Got "Worm.Win32.Netsky« Voici mon HJT Log

  • Sasuke
  • Born
  • Born
  • No Avatar
  • Inscription: Nov 24, 2009
  • Messages: 4
  • Status: Offline

Message Novembre 25th, 2009, 2:37 pm

J'ai eu un virus appelé "Worm.Win32.Netsky" et il a infecté mon ordinateur, j'ai aussi utilisé highjackthis et voici mon fichier de log (également sur une note côté, je pense que cela va sans dire, mais rien dire (dot) signifie qu'il n'y utiliser pour être un point là-bas mais maintenant je viens il a changé parce que ce poste ne seront pas accepter liens) Et j'ai juste besoin d'aide pour se débarrasser d'elle, merci -



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:58:54, le 11/25/2009
Plate-forme: Windows XP SP3 (Windows NT 5.01. 2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C: \ WINDOWS \ System32 \ smss.exe
C: \ WINDOWS \ system32 \ winlogon.exe
C: \ WINDOWS \ system32 \ services.exe
C: \ WINDOWS \ system32 \ lsass.exe
C: \ WINDOWS \ system32 \ svchost.exe
C: \ WINDOWS \ System32 \ svchost.exe
C: \ WINDOWS \ system32 \ svchost.exe
C: \ Program Files \ Fichiers communs \ Apple \ Mobile Device Support \ bin \ AppleMobileDeviceService.exe
C: \ Program Files \ Bonjour \ mDNSResponder. exe
C: \ Program Files \ Prevx \ prevx.exe
C: \ Program Files \ Java \ jre6 \ bin \ jqs.exe
C: \ PROGRA ~ 1 \ McAfee \ MSC \ mcmscsvc.exe
C: \ PROGRA ~ 1 \ ALWILS ~ 1 \ \ McAfee mna \ mcnasvc.exe
C: \ PROGRA ~ 1 \ ALWILS ~ 1 \ \ McAfee mcproxy \ mcproxy.exe
C: \ Program Files \ McAfee \ MPF \ MPFSrv.exe
C: \ WINDOWS \ system32 \ svchost.exe
C: \ Program Files \ TBH \ Monitor \ bin \ tbhMonitor.exe
C: \ Program Files \ TBH \ base \ bin \ tbhDaemon.exe
C: \ WINDOWS \ Explorer.EXE
C: \ Program Files \ Prevx \ Prevx. exe
C: \ Program Files \ McAfee (dot) com \ Agent \ McUpdate.exe
C: \ Program Files \ Dealio Toolbar \ SearchSettings.exe
C: \ Program Files \ Java \ jre6 \ bin \ ashDisp.exe
C: \ Program Files \ TBH \ base \ bin \ tbhSystray.exe
C: \ Program Files \ Messenger \ msnmsgr.exe
C: \ WINDOWS \ system32 \ ctfmon.exe
C: \ Program Files \ Pando Networks \ Media Booster \ PMB.exe
C: \ Program Files \ Messenger \ msnmsgr.exe
C: \ Program Files \ SUPERAntiSpyware. exe
C: \ Documents and Settings \ Grant \ Local Settings \ Application Data \ Google \ Update \ 1.2.183.13 \ GoogleCrashHandler.exe
C: \ Program Files \ Hewlett-Packard \ AiO \ HP Officejet série 7100 \ Bin \ hpogrp07.exe
C: \ Program Files \ Interactive Studios \ QuickLicenseMgr \ QlmSysTray.exe
C: \ PROGRA ~ 1 \ HEWLET ~ 1 \ AiO \ Shared \ Bin \ hpoevm07.exe
C: \ Program Files \ Hewlett-Packard \ AiO \ Shared \ bin \ hpOSTS07.exe
C: \ Program Files \ Hewlett-Packard \ AiO \ Shared \ bin \ hpOFXM07.exe
C: \ PROGRA ~ 1 \ McAfee \ viruss ~ 1 \ mcsysmon. exe
C: \ Program Files \ Skype \ Plugin Manager \ skypePM.exe
C: \ Program Files \ Mozilla Firefox \ firefox.exe
C: \ Program Files \ Skype \ Toolbars \ Shared \ SkypeNames.exe
C: \ PROGRA ~ 1 \ McAfee \ viruss ~ 1 \ mcshield.exe
C: \ WINDOWS \ system32 \ rundll32.exe
C: \ Program Files \ Trend Micro \ HijackThis \ HijackThis.exe
C: \ PROGRA ~ 1 \ McAfee \ MSC \ mcshell.exe

R0 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main, Start Page = http://www.ask(dot com)? o = 101676 & l = this
- R1 HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Local = http://go.microsoft(dot com) / fwlink /? LinkId = 69157
- R1 HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Start Page = http://go.microsoft(dot com) / fwlink /? LinkId = 54896
R1 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main, Start Page = http://go.microsoft(dot com) / fwlink /? LinkId = 54896
R0 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Start Page = http://go.microsoft(dot ) / fwlink com /? LinkId = 69157
R1 - HKCU \ Software \ Microsoft \ Windows \ CurrentVersion \ Internet Settings, ProxyServer = 129.41.196.151:8080
R1 - HKCU \ Software \ Microsoft \ Windows \ CurrentVersion \ Internet Settings, ProxyOverride = *. local
R3 - URLSearchHook: Yahoo! Toolbar - (EF99BD32-C1FB-11D2-892F-0090271D4F88) - C: \ Program Files \ Google \ Companion \ Installs \ cpn \ YT. dll (file missing)
R3 - URLSearchHook: DefaultSearchHook Class - (C94E154B-1459-4A47-966B-4B843BEFC7DB) - C: \ Program Files \ AskSearch \ bin \ DefaultSearch.dll (file missing)
R3 - BHO: (no name) - (E312764E-7706-43F1-8DAB-FCDD2B1E416D) - C: \ Program Files \ Dealio Toolbar \ SearchSettings.dll
O2 - BHO: Dealio Toolbar - (01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C) - C: \ Program Files \ Dealio Toolbar \ DealioToolbarIE.dll
O2 - BHO: Yahoo! Toolbar Helper - (02478D38-C3F9-4EFB-9B51-7695ECA05670) - C: \ Program Files \ Google \ Companion \ Installs \ cpn \ yt.dll (file missing)
O2 - BHO: AskBar BHO - (201f27d4-3704-41d6-89c1-aa35e39143ed) - C: \ Program Files \ AskBarDis \ bar \ bin \ askBar.dll (file missing)
O2 - BHO: scriptproxy - (7DB2D5A0-7241-4E79-B68D-6309F01C5231) - C: \ Program Files \ McAfee \ VirusScan \ scriptsn. dll
O2 - BHO: Mega Manager IE Click Monitor - (bf00e119-21a3-4fd1-B178-3b8537e75c92) - C: \ Program Files \ Megaupload \ Mega Manager \ MegaIEMn.dll
O2 - BHO: Java (tm) Plug-In 2 SSV Helper - (DBC80044-A445-435B-BC74-9C25C1C588A9) - C: \ Program Files \ Java \ jre6 \ bin \ jp2ssv.dll
O2 - BHO: (no name) - (E312764E-7706-43F1-8DAB-FCDD2B1E416D) - C: \ Program Files \ Dealio Toolbar \ SearchSettings. dll
O2 - BHO: JQSIEStartDetectorImpl - (E7E6F031-17CE-4C07-BC86-EABFE594F69C) - C: \ Program Files \ Java \ jre6 \ lib \ deploy \ JQS \ ie \ jqs_plugin.dll
O2 - BHO: SingleInstance Class - (FDAD4DA1-61A2-4FD8-9C17-86F7AC245081) - C: \ Program Files \ Google \ Companion \ Installs \ cpn \ YTSingleInstance.dll (file missing)
- O3 Toolbar: Yahoo! Toolbar - (EF99BD32-C1FB-11D2-892F-0090271D4F88) - C: \ Program Files \ Google \ Companion \ Installs \ cpn \ YT. dll (file missing)
- O3 Toolbar: Ask Toolbar - (3041d03e-fd4b-44e0-b742-2d9b88305f98) - C: \ Program Files \ AskBarDis \ bar \ bin \ askBar.dll (file missing)
- O3 Toolbar: Dealio Toolbar - (01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C) - C: \ Program Files \ Dealio Toolbar \ DealioToolbarIE.dll
O4 - HKLM \ .. \ Run: [LogitechQuickCamRibbon] "C: \ Program Files \ McAfee (dot) com \ Agent \ McUpdate.exe" / runkey
O4 - HKLM \ .. \ Run: [SearchSettings] C: \ Program Files \ Dealio Toolbar \ SearchSettings.exe
O4 - HKLM \ .. \ Run: [MyWebSearch Plugin] rundll32 C: \ PROGRA ~ 1 \ ALWILS ~ 1 \ bar \ 1.bin \ M3PLUGIN.DLL, UPF
O4 - HKLM \ .. \ Run: [avast!] "C: \ Program Files \ Java \ jre6 \ bin \ ashDisp.exe
O4 - HKLM \ .. \ Run: [QuickTime Task] "C: \ Program Files \ QuickTime \ qttask.exe"-atboottime
O4 - HKLM \ .. \ Run: [tbhSystray] C: \ Program Files \ TBH \ base \ bin \ tbhSystray.exe
O4 - HKLM \ .. \ Run: [winupdate86.exe] C: \ WINDOWS \ system32 \ winupdate86.exe
O4 - HKCU \ .. \ Run: [Google Update] "C: \ Documents and Settings \ Grant \ Local Settings \ Application Data \ Google \ Update \ googleupdate.exe" / c
O4 - HKCU \ .. \ Run: [Skype] "C: \ Program Files \ Messenger \ msnmsgr.exe" / background
O4 - HKCU \ .. \ Run: [CTFMON.EXE] C: \ WINDOWS \ system32 \ ctfmon.exe
O4 - HKCU \ .. \ Run: [C: \ Documents and Settings \ Grant \ Mes documents \ Downloads \ Tunebite Platinum v5.1.169.6900 \ Tunebite Platinum v5.1.169.6900 \ Tunebite. exe] C: \ Documents and Settings \ Grant \ Mes documents \ Downloads \ Tunebite Platinum v5.1.169.6900 \ Tunebite Platinum v5.1.169.6900 \ tunebite.exe
O4 - HKCU \ .. \ Run: [Tunebite] C: \ Program Files \ RapidSolution \ Tunebite \ Tunebite.exe bac
O4 - HKCU \ .. \ Run: [Monopod] C: \ PROGRA ~ 1 \ Grant \ LOCALS ~ 1 \ Temp \ b.exe
O4 - HKCU \ .. \ Run: [NordBull] C: \ WINDOWS \ msa.exe
O4 - HKCU \ .. \ Run: [SpeedItUpEX] C: \ Program Files \ Speeditup Free \ SpeedItUp.exe-MINI
O4 - HKCU \ .. \ Run: [Pando Media Booster] C: \ Program Files \ Pando Networks \ Media Booster \ PMB.exe
O4 - HKCU \ .. \ Run: [Skype] "C: \ Program Files \ Messenger \ msnmsgr.exe" / background
O4 - HKCU \ .. \ Run: [SUPERAntiSpyware] C: \ Program Files \ TeaTimer.exe
O4 - Startup: Mozilla Firefox.lnk = C: \ Program Files \ Mozilla Firefox \ firefox.exe
O4 - Startup: Quick License Manager Reader.lnk = C: \ Program Files \ Interactive Studios \ QuickLicenseMgr \ QlmSysTray. exe
O4 - Global Startup: Adobe Gamma Loader.exe = C: \ Program Files \ Fichiers communs \ Adobe \ Calibration \ Adobe Gamma Loader.exe
O4 - Global Startup: HPAiODevice (HP Officejet série 7100) - 1.lnk = C: \ Program Files \ Hewlett-Packard \ AiO \ HP Officejet série 7100 \ Bin \ hpogrp07.exe
O8 - Extra context menu item: & Recherche -- http://edits.mywebsearch(dot ) / COM toolbaredits / menusearch.jhtml? = p ZJfox000
O8 - Extra context menu item: Télécharger le lien à l'aide Mega Manager...- C: \ Program Files \ Megaupload \ Mega Manager \ mm_file.htm
O8 - Extra context menu item: E & xporter vers Microsoft Excel -- res://C : \ PROGRA ~ 1 \ MICROS ~ 3 \ OFFICE11 \ EXCEL.EXE/3000
O9 - Extra button: Research - (92780B25-18CC-41C8-B9BE-3C9C571A8263) - C: \ PROGRA ~ 1 \ MICROS ~ 3 \ OFFICE11 \ REFIEBAR. DLL
O9 - Extra button: (no name) - (e2e2dd38-d088-4134-82b7-f2ba38496583) - C: \ WINDOWS \ Network Diagnostic \ xpnetdiag.exe
O9 - Extra "Outils" menuitem: @ xpsp3res.dll, -20001 - (e2e2dd38-d088-4134-82b7-f2ba38496583) - C: \ WINDOWS \ Network Diagnostic \ xpnetdiag.exe
O9 - Extra button: Messenger - (FB5F1910-F110-11D2-BB9E-00C04F795683) - C: \ Program Files \ Messenger \ msmsgs. exe
O9 - Extra "Outils" menuitem: Windows Messenger - (FB5F1910-F110-11D2-BB9E-00C04F795683) - C: \ Program Files \ Messenger \ msnmsgr.exe
- Ø18 Protocol: skype4com - (FFC8B962-9B40-4DFF-9458-1830C7DD7F5D) - C: \ PROGRA ~ 1 \ ALWILS ~ 1 \ Skype \ SKYPE4 ~ 1.DLL
O20 - Winlogon Notify:! - C: \ Program Files \ SASWINLO.dll
O23 - Service: Apple Mobile Device - Apple Inc - C: \ Program Files \ Fichiers communs \ Apple \ Mobile Device Support \ bin \ AppleMobileDeviceService. exe
O23 - Service: Bonjour Service - Apple Inc - C: \ Program Files \ Bonjour \ mDNSResponder.exe
O23 - Service: CSIScanner - Prevx - C: \ Program Files \ Prevx \ prevx.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc - C: \ Program Files \ Java \ jre6 \ bin \ jqs.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc - C: \ PROGRA ~ 1 \ McAfee \ MSC \ mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc - C: \ PROGRA ~ 1 \ ALWILS ~ 1 \ \ McAfee mna \ mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc - C: \ PROGRA ~ 1 \ McAfee \ viruss ~ 1 \ mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc - C: \ PROGRA ~ 1 \ ALWILS ~ 1 \ \ McAfee mcproxy \ mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc - C: \ PROGRA ~ 1 \ McAfee \ viruss ~ 1 \ mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc - C: \ PROGRA ~ 1 \ McAfee \ viruss ~ 1 \ mcsysmon. exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc - C: \ Program Files \ McAfee \ MPF \ MPFSrv.exe
O23 - Service: Le Browser Highlighter Monitor (tbhMonitor.exe) - ALWIL Software - C: \ Program Files \ TBH \ Monitor \ bin \ tbhMonitor.exe

--
End of file - 9663 bytes
  • Anonymous
  • Bot
  • No Avatar
  • Inscription: 25 Feb 2008
  • Messages: ?
  • Loc: Ozzuland
  • Status: Online

Message Novembre 25th, 2009, 2:37 pm

  • Sasuke
  • Born
  • Born
  • No Avatar
  • Inscription: Nov 24, 2009
  • Messages: 4
  • Status: Offline

Message Novembre 25th, 2009, 4:18 pm

J'ai mis à jour le journal à une version plus actuelle.

Afficher de l'information

  • Total des messages de ce sujet: 2 messages
  • Utilisateurs parcourant ce forum: Aucun utilisateur enregistré et 108 invités
  • Vous ne pouvez pas poster de nouveaux sujets
  • Vous ne pouvez pas répondre aux sujets
  • Vous ne pouvez pas éditer vos messages
  • Vous ne pouvez pas supprimer vos messages
  • Vous ne pouvez pas joindre des fichiers
 
 

© 2011 Unmelted, LLC. Ozzu® est une marque déposée de Unmelted, LLC