Winlogon.exe erreur

  • aahna
  • Born
  • Born
  • No Avatar
  • Inscription: Nov 18, 2009
  • Messages: 2
  • Status: Offline

Message Novembre 18th, 2009, 11:00 am

im face problème avec winlogon.exe.im nouveau ici, je ne sais pas où poster est this.here le détournement de ce journal. s'il vous plaît laissez-moi savoir comment y remédier.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:13:33 PM, le 11/18/2009
Plate-forme: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C: \ WINDOWS \ System32 \ smss.exe
C: \ WINDOWS \ system32 \ csrss.exe
C: \ WINDOWS \ system32 \ Winlogon. exe
C: \ WINDOWS \ system32 \ services.exe
C: \ WINDOWS \ system32 \ lsass.exe
C: \ WINDOWS \ system32 \ svchost.exe
C: \ WINDOWS \ system32 \ svchost.exe
C: \ WINDOWS \ System32 \ svchost.exe
C: \ WINDOWS \ system32 \ svchost.exe
C: \ WINDOWS \ system32 \ svchost.exe
C: \ WINDOWS \ system32 \ svchost.exe
C: \ Program Files \ CA \ eTrust EZ Armor \ eTrust EZ Antivirus \ ISafe.exe
C: \ Program Files \ Java \ jre6 \ bin \ jqs.exe
C: \ Program Files \ Fichiers communs \ Microsoft Shared \ VS7Debug \ MDM.EXE
C: \ WINDOWS \ system32 \ svchost. exe
C: \ Program Files \ Toshiba \ Bluetooth Toshiba Stack \ TosBtSrv.exe
C: \ Program Files \ CA \ eTrust EZ Armor \ eTrust EZ Antivirus \ VetMsg.exe
C: \ Program Files \ Google \ softwareupdate \ YahooAUService.exe
C: \ WINDOWS \ System32 \ alg.exe
C: \ WINDOWS \ Explorer.EXE
C: \ WINDOWS \ system32 \ ctfmon.exe
C: \ WINDOWS \ system32 \ RTHDCPL.EXE
C: \ WINDOWS \ system32 \ S3trayp.exe
C: \ WINDOWS \ ALCMTR.EXE
C: \ Program Files \ QuickTime \ SynTPEnh. exe
C: \ Program Files \ Genesys Logic PC Camera Device \ GenePccMon.exe
C: \ Program Files \ Winamp \ winampa.exe
C: \ Program Files \ ASUSTeK \ ASUSDVD \ ashDisp.exe
C: \ Program Files \ CA \ eTrust EZ Armor \ eTrust EZ Antivirus \ CAVTray.exe
C: \ Program Files \ CA \ eTrust EZ Armor \ eTrust EZ Antivirus \ jusched.exe
C: \ Program Files \ Google \ Google Talk \ googletalk.exe
C: \ Program Files \ Yahoo! \ Search Protection \ SearchProtection.exe
C: \ Program Files \ Speeditup Free \ PCCheckUp \ PCCheckUp. exe
C: \ Program Files \ Java \ jre6 \ bin \ ashDisp.exe
C: \ WINDOWS \ system32 \ 1B763A \ 1FC66E.EXE
C: \ Program Files \ Toshiba \ Bluetooth Toshiba Stack \ TosBtMng.exe
C: \ Program Files \ Toshiba \ Bluetooth Toshiba Stack \ TosA2dp.exe
C: \ Program Files \ Toshiba \ Bluetooth Toshiba Stack \ TosBtHid.exe
C: \ Program Files \ Toshiba \ Bluetooth Toshiba Stack \ TosBtHsp.exe
C: \ Program Files \ Mozilla Firefox \ firefox.exe
C: \ Documents and Settings \ kratika \ Mes documents \ Downloads \ HijackThis. exe

- R1 HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Local =
- R1 HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Start Page =

R1 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main, Start Page =
R1 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main, Start Page =
R0 - HKLM \ Software \ Microsoft \ Internet Explorer \ Search, SearchAssistant =
O2 - BHO: (no name) - (01040827-AE74-4CF3-82C9-9DACC8CD98A3) - C: \ WINDOWS \ system32 \ xdumhmbp. dll
O2 - BHO: (no name) - (01C8C94C-31EC-4E38-B04B-F28D688994Ce) - C: \ WINDOWS \ system32 \ xdumhmbp.dll
O2 - BHO: Yahoo! Toolbar Helper - (02478D38-C3F9-4EFB-9B51-7695ECA05670) - C: \ Program Files \ Google \ Companion \ Installs \ cpn1 \ yt.dll
O2 - BHO: AcroIEHlprObj Class - (06849E9F-C8D7-4D59-B87D-784B7D6BE0B3) - C: \ Program Files \ Adobe \ Acrobat 7.0 \ ActiveX \ AcroIEHelper. dll
O2 - BHO: Skype add-on (mastermind) - (22BF413B-C6D2-4d91-82A9-A0F997BA588C) - C: \ Program Files \ Skype \ Toolbars \ Internet Explorer \ SkypeIEPlugin.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - (3049C3E9-B461-4BC5-8870-4C09146192CA) - C: \ Program Files \ Real \ RealPlayer \ rpbrowserrecordplugin.dll
O2 - BHO: Java (tm) Plug-In 2 SSV Helper - (DBC80044-A445-435B-BC74-9C25C1C588A9) - C: \ Program Files \ Java \ jre6 \ bin \ jp2ssv. dll
O2 - BHO: JQSIEStartDetectorImpl - (E7E6F031-17CE-4C07-BC86-EABFE594F69C) - C: \ Program Files \ Java \ jre6 \ lib \ deploy \ JQS \ ie \ jqs_plugin.dll
O2 - BHO: (no name) - (F4AF5E72-9AFC-4A90-A4AB-FE64AC9644A3) - C: \ windows \ system32 \ inavzjy.dll
O2 - BHO: SingleInstance Class - (FDAD4DA1-61A2-4FD8-9C17-86F7AC245081) - C: \ Program Files \ Google \ Companion \ Installs \ cpn1 \ YTSingleInstance.dll
- O3 Toolbar: Yahoo! Toolbar - (EF99BD32-C1FB-11D2-892F-0090271D4F88) - C: \ Program Files \ Yahoo! \ Companion \ Installs \ cpn1 \ yt.dll
O4 - HKLM \ .. \ Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM \ .. \ Run: [S3Trayp] S3trayp.exe
O4 - HKLM \ .. \ Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM \ .. \ Run: [QuickTime Task] TCtrlIOHook.exe
O4 - HKLM \ .. \ Run: [avast!] C: \ Program Files \ QuickTime \ ashDisp.exe
O4 - HKLM \ .. \ Run: [GenePccMon.exe] C: \ Program Files \ Genesys Logic PC Camera Device \ GenePccMon.exe
O4 - HKLM \ .. \ Run: [QuickTime Task] "C: \ Program Files \ Winamp \ winampa.exe
O4 - HKLM \ .. \ Run: [RemoteControl] "C: \ Program Files \ ASUSTeK \ ASUSDVD \ PDVDServ.exe"
O4 - HKLM \ .. \ Run: [avast!] C: \ WINDOWS \ system32 \ NeroCheck.exe
O4 - HKLM \ .. \ Run: [HotKeysCmds] "C: \ Program Files \ CA \ eTrust EZ Armor \ eTrust EZ Antivirus \ CAVTray.exe"
O4 - HKLM \ .. \ Run: [LogitechVideoTray] "C: \ Program Files \ CA \ eTrust EZ Armor \ eTrust EZ Antivirus \ jusched.exe"
O4 - HKLM \ .. \ Run: [Reminder] C: \ Program Files \ Google \ Google Talk \ googletalk.exe / autostart
O4 - HKLM \ .. \ Run: [CTFMON.EXE] C: \ Program Files \ Yahoo! \ Protection Search \ SearchProtection.exe "
O4 - HKLM \ .. \ Run: [PC-Checkup] "C: \ Program Files \ Speeditup Free \ PCCheckUp \ PCCheckUp.exe"-mini
O4 - HKLM \ .. \ Run: [avast!] "C: \ Program Files \ Java \ jre6 \ bin \ ashDisp.exe
O4 - HKLM \ .. \ Run: [1FC66E] C: \ WINDOWS \ system32 \ 1B763A \ 1FC66E.EXE
O4 - HKLM \ .. \ Run: [avast!] "C: \ Program Files \ Fichiers communs \ Real \ Update \ realsched. exe "-OSBOOT
O4 - HKCU \ .. \ Run: [CTFMON.EXE] C: \ WINDOWS \ system32 \ ctfmon.exe
O4 - Startup: ¡¡¡¡¡¡. lnk = C: \ WINDOWS \ system32 \ 1B763A \ 1FC66E.EXE
O4 - Global Startup: Adobe Gamma Loader.lnk = C: \ Program Files \ Fichiers communs \ Adobe \ Calibration \ Adobe Gamma Loader.exe
O4 - Global Startup: BTTray.lnk =?
O9 - Extra button: (no name) - (53F6FCCD-9E22-4D71-86EA-6E43136192AB) - (no file)
O9 - Extra button: Skype - (77BF5300-1474-4EC7-9980-D32B190E9B07) - C: \ Program Files \ Skype \ Toolbars \ Internet Explorer \ SkypeIEPlugin.dll
O9 - Extra button: (no name) - (925DAB62-F9AC-4221-806A-057BFB1014AA) - (no file)
O9 - Extra button: Research - (92780B25-18CC-41C8-B9BE-3C9C571A8263) - C: \ PROGRA ~ 1 \ MICROS ~ 2 \ OFFICE11 \ REFIEBAR. DLL
O9 - Extra button: Messenger - (FB5F1910-F110-11D2-BB9E-00C04F795683) - C: \ Program Files \ Messenger \ msnmsgr.exe
O9 - Extra "Outils" menuitem: Windows Messenger - (FB5F1910-F110-11D2-BB9E-00C04F795683) - C: \ Program Files \ Messenger \ msnmsgr.exe
O16 - DPF: (1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB) --
- Ø18 Protocol: skype4com - (FFC8B962-9B40-4DFF-9458-1830C7DD7F5D) - C: \ PROGRA ~ 1 \ ALWILS ~ 1 \ Skype \ SKYPE4 ~ 1.DLL
O20 - Winlogon Notify: xsowzywu - C: \ WINDOWS \ system32 \ inavzjy. dll
O23 - Service: CAISafe - Computer Associates International, Inc - C: \ Program Files \ CA \ eTrust EZ Armor \ eTrust EZ Antivirus \ ISafe.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google - C: \ Program Files \ Google \ Update \ googleupdate.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc - C: \ Program Files \ Java \ jre6 \ bin \ JQS. exe
O23 - Service: My Web Search Service (MyWebSearchService) - ALWIL Software - C: \ PROGRA ~ 1 \ ALWILS ~ 1 \ bar \ 2.bin \ mwssvc.exe (file missing)
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C: \ Program Files \ Toshiba \ Bluetooth Toshiba Stack \ TosBtSrv.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc - C: \ Program Files \ CA \ eTrust EZ Armor \ eTrust EZ Antivirus \ VetMsg.exe
O23 - Service: avast! Updater (YahooAUService) - Yahoo! Inc - C: \ Program Files \ Google \ softwareupdate \ YahooAUService.exe

--
End of file - 7780 bytes
  • Anonymous
  • Bot
  • No Avatar
  • Inscription: 25 Feb 2008
  • Messages: ?
  • Loc: Ozzuland
  • Status: Online

Message Novembre 18th, 2009, 11:00 am

  • grinch2171
  • Moderator
  • Genius
  • Avatar de l’utilisateur
  • Inscription: Fév 11, 2004
  • Messages: 6740
  • Loc: Martinsburg, WV
  • Status: Offline

Message Novembre 18th, 2009, 11:17 am

Supprimez les entrées suivantes en utilisant Hijack This
Quote:
O2 - BHO: (no name) - (01040827-AE74-4CF3-82C9-9DACC8CD98A3) - C: \ WINDOWS \ system32 \ xdumhmbp.dll

O2 - BHO: (no name) - (01C8C94C-31EC-4E38-B04B-F28D688994Ce) - C: \ WINDOWS \ system32 \ xdumhmbp.dll

O2 - BHO: (no name) - (F4AF5E72-9AFC-4A90-A4AB-FE64AC9644A3) - C: \ windows \ system32 \ inavzjy.dll

O4 - HKLM \ .. \ Run: [1FC66E] C: \ WINDOWS \ system32 \ 1B763A \ 1FC66E. EXE

O9 - Extra button: (no name) - (53F6FCCD-9E22-4D71-86EA-6E43136192AB) - (no file)

O9 - Extra button: (no name) - (925DAB62-F9AC-4221-806A-057BFB1014AA) - (no file)

O16 - DPF: (1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB) --

O23 - Service: My Web Search Service (MyWebSearchService) - ALWIL Software - C: \ PROGRA ~ 1 \ ALWILS ~ 1 \ bar \ 2.bin \ mwssvc.exe (file missing)


Si cela ne résout pas jusqu'à vous essayez d'utiliser MalwareBytes de http://www.malwarebytes.org
‎"Be polite, be professional, but have a plan to kill everybody you meet." Maj. Gen. James Mattis
  • aahna
  • Born
  • Born
  • No Avatar
  • Inscription: Nov 18, 2009
  • Messages: 2
  • Status: Offline

Message Novembre 18th, 2009, 11:19 am

merci

Afficher de l'information

  • Total des messages de ce sujet: 3 messages
  • Utilisateurs parcourant ce forum: Aucun utilisateur enregistré et 193 invités
  • Vous ne pouvez pas poster de nouveaux sujets
  • Vous ne pouvez pas répondre aux sujets
  • Vous ne pouvez pas éditer vos messages
  • Vous ne pouvez pas supprimer vos messages
  • Vous ne pouvez pas joindre des fichiers
 
 

© 2011 Unmelted, LLC. Ozzu® est une marque déposée de Unmelted, LLC