a tous
Bon voila, j'ai une merde que j'arrive pas virer un "dialer"
Spybot, et avast n'y font rien, j'ai essayé hijack avec l'analyseur en ligne mais j'aurais besoin de vos avis
Code :
- Logfile of HijackThis v1.99.1
- Scan saved at 12:51:54, on 08/01/2007
- Platform: Windows XP SP2 (WinNT 5.01.2600)
- MSIE: Internet Explorer v7.00 (7.00.5730.0011)
- Running processes:
- C:\WINDOWS\System32\smss.exe
- C:\WINDOWS\system32\winlogon.exe
- C:\WINDOWS\system32\services.exe
- C:\WINDOWS\system32\lsass.exe
- C:\WINDOWS\system32\svchost.exe
- C:\WINDOWS\System32\svchost.exe
- C:\WINDOWS\system32\spoolsv.exe
- C:\WINDOWS\Explorer.EXE
- C:\Program Files\Ideazon\Zboard Software\Driver\ZboardTray.exe
- C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
- C:\Program Files\Asus\PC Probe II\Probe2.exe
- C:\WINDOWS\system32\RunDLL32.exe
- C:\WINDOWS\SOUNDMAN.EXE
- C:\WINDOWS\system32\ctfmon.exe
- C:\Program Files\Logitech\SetPoint\SetPoint.exe
- C:\Program Files\Fichiers communs\Logitech\KHAL\KHALMNPR.EXE
- C:\Program Files\Ideazon\Zboard Software\Driver\Zboard.exe
- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
- C:\Program Files\Alwil Software\Avast4\ashServ.exe
- C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
- C:\WINDOWS\system32\nvsvc32.exe
- C:\Program Files\Alcohol Soft\Alcohol 52\StarWind\StarWindService.exe
- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
- C:\WINDOWS\System32\wbem\wmiapsrv.exe
- C:\WINDOWS\system32\wscntfy.exe
- C:\Program Files\OpenOffice.org 2.0\program\soffice.exe
- C:\Program Files\OpenOffice.org 2.0\program\soffice.BIN
- D:\Mes documents\hijackthis_hijackthis_1.99.1_anglais_17891.exe
- R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
- R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
- R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
- R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
- R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
- R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
- O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
- O2 - BHO: GigagetIEHelper - {111CAA23-6F4F-42AC-8555-B48C1D87BBAB} - C:\WINDOWS\system32\gigagetbho_v10.dll
- O2 - BHO: (no name) - {1D29C7B8-1B3D-4232-B1EB-CB5B4C83D207} - C:\WINDOWS\system32\ssqqqqo.dll
- O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
- O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
- O2 - BHO: (no name) - {7DA39570-5FD2-4f18-94B4-20730CB3F727} - C:\WINDOWS\system32\nlafpegu.dll
- O2 - BHO: (no name) - {84E6524A-D594-45DD-97CD-17D3C6D952A2} - C:\WINDOWS\system32\pmkhi.dll
- O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
- O4 - HKLM\..\Run: [Launch PC Probe II] "C:\Program Files\Asus\PC Probe II\Probe2.exe" 1
- O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
- O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
- O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
- O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
- O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
- O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
- O8 - Extra context menu item: &Download All by Gigaget - C:\Program Files\Giganology\Gigaget\getallurl.htm
- O8 - Extra context menu item: &Download by Gigaget - C:\Program Files\Giganology\Gigaget\geturl.htm
- O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
- O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
- O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
- O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
- O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activ [...] asinst.cab
- O17 - HKLM\System\CCS\Services\Tcpip\..\{070CC3BA-805C-4953-81A0-92A3FC42D1B0}: NameServer = 86.64.145.146 84.103.237.146
- O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
- O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
- O20 - Winlogon Notify: pmkhi - C:\WINDOWS\system32\pmkhi.dll
- O20 - Winlogon Notify: ssqqqqo - C:\WINDOWS\SYSTEM32\ssqqqqo.dll
- O20 - Winlogon Notify: winxtx32 - C:\WINDOWS\SYSTEM32\winxtx32.dll
- O20 - Winlogon Notify: Zboard - C:\WINDOWS\SYSTEM32\Winlognotif.dll
- O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
- O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
- O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
- O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
- O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
- O23 - Service: nTune Service (nTuneService) - NVIDIA - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
- O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
- O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 52\StarWind\StarWindService.exe
|
Je precise que ces merdes se trouvent dans C:\Windows\Temp :
Bon voila, c'est tres soulant d'autant que ca ramène d'autres spyware trojan de partout dans mon pc, ca se fout en premier plan quand je joue.
Merci bien
ps modo: je sais pas s je suis dans la bonne sous-cat, merci de déplacer le topic si je ne suis aps au bon endroit
edit en gras dans le log,je sais pas ce que c'est !/
Message édité par charask8 le 08-01-2007 à 13:46:09