| Soproc.exe au démarrage [Résolu] | |
|
Aller à la page : 1, 2  |
| Auteur | Message |
|---|
Ninie62 Accro


   Age : 22 Inscrit le : 12 Aoû 2005 Messages : 333 Localisation : Lens
| Sujet: Soproc.exe au démarrage [Résolu] Lun 15 Mai 2006 - 0:05 | |
| Bonsoir, (je ne savais pas où poster...)
depuis peu à chaque fois que j'allume mon pc voilà ce qui s'affiche :

je vois pas c'est quoi... Mais je pense qu'on vas pouvoir m'éclairer hihi !
 |
|
 | |
InfoPC Administrateur


  Age : 23 Inscrit le : 14 Avr 2005 Messages : 3044 Localisation : 93150 Seine Saint Denis Configuration : Intel Core 2 Duo E6400, 2048Mo DDR2 PC6400, X1950Pro 256Mo DDR3, Vista Premium
| Sujet: Re: Soproc.exe au démarrage [Résolu] Lun 15 Mai 2006 - 19:48 | |
| Bonsoir,
Après une petite recherche, ceçi est-un spyware (Voir Infos)
Tu devrais faire un scan avec Panda en ligne et passer Spybots et Ad-Aware.
Je déplace dans le bon "Forum".
 |
|
 | |
Ninie62 Accro


   Age : 22 Inscrit le : 12 Aoû 2005 Messages : 333 Localisation : Lens
| Sujet: Re: Soproc.exe au démarrage [Résolu] Lun 15 Mai 2006 - 21:18 | |
| Bonsoir,
merci, je fais un scan, et ce que tu as dis, et je dis quoi...
 |
|
 | |
Ninie62 Accro


   Age : 22 Inscrit le : 12 Aoû 2005 Messages : 333 Localisation : Lens
| Sujet: Re: Soproc.exe au démarrage [Résolu] Lun 15 Mai 2006 - 22:46 | |
| Re,
voilà aprés deux scan avec panda, spybot et ad ware, ce qui s'affiche avec HijackThis :
Logfile of HijackThis v1.99.1 Scan saved at 22:37:37, on 15/05/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\Program Files\Ahead\InCD\InCDsrv.exe C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe C:\WINDOWS\system32\slserv.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\SOUNDMAN.EXE C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE C:\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\apps\ABoard\ABoard.exe C:\Program Files\Packard Bell EverSafe\TrayControl.exe C:\apps\ABoard\AOSD.exe C:\Program Files\Ahead\InCD\InCD.exe C:\Program Files\Virtual CD v4 SDK\system\vcsplay.exe C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe C:\Program Files\Philips ToUcam Camera\VProperty.exe C:\PROGRA~1\NUMERI~1\MONASS~1\SMARTB~1\MotiveSB.exe C:\Program Files\MsgPlus.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\Documents and Settings\stef\Mes documents\Athan\Athan.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\system32\rundll32.exe C:\program files\mailskinner\mailskinner.exe c:\Program Files\Numericable\Mon Assistant Internet\bin\mad.exe C:\PROGRA~1\INCRED~1\bin\IMApp.exe C:\Program Files\MSN Messenger\msnmsgr.exe c:\Program Files\Numericable\Mon Assistant Internet\bin\mpbtn.exe C:\PROGRA~1\Motive\ASSTCO~1\MOTIVE~1.EXE C:\Program Files\MSN Messenger\msnmsgr.exe C:\WINDOWS\system32\wscntfy.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Documents and Settings\stef\Local Settings\Temporary Internet Files\Content.IE5\65ROH71X\HijackThis[1].exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = file://C:\APPS\IE\offline\fr.htm R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Packard Bell R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens R3 - URLSearchHook: (no name) - - (no file) O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\apps\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O3 - Toolbar: (no name) - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - (no file) O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe O4 - HKLM\..\Run: [ATIPTA] C:\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe O4 - HKLM\..\Run: [NovaNet-WEB Tray Control] C:\Program Files\Packard Bell EverSafe\TrayControl.exe O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [VCSPlayer] "C:\Program Files\Virtual CD v4 SDK\system\vcsplay.exe" O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [VTTimer] VTTimer.exe O4 - HKLM\..\Run: [ToUcamVProperty] C:\Program Files\Philips ToUcam Camera\VProperty.exe O4 - HKLM\..\Run: [DXM6Patch_981116] C:\WINDOWS\p_981116.exe /Q:A O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\NUMERI~1\MONASS~1\SMARTB~1\MotiveSB.exe O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MsgPlus.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [navapp] C:\Program Files\NavExcel\NavHelper\v2.0.4d\navapp.exe O4 - HKLM\..\Run: [OPSE reminder] "C:\Program Files\ScanSoft\OmniPageSE2.0\EregFre\Ereg.exe" -r "C:\Program Files\ScanSoft\OmniPageSE2.0\EregFre\ereg.ini" O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe" O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [Athan] C:\Documents and Settings\stef\Mes documents\Athan\Athan.exe O4 - HKLM\..\Run: [ecswdpr] c:\windows\system32\ecswdpr.exe ecswdpr O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [Instant Access] rundll32.exe EGACCESS4_1058.dll,InstantAccess O4 - HKCU\..\Run: [MailSkinner] c:\program files\mailskinner\mailskinner.exe O4 - HKCU\..\Run: [SOProc_SoRefRegSoAlertWxLiteNnAj] rundll32 shell32.dll,ShellExec_RunDLL C:\PROGRA~1\SOFTWA~1\soproc.exe -pack SoRefRegSoAlertWxLiteNnAj O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MsgPlus.exe" /WinStart O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background O4 - Global Startup: Mon Assistant Internet.lnk = C:\Program Files\Numericable\Mon Assistant Internet\bin\matcli.exe O4 - Global Startup: Packard Bell EverSafe Tray Control.lnk = C:\Program Files\Packard Bell EverSafe\TrayControl.exe O4 - Global Startup: SM.lnk = C:\Program Files\SM\skymess.exe O8 - Extra context menu item: Easy-WebPrint Ajouter à la liste d'impressions - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html O8 - Extra context menu item: Easy-WebPrint Impression rapide - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html O8 - Extra context menu item: Easy-WebPrint Imprimer - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html O8 - Extra context menu item: Easy-WebPrint Prévisualiser - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm O16 - DPF: Interface Chat Voila - http://chat7.x-echo.com/version5/Applet/vchatsign.cab O16 - DPF: Interface Chat Wanadoo - http://chat7.x-echo.com/version6/Applet/wchatsign.cab O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab O16 - DPF: {01BE5BD7-B2DD-48B3-A759-59265A91E787} - http://akamai.downloadv3.com/binaries/EGDAccess/EGDACCESS_1064_XP.cab O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab O16 - DPF: {07C9CFC7-DE33-4A0C-9FFB-CDFBA843B157} - http://akamai.downloadv3.com/binaries/EGDAccess/EGDACCESS_1063_XP.cab O16 - DPF: {0D1011B3-89C8-4F8E-8693-BB970E2E81E0} - http://scripts.downloadv3.com/binaries/EGDAccess/EGDACCESS_1069_ASPIV4_XP.cab O16 - DPF: {0DA910BC-6919-489E-B584-D9A4AAC7B8DE} - http://scripts.downloadv3.com/binaries/EGDAccess/EGDACCESS_1068_ASPIV4_XP.cab O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab O16 - DPF: {17BFC8DA-B4D6-4DB9-AA40-1CD32EDA9845} - http://scripts.downloadv3.com/binaries/EGDAccess/EGDACCESS_1066_ASPIV4_XP.cab O16 - DPF: {2472DCCC-68CE-49DA-AA81-E7E6D83C1DFA} (PackageHTML) - http://acces.blonde.com/package/op/PackageHtmlCab.CAB O16 - DPF: {2A3DFC59-8A87-49A1-85D1-42903410911F} - http://scripts.dlv4.com/binaries/egaccess4/egaccess4_1058_XP.cab O16 - DPF: {39EA2F6F-3F50-4F58-9C63-4B3D53B0926E} - http://scripts.downloadv3.com/binaries/P2EClient/EGAUTH_1049_FR_XP.cab O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab O16 - DPF: {624321F1-0581-49D8-99BD-2E952C2DF31B} - http://akamai.downloadv3.com/binaries/EGDAccess/EGDACCESS_1063_ASPIV4_XP.cab O16 - DPF: {6AA85413-165C-4200-8154-71166077B22E} - http://scripts.downloadv3.com/binaries/IA/sysiasvc32_FR_XP.cab O16 - DPF: {8B3B8135-9DAA-40E7-8941-962795F9C1CB} - http://scripts.downloadv3.com/binaries/IA/syswbsvc32_FR_XP.cab O16 - DPF: {8D8BAF56-B581-4B90-A549-C4AC6B03F1BB} - http://scripts.downloadv3.com/binaries/EGDAccess/EGDACCESS_1074_XP.cab O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab O16 - DPF: {B2B0AEDF-7CDF-4792-BB67-7654AD1E1B13} - http://scripts.downloadv3.com/binaries/IA/sysinetsvc32_FR_XP.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab O16 - DPF: {BA749BC1-143E-430D-B1DA-1D2AF67A3658} - http://scripts.downloadv3.com/binaries/EGDAccess/EGDACCESS_1069_XP.cab O16 - DPF: {BD3653E4-884B-43C4-970B-670802501B7F} - http://akamai.downloadv3.com/binaries/P2EClient/EGAUTH_1043_FR_XP.cab O16 - DPF: {BE5A7132-329F-4319-B781-2A83BFE51534} - http://akamai.downloadv3.com/binaries/P2EClient/EGAUTH_1045_FR_XP.cab O16 - DPF: {C6760A07-A574-4705-B113-7856315922C3} - http://akamai.downloadv3.com/binaries/IA/sysnetsvc32_FR_XP.cab O16 - DPF: {E114CD5B-17CE-4807-890E-7B1EDF9F2E5E} - http://scripts.downloadv3.com/binaries/EGDAccess/EGDACCESS_1066_XP.cab O16 - DPF: {E7AE1661-EBEB-492B-AE0D-860DF24174C6} - http://akamai.downloadv3.com/binaries/EGDAccess/EGDACCESS_1064_ASPIV4_XP.cab O16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IncrediMail) - http://www2.incredimail.com/contents/setup/downloader/imloader.cab O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/controls/msnchat45.cab O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing) O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing) O23 - Service: InCD File System Service (InCDsrv) - AHEAD Software - C:\Program Files\Ahead\InCD\InCDsrv.exe O23 - Service: Kerio Personal Firewall 4 (KPF4) - Kerio Technologies - C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe O23 - Service: Virtual CD v4 Security service (SDK - Version) (VCSSecS) - H+H Software GmbH - C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe |
|
 | |
Marie Informaticien


   Age : 49 Inscrit le : 20 Mar 2006 Messages : 302 Configuration : Windows Vista
| |
 | |
Ninie62 Accro


   Age : 22 Inscrit le : 12 Aoû 2005 Messages : 333 Localisation : Lens
| Sujet: Re: Soproc.exe au démarrage [Résolu] Mar 16 Mai 2006 - 21:01 | |
| Bonsoir,
Merci Marie pour ta réponse
Le message d'erreur ne s'affiche plus
Je viens de faire un scan (aprés avoir fais tout ce que tu as indiqué) voilà le rapport :
Dialer:dialer.b Not disinfected c:\windows\system32\eg_auth_srv_1049.dll Adware:adware/gator Not disinfected c:\windows\GatorFDDLI.log Adware:adware/ist.istbar Not disinfected c:\program files\fichiers communs\Totem Shared Potentially unwanted tool:application/winantivirus2006 Not disinfected c:\documents and settings\all users\application data\WinAntiVirus Pro 2006 Adware:adware/block-checker Not disinfected Windows Registry Adware:adware/navipromo Not disinfected Windows Registry Spyware:Cookie/Bluestreak Not disinfected C:\Documents and Settings\All Users\Application Data\mozilla\cookies.txt[.bluestreak.com/] Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\All Users\Application Data\mozilla\cookies.txt[.doubleclick.net/] Spyware:Cookie/Comclick Not disinfected C:\Documents and Settings\All Users\Application Data\mozilla\cookies.txt[fl01.ct2.comclick.com/] Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\All Users\Application Data\mozilla\cookies.txt[.xiti.com/] Spyware:Cookie/Weborama Not disinfected C:\Documents and Settings\All Users\Application Data\mozilla\cookies.txt[.weborama.fr/] Spyware:Cookie/Valueclick Not disinfected C:\Documents and Settings\All Users\Application Data\mozilla\cookies.txt[.valueclick.com/] et avec Hijackthis :
Logfile of HijackThis v1.99.1 Scan saved at 20:55:15, on 16/05/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\Program Files\Ahead\InCD\InCDsrv.exe C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe C:\WINDOWS\system32\slserv.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\SOUNDMAN.EXE C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE C:\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\apps\ABoard\ABoard.exe C:\Program Files\Packard Bell EverSafe\TrayControl.exe C:\Program Files\Ahead\InCD\InCD.exe C:\Program Files\Virtual CD v4 SDK\system\vcsplay.exe C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe C:\Program Files\Philips ToUcam Camera\VProperty.exe C:\PROGRA~1\NUMERI~1\MONASS~1\SMARTB~1\MotiveSB.exe C:\Program Files\MsgPlus.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
 |
|
 | |
Marie Informaticien


   Age : 49 Inscrit le : 20 Mar 2006 Messages : 302 Configuration : Windows Vista
| Sujet: Re: Soproc.exe au démarrage [Résolu] Mer 17 Mai 2006 - 0:01 | |
| Bonsoir Ninie
Ton log HijackThis est incomplet. Repostes en un complet. (Clic droit/sélectionner tout, Clic droit/copier)
Il y aura encore des fichiers à supprimer (ceux trouvés par Panda) mais je veux m'assurer que ton log HijackThis est propre avant.
@+ |
|
 | |
Ninie62 Accro


   Age : 22 Inscrit le : 12 Aoû 2005 Messages : 333 Localisation : Lens
| Sujet: Re: Soproc.exe au démarrage [Résolu] Mer 17 Mai 2006 - 0:56 | |
| Bonsoir,
désolé je n'ai pas fais attention !
le voilà...
Logfile of HijackThis v1.99.1 Scan saved at 00:52:56, on 17/05/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\SOUNDMAN.EXE C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE C:\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\apps\ABoard\ABoard.exe C:\Program Files\Packard Bell EverSafe\TrayControl.exe C:\Program Files\Ahead\InCD\InCD.exe C:\Program Files\Virtual CD v4 SDK\system\vcsplay.exe C:\apps\ABoard\AOSD.exe C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe C:\Program Files\Philips ToUcam Camera\VProperty.exe C:\PROGRA~1\NUMERI~1\MONASS~1\SMARTB~1\MotiveSB.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\MsgPlus.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Ahead\InCD\InCDsrv.exe C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe c:\Program Files\Numericable\Mon Assistant Internet\bin\mad.exe C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe C:\WINDOWS\system32\slserv.exe C:\Program Files\MSN Messenger\msnmsgr.exe C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe C:\WINDOWS\System32\svchost.exe C:\PROGRA~1\INCRED~1\bin\IMApp.exe c:\Program Files\Numericable\Mon Assistant Internet\bin\mpbtn.exe C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe C:\PROGRA~1\Motive\ASSTCO~1\MOTIVE~1.EXE C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe C:\apps\Adobe\Acrobat 5.0\Reader\AcroRd32.exe C:\Documents and Settings\All Users\Documents\eMule\emule.exe C:\Program Files\Internet Explorer\iexplore.exe C:\HJT\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = file://C:\APPS\IE\offline\fr.htm R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Packard Bell R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\apps\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O3 - Toolbar: (no name) - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - (no file) O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe O4 - HKLM\..\Run: [ATIPTA] C:\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe O4 - HKLM\..\Run: [NovaNet-WEB Tray Control] C:\Program Files\Packard Bell EverSafe\TrayControl.exe O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [VCSPlayer] "C:\Program Files\Virtual CD v4 SDK\system\vcsplay.exe" O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [VTTimer] VTTimer.exe O4 - HKLM\..\Run: [ToUcamVProperty] C:\Program Files\Philips ToUcam Camera\VProperty.exe O4 - HKLM\..\Run: [DXM6Patch_981116] C:\WINDOWS\p_981116.exe /Q:A O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\NUMERI~1\MONASS~1\SMARTB~1\MotiveSB.exe O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MsgPlus.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [OPSE reminder] "C:\Program Files\ScanSoft\OmniPageSE2.0\EregFre\Ereg.exe" -r "C:\Program Files\ScanSoft\OmniPageSE2.0\EregFre\ereg.ini" O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe" O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [Athan] C:\Documents and Settings\stef\Mes documents\Athan\Athan.exe O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MsgPlus.exe" /WinStart O4 - Global Startup: Mon Assistant Internet.lnk = C:\Program Files\Numericable\Mon Assistant Internet\bin\matcli.exe O4 - Global Startup: Packard Bell EverSafe Tray Control.lnk = C:\Program Files\Packard Bell EverSafe\TrayControl.exe O4 - Global Startup: SM.lnk = C:\Program Files\SM\skymess.exe O8 - Extra context menu item: Easy-WebPrint Ajouter à la liste d'impressions - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html O8 - Extra context menu item: Easy-WebPrint Impression rapide - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html O8 - Extra context menu item: Easy-WebPrint Imprimer - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html O8 - Extra context menu item: Easy-WebPrint Prévisualiser - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm O16 - DPF: Interface Chat Voila - http://chat7.x-echo.com/version5/Applet/vchatsign.cab O16 - DPF: Interface Chat Wanadoo - http://chat7.x-echo.com/version6/Applet/wchatsign.cab O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab O16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IncrediMail) - http://www2.incredimail.com/contents/setup/downloader/imloader.cab O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/controls/msnchat45.cab O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing) O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing) O23 - Service: InCD File System Service (InCDsrv) - AHEAD Software - C:\Program Files\Ahead\InCD\InCDsrv.exe O23 - Service: Kerio Personal Firewall 4 (KPF4) - Kerio Technologies - C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe O23 - Service: Virtual CD v4 Security service (SDK - Version) (VCSSecS) - H+H Software GmbH - C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
bonne nuit !
 |
|
 | |
Marie Informaticien


   Age : 49 Inscrit le : 20 Mar 2006 Messages : 302 Configuration : Windows Vista
| Sujet: Re: Soproc.exe au démarrage [Résolu] Mer 17 Mai 2006 - 11:01 | |
| Bonjour Ninie
Ton log est propre.
On va maintenant supprimer les fichiers trouvés par Panda.
A l'aide de l'explorateur Windows, supprime les fichiers suivants (en gras): c:\windows\system32\eg_auth_srv_1049.dll c:\windows\GatorFDDLI.log c:\program files\fichiers communs\Totem Shared <-- le répertoire c:\documents and settings\all users\application data\WinAntiVirus Pro 2006 <-- le répertoire
Ensuite, rends toi sur le site de Pest Patrol et scanne ton ordinateur (le scan est très rapide). Pour cela clique sur et laisse toi guider. Le scan doit être fait avec Internet Explorer obligatoirement. A la fin du scan un rapport va être généré. Colle le dans ta prochaine réponse.
@+ |
|
 | |
Ninie62 Accro


   Age : 22 Inscrit le : 12 Aoû 2005 Messages : 333 Localisation : Lens
| Sujet: Re: Soproc.exe au démarrage [Résolu] Mer 17 Mai 2006 - 11:51 | |
| Bonjour,
Merci Marie
Mais je viens de faire un scan avec Pest Patrol... Mais euh... Je comprends pas trop ! J'ai fais "Scan For Spyware", je sais pas si c'était ca...
Je sais
Mais je ne vois pas le rapport
vraiment pas trés fut-fut...  |
|
 | |
Marie Informaticien


   Age : 49 Inscrit le : 20 Mar 2006 Messages : 302 Configuration : Windows Vista
| Sujet: Re: Soproc.exe au démarrage [Résolu] Mer 17 Mai 2006 - 14:55 | |
| Euh ... Je t'ai donné la mauvaise page.
Rends toi sur cette page.
Clique sur 
Selon le paramétrage de ton ordinateur, une barre jaune peut apparaitre en haut de la fenêtre te prévenant que tu dois installer un contrôle Active X. Clique sur la barre jaune puis choisis Installer.

Une boite de dialogue va s'ouvrir, clique sur Installer.

Une fois l'installation terminée, clique sur Démarrer pour lancer le scan.

Lorsque le scan est terminé clique sur le petit + devant Tout développer puis fais un copier-coller de l'intégralité de la fenêtre dans ta prochaine réponse.

@+ |
|
 | |
Ninie62 Accro


   Age : 22 Inscrit le : 12 Aoû 2005 Messages : 333 Localisation : Lens
| Sujet: Re: Soproc.exe au démarrage [Résolu] Mer 17 Mai 2006 - 20:44 | |
| Bonjour,
voilà le rapport :
eMule P2P "eMule" trouvé(s) dans: Key "hkey_classes_root \emule" Key "hkey_local_machine \software\microsoft\windows\currentversion\uninstall\emule" Key "hkey_current_user \software\emule" Key "hkey_classes_root \.emulecollection" Key "hkey_local_machine \software\classes\ed2k"
Hotbar.ShopperReports Toolbar Toolbar "Hotbar.ShopperReports" trouvé(s) dans: Key "hkey_current_user \software\microsoft\internet explorer\extensions\cmdmapping" value "{946b3e9e-e21a-49c8-9f63-900533fafe14}"
Lop.com Spyware Spyware "Lop.com" trouvé(s) dans: Key "hkey_current_user \software\microsoft\internet explorer\new windows\allow" value "searchweb2.com" Key "hkey_current_user \software\microsoft\internet explorer\new windows\allow" value "dns-look-up.com" Key "hkey_current_user \software\microsoft\internet explorer\new windows\allow" value "www.dns-look-up.com" Key "hkey_current_user \software\microsoft\internet explorer\new windows\allow" value "www.searchweb2.com"
SystemProcess Adware Adware "SystemProcess" trouvé(s) dans: Key "hkey_current_user \software\microsoft\internet explorer\new windows\allow" value "*.system-processes.com" Key "hkey_local_machine \software\microsoft\windows\currentversion\uninstall\startup" value "uninstallstring" data "c:\windows\system32\ccapp.exe" Key "hkey_local_machine \software\microsoft\windows\currentversion\uninstall\startup" value "displayname" data "system process"
Trojan.Win32.P2E.ai Trojan Trojan "Trojan.Win32.P2E.ai" trouvé(s) dans: Key "hkey_current_user \software\microsoft\systemcertificates\trustedpublisher\certificates\bd8400524261df1adbd8860f22c9ce2b97471448"
HotBar Adware Adware "HotBar" trouvé(s) dans: Key "hkey_current_user \software\microsoft\internet explorer\toolbar\webbrowser" value "{74cc49f7-eb32-4a08-b204-948962a6e3db}" Key "hkey_local_machine \software\microsoft\internet explorer\explorer bars\{7e66936c-fea0-4984-ad26-7b6661ac5b2e}" Key "hkey_current_user \software\microsoft\internet explorer\toolbar\shellbrowser" value "{74cc49f7-eb32-4a08-b204-948962a6e3db}" Key "hkey_local_machine \software\hbtools"
Backdoor.Bifrose Backdoor Backdoor "Backdoor.Bifrose" trouvé(s) dans: Key "hkey_local_machine \software\microsoft\windows\currentversion\uninstall\xvid"
247RealMedia.com Tracking Cookie Tracking Cookie "247RealMedia.com" trouvé(s) dans: Cookie "stef@247realmedia[1].txt" File "C:\Documents and Settings\stef\Cookies\stef@247realmedia[1].txt"
Advertising.com Tracking Cookie Tracking Cookie "Advertising.com" trouvé(s) dans: Cookie "stef@advertising[2].txt" File "C:\Documents and Settings\stef\Cookies\stef@advertising[2].txt"
AtlasDMT.com Tracking Cookie Tracking Cookie "AtlasDMT.com" trouvé(s) dans: Cookie "stef@atdmt[2].txt" File "C:\Documents and Settings\stef\Cookies\stef@atdmt[2].txt"
Bluestreak.com Tracking Cookie Tracking Cookie "Bluestreak.com" trouvé(s) dans: Cookie "stef@bluestreak[1].txt" File "C:\Documents and Settings\stef\Cookies\stef@bluestreak[1].txt"
HitBox.com Tracking Cookie Tracking Cookie "HitBox.com" trouvé(s) dans: Cookie "stef@hitbox[2].txt" File "C:\Documents and Settings\stef\Cookies\stef@hitbox[2].txt"
Mediaplex.com Tracking Cookie Tracking Cookie "Mediaplex.com" trouvé(s) dans: Cookie "stef@mediaplex[1].txt" File "C:\Documents and Settings\stef\Cookies\stef@mediaplex[1].txt"
TradeDoubler.com Tracking Cookie Tracking Cookie "TradeDoubler.com" trouvé(s) dans: Cookie "stef@tradedoubler[2].txt" File "C:\Documents and Settings\stef\Cookies\stef@tradedoubler[2].txt"
Weborama Tracking Cookie Tracking Cookie "Weborama" trouvé(s) dans: Cookie "stef@weborama[1].txt" File "C:\Documents and Settings\stef\Cookies\stef@weborama[1].txt"
Cibleclick Tracking Cookie Tracking Cookie "Cibleclick" trouvé(s) dans: Cookie "stef@www.cibleclick[2].txt" File "C:\Documents and Settings\stef\Cookies\stef@www.cibleclick[2].txt"
 |
|
 | |
| Soproc.exe au démarrage [Résolu] | |
|