

  • Télécharge Random's System Information Tool (RSIT) (par random/random) sur ton Bureau.
  • Double-clique sur RSIT.exe afin de lancer le programme.
    (Sous Vista, il faut cliquer droit sur RSIT.exe et choisir Exécuter en tant qu'administrateur)
  • Clique sur Continue à l'écran Disclaimer.
  • Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.
  • Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront. Poste le contenu de log.txt (c'est celui qui apparaît à l'écran) ainsi que de info.txt (que tu verras dans la barre des tâches).

    Note : les rapports sont sauvegardés dans le dossier C:\rsit.
    Tom's guide dans le monde
    • Allemagne
    • Italie
    • Irlande
    • Royaume Uni
    • Etats Unis
    Suivre Tom's Guide
    Inscrivez-vous à la Newsletter
    • ajouter à twitter
    • ajouter à facebook
    • ajouter un flux RSS