voici mes log :
SmitFraudFix v1.86
Rapport fait à 17:35:58,73 le 11/10/2005
Executé à partir de C:Documents and SettingsSpidermanBureaurdrivRemSmitfraudFix
OS: Microsoft Windows XP [version 5.1.2600]
»»»»»»»»»»»»»»»»»»»»»»»» Recherche C:
»»»»»»»»»»»»»»»»»»»»»»»» Recherche C:WINDOWS
»»»»»»»»»»»»»»»»»»»»»»»» Recherche C:WINDOWSsystem
»»»»»»»»»»»»»»»»»»»»»»»» Recherche C:WINDOWSWeb
»»»»»»»»»»»»»»»»»»»»»»»» Recherche C:WINDOWSsystem32
»»»»»»»»»»»»»»»»»»»»»»»» Recherche C:WINDOWSsystem32LogFiles
»»»»»»»»»»»»»»»»»»»»»»»» Recherche C:Documents and SettingsSpidermanApplication Data
»»»»»»»»»»»»»»»»»»»»»»»» Recherche C:Documents and SettingsSpidermanBureau
»»»»»»»»»»»»»»»»»»»»»»»» Recherche présence de la clé HKLMSOFTWARESHUDDERLTD
HKLMSOFTWARESHUDDERLTD non trouvé.
»»»»»»»»»»»»»»»»»»»»»»»» Fin du rapport
=====================================
Logfile of HijackThis v1.99.1
Scan saved at 17:35:39, on 11/10/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32LEXBCES.EXE
C:WINDOWSsystem32spoolsv.exe
C:PROGRA~1GrisoftAVG Freeavgamsvr.exe
C:PROGRA~1GrisoftAVG Freeavgupsvc.exe
C:WINDOWSSystem32driversCDAC11BA.EXE
C:Program FilesCPUCooLCooLSrv.exe
C:PROGRA~1NORTON~2NORTON~3GHOSTS~2.EXE
C:WINDOWSSystem32nvsvc32.exe
C:WINDOWSSystem32tcpsvcs.exe
C:WINDOWSSystem32snmp.exe
C:PROGRA~1NORTON~2NORTON~1SPEEDD~1NOPDB.EXE
C:WINDOWSSystem32svchost.exe
C:WINDOWSExplorer.EXE
C:WINDOWSSystem32wuauclt.exe
C:Program FilesMessenger Plus! 3MsgPlus.exe
C:PROGRA~1GrisoftAVG Freeavgcc.exe
C:PROGRA~1GrisoftAVG Freeavgemc.exe
C:WINDOWSSystem32MicreSoftUpdate.exe
C:WINDOWSSystem32MrNo5.exe
C:WINDOWSSystem32MrNoHTTP.exe
C:WINDOWSSystem32MrNo32235.exe
C:Program FilesMUSICMATCHMUSICMATCH Jukeboxmmtask.exe
C:Program FilesLecteur CANALPLAYCanalPlayerHelper.exe
C:WINDOWSSystem32svchost32.exe
C:WINDOWSSystem32sanupdate.exe
C:WINDOWSSystem32lexpps.exe
C:Program FilesWinMXWinMX.exe
C:WINDOWSHelpinfsm56help.exe
C:Program FilesLogitechMouseWaresystemem_exec.exe
C:Program FilesMSN Messengermsnmsgr.exe
C:Program FilesInternet ExplorerIEXPLORE.EXE
C:Program FilesFlashGetflashget.exe
C:WINDOWSsystem32osk.exe
C:WINDOWSsystem32MSSWCHX.EXE
C:Program FilesInternet ExplorerIEXPLORE.EXE
C:Program FilesWinRARWinRAR.exe
C:WINDOWSSystem32cmd.exe
C:DOCUME~1SPIDER~1LOCALS~1TempRar$EX39.3875HijackThis.exe
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.google.fr/
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant = http://www.shareware.us/srchasst.html
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Local Page =
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page_bak = about:blank
R1 - HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,ProxyOverride = localhost
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - _{BE89472C-B803-4D1D-9A9A-0A63660E0FE3} - (no file)
O1 - Hosts: 82.195.155.5 c3310.z1301.winmx.com c3311.z1301.winmx.com c3312.z1301.winmx.com c3313.z1301.winmx.com c3314.z1301.winmx.com c3315.z1301.winmx.com c3316.z1301.winmx.com c3317.z1301.winmx.com c3318.z1301.winmx.com c3319.z1301.winmx.com
O1 - Hosts: 82.195.155.5 c3310.z1302.winmx.com c3311.z1302.winmx.com c3312.z1302.winmx.com c3313.z1302.winmx.com c3314.z1302.winmx.com c3315.z1302.winmx.com c3316.z1302.winmx.com c3317.z1302.winmx.com c3318.z1302.winmx.com c3319.z1302.winmx.com
O1 - Hosts: 82.195.155.5 c3310.z1303.winmx.com c3311.z1303.winmx.com c3312.z1303.winmx.com c3313.z1303.winmx.com c3314.z1303.winmx.com c3315.z1303.winmx.com c3316.z1303.winmx.com c3317.z1303.winmx.com c3318.z1303.winmx.com c3319.z1303.winmx.com
O1 - Hosts: 82.195.155.5 c3310.z1304.winmx.com c3311.z1304.winmx.com c3312.z1304.winmx.com c3313.z1304.winmx.com c3314.z1304.winmx.com c3315.z1304.winmx.com c3316.z1304.winmx.com c3317.z1304.winmx.comc3318.z1304.winmx.com c3319.z1304.winmx.com
O1 - Hosts: 82.195.155.5 c3310.z1305.winmx.com c3311.z1305.winmx.com c3312.z1305.winmx.com c3313.z1305.winmx.com c3314.z1305.winmx.com c3315.z1305.winmx.com c3316.z1305.winmx.com c3317.z1305.winmx.com c3318.z1305.winmx.com c3319.z1305.winmx.com
O1 - Hosts: 82.195.155.5 c3310.z1306.winmx.com c3311.z1306.winmx.com c3312.z1306.winmx.com c3313.z1306.winmx.com c3314.z1306.winmx.com c3315.z1306.winmx.com c3316.z1306.winmx.com c3317.z1306.winmx.comc3318.z1306.winmx.com c3319.z1306.winmx.com
O1 - Hosts: 82.195.155.5 c3520.z1301.winmx.com c3521.z1301.winmx.com c3522.z1301.winmx.com c3523.z1301.winmx.com c3524.z1301.winmx.com c3525.z1301.winmx.com c3526.z1301.winmx.com c3527.z1301.winmx.com c3528.z1301.winmx.com c3529.z1301.winmx.com
O1 - Hosts: 82.195.155.5 c3520.z1302.winmx.com c3521.z1302.winmx.com c3522.z1302.winmx.com c3523.z1302.winmx.com c3524.z1302.winmx.com c3525.z1302.winmx.com c3526.z1302.winmx.com c3527.z1302.winmx.com 3528.z1302.winmx.com c3529.z1302.winmx.com
O1 - Hosts: 82.195.155.5 c3520.z1303.winmx.com c3521.z1303.winmx.com c3522.z1303.winmx.com c3523.z1303.winmx.com c3524.z1303.winmx.com c3525.z1303.winmx.com c3526.z1303.winmx.com c3527.z1303.winmx.com c3528.z1303.winmx.com c3529.z1303.winmx.com
O1 - Hosts: 82.195.155.5 c3520.z1304.winmx.com c3521.z1304.winmx.com c3522.z1304.winmx.com c3523.z1304.winmx.com c3524.z1304.winmx.com c3525.z1304.winmx.com c3526.z1304.winmx.com c3527.z1304.winmx.com c3528.z1304.winmx.com c3529.z1304.winmx.com
O1 - Hosts: 82.195.155.5 c3520.z1305.winmx.com c3521.z1305.winmx.com c3522.z1305.winmx.com c3523.z1305.winmx.com c3524.z1305.winmx.com c3525.z1305.winmx.com c3526.z1305.winmx.com c3527.z1305.winmx.com c3528.z1305.winmx.com c3529.z1305.winmx.com
O1 - Hosts: 82.195.155.5 c3520.z1306.winmx.com c3521.z1306.winmx.com c3522.z1306.winmx.com c3523.z1306.winmx.comc3524.z1306.winmx.com c3525.z1306.winmx.com c3526.z1306.winmx.com c3527.z1306.winmx.com c3528.z1306.winmx.comc3529.z1306.winmx.com
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:PROGRA~1FlashGetjccatch.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:WINDOWSSystem32msdxm.ocx
O4 - HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSSystem32NvCpl.dll,NvStartup
O4 - HKLM..Run: [SSC_UserPrompt] C:Program FilesFichiers communsSymantec SharedSecurity CenterUsrPrmpt.exe
O4 - HKLM..Run: [QuickTime Task] "C:Program FilesQuickTimeqttask.exe" -atboottime
O4 - HKLM..Run: [MessengerPlus3] "C:Program FilesMessenger Plus! 3MsgPlus.exe"
O4 - HKLM..Run: [nwiz] nwiz.exe /install
O4 - HKLM..Run: [NvMediaCenter] RUNDLL32.EXE C:WINDOWSSystem32NvMcTray.dll,NvTaskbarInit
O4 - HKLM..Run: [AVG7_CC] C:PROGRA~1GrisoftAVG Freeavgcc.exe /STARTUP
O4 - HKLM..Run: [AVG7_EMC] C:PROGRA~1GrisoftAVG Freeavgemc.exe
O4 - HKLM..Run: [sm56hlep] C:WINDOWSHelpinfsm56hlep.exe
O4 - HKLM..Run: [iexplore.exe] MicreSoftUpdate.exe
O4 - HKLM..Run: [Syga1te P1ersonal F1rewall] MrNo5.exe
O4 - HKLM..Run: [M1cros0ft Intr3net Explo1r3r] MrNoHTTP.exe
O4 - HKLM..Run: [Syga432te Pe432rsonal Firewall] MrNo4236.exe
O4 - HKLM..Run: [Sygat3 P3rfdsxsonal Firewall] MrNo32235.exe
O4 - HKLM..Run: [Syg54vate Pesrsonal Firewall] AgreSor Fire W4ll v6
O4 - HKLM..Run: [mmtask] C:Program FilesMUSICMATCHMUSICMATCH Jukeboxmmtask.exe
O4 - HKLM..Run: [CanalPlayerHelper] C:Program FilesLecteur CANALPLAYCanalPlayerHelper.exe
O4 - HKLM..Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM..Run: [System Service] svchost32.exe
O4 - HKLM..Run: [Sygate Personal Firewall] sanupdate.exe
O4 - HKLM..RunServices: [iexplore.exe] MicreSoftUpdate.exe
O4 - HKLM..RunServices: [Syga1te P1ersonal F1rewall] MrNo5.exe
O4 - HKLM..RunServices: [M1cros0ft Intr3net Explo1r3r] MrNoHTTP.exe
O4 - HKLM..RunServices: [Syga432te Pe432rsonal Firewall] MrNo4236.exe
O4 - HKLM..RunServices: [Sygat3 P3rfdsxsonal Firewall] MrNo32235.exe
O4 - HKLM..RunServices: [Syg54vate Pesrsonal Firewall] AgreSor Fire W4ll v6
O4 - HKLM..RunServices: [System Service] svchost32.exe
O4 - HKLM..RunServices: [Sygate Personal Firewall] sanupdate.exe
O4 - HKCU..Run: [WinMX] C:Program FilesWinMXWinMX.exe -m
O4 - HKCU..Run: [MessengerPlus3] "C:Program FilesMessenger Plus! 3MsgPlus.exe" /WinStart
O4 - HKCU..Run: [iexplore.exe] MicreSoftUpdate.exe
O4 - HKCU..Run: [Syga1te P1ersonal F1rewall] MrNo5.exe
O4 - HKCU..Run: [Syga432te Pe432rsonal Firewall] MrNo4236.exe
O4 - HKCU..Run: [Sygat3 P3rfdsxsonal Firewall] MrNo32235.exe
O4 - HKCU..Run: [Syg54vate Pesrsonal Firewall] AgreSor Fire W4ll v6
O4 - HKCU..Run: [Sygate Personal Firewall] sanupdate.exe
O4 - HKCU..Run: [msnmsgr] "C:Program FilesMSN Messengermsnmsgr.exe" /background
O4 - HKCU..RunServices: [iexplore.exe] MicreSoftUpdate.exe
O4 - Startup: Adobe Gamma.lnk = C:Program FilesFichiers communsAdobeCalibrationAdobe Gamma Loader.exe
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:Program FilesAdobeAcrobat 7.0Readerreader_sl.exe
O6 - HKCUSoftwarePoliciesMicrosoftInternet ExplorerRestrictions present
O8 - Extra context menu item: &Recherche AOL Toolbar - res://C:Program FilesAOL Toolbartoolbar.dll/SEARCH.HTML
O8 - Extra context menu item: Chercher avec Copernic Agent - res://C:Program FilesCopernic AgentCopernicAgentExt.rdl/INTEGRATION_MENU_SEARCHEXT
O8 - Extra context menu item: Traduire cette page - C:WINDOWSWEBpowertoy.htm
O8 - Extra context menu item: Télécharger avec FlashGet - C:Program FilesFlashGetjc_link.htm
O8 - Extra context menu item: Télécharger tout avec FlashGet - C:Program FilesFlashGetjc_all.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavaj2re1.4.2_05binnpjpi142_05.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavaj2re1.4.2_05binnpjpi142_05.dll
O9 - Extra button: (no name) - {193B17B0-7C9F-4D5B-AEAB-8D3605EFC084} - C:WINDOWSSystem32shdocvw.dll
O9 - Extra 'Tools' menuitem: Démarrer Copernic Agent - {193B17B0-7C9F-4D5B-AEAB-8D3605EFC084} - C:WINDOWSSystem32shdocvw.dll
O9 - Extra button: Copernic Agent - {688DC797-DC11-46A7-9F1B-445F4F58CE6E} - C:WINDOWSSystem32shdocvw.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:WINDOWSSystem32Shdocvw.dll
O9 - Extra button: PhotoCapt - {D4935849-9EBC-4eac-A3AF-0C861DDAF397} - C:Program FilesPhotoCaptPhotoCapt.exe
O9 - Extra 'Tools' menuitem: PhotoCapt - {D4935849-9EBC-4eac-A3AF-0C861DDAF397} - C:Program FilesPhotoCaptPhotoCapt.exe
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:PROGRA~1FlashGetflashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:PROGRA~1FlashGetflashget.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengerMSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengerMSMSGS.EXE
O15 - Trusted Zone: *.boxsearch.net
O15 - Trusted Zone: *.brdatahost.com
O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should be Internet Zone
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windup.../bridge-c11.cab
O16 - DPF: {D7BF3304-138B-4DD5-86EE-491BB6A2286C} - http://www.azebar.co.../azesearch3.cab
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by23fd.bay23....ex/HMAtchmt.ocx
O20 - Winlogon Notify: StillImage - C:WINDOWSsystem32mujet40.dll
O20 - Winlogon Notify: Telephony - C:WINDOWSsystem32l46olej31ho.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:Program FilesFichiers communsAdobe Systems SharedServiceAdobelmsvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:PROGRA~1GrisoftAVG Freeavgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:PROGRA~1GrisoftAVG Freeavgupsvc.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:WINDOWSSystem32driversCDAC11BA.EXE
O23 - Service: CPUCooLServer Service (CPUCooLServer) - Unknown owner - C:Program FilesCPUCooLCooLSrv.exe
O23 - Service: GhostStartService - Symantec Corporation - C:PROGRA~1NORTON~2NORTON~3GHOSTS~2.EXE
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:WINDOWSsystem32LEXBCES.EXE
O23 - Service: Macromedia Licensing Service - Macromedia - C:Program FilesFichiers communsMacromedia SharedServiceMacromedia Licensing.exe
O23 - Service: netinfo - Unknown owner - C:WINDOWSnetinfo.exe (file missing)
O23 - Service: Norton Unerase Protection (NProtectService) - Unknown owner - C:Program FilesNorton Internet Security ProfessionalNorton AntiVirusAdvToolsNPROTECT.EXE (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:WINDOWSSystem32nvsvc32.exe
O23 - Service: Remote Procedure Call (RPC) Monitoring (Rpcmon) - Unknown owner - C:WINDOWSSystem32Rpcmon.exe (file missing)
O23 - Service: Speed Disk service - Symantec Corporation - C:PROGRA~1NORTON~2NORTON~1SPEEDD~1NOPDB.EXE
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:Program FilesFichiers communsSymantec SharedSecurity CenterSymWSC.exe
O23 - Service: Windows Updates - Unknown owner - C:WINDOWSwindowsupdates.exe
O23 - Service: Windows Time Sync (wservtime) - Unknown owner - C:WINDOWScsrss.exe (file missing)
Merci a ceux qui m'aiderons
PS : Je tien à rajouter que je ne peut acceder au mode sans echec car au chargemen de celui ci, le pc reboot ...
Connexion
Inscription
Aide


Retour en haut
Multi-citation