salut r@in/bow tout d abord merci beaucoup pour ton aide et aussi a toutes les autres personnes qui sont sur ce forum et qui aide les novices comme moi ,merci encore.je poste les derniers rapports hijt et tooblar mais je pense que je n ai plus d infection j ai fait un scan aussi avec spybot et il est sorti ca je l elimine ou le restaure merci encore .Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:36:45, on 01/04/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:Program FilesAlwil SoftwareAvast4aswUpdSv.exe
C:WINDOWSExplorer.EXE
C:Program FilesAlwil SoftwareAvast4ashServ.exe
C:windowssystemhpsysdrv.exe
C:Program FilesHewlett-PackardDigital ImagingUnloadhpqcmon.exe
C:Program FilesHPHP Software UpdateHPWuSchd.exe
C:WINDOWSSystem32hphmon05.exe
C:HPKBDKBD.EXE
C:PROGRA~1ALWILS~1Avast4ashDisp.exe
C:WINDOWSsystem32ctfmon.exe
C:Program FilesHewlett-PackardDigital Imaginginhpqtra08.exe
C:Program FilesHewlett-PackardDigital Imaginginhpohmr08.exe
C:Program FilesHewlett-PackardDigital Imaginginhpotdd01.exe
C:WINDOWSsystem32
undll32.exe
C:WINDOWSsystem32spoolsv.exe
C:Program FilesHewlett-PackardDigital Imaginginhpoevm08.exe
C:Program FilesAskBarDisarinAskService.exe
C:Program FilesAskBarDisarinASKUpgrade.exe
C:Program FilesJavajre6injqs.exe
C:WINDOWSSystem32
vsvc32.exe
C:WINDOWSSystem32svchost.exe
C:Program FilesAlwil SoftwareAvast4ashMaiSv.exe
C:Program FilesAlwil SoftwareAvast4ashWebSv.exe
C:Program FilesHewlett-PackardDigital ImagingBinhpoSTS08.exe
C:WINDOWSsystem32wuauclt.exe
C:Program FilesMessengermsmsgs.exe
C:Program FilesSpybot - Search & DestroySpybotSD.exe
C:Program FilesSpybot - Search & DestroyTeaTimer.exe
C:Program FilesTrend MicroHijackThisHijackThis.exe
C:Program FilesMozilla Firefoxfirefox.exe
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page =
http://google.fr/
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Bar =
http://srch-fr9.hpwis.com/
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:Program FilesAdobeAcrobat 5.0ReaderActiveXAcroIEHelper.ocx
O2 - BHO: TBSB06153 - {07CA483F-30BC-425D-823D-48620A3BD13F} - C:Program FilesIEToolbarShare AcceleratorShareAcceleratorToolbar12_11_08.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:Program FilesAskBarDisarinaskBar.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:PROGRA~1SPYBOT~1SDHelper.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:Program FilesFichiers communsMicrosoft SharedWindows LiveWindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:program filesgooglegoogletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:Program FilesGoogleGoogleToolbarNotifier3.1.807.1746swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:Program FilesJavajre6injp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:Program FilesJavajre6libdeployjqsiejqs_plugin.dll
O3 - Toolbar: Vue HP - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:Program FilesHewlett-PackardDigital Imaginginhpdtlk02.dll
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:Program FilesAskBarDisarinaskBar.dll
O3 - Toolbar: Share Accelerator - {FA34EE7E-55EB-41DB-9718-1AE6EA1CF9A5} - C:Program FilesIEToolbarShare AcceleratorShareAcceleratorToolbar12_11_08.dll
O4 - HKLM..Run: [hpsysdrv] c:windowssystemhpsysdrv.exe
O4 - HKLM..Run: [HotKeysCmds] C:WINDOWSSystem32hkcmd.exe
O4 - HKLM..Run: [CamMonitor] c:Program FilesHewlett-PackardDigital ImagingUnloadhpqcmon.exe
O4 - HKLM..Run: [HP Software Update] "c:Program FilesHPHP Software UpdateHPWuSchd.exe"
O4 - HKLM..Run: [HPHUPD05] c:Program FilesHewlett-Packard{45B6180B-DCAB-4093-8EE8-6164457517F0}hphupd05.exe
O4 - HKLM..Run: [HPHmon05] C:WINDOWSSystem32hphmon05.exe
O4 - HKLM..Run: [KBD] C:HPKBDKBD.EXE
O4 - HKLM..Run: [Recguard] C:WINDOWSSMINSTRECGUARD.EXE
O4 - HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSSystem32NvCpl.dll,NvStartup
O4 - HKLM..Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
O4 - HKLM..Run: [PS2] C:WINDOWSsystem32ps2.exe
O4 - HKLM..Run: [HPDJ Taskbar Utility] C:WINDOWSsystem32spooldriversw32x863hpztsb07.exe
O4 - HKLM..Run: [avast!] C:PROGRA~1ALWILS~1Avast4ashDisp.exe
O4 - HKCU..Run: [BackupNotify] c:Program FilesHewlett-PackardDigital Imaginginackupnotify.exe
O4 - HKCU..Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU..Run: [ctfmon.exe] C:WINDOWSsystem32ctfmon.exe
O4 - HKCU..Run: [swg] C:Program FilesGoogleGoogleToolbarNotifierGoogleToolbarNotifier.exe
O4 - HKCU..Run: [SpybotSD TeaTimer] C:Program FilesSpybot - Search & DestroyTeaTimer.exe
O4 - HKUSS-1-5-21-2594731810-3581480619-3276455640-500..Run: [BackupNotify] c:Program FilesHewlett-PackardDigital Imaginginackupnotify.exe (User 'Administrateur')
O4 - HKUSS-1-5-21-2594731810-3581480619-3276455640-500..Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook (User 'Administrateur')
O4 - S-1-5-21-2594731810-3581480619-3276455640-500 Startup: mod_sm.lnk = C:hpincloaker.exe (User 'Administrateur')
O4 - S-1-5-21-2594731810-3581480619-3276455640-500 User Startup: mod_sm.lnk = C:hpincloaker.exe (User 'Administrateur')
O4 - .DEFAULT User Startup: mod_sm.lnk = C:hpincloaker.exe (User 'Default user')
O4 - Startup: OneNote 2007 - Capture d'écran et lancement.lnk = C:Program FilesMicrosoft OfficeOffice12ONENOTEM.EXE
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:Program FilesHewlett-PackardDigital Imaginginhpqtra08.exe
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O8 - Extra context menu item: Add to Google Photos Screensa&ver -
res://C:WINDOWSsystem32GPhotos.scr/200
O8 - Extra context menu item: E&xporter vers Microsoft Excel -
res://C:PROGRA~1MICROS~3Office12EXCEL.EXE/3000
O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:PROGRA~1MICROS~3Office12ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:PROGRA~1MICROS~3Office12ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:PROGRA~1MICROS~3Office12REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:PROGRA~1SPYBOT~1SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:PROGRA~1SPYBOT~1SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:WINDOWSNetwork Diagnosticxpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:WINDOWSNetwork Diagnosticxpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe
O15 - Trusted Zone:
http://www.secuser.com
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.microsoft.com/windows ... 6077696015
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/s ... wflash.cab
O23 - Service: ASKService - Unknown owner - C:Program FilesAskBarDisarinAskService.exe
O23 - Service: ASKUpgrade - Unknown owner - C:Program FilesAskBarDisarinASKUpgrade.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:Program FilesAlwil SoftwareAvast4aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:Program FilesAlwil SoftwareAvast4ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:Program FilesAlwil SoftwareAvast4ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:Program FilesAlwil SoftwareAvast4ashWebSv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:Program FilesGoogleCommonGoogle UpdaterGoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:Program FilesJavajre6injqs.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:WINDOWSSystem32
vsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:WINDOWSsystem32HPZipm12.exe
--
End of file - 9146 bytes
rapport toolbar : 0
-----------\ ToolBar S&D 1.2.8 XP/Vista
Microsoft Windows XP Edition familiale ( v5.1.2600 ) Service Pack 3
X86-based PC ( Uniprocessor Free : Intel(R) Pentium(R) 4 CPU 2.60GHz )
BIOS : Phoenix - AwardBIOS v6.00PG
USER : Propriétaire ( Administrator )
BOOT : Normal boot
Antivirus : avast! antivirus 4.8.1335 [VPS 090331-0] 4.8.1335 (Activated)
A: (USB)
C: (Local Disk) - NTFS - Total:144 Go (Free:75 Go)
D: (Local Disk) - FAT32 - Total:4 Go (Free:0 Go)
E: (CD or DVD)
F: (USB)
G: (USB)
I: (CD or DVD)
"C:ToolBar SD" ( MAJ : 21-12-2008|20:47 )
Option : [1] ( 01/04/2009|15:38 )
-----------\ Recherche de Fichiers / Dossiers ...
[Service] ASKService
[Service] ASKUpgrade
C:Program FilesAskBarDis
C:Program FilesAskBarDisar
C:Program FilesAskBarDisunins000.dat
C:Program FilesAskBarDisunins000.exe
C:Program FilesAskBarDisarin
C:Program FilesAskBarDisarCache
C:Program FilesAskBarDisarHistory
C:Program FilesAskBarDisarSettings
C:Program FilesAskBarDisarinaskBar.dll
C:Program FilesAskBarDisarinaskPopStp.dll
C:Program FilesAskBarDisarinAskService.exe
C:Program FilesAskBarDisarinAskSplash.exe
C:Program FilesAskBarDisarinAskTBApp.exe
C:Program FilesAskBarDisarinASKUpgrade.exe
C:Program FilesAskBarDisarinpsvince.dll
C:Program FilesAskBarDisarCache 127D239
C:Program FilesAskBarDisarCache 127D517
C:Program FilesAskBarDisarCache 127D6CD.bin
C:Program FilesAskBarDisarCache 127D8E0.bin
C:Program FilesAskBarDisarCache 127DA67.bin
C:Program FilesAskBarDisarCache 127DBDE.bin
C:Program FilesAskBarDisarCache 127DD45.bin
C:Program FilesAskBarDisarCache 127DEAD.bin
C:Program FilesAskBarDisarCache 127E014.bin
C:Program FilesAskBarDisarCachefiles.ini
C:Program FilesAskBarDisarHistorysearch
C:Program FilesAskBarDisarSettingsAskLogo.ico
C:Program FilesAskBarDisarSettingsconfig.dat
C:Program FilesAskBarDisarSettingsprevcfg.htm
C:Program FilesAskBarDisarSettingsprevCfg2.htm
-----------\ Extensions
(Propriétaire) - {4b897551-0a2b-4159-99e7-3cd721caec78} => references.tv
(Propriétaire) - {fe37be35-b028-49f9-bb0c-6a38c4e55b97} => p2p_max_france
-----------\ [..Internet ExplorerMain]
[HKEY_CURRENT_USERSoftwareMicrosoftInternet ExplorerMain]
"Local Page"="C:\WINDOWS\system32\blank.htm"
"Start Page"="http://google.fr/"
"Search Page"="http://www.google.com"
"Search Bar"="http://www.google.com/ie"
"Default_Search_URL"="http://www.google.com/ie"
[HKEY_LOCAL_MACHINESoftwareMicrosoftInternet ExplorerMain]
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page"="http://www.msn.com/"
"Search Bar"="http://srch-fr9.hpwis.com/"
--------------------\ Recherche d'autres infections
--------------------\ Cracks & Keygens ..
C:DOCUME~1PROPRI~1Mes documentsA-one.DVD.Copy.v6.8.5.Incl-Keygen.[emule-island.com].rar
C:DOCUME~1PROPRI~1Mes documentsAvast.Antivirus.Pro.v4.8.1335.FR.Incl-Keygen.[eMule-DivX.com].rar
C:DOCUME~1PROPRI~1Mes documentsKeygen
C:DOCUME~1PROPRI~1Mes documentsNero.9.v9.2.6.0.FR.Incl-Keygen.[emule-island.com].rar
C:DOCUME~1PROPRI~1Mes documentsNero.v6.6.1.15c.Ultra.Edition.Incl-Keygen.et.Patch.FR.[emule-island.com].rar
C:DOCUME~1PROPRI~1Mes documentsWinRAR.v3.80.FR.Incl-Crack.[eMule-DivX.com].zip
C:DOCUME~1PROPRI~1Mes documentsKeygencrd-mbam.1.05_Keygen.exe
C:DOCUME~1PROPRI~1Mes documentsMa musiqueCCrack Ov Dawn
C:DOCUME~1PROPRI~1Mes documentsMa musiqueCCracknell, Debbie
C:DOCUME~1PROPRI~1Mes documentsMa musiqueCCrack Ov DawnCrack Ov Dawn - Miss Suicide.gp4
C:DOCUME~1PROPRI~1Mes documentsMa musiqueCCrack Ov DawnCrack Ov Dawn - Rise And Fall.gp4
C:DOCUME~1PROPRI~1Mes documentsMa musiqueCCracknell, DebbieCracknell, Debbie - Guitar Talk.gp4
C:DOCUME~1PROPRI~1Mes documentsMa musiqueFFaith No MoreFaith No More - Crack Hitler.gp3
C:DOCUME~1PROPRI~1Mes documentsMa musiqueLLeftover Crack
C:DOCUME~1PROPRI~1Mes documentsMa musiqueLLeftover CrackLeftover Crack - Gang Control.gp4
C:DOCUME~1PROPRI~1Mes documentsMa musiqueLLeftover CrackLeftover Crack - Nazi White Trash.gp4
C:DOCUME~1PROPRI~1Mes documentsMa musiqueLLeftover CrackLeftover Crack - Operation Mouve.gp4
C:DOCUME~1PROPRI~1Mes documentsMa musiqueLLimp BizkitLimp Bizkit - Crack Addict (2).gp4
C:DOCUME~1PROPRI~1Mes documentsMa musiqueLLimp BizkitLimp Bizkit - Crack Addict (3).gp4
C:DOCUME~1PROPRI~1Mes documentsMa musiqueLLimp BizkitLimp Bizkit - Crack Addict.gp4
C:DOCUME~1PROPRI~1Mes documentsMa musiqueMMalmsteen, YngwieMalmsteen, Yngwie - Cracking The Whip.gp4
C:DOCUME~1PROPRI~1Mes documentsMa musiquePPixiesPixies - Crackity Jones.gp3
C:DOCUME~1PROPRI~1Mes documentsMa musiqueSSoliz, DavidSoliz, David - Crack Kills.gp4
C:DOCUME~1PROPRI~1Mes documentsMes vidéosNero.9.v9.2.6.0.FR.Incl-Keygen.[eMule-DivX.com].rar
C:DOCUME~1PROPRI~1Mes documentsMes vidéosPerfect.Uninstaller.v6.3.2.6.Incl-Keygen.[eMule-DivX.com].rar
C:DOCUME~1PROPRI~1Mes documentsNouveau dossierBabylon.7.0.0.17.Pro.Multilingual.Incl.Crack.-.zip
C:DOCUME~1PROPRI~1Mes documentsNouveau dossierGoogle Sketchup 5.0.260.00 Pro Keygen (Français).rar
C:DOCUME~1PROPRI~1Mes documentsNouveau dossierGoogle SketchUp Pro v6.0.312 + Components + Crack.rar
1 - "C:ToolBar SDTB_1.txt" - 27/03/2009|15:14 - Option : [1]
2 - "C:ToolBar SDTB_2.txt" - 27/03/2009|16:39 - Option : [1]
3 - "C:ToolBar SDTB_3.txt" - 27/03/2009|18:37 - Option : [2]
4 - "C:ToolBar SDTB_4.txt" - 27/03/2009|21:08 - Option : [1]
5 - "C:ToolBar SDTB_5.txt" - 28/03/2009|11:11 - Option : [1]
6 - "C:ToolBar SDTB_6.txt" - 01/04/2009|15:41 - Option : [1]
-----------\ Fin du rapport a 15:41:23,26
.reglages:
rapport spybot trouve:microsoft.window.security explorer -HKEY-USERS 1-5-21-2594731810-35814806119-327645 JE LE SUPPRIME OU LE RESTAURE MERCI