Pas capable de finir

serdeninc Messages postés 37 Statut Membre -  
 ^^Marie^^ -
Bonjour, j'ai le foutu viruse antiverus 2009 ,la je suis rendu a faire analiser les rapport . J'espere que quelqu'un va pouvoir m'aider. Mesci.

"C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
Option : [1] ( 2009-01-02|12:38 )

--------------------\\ Listing des dossiers dans APPLIC~1

[2005-04-15|14:55] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Identities
[2005-04-15|14:36] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft

[2008-10-17|22:24] C:\DOCUME~1\ALLUSE~1\APPLIC~1\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[2007-09-13|14:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ACD Systems
[2008-12-26|15:08] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[2007-09-13|08:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ahead
[2007-10-23|22:11] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
[2007-11-17|12:08] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[2008-12-21|14:02] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Avira
[2006-12-16|09:51] C:\DOCUME~1\ALLUSE~1\APPLIC~1\CyberLink
[2007-01-13|21:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
[2008-08-07|10:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Logishrd
[2008-08-07|10:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Logitech
[2008-08-06|11:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!
[2005-04-15|14:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[2007-03-23|21:57] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft Help
[2007-09-13|08:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Nero
[2008-12-26|15:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\NOS
[2008-12-23|19:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\nView_Profiles
[2008-12-20|13:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SITEguard
[2007-09-07|22:02] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Skype
[2008-12-27|08:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Sony Corporation
[2008-12-20|12:22] C:\DOCUME~1\ALLUSE~1\APPLIC~1\STOPzilla!
[2006-08-30|20:50] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec
[2008-10-01|11:10] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
[2008-05-31|20:40] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TrackMania
[2007-06-19|17:26] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ulead Systems
[2006-12-19|17:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage

[2005-04-15|14:36] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft

[2005-04-15|14:36] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft

[2005-04-15|14:55] C:\DOCUME~1\ADMINI~1\APPLIC~1\Identities
[2005-04-15|14:36] C:\DOCUME~1\ADMINI~1\APPLIC~1\Microsoft

[2007-09-13|14:37] C:\DOCUME~1\SERGEL~1\APPLIC~1\ACD Systems
[2007-01-03|11:22] C:\DOCUME~1\SERGEL~1\APPLIC~1\Adobe
[2007-01-03|11:22] C:\DOCUME~1\SERGEL~1\APPLIC~1\AdobeUM
[2007-09-13|08:35] C:\DOCUME~1\SERGEL~1\APPLIC~1\Ahead
[2007-11-17|12:09] C:\DOCUME~1\SERGEL~1\APPLIC~1\Apple Computer
[2008-12-21|15:57] C:\DOCUME~1\SERGEL~1\APPLIC~1\Avira
[2006-12-16|09:51] C:\DOCUME~1\SERGEL~1\APPLIC~1\CyberLink
[2006-12-24|10:27] C:\DOCUME~1\SERGEL~1\APPLIC~1\DWGeditor
[2007-05-07|18:59] C:\DOCUME~1\SERGEL~1\APPLIC~1\F-Secure
[2007-10-04|21:03] C:\DOCUME~1\SERGEL~1\APPLIC~1\FunWebProducts
[2007-01-13|21:29] C:\DOCUME~1\SERGEL~1\APPLIC~1\Google
[2007-06-19|17:33] C:\DOCUME~1\SERGEL~1\APPLIC~1\Help
[2005-04-15|14:55] C:\DOCUME~1\SERGEL~1\APPLIC~1\Identities
[2008-12-27|08:36] C:\DOCUME~1\SERGEL~1\APPLIC~1\InstallShield
[2008-06-14|18:45] C:\DOCUME~1\SERGEL~1\APPLIC~1\InterTrust
[2007-05-07|18:55] C:\DOCUME~1\SERGEL~1\APPLIC~1\ispnews
[2006-12-14|18:00] C:\DOCUME~1\SERGEL~1\APPLIC~1\Macromedia
[2005-04-15|14:36] C:\DOCUME~1\SERGEL~1\APPLIC~1\Microsoft
[2007-09-29|17:05] C:\DOCUME~1\SERGEL~1\APPLIC~1\mIRC
[2006-12-20|18:44] C:\DOCUME~1\SERGEL~1\APPLIC~1\MSNInstaller
[2008-10-04|20:16] C:\DOCUME~1\SERGEL~1\APPLIC~1\Nero
[2007-05-07|18:59] C:\DOCUME~1\SERGEL~1\APPLIC~1\PEX
[2008-02-24|15:27] C:\DOCUME~1\SERGEL~1\APPLIC~1\skypePM
[2006-12-24|11:01] C:\DOCUME~1\SERGEL~1\APPLIC~1\SolidWorks
[2008-12-27|08:47] C:\DOCUME~1\SERGEL~1\APPLIC~1\Sony Corporation
[2007-08-30|17:43] C:\DOCUME~1\SERGEL~1\APPLIC~1\Sun
[2007-02-18|12:39] C:\DOCUME~1\SERGEL~1\APPLIC~1\teamspeak2
[2006-12-14|21:34] C:\DOCUME~1\SERGEL~1\APPLIC~1\U3
[2007-06-19|17:41] C:\DOCUME~1\SERGEL~1\APPLIC~1\Ulead Systems
[2007-01-05|20:40] C:\DOCUME~1\SERGEL~1\APPLIC~1\uTorrent
[2008-05-03|17:33] C:\DOCUME~1\SERGEL~1\APPLIC~1\Ventrilo
[2007-12-31|00:37] C:\DOCUME~1\SERGEL~1\APPLIC~1\WinRAR

--------------------\\ Tâches planifiées dans C:\WINDOWS\tasks

[2009-01-01 18:09][--a------] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009-01-02 12:10][--ah-----] C:\WINDOWS\tasks\SA.DAT
[2004-08-10 05:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini

--------------------\\ Listing des dossiers dans C:\Program Files

[2008-12-22|18:40] C:\Program Files\1ClickUnZip
[2007-09-13|14:36] C:\Program Files\ACD Systems
[2006-08-30|20:40] C:\Program Files\Acer Inc
[2006-08-30|20:41] C:\Program Files\Adobe
[2008-06-07|11:04] C:\Program Files\Apple Software Update
[2008-12-21|14:02] C:\Program Files\Avira
[2008-10-17|22:23] C:\Program Files\Bonjour
[2008-08-05|21:59] C:\Program Files\Circle Developement
[2005-04-15|14:42] C:\Program Files\ComPlus Applications
[2006-08-30|20:35] C:\Program Files\CONEXANT
[2006-12-14|18:00] C:\Program Files\CyberLink
[2006-08-30|20:30] C:\Program Files\DIFX
[2007-12-23|14:58] C:\Program Files\Dofus
[2007-04-07|09:10] C:\Program Files\Dofus-Arena
[2007-06-19|17:32] C:\Program Files\DSC_Program
[2008-06-14|18:46] C:\Program Files\DSS
[2006-12-24|10:26] C:\Program Files\DWGeditor
[2008-10-01|11:10] C:\Program Files\Eltima Software
[2008-12-13|10:15] C:\Program Files\FBrowserAdvisor
[2008-12-13|10:15] C:\Program Files\FBrowsingAdvisor
[2005-04-15|14:37] C:\Program Files\Fichiers communs
[2007-01-12|22:38] C:\Program Files\Google
[2006-08-30|20:33] C:\Program Files\InstallShield Installation Information
[2005-04-15|14:44] C:\Program Files\Internet Explorer
[2008-10-17|22:24] C:\Program Files\iPod
[2008-10-17|22:24] C:\Program Files\iTunes
[2006-12-24|12:42] C:\Program Files\Java
[2006-12-14|18:03] C:\Program Files\Launch Manager
[2006-12-24|12:41] C:\Program Files\LimeWire
[2006-12-14|22:55] C:\Program Files\Logitech
[2005-04-15|14:41] C:\Program Files\Messenger
[2008-08-05|21:59] C:\Program Files\Messenger Plus! Live
[2005-04-15|14:47] C:\Program Files\microsoft frontpage
[2006-12-24|10:26] C:\Program Files\Microsoft Office
[2007-03-23|22:01] C:\Program Files\Microsoft Visual Studio
[2007-03-23|22:01] C:\Program Files\Microsoft Works
[2007-03-23|22:00] C:\Program Files\Microsoft.NET
[2007-09-29|17:04] C:\Program Files\mIRC
[2005-04-15|14:41] C:\Program Files\Movie Maker
[2005-04-15|14:41] C:\Program Files\MSN
[2005-04-15|14:41] C:\Program Files\MSN Gaming Zone
[2006-12-26|17:59] C:\Program Files\MSN Messenger
[2008-11-13|17:58] C:\Program Files\MSXML 4.0
[2009-01-02|12:30] C:\Program Files\Navilog1
[2007-09-13|08:32] C:\Program Files\Nero
[2005-04-15|14:44] C:\Program Files\NetMeeting
[2006-08-30|20:39] C:\Program Files\NewTech Infosystems
[2008-12-26|15:06] C:\Program Files\NOS
[2005-04-15|14:42] C:\Program Files\Online Services
[2005-04-15|14:44] C:\Program Files\Outlook Express
[2007-10-16|18:07] C:\Program Files\PhotoFrame_V1.5
[2008-10-17|22:22] C:\Program Files\QuickTime
[2006-08-30|20:34] C:\Program Files\Realtek
[2007-12-02|20:00] C:\Program Files\Runtime Software
[2008-10-17|22:16] C:\Program Files\Safari
[2007-02-08|22:03] C:\Program Files\Slayers Online
[2007-03-07|23:09] C:\Program Files\Softnyx
[2007-09-13|13:20] C:\Program Files\SolidWorks
[2007-09-13|13:31] C:\Program Files\SolidWorks Installation Manager
[2008-12-27|08:41] C:\Program Files\Sonic
[2008-12-26|15:05] C:\Program Files\Sony
[2008-12-22|17:49] C:\Program Files\Steam
[2006-08-30|20:50] C:\Program Files\Symantec
[2006-08-30|20:35] C:\Program Files\Synaptics
[2008-12-22|18:28] C:\Program Files\SystemRequirementsLab
[2007-02-18|12:39] C:\Program Files\Teamspeak2_RC2
[2008-12-20|11:28] C:\Program Files\Trend Micro
[2008-09-06|16:35] C:\Program Files\TSO
[2007-06-19|17:27] C:\Program Files\Ulead Systems
[2005-04-15|14:55] C:\Program Files\Uninstall Information
[2007-02-17|16:39] C:\Program Files\Valve
[2008-05-03|17:33] C:\Program Files\Ventrilo
[2008-10-18|16:29] C:\Program Files\VirtualDJ
[2008-12-13|10:15] C:\Program Files\VisualTool
[2007-03-25|13:59] C:\Program Files\WarRock
[2007-09-13|13:20] C:\Program Files\Windows Desktop Search
[2008-08-05|21:59] C:\Program Files\Windows Live
[2006-12-14|22:57] C:\Program Files\Windows Media Components
[2007-10-26|20:29] C:\Program Files\Windows Media Connect 2
[2005-04-15|14:42] C:\Program Files\Windows Media Player
[2005-04-15|14:41] C:\Program Files\Windows NT
[2005-04-15|14:42] C:\Program Files\Windows Plus
[2005-04-15|14:45] C:\Program Files\WindowsUpdate
[2007-12-31|00:37] C:\Program Files\WinRAR
[2005-04-15|14:47] C:\Program Files\xerox
[2007-06-19|17:36] C:\Program Files\XviD
[2006-12-14|18:10] C:\Program Files\Yahoo!

--------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs

[2007-09-13|14:36] C:\Program Files\Fichiers communs\ACD Systems
[2008-05-09|21:04] C:\Program Files\Fichiers communs\Adobe
[2007-09-13|08:32] C:\Program Files\Fichiers communs\Ahead
[2007-11-17|12:07] C:\Program Files\Fichiers communs\Apple
[2006-12-24|10:44] C:\Program Files\Fichiers communs\Bluebeam Software
[2006-12-24|10:26] C:\Program Files\Fichiers communs\Designer
[2006-08-30|20:31] C:\Program Files\Fichiers communs\InstallShield
[2008-12-20|12:22] C:\Program Files\Fichiers communs\iS3
[2006-12-24|12:41] C:\Program Files\Fichiers communs\Java
[2006-08-30|20:40] C:\Program Files\Fichiers communs\LightScribe
[2008-08-07|10:34] C:\Program Files\Fichiers communs\logishrd
[2006-12-14|22:57] C:\Program Files\Fichiers communs\Logitech
[2005-04-15|14:37] C:\Program Files\Fichiers communs\Microsoft Shared
[2005-04-15|14:44] C:\Program Files\Fichiers communs\MSSoap
[2006-08-30|20:39] C:\Program Files\Fichiers communs\muvee Technologies
[2006-08-30|20:39] C:\Program Files\Fichiers communs\NewTech Infosystems
[2005-04-15|14:37] C:\Program Files\Fichiers communs\ODBC
[2005-04-15|14:44] C:\Program Files\Fichiers communs\Services
[2007-09-13|13:20] C:\Program Files\Fichiers communs\Solidworks Data
[2007-09-13|13:21] C:\Program Files\Fichiers communs\SolidWorks Shared
[2005-04-15|14:37] C:\Program Files\Fichiers communs\SpeechEngines
[2007-01-01|22:59] C:\Program Files\Fichiers communs\SWF Studio
[2006-08-30|20:49] C:\Program Files\Fichiers communs\Symantec Shared
[2005-04-15|14:44] C:\Program Files\Fichiers communs\System
[2007-06-19|17:27] C:\Program Files\Fichiers communs\Ulead Systems
[2008-05-03|17:33] C:\Program Files\Fichiers communs\Wise Installation Wizard

--------------------\\ Process

( 64 Processes )

iexplore.exe ~ [PID:564]

--------------------\\ Recherche avec S_Lop

Aucun fichier / dossier Lop trouvé !

--------------------\\ Recherche de Fichiers / Dossiers Lop

C:\DOCUME~1\SERGEL~1\LOCALS~1\Temp\nsz14.tmp
C:\DOCUME~1\SERGEL~1\LOCALS~1\Temp\nsl6.tmp
C:\DOCUME~1\SERGEL~1\LOCALS~1\Temp\nsn6.tmp
C:\DOCUME~1\SERGEL~1\LOCALS~1\Temp\nsy1E.tmp
C:\DOCUME~1\SERGEL~1\LOCALS~1\Temp\nsx63.tmp
C:\DOCUME~1\SERGEL~1\LOCALS~1\Temp\nsk3E.tmp
C:\DOCUME~1\SERGEL~1\LOCALS~1\Temp\nsi1C.tmp
C:\DOCUME~1\SERGEL~1\LOCALS~1\Temp\nsz37.tmp
C:\DOCUME~1\SERGEL~1\LOCALS~1\Temp\nsx48.tmp
C:\DOCUME~1\SERGEL~1\LOCALS~1\Temp\nsy91.tmp
C:\DOCUME~1\SERGEL~1\LOCALS~1\Temp\nsf19.tmp
C:\DOCUME~1\SERGEL~1\LOCALS~1\Temp\nsv1B9.tmp
C:\DOCUME~1\SERGEL~1\LOCALS~1\Temp\nsy32.tmp
C:\DOCUME~1\SERGEL~1\LOCALS~1\Temp\nsfE.tmp
C:\DOCUME~1\SERGEL~1\LOCALS~1\Temp\nsxD3.tmp
C:\DOCUME~1\SERGEL~1\LOCALS~1\Temp\nst181.tmp
C:\DOCUME~1\SERGEL~1\LOCALS~1\Temp\nsc209.tmp
C:\DOCUME~1\SERGEL~1\LOCALS~1\Temp\nsi20E.tmp
C:\DOCUME~1\SERGEL~1\LOCALS~1\Temp\nsn219.tmp
C:\Program Files\Circle Developement
C:\DOCUME~1\SERGEL~1\Cookies\serge_laplante@advertstream[2].txt
C:\DOCUME~1\SERGEL~1\Cookies\serge_laplante@adultfriendfinder[2].txt
C:\DOCUME~1\SERGEL~1\Cookies\serge_laplante@advertising[1].txt
C:\DOCUME~1\SERGEL~1\Cookies\serge_laplante@ero-advertising[2].txt
C:\DOCUME~1\SERGEL~1\Cookies\serge_laplante@adopt.euroclick[2].txt
C:\DOCUME~1\SERGEL~1\Cookies\serge_laplante@partypoker[1].txt

--------------------\\ Verification du Registre

..... OK !

--------------------\\ Verification du fichier Hosts

Fichier Hosts PROPRE

--------------------\\ Recherche de fichiers avec Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-02 12:42:16
Windows 5.1.2600 Service Pack 3 FAT NTAPI
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 0

--------------------\\ Recherche d'autres infections

Aucune autre infection trouvée !

[F:4683][D:97]-> C:\DOCUME~1\SERGEL~1\LOCALS~1\Temp
[F:396][D:0]-> C:\DOCUME~1\SERGEL~1\Cookies
[F:30711][D:84]-> C:\DOCUME~1\SERGEL~1\LOCALS~1\TEMPOR~1\content.IE5
[F:2][D:0]-> C:\Recycled

1 - "C:\Lop SD\LopR_1.txt" - 2009-01-02|12:44 - Option : [1]

--------------------\\ Fin du rapport a 12:44:31
A voir également:

62 réponses

darkpoet Messages postés 1696 Statut Contributeur sécurité 62
 
execute en tant qu administrateur (clic droit
1
darkpoet Messages postés 1696 Statut Contributeur sécurité 62
 
télécharge hijackthis
http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis/download

-> enregistre la cible sous .... "le bureau"

-> Fais un double-clic sur "HJTInstall.exe" afin de lancer l'installation

-> Clique sur Install ensuite sur "I Accept"

-> Clique sur" Do a scan system and save log file"

-> Le bloc-notes s'ouvrira, fais un copier-coller de tout son contenu ici dans ta prochaine réponse

->
http://pageperso.aol.fr/balltrap34/Hijenr.gif
Démo : (Merci a Balltrap34 pour cette réalisation)
0
serdeninc Messages postés 37 Statut Membre
 
Merci ,ca donne ca le rapport.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:33:33, on 2009-01-02
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\Avira\Avira Premium Security Suite\sched.exe
C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Avira\Avira Premium Security Suite\avguard.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Avira\Avira Premium Security Suite\avesvc.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Acer\Empowering Technology\eLock\LockServ.exe
C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
C:\Acer\Empowering Technology\ePresentation\ePresentation.exe
C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
C:\Program Files\Fichiers communs\Logitech\QCDriver3\LVCOMS.EXE
C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\NCLAUNCH.EXe
C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\program files\steam\steam.exe
C:\Program Files\MSN Messenger\MSNMSGR.EXE
C:\WINDOWS\system32\svchost.exe
C:\Acer\Empowering Technology\Acer.Empowering.Framework.Launcher.exe
C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe
C:\Program Files\Avira\Avira Premium Security Suite\avmailc.exe
C:\Program Files\Avira\Avira Premium Security Suite\AVWEBGRD.EXE
C:\DOCUME~1\SERGEL~1\LOCALS~1\Temp\RtkBtMnt.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?redirfallthru=http%3a%2f%2fsympatico.msn.ca%2fdefaultf.aspx%2f%3f
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;*.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: (no name) - {01c543da-fed5-4b54-ac92-ba63c42f2c52} - C:\WINDOWS\system32\fuzoyalu.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll (file missing)
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O2 - BHO: VisualTool - {F3A54897-9E68-B11E-A37A-4D1422CE9CAA} - C:\Program Files\VisualTool\VisualTool-3.dll (file missing)
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\WINDOWS\system32\eDStoolbar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll (file missing)
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ntiMUI] C:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [ePower_DMC] C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
O4 - HKLM\..\Run: [Boot] C:\Acer\Empowering Technology\ePower\Boot.exe
O4 - HKLM\..\Run: [Acer ePresentation HPD] C:\Acer\Empowering Technology\ePresentation\ePresentation.exe
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe 0
O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Fichiers communs\Logitech\QCDriver3\LVCOMS.EXE
O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Program Files\Logitech\ImageStudio\ISStart.exe
O4 - HKLM\..\Run: [Microsoft] C:\WINDOWS\wuauclt.exe
O4 - HKLM\..\Run: [Ulead AutoDetector] C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\Avira Premium Security Suite\avgnt.exe" /min
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [0b790604] rundll32.exe "C:\WINDOWS\system32\dokakuru.dll",b
O4 - HKLM\..\Run: [diwodakefa] Rundll32.exe "C:\WINDOWS\system32\loboseta.dll",s
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [NCLaunch] C:\WINDOWS\NCLAUNCH.EXe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\MSNMSGR.EXE" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Outil de détection de support Picture Motion Browser.lnk = C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe
O4 - Global Startup: Acer Empowering Technology.lnk = ?
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - https://www.nvidia.com/content/DriverDownload/srl/3.0.0.0/srl_bin/sysreqlab3.cab
O16 - DPF: {56393399-041A-4650-94C7-13DFCB1F4665} (PSFormX Control) - http://www.ca.com/us/securityadvisor/pestscan/pestscan.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-CA/a-UNO1/GAME_UNO1.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/ractrl.cab?lmi=100
O20 - AppInit_DLLs: C:\WINDOWS\system32\relipasi.dll
O23 - Service: Memory Check Service (AcerMemUsageCheckService) - Acer Inc. - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
O23 - Service: Avira Premium Security Suite Pare-feu (AntiVirFirewallService) - Avira GmbH - C:\Program Files\Avira\Avira Premium Security Suite\avfwsvc.exe
O23 - Service: Avira Premium Security Suite MailGuard (AntiVirMailService) - Avira GmbH - C:\Program Files\Avira\Avira Premium Security Suite\avmailc.exe
O23 - Service: Planificateur Avira Premium Security Suite (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\Avira Premium Security Suite\sched.exe
O23 - Service: Avira Premium Security Suite Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\Avira Premium Security Suite\avguard.exe
O23 - Service: Avira Premium Security Suite WebGuard (antivirwebservice) - Avira GmbH - C:\Program Files\Avira\Avira Premium Security Suite\AVWEBGRD.EXE
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Service d'assistance Avira Premium Security Suite MailGuard (AVEService) - Avira GmbH - C:\Program Files\Avira\Avira Premium Security Suite\avesvc.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
O23 - Service: LockServ - Unknown owner - C:\Acer\Empowering Technology\eLock\LockServ.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files\Fichiers communs\SolidWorks Shared\Service\SolidWorksLicensing.exe
0
darkpoet Messages postés 1696 Statut Contributeur sécurité 62
 
Télécharge Toolbar-S&D (Team IDN) sur ton Bureau.
https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/ToolBarSD.exe?attachauth=ANoY7cqJWPphpudyTqv7TRo5RQ3nm_Sx8JluVMO59X5E9cyE3j3LqKlmStIqiDqJdIgMJLi7MXn2nKVajQfoWuVvZZ2wIx_vkqO4k4P0K9jh-ra9jaKPXdZcoaVF2UqJZNH8ubL_42uIwh6f35xJ2GJMuzddVj2Qth1DgZ839lxEIFGkgWz3TdfvNMy-YtxfA3gqBUrj4U4LFeAPiWr3ClmjIP0t_Xs5PQ%3D%3D&attredirects=2

* Lance l'installation du programme en exécutant le fichier téléchargé.
* Double-clique maintenant sur le raccourci de Toolbar-S&D.
* Sélectionne la langue souhaitée en tapant la lettre de ton choix puis en validant avec la touche Entrée.
* Choisis maintenant l'option 1 (Recherche). Patiente jusqu'à la fin de la recherche.
* Poste le rapport généré. (C:\TB.txt)
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
serdeninc Messages postés 37 Statut Membre
 
Voici le raport

-----------\\ ToolBar S&D 1.2.8 XP/Vista

Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 3
X86-based PC ( Multiprocessor Free : AMD Turion(tm) 64 Mobile Technology MK-36 )
BIOS : PhoenixBIOS 4.0 Release 6.1
USER : Serge Laplante ( Administrator )
BOOT : Normal boot
Antivirus : Avira AntiVir PersonalEdition Classic 0.0.0.0 (Activated)
Firewall : Avira Pare-feu 8.0.1.30 (Not Activated)
C:\ (Local Disk) - FAT32 - Total:53 Go (Free:1 Go)
D:\ (Local Disk) - FAT32 - Total:53 Go (Free:34 Go)
E:\ (CD or DVD)

"C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
Option : [1] ( 2009-01-03|11:43 )

-----------\\ Recherche de Fichiers / Dossiers ...

C:\DOCUME~1\SERGEL~1\LOCALS~1\Temp\NERF.tmp\Toolbar.exe
C:\Program Files\FBrowserAdvisor
C:\Program Files\FBrowsingAdvisor
C:\Program Files\FBrowsingAdvisor\unins000.dat
C:\Program Files\FBrowsingAdvisor\main.db
C:\Program Files\FBrowsingAdvisor\Logo.png
C:\Program Files\FBrowsingAdvisor\IXPCOMEvents.xpt
C:\Program Files\FBrowsingAdvisor\unins000.exe
C:\DOCUME~1\SERGEL~1\APPLIC~1\FunWebProducts
C:\DOCUME~1\SERGEL~1\APPLIC~1\FunWebProducts\Data
C:\DOCUME~1\SERGEL~1\APPLIC~1\FunWebProducts\Data\Serge Laplante
C:\DOCUME~1\SERGEL~1\APPLIC~1\FunWebProducts\Data\Serge Laplante\avatar.dat
C:\DOCUME~1\SERGEL~1\LOCALS~1\Temp\tem201.tmp.exe
C:\DOCUME~1\SERGEL~1\LOCALS~1\Temp\tem205.tmp.exe
C:\DOCUME~1\SERGEL~1\LOCALS~1\Temp\tem20B.tmp.exe
C:\DOCUME~1\SERGEL~1\LOCALS~1\Temp\tem211.tmp.exe
C:\DOCUME~1\SERGEL~1\LOCALS~1\Temp\tem215.tmp.exe
C:\DOCUME~1\SERGEL~1\LOCALS~1\Temp\tem21B.tmp.exe
C:\DOCUME~1\SERGEL~1\LOCALS~1\Temp\nsz14.tmp
C:\DOCUME~1\SERGEL~1\LOCALS~1\Temp\nsl6.tmp
C:\DOCUME~1\SERGEL~1\LOCALS~1\Temp\nsn6.tmp
C:\DOCUME~1\SERGEL~1\LOCALS~1\Temp\nsy1E.tmp
C:\DOCUME~1\SERGEL~1\LOCALS~1\Temp\nsx63.tmp
C:\DOCUME~1\SERGEL~1\LOCALS~1\Temp\nsk3E.tmp
C:\DOCUME~1\SERGEL~1\LOCALS~1\Temp\nsi1C.tmp
C:\DOCUME~1\SERGEL~1\LOCALS~1\Temp\nsz37.tmp
C:\DOCUME~1\SERGEL~1\LOCALS~1\Temp\nsx48.tmp
C:\DOCUME~1\SERGEL~1\LOCALS~1\Temp\nsy91.tmp
C:\DOCUME~1\SERGEL~1\LOCALS~1\Temp\nsf19.tmp
C:\DOCUME~1\SERGEL~1\LOCALS~1\Temp\nsv1B9.tmp
C:\DOCUME~1\SERGEL~1\LOCALS~1\Temp\nsy32.tmp
C:\DOCUME~1\SERGEL~1\LOCALS~1\Temp\nsfE.tmp
C:\DOCUME~1\SERGEL~1\LOCALS~1\Temp\nsxD3.tmp
C:\DOCUME~1\SERGEL~1\LOCALS~1\Temp\nst181.tmp
C:\DOCUME~1\SERGEL~1\LOCALS~1\Temp\nsc209.tmp
C:\DOCUME~1\SERGEL~1\LOCALS~1\Temp\nsi20E.tmp
C:\DOCUME~1\SERGEL~1\LOCALS~1\Temp\nsn219.tmp

-----------\\ [..\Internet Explorer\Main]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Local Page"="C:\\WINDOWS\\system32\\blank.htm"
"Start Page"="https://www.msn.com/fr-fr/?redirfallthru=http%3a%2f%2fsympatico.msn.ca%2fdefaultf.aspx%2f%3f"
"Search Page"="https://www.google.com/?gws_rd=ssl"
"SearchMigratedDefaultURL"="https://search.yahoo.com/web{searchTerms}&ei=utf-8&fr=b1ie7"
"Search Bar"="http://www.google.com/toolbar/ie8/sidebar.html"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
"Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Start Page"="https://www.msn.com/fr-fr/"

--------------------\\ Recherche d'autres infections

Aucune autre infection trouvée !

1 - "C:\ToolBar SD\TB_1.txt" - 2009-01-03|11:44 - Option : [1]

-----------\\ Fin du rapport a 11:44:58,38
0
darkpoet Messages postés 1696 Statut Contributeur sécurité 62
 
relance toolbarsd et fait option 2 post le rapport
0
serdeninc Messages postés 37 Statut Membre
 
Salut , j'ai fait option 2

-----------\\ ToolBar S&D 1.2.8 XP/Vista

Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 3
X86-based PC ( Multiprocessor Free : AMD Turion(tm) 64 Mobile Technology MK-36 )
BIOS : PhoenixBIOS 4.0 Release 6.1
USER : Serge Laplante ( Administrator )
BOOT : Normal boot
Antivirus : Avira AntiVir PersonalEdition Classic 0.0.0.0 (Activated)
Firewall : Avira Pare-feu 8.0.1.30 (Not Activated)
C:\ (Local Disk) - FAT32 - Total:53 Go (Free:1 Go)
D:\ (Local Disk) - FAT32 - Total:53 Go (Free:34 Go)
E:\ (CD or DVD)

"C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
Option : [2] ( 2009-01-04| 3:18 )

-----------\\ SUPPRESSION

Supprime! - C:\DOCUME~1\SERGEL~1\LOCALS~1\Temp\NERF.tmp\Toolbar.exe
Supprime! - C:\Program Files\FBrowsingAdvisor\unins000.dat
Supprime! - C:\Program Files\FBrowsingAdvisor\main.db
Supprime! - C:\Program Files\FBrowsingAdvisor\Logo.png
Supprime! - C:\Program Files\FBrowsingAdvisor\IXPCOMEvents.xpt
Supprime! - C:\Program Files\FBrowsingAdvisor\unins000.exe
Supprime! - C:\DOCUME~1\SERGEL~1\APPLIC~1\FunWebProducts\Data
Supprime! - C:\DOCUME~1\SERGEL~1\LOCALS~1\Temp\tem201.tmp.exe
Supprime! - C:\DOCUME~1\SERGEL~1\LOCALS~1\Temp\tem205.tmp.exe
Supprime! - C:\DOCUME~1\SERGEL~1\LOCALS~1\Temp\tem20B.tmp.exe
Supprime! - C:\DOCUME~1\SERGEL~1\LOCALS~1\Temp\tem211.tmp.exe
Supprime! - C:\DOCUME~1\SERGEL~1\LOCALS~1\Temp\tem215.tmp.exe
Supprime! - C:\DOCUME~1\SERGEL~1\LOCALS~1\Temp\tem21B.tmp.exe
Supprime! - C:\DOCUME~1\SERGEL~1\LOCALS~1\Temp\nsz14.tmp
Supprime! - C:\DOCUME~1\SERGEL~1\LOCALS~1\Temp\nsl6.tmp
Supprime! - C:\DOCUME~1\SERGEL~1\LOCALS~1\Temp\nsn6.tmp
Supprime! - C:\DOCUME~1\SERGEL~1\LOCALS~1\Temp\nsy1E.tmp
Supprime! - C:\DOCUME~1\SERGEL~1\LOCALS~1\Temp\nsx63.tmp
Supprime! - C:\DOCUME~1\SERGEL~1\LOCALS~1\Temp\nsk3E.tmp
Supprime! - C:\DOCUME~1\SERGEL~1\LOCALS~1\Temp\nsi1C.tmp
Supprime! - C:\DOCUME~1\SERGEL~1\LOCALS~1\Temp\nsz37.tmp
Supprime! - C:\DOCUME~1\SERGEL~1\LOCALS~1\Temp\nsx48.tmp
Supprime! - C:\DOCUME~1\SERGEL~1\LOCALS~1\Temp\nsy91.tmp
Supprime! - C:\DOCUME~1\SERGEL~1\LOCALS~1\Temp\nsf19.tmp
Supprime! - C:\DOCUME~1\SERGEL~1\LOCALS~1\Temp\nsv1B9.tmp
Supprime! - C:\DOCUME~1\SERGEL~1\LOCALS~1\Temp\nsy32.tmp
Supprime! - C:\DOCUME~1\SERGEL~1\LOCALS~1\Temp\nsfE.tmp
Supprime! - C:\DOCUME~1\SERGEL~1\LOCALS~1\Temp\nsxD3.tmp
Supprime! - C:\DOCUME~1\SERGEL~1\LOCALS~1\Temp\nst181.tmp
Supprime! - C:\DOCUME~1\SERGEL~1\LOCALS~1\Temp\nsc209.tmp
Supprime! - C:\DOCUME~1\SERGEL~1\LOCALS~1\Temp\nsi20E.tmp
Supprime! - C:\DOCUME~1\SERGEL~1\LOCALS~1\Temp\nsn219.tmp
Supprime! - C:\Program Files\FBrowserAdvisor
Supprime! - C:\Program Files\FBrowsingAdvisor
Supprime! - C:\DOCUME~1\SERGEL~1\APPLIC~1\FunWebProducts

-----------\\ Recherche de Fichiers / Dossiers ...

-----------\\ [..\Internet Explorer\Main]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Local Page"="C:\\WINDOWS\\system32\\blank.htm"
"Start Page"="https://www.msn.com/fr-fr/?redirfallthru=http%3a%2f%2fsympatico.msn.ca%2fdefaultf.aspx%2f%3f"
"Search Page"="https://www.google.com/?gws_rd=ssl"
"SearchMigratedDefaultURL"="https://search.yahoo.com/web{searchTerms}&ei=utf-8&fr=b1ie7"
"Search Bar"="http://www.google.com/toolbar/ie8/sidebar.html"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
"Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Start Page"="https://www.msn.com/fr-fr/"

--------------------\\ Recherche d'autres infections

Aucune autre infection trouvée !

1 - "C:\ToolBar SD\TB_1.txt" - 2009-01-03|11:44 - Option : [1]
2 - "C:\ToolBar SD\TB_2.txt" - 2009-01-04| 3:20 - Option : [2]

-----------\\ Fin du rapport a 3:20:03,38
0
darkpoet Messages postés 1696 Statut Contributeur sécurité 62
 
▶ Relance Lop S&D

▶ Choisis cette fois ci l'Option 2 ( Suppression )

▶ Ne ferme pas la fenêtre lors de la suppression !

▶ Poste le rapport généré ( C:\lopR.txt )

( Si le Bureau ne réapparaît pas presse Ctrl + Alt + Suppr, Onglet Fichier,

Nouvelle tâche, tape explorer.exe et valide )
0
serdeninc Messages postés 37 Statut Membre
 
voici le résultat.
Clean Navipromo version 3.7.0 commencé le 2009-01-04 à 17:00:46,46

Outil exécuté depuis C:\Program Files\navilog1

Mise à jour le 10.12.2008 à 21h00 par IL-MAFIOSO

Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 3
X86-based PC ( Multiprocessor Free : AMD Turion(tm) 64 Mobile Technology MK-36 )
BIOS : PhoenixBIOS 4.0 Release 6.1
USER : Serge Laplante ( Administrator )
BOOT : Normal boot

Antivirus : Avira AntiVir PersonalEdition Classic 0.0.0.0 (Activated)
Firewall : Avira Pare-feu 8.0.1.30 (Not Activated)

C:\ (Local Disk) - FAT32 - Total:53 Go (Free:1 Go)
D:\ (Local Disk) - FAT32 - Total:53 Go (Free:34 Go)
E:\ (CD or DVD)

Mode suppression automatique
avec prise en charge résultats Catchme et GNS

Nettoyage exécuté au redémarrage de l'ordinateur

*** fsbl1.txt non trouvé ***
(Assurez-vous que Catchme n'avait rien trouvé lors de la recherche)

*** Suppression avec sauvegardes résultats GenericNaviSearch ***

* Suppression dans "C:\WINDOWS\System32" *

* Suppression dans "C:\Documents and Settings\Serge Laplante\locals~1\applic~1" *

* Suppression dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" *

*** Suppression dossiers dans "C:\WINDOWS" ***

*** Suppression dossiers dans "C:\Program Files" ***

*** Suppression dossiers dans "C:\Documents and Settings\All Users\menudÉ~1\progra~1" ***

*** Suppression dossiers dans "C:\Documents and Settings\All Users\menudÉ~1" ***

*** Suppression dossiers dans "c:\docume~1\alluse~1\applic~1" ***

*** Suppression dossiers dans "C:\Documents and Settings\Serge Laplante\applic~1" ***

*** Suppression dossiers dans "C:\DOCUME~1\ADMINI~1\applic~1" ***

*** Suppression dossiers dans "C:\Documents and Settings\Serge Laplante\locals~1\applic~1" ***

*** Suppression dossiers dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" ***

*** Suppression dossiers dans "C:\Documents and Settings\Serge Laplante\menud+~1\progra~1" ***

*** Suppression fichiers ***

*** Suppression fichiers temporaires ***

Nettoyage contenu C:\WINDOWS\Temp effectué !
Nettoyage contenu C:\Documents and Settings\Serge Laplante\locals~1\Temp effectué !

*** Traitement Recherche complémentaire ***
(Recherche fichiers spécifiques)

1)Suppression avec sauvegardes nouveaux fichiers Instant Access :

2)Recherche, création sauvegardes et suppression Heuristique :

* Dans "C:\WINDOWS\system32" *

* Dans "C:\Documents and Settings\Serge Laplante\locals~1\applic~1" *

* Dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" *

*** Sauvegarde du Registre vers dossier Safebackup ***

sauvegarde du Registre réalisée avec succès !

*** Nettoyage Registre ***

Nettoyage Registre Ok

*** Certificats ***

Certificat Egroup absent !
Certificat Electronic-Group absent !
Certificat Montorgueil absent !
Certificat OOO-Favorit absent !
Certificat Sunny-Day-Design-Ltdt absent !

*** Recherche autres dossiers et fichiers connus ***

*** Nettoyage terminé le 2009-01-04 à 17:05:42,79 ***
0
darkpoet Messages postés 1696 Statut Contributeur sécurité 62
 
tu as fait navilog j ai demande lopsd 2 post 7
0
serdeninc Messages postés 37 Statut Membre
 
Salut darkpoet desolé pour l,erreur J'ai de gros probleme ,j'ai du désinstaler mon antivérus, je n'avaitplus de bureau.
voici le résultat du raport. je ne peut plus prendre mes email sur hotmail pour le moment????

--------------------\\ Lop S&D 4.2.5-0 XP/Vista

Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 3
X86-based PC ( Multiprocessor Free : AMD Turion(tm) 64 Mobile Technology MK-36 )
BIOS : PhoenixBIOS 4.0 Release 6.1
USER : Serge Laplante ( Administrator )
BOOT : Normal boot
Antivirus : Avira AntiVir PersonalEdition Classic 0.0.0.0 (Activated)
C:\ (Local Disk) - FAT32 - Total:53 Go (Free:5 Go)
D:\ (Local Disk) - FAT32 - Total:53 Go (Free:34 Go)
E:\ (CD or DVD)

"C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
Option : [2] ( 2009-01-10|11:35 )

\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ SUPPRESSION

Supprime! - C:\DOCUME~1\SERGEL~1\Cookies\serge_laplante@advertstream[2].txt
Supprime! - C:\DOCUME~1\SERGEL~1\Cookies\serge_laplante@adultfriendfinder[2].txt
Supprime! - C:\DOCUME~1\SERGEL~1\Cookies\serge_laplante@advertising[1].txt
Supprime! - C:\DOCUME~1\SERGEL~1\Cookies\serge_laplante@ero-advertising[2].txt
Supprime! - C:\DOCUME~1\SERGEL~1\Cookies\serge_laplante@adopt.euroclick[2].txt
Supprime! - C:\DOCUME~1\SERGEL~1\Cookies\serge_laplante@partypoker[1].txt

\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\

--------------------\\ Listing des dossiers dans APPLIC~1

[2005-04-15|14:55] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Identities
[2005-04-15|14:36] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft

[2008-10-17|22:24] C:\DOCUME~1\ALLUSE~1\APPLIC~1\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[2007-09-13|14:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ACD Systems
[2008-12-26|15:08] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[2007-09-13|08:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ahead
[2007-10-23|22:11] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
[2007-11-17|12:08] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[2008-12-21|14:02] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Avira
[2006-12-16|09:51] C:\DOCUME~1\ALLUSE~1\APPLIC~1\CyberLink
[2007-01-13|21:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
[2008-08-07|10:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Logishrd
[2008-08-07|10:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Logitech
[2008-08-06|11:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!
[2005-04-15|14:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[2007-03-23|21:57] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft Help
[2007-09-13|08:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Nero
[2008-12-26|15:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\NOS
[2008-12-23|19:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\nView_Profiles
[2008-12-20|13:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SITEguard
[2007-09-07|22:02] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Skype
[2008-12-27|08:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Sony Corporation
[2008-12-20|12:22] C:\DOCUME~1\ALLUSE~1\APPLIC~1\STOPzilla!
[2006-08-30|20:50] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec
[2008-10-01|11:10] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
[2008-05-31|20:40] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TrackMania
[2007-06-19|17:26] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ulead Systems
[2006-12-19|17:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage

[2005-04-15|14:36] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft

[2005-04-15|14:36] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft

[2005-04-15|14:55] C:\DOCUME~1\ADMINI~1\APPLIC~1\Identities
[2005-04-15|14:36] C:\DOCUME~1\ADMINI~1\APPLIC~1\Microsoft

[2007-09-13|14:37] C:\DOCUME~1\SERGEL~1\APPLIC~1\ACD Systems
[2007-01-03|11:22] C:\DOCUME~1\SERGEL~1\APPLIC~1\Adobe
[2007-01-03|11:22] C:\DOCUME~1\SERGEL~1\APPLIC~1\AdobeUM
[2007-09-13|08:35] C:\DOCUME~1\SERGEL~1\APPLIC~1\Ahead
[2007-11-17|12:09] C:\DOCUME~1\SERGEL~1\APPLIC~1\Apple Computer
[2006-12-16|09:51] C:\DOCUME~1\SERGEL~1\APPLIC~1\CyberLink
[2009-01-02|14:08] C:\DOCUME~1\SERGEL~1\APPLIC~1\Desktopicon
[2006-12-24|10:27] C:\DOCUME~1\SERGEL~1\APPLIC~1\DWGeditor
[2007-05-07|18:59] C:\DOCUME~1\SERGEL~1\APPLIC~1\F-Secure
[2007-01-13|21:29] C:\DOCUME~1\SERGEL~1\APPLIC~1\Google
[2007-06-19|17:33] C:\DOCUME~1\SERGEL~1\APPLIC~1\Help
[2005-04-15|14:55] C:\DOCUME~1\SERGEL~1\APPLIC~1\Identities
[2008-12-27|08:36] C:\DOCUME~1\SERGEL~1\APPLIC~1\InstallShield
[2008-06-14|18:45] C:\DOCUME~1\SERGEL~1\APPLIC~1\InterTrust
[2007-05-07|18:55] C:\DOCUME~1\SERGEL~1\APPLIC~1\ispnews
[2006-12-14|18:00] C:\DOCUME~1\SERGEL~1\APPLIC~1\Macromedia
[2005-04-15|14:36] C:\DOCUME~1\SERGEL~1\APPLIC~1\Microsoft
[2007-09-29|17:05] C:\DOCUME~1\SERGEL~1\APPLIC~1\mIRC
[2006-12-20|18:44] C:\DOCUME~1\SERGEL~1\APPLIC~1\MSNInstaller
[2008-10-04|20:16] C:\DOCUME~1\SERGEL~1\APPLIC~1\Nero
[2007-05-07|18:59] C:\DOCUME~1\SERGEL~1\APPLIC~1\PEX
[2008-02-24|15:27] C:\DOCUME~1\SERGEL~1\APPLIC~1\skypePM
[2006-12-24|11:01] C:\DOCUME~1\SERGEL~1\APPLIC~1\SolidWorks
[2008-12-27|08:47] C:\DOCUME~1\SERGEL~1\APPLIC~1\Sony Corporation
[2007-08-30|17:43] C:\DOCUME~1\SERGEL~1\APPLIC~1\Sun
[2007-02-18|12:39] C:\DOCUME~1\SERGEL~1\APPLIC~1\teamspeak2
[2006-12-14|21:34] C:\DOCUME~1\SERGEL~1\APPLIC~1\U3
[2007-06-19|17:41] C:\DOCUME~1\SERGEL~1\APPLIC~1\Ulead Systems
[2007-01-05|20:40] C:\DOCUME~1\SERGEL~1\APPLIC~1\uTorrent
[2008-05-03|17:33] C:\DOCUME~1\SERGEL~1\APPLIC~1\Ventrilo
[2007-12-31|00:37] C:\DOCUME~1\SERGEL~1\APPLIC~1\WinRAR

--------------------\\ Tâches planifiées dans C:\WINDOWS\tasks

[2009-01-08 18:09][--a------] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009-01-10 11:13][--ah-----] C:\WINDOWS\tasks\SA.DAT
[2004-08-10 05:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini

--------------------\\ Listing des dossiers dans C:\Program Files

[2008-12-22|18:40] C:\Program Files\1ClickUnZip
[2007-09-13|14:36] C:\Program Files\ACD Systems
[2006-08-30|20:40] C:\Program Files\Acer Inc
[2006-08-30|20:41] C:\Program Files\Adobe
[2008-06-07|11:04] C:\Program Files\Apple Software Update
[2008-12-21|14:02] C:\Program Files\Avira
[2008-10-17|22:23] C:\Program Files\Bonjour
[2006-08-30|20:35] C:\Program Files\CONEXANT
[2006-12-14|18:00] C:\Program Files\CyberLink
[2006-08-30|20:30] C:\Program Files\DIFX
[2007-12-23|14:58] C:\Program Files\Dofus
[2007-04-07|09:10] C:\Program Files\Dofus-Arena
[2007-06-19|17:32] C:\Program Files\DSC_Program
[2006-12-24|10:26] C:\Program Files\DWGeditor
[2008-10-01|11:10] C:\Program Files\Eltima Software
[2005-04-15|14:37] C:\Program Files\Fichiers communs
[2007-01-12|22:38] C:\Program Files\Google
[2006-08-30|20:33] C:\Program Files\InstallShield Installation Information
[2005-04-15|14:44] C:\Program Files\Internet Explorer
[2008-10-17|22:24] C:\Program Files\iPod
[2008-10-17|22:24] C:\Program Files\iTunes
[2006-12-24|12:42] C:\Program Files\Java
[2006-12-14|18:03] C:\Program Files\Launch Manager
[2006-12-24|12:41] C:\Program Files\LimeWire
[2006-12-14|22:55] C:\Program Files\Logitech
[2005-04-15|14:41] C:\Program Files\Messenger
[2008-08-05|21:59] C:\Program Files\Messenger Plus! Live
[2005-04-15|14:47] C:\Program Files\microsoft frontpage
[2006-12-24|10:26] C:\Program Files\Microsoft Office
[2007-03-23|22:01] C:\Program Files\Microsoft Visual Studio
[2007-03-23|22:01] C:\Program Files\Microsoft Works
[2007-03-23|22:00] C:\Program Files\Microsoft.NET
[2007-09-29|17:04] C:\Program Files\mIRC
[2005-04-15|14:41] C:\Program Files\Movie Maker
[2005-04-15|14:41] C:\Program Files\MSN
[2005-04-15|14:41] C:\Program Files\MSN Gaming Zone
[2006-12-26|17:59] C:\Program Files\MSN Messenger
[2009-01-02|12:30] C:\Program Files\Navilog1
[2007-09-13|08:32] C:\Program Files\Nero
[2005-04-15|14:44] C:\Program Files\NetMeeting
[2006-08-30|20:39] C:\Program Files\NewTech Infosystems
[2008-12-26|15:06] C:\Program Files\NOS
[2005-04-15|14:44] C:\Program Files\Outlook Express
[2007-10-16|18:07] C:\Program Files\PhotoFrame_V1.5
[2008-10-17|22:22] C:\Program Files\QuickTime
[2006-08-30|20:34] C:\Program Files\Realtek
[2007-12-02|20:00] C:\Program Files\Runtime Software
[2007-02-08|22:03] C:\Program Files\Slayers Online
[2007-03-07|23:09] C:\Program Files\Softnyx
[2007-09-13|13:20] C:\Program Files\SolidWorks
[2007-09-13|13:31] C:\Program Files\SolidWorks Installation Manager
[2008-12-27|08:41] C:\Program Files\Sonic
[2008-12-26|15:05] C:\Program Files\Sony
[2008-12-22|17:49] C:\Program Files\Steam
[2006-08-30|20:50] C:\Program Files\Symantec
[2006-08-30|20:35] C:\Program Files\Synaptics
[2008-12-22|18:28] C:\Program Files\SystemRequirementsLab
[2007-02-18|12:39] C:\Program Files\Teamspeak2_RC2
[2008-12-20|11:28] C:\Program Files\Trend Micro
[2008-09-06|16:35] C:\Program Files\TSO
[2007-06-19|17:27] C:\Program Files\Ulead Systems
[2005-04-15|14:55] C:\Program Files\Uninstall Information
[2007-02-17|16:39] C:\Program Files\Valve
[2009-01-02|14:08] C:\Program Files\VDOWNLOADER
[2008-05-03|17:33] C:\Program Files\Ventrilo
[2008-10-18|16:29] C:\Program Files\VirtualDJ
[2008-12-13|10:15] C:\Program Files\VisualTool
[2007-09-13|13:20] C:\Program Files\Windows Desktop Search
[2008-08-05|21:59] C:\Program Files\Windows Live
[2006-12-14|22:57] C:\Program Files\Windows Media Components
[2007-10-26|20:29] C:\Program Files\Windows Media Connect 2
[2005-04-15|14:42] C:\Program Files\Windows Media Player
[2005-04-15|14:41] C:\Program Files\Windows NT
[2005-04-15|14:42] C:\Program Files\Windows Plus
[2005-04-15|14:45] C:\Program Files\WindowsUpdate
[2007-12-31|00:37] C:\Program Files\WinRAR
[2009-01-04|16:43] C:\Program Files\xerox

--------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs

[2007-09-13|14:36] C:\Program Files\Fichiers communs\ACD Systems
[2008-05-09|21:04] C:\Program Files\Fichiers communs\Adobe
[2007-09-13|08:32] C:\Program Files\Fichiers communs\Ahead
[2007-11-17|12:07] C:\Program Files\Fichiers communs\Apple
[2006-12-24|10:44] C:\Program Files\Fichiers communs\Bluebeam Software
[2006-12-24|10:26] C:\Program Files\Fichiers communs\Designer
[2006-08-30|20:31] C:\Program Files\Fichiers communs\InstallShield
[2008-12-20|12:22] C:\Program Files\Fichiers communs\iS3
[2006-12-24|12:41] C:\Program Files\Fichiers communs\Java
[2006-08-30|20:40] C:\Program Files\Fichiers communs\LightScribe
[2008-08-07|10:34] C:\Program Files\Fichiers communs\logishrd
[2006-12-14|22:57] C:\Program Files\Fichiers communs\Logitech
[2005-04-15|14:37] C:\Program Files\Fichiers communs\Microsoft Shared
[2005-04-15|14:44] C:\Program Files\Fichiers communs\MSSoap
[2006-08-30|20:39] C:\Program Files\Fichiers communs\muvee Technologies
[2006-08-30|20:39] C:\Program Files\Fichiers communs\NewTech Infosystems
[2005-04-15|14:37] C:\Program Files\Fichiers communs\ODBC
[2005-04-15|14:44] C:\Program Files\Fichiers communs\Services
[2007-09-13|13:20] C:\Program Files\Fichiers communs\Solidworks Data
[2007-09-13|13:21] C:\Program Files\Fichiers communs\SolidWorks Shared
[2005-04-15|14:37] C:\Program Files\Fichiers communs\SpeechEngines
[2007-01-01|22:59] C:\Program Files\Fichiers communs\SWF Studio
[2006-08-30|20:49] C:\Program Files\Fichiers communs\Symantec Shared
[2005-04-15|14:44] C:\Program Files\Fichiers communs\System
[2007-06-19|17:27] C:\Program Files\Fichiers communs\Ulead Systems
[2008-05-03|17:33] C:\Program Files\Fichiers communs\Wise Installation Wizard

--------------------\\ Process

( 55 Processes )

... OK !

--------------------\\ Recherche avec S_Lop

Aucun fichier / dossier Lop trouvé !

--------------------\\ Recherche de Fichiers / Dossiers Lop

Aucun fichier / dossier Lop trouvé !

--------------------\\ Verification du Registre

..... OK !

--------------------\\ Verification du fichier Hosts

Fichier Hosts PROPRE

--------------------\\ Recherche de fichiers avec Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-10 12:05:38
Windows 5.1.2600 Service Pack 3 FAT NTAPI
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 0

--------------------\\ Recherche d'autres infections

Aucune autre infection trouvée !

[F:91][D:2]-> C:\DOCUME~1\SERGEL~1\LOCALS~1\Temp
[F:421][D:0]-> C:\DOCUME~1\SERGEL~1\Cookies
[F:410][D:52]-> C:\DOCUME~1\SERGEL~1\LOCALS~1\TEMPOR~1\content.IE5
[F:989][D:266]-> C:\Recycled

1 - "C:\Lop SD\LopR_1.txt" - 2009-01-02|12:44 - Option : [1]
2 - "C:\Lop SD\LopR_2.txt" - 2009-01-10|12:15 - Option : [2]

--------------------\\ Fin du rapport a 12:15:17
0
darkpoet Messages postés 1696 Statut Contributeur sécurité 62
 
repost un nouvel hijack svp
0
serdeninc Messages postés 37 Statut Membre
 
Le voici ,merci j'ai toujour la fenetre antivirus 2009 qui ouvre. Ca gosse!!!!

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:27:01, on 2009-01-10
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\Acer\Empowering Technology\eLock\LockServ.exe
C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
C:\Acer\Empowering Technology\ePresentation\ePresentation.exe
C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
C:\Program Files\Fichiers communs\Logitech\QCDriver3\LVCOMS.EXE
C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe
C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\NCLAUNCH.EXe
C:\Acer\Empowering Technology\Acer.Empowering.Framework.Launcher.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\DOCUME~1\SERGEL~1\LOCALS~1\Temp\RtkBtMnt.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?redirfallthru=http%3a%2f%2fsympatico.msn.ca%2fdefaultf.aspx%2f%3f
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;*.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {01c543da-fed5-4b54-ac92-ba63c42f2c52} - C:\WINDOWS\system32\gotumuda.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll (file missing)
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O2 - BHO: VisualTool - {F3A54897-9E68-B11E-A37A-4D1422CE9CAA} - C:\Program Files\VisualTool\VisualTool-3.dll (file missing)
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\WINDOWS\system32\eDStoolbar.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ntiMUI] C:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [ePower_DMC] C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
O4 - HKLM\..\Run: [Boot] C:\Acer\Empowering Technology\ePower\Boot.exe
O4 - HKLM\..\Run: [Acer ePresentation HPD] C:\Acer\Empowering Technology\ePresentation\ePresentation.exe
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe 0
O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Fichiers communs\Logitech\QCDriver3\LVCOMS.EXE
O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Program Files\Logitech\ImageStudio\ISStart.exe
O4 - HKLM\..\Run: [Microsoft] C:\WINDOWS\wuauclt.exe
O4 - HKLM\..\Run: [Ulead AutoDetector] C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [0b790604] rundll32.exe "C:\WINDOWS\system32\gihujasu.dll",b
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [diwodakefa] Rundll32.exe "C:\WINDOWS\system32\lozugava.dll",s
O4 - HKLM\..\Run: [CPM084a3598] Rundll32.exe "c:\windows\system32\bobebeji.dll",a
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [NCLaunch] C:\WINDOWS\NCLAUNCH.EXe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [diwodakefa] Rundll32.exe "C:\WINDOWS\system32\lozugava.dll",s (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Acer Empowering Technology.lnk = ?
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - https://www.nvidia.com/content/DriverDownload/srl/3.0.0.0/srl_bin/sysreqlab3.cab
O16 - DPF: {56393399-041A-4650-94C7-13DFCB1F4665} (PSFormX Control) - http://www.ca.com/us/securityadvisor/pestscan/pestscan.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-CA/a-UNO1/GAME_UNO1.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/ractrl.cab?lmi=100
O20 - AppInit_DLLs: c:\windows\system32\diwosama.dll C:\WINDOWS\system32\gelilawe.dll c:\windows\system32\bobebeji.dll
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\bobebeji.dll
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\bobebeji.dll
O23 - Service: Memory Check Service (AcerMemUsageCheckService) - Acer Inc. - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
O23 - Service: LockServ - Unknown owner - C:\Acer\Empowering Technology\eLock\LockServ.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files\Fichiers communs\SolidWorks Shared\Service\SolidWorksLicensing.exe
0
serdeninc Messages postés 37 Statut Membre
 
Cette page ouvre souvent aussi mais il ni a rien qui s'affiche.
http://c5.zero.com/jsc/c5/ff2.html?n=377;c99;s=36;d=16;w=720;h300
0
serdeninc Messages postés 37 Statut Membre
 
Peut-etre que aussi il y a mirar dans ma liste de program que je ne peut éliminer ,j'ai fait un tas de chose pour l'enlever
quand je le supprime il y a un fentre qui ouvre avec rien ,puis il est toujours la.
0
darkpoet Messages postés 1696 Statut Contributeur sécurité 62
 
ok ça avance tu passeras smitfraufix et tu poste le rapport,Merci

Ouvre ce lien (merci a S!RI pour ce programme). http://siri.urz.free.fr/Fix/SmitfraudFix.php

le mieux serait que tu désaxctives tes protections résidente "anti-virus et anti-spyware" le temps d'installer smitfraudfix et de faire l'analyse.

et télécharge SmitfraudFix.exe.

Regarde le tuto

Exécute le en choisissant l’option 1
il va générer un rapport

Copie/colle le sur le poste stp.

Process.exe est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus, ect...) comme étant un RiskTool. Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus. Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.

une petites démo en vidéo :http://pagesperso-orange.fr/rginformatique/section%20virus/smitfraudfix.htm
0
serdeninc Messages postés 37 Statut Membre
 
Voici le raport. Merci

SmitFraudFix v2.388

Rapport fait à 11:13:07,37, 2009-01-11
Executé à partir de C:\Documents and Settings\Serge Laplante\Bureau\SmitfraudFix
OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
Le type du système de fichiers est FAT32
Fix executé en mode normal

»»»»»»»»»»»»»»»»»»»»»»»» Process

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\Acer\Empowering Technology\eLock\LockServ.exe
C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
C:\Acer\Empowering Technology\ePresentation\ePresentation.exe
C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
C:\Program Files\Fichiers communs\Logitech\QCDriver3\LVCOMS.EXE
C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe
C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\NCLAUNCH.EXe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Acer\Empowering Technology\Acer.Empowering.Framework.Launcher.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\DOCUME~1\SERGEL~1\LOCALS~1\Temp\RtkBtMnt.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\Steam\Steam.exe
C:\WINDOWS\explorer.exe
C:\Program Files\QuickTime\QuickTimePlayer.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Serge Laplante\Bureau\SmitfraudFix\Policies.exe
C:\WINDOWS\system32\cmd.exe

»»»»»»»»»»»»»»»»»»»»»»»» hosts

»»»»»»»»»»»»»»»»»»»»»»»» C:\

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles

»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Serge Laplante

»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\SERGEL~1\LOCALS~1\Temp

»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Serge Laplante\Application Data

»»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\SERGEL~1\FAVORIS

»»»»»»»»»»»»»»»»»»»»»»»» Bureau

»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

»»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

»»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="Ma page d'accueil"

»»»»»»»»»»»»»»»»»»»»»»»» o4Patch
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

o4Patch
Credits: Malware Analysis & Diagnostic
Code: S!Ri

»»»»»»»»»»»»»»»»»»»»»»»» IEDFix
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

IEDFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri

»»»»»»»»»»»»»»»»»»»»»»»» Agent.OMZ.Fix
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

Agent.OMZ.Fix
Credits: Malware Analysis & Diagnostic
Code: S!Ri

»»»»»»»»»»»»»»»»»»»»»»»» VACFix
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

VACFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri

»»»»»»»»»»»»»»»»»»»»»»»» 404Fix
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

404Fix
Credits: Malware Analysis & Diagnostic
Code: S!Ri

»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4}"="STS"

[HKEY_CLASSES_ROOT\CLSID\{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4}\InProcServer32]
@="c:\windows\system32\nosunilo.dll"

[HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4}\InProcServer32]
@="c:\windows\system32\nosunilo.dll"

»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="c:\\windows\\system32\\diwosama.dll C:\\WINDOWS\\system32\\gelilawe.dll c:\\windows\\system32\\nosunilo.dll"
"LoadAppInit_DLLs"=dword:00000001

»»»»»»»»»»»»»»»»»»»»»»»» Winlogon
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
"System"=""

»»»»»»»»»»»»»»»»»»»»»»»» RK

»»»»»»»»»»»»»»»»»»»»»»»» DNS

Description: NVIDIA nForce Networking Controller - Miniport d'ordonnancement de paquets
DNS Server Search Order: 205.151.67.6
DNS Server Search Order: 205.151.67.2

HKLM\SYSTEM\CCS\Services\Tcpip\..\{B2531025-54CE-420B-8F6A-C0C0E924D39B}: DhcpNameServer=205.151.67.6 205.151.67.2
HKLM\SYSTEM\CS1\Services\Tcpip\..\{B2531025-54CE-420B-8F6A-C0C0E924D39B}: DhcpNameServer=205.151.67.6 205.151.67.2
HKLM\SYSTEM\CS3\Services\Tcpip\..\{9520F61C-51A6-4E10-A8A9-6CA04DA521CB}: DhcpNameServer=205.151.67.6 205.151.67.2
HKLM\SYSTEM\CS3\Services\Tcpip\..\{B2531025-54CE-420B-8F6A-C0C0E924D39B}: DhcpNameServer=205.151.67.6 205.151.67.2
HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=205.151.67.6 205.151.67.2

»»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

»»»»»»»»»»»»»»»»»»»»»»»» Fin
0
darkpoet Messages postés 1696 Statut Contributeur sécurité 62
 
Démarre en mode sans échec :
Pour cela, tu tapotes la touche F8 dès le début de l’allumage du pc sans t’arrêter.
Une fenêtre va s’ouvrir tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec puis tape entrée.
Une fois sur le bureau s’il n’y a pas toutes les couleurs et autres c’est normal !
(Si F8 ne marche pas utilise la touche F5).

http://www.coupdepoucepc.com/modules/news/article.php?storyi­d=253
http://www.micro-astuce.com/depannage/demarrer-mode-sans-ech­ec

------------------------------------------------------------­----------------
Relance le programme Smitfraud,
Cette fois choisit l’option 2, répond oui a tous ;
Sauvegarde le rapport,
Redémarre en mode normal,
copie/colle le rapport sauvegardé sur le forum

process.exe
est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool. Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus. Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.
http://www.beyondlogic.org/consulting/processutil/processuti­l.htm

+ un log Hijackthis en Mode Normal
0
serdeninc Messages postés 37 Statut Membre
 
Je crois que j'ai fait correct.

SmitFraudFix v2.388

Rapport fait à 11:29:09,93, 2009-01-11
Executé à partir de C:\Documents and Settings\Serge Laplante\Bureau\SmitfraudFix
OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
Le type du système de fichiers est FAT32
Fix executé en mode sans echec

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Avant SmitFraudFix
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4}"="STS"

[HKEY_CLASSES_ROOT\CLSID\{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4}\InProcServer32]
@="c:\windows\system32\nosunilo.dll"

[HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4}\InProcServer32]
@="c:\windows\system32\nosunilo.dll"

»»»»»»»»»»»»»»»»»»»»»»»» Arret des processus

»»»»»»»»»»»»»»»»»»»»»»»» hosts

127.0.0.1 localhost

»»»»»»»»»»»»»»»»»»»»»»»» VACFix

VACFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri

»»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

S!Ri's WS2Fix: LSP not Found.

»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

GenericRenosFix by S!Ri

»»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés

»»»»»»»»»»»»»»»»»»»»»»»» IEDFix

IEDFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri

»»»»»»»»»»»»»»»»»»»»»»»» Agent.OMZ.Fix

Agent.OMZ.Fix
Credits: Malware Analysis & Diagnostic
Code: S!Ri

»»»»»»»»»»»»»»»»»»»»»»»» 404Fix

404Fix
Credits: Malware Analysis & Diagnostic
Code: S!Ri

»»»»»»»»»»»»»»»»»»»»»»»» RK

»»»»»»»»»»»»»»»»»»»»»»»» DNS

HKLM\SYSTEM\CCS\Services\Tcpip\..\{B2531025-54CE-420B-8F6A-C0C0E924D39B}: DhcpNameServer=205.151.67.6 205.151.67.2
HKLM\SYSTEM\CS1\Services\Tcpip\..\{B2531025-54CE-420B-8F6A-C0C0E924D39B}: DhcpNameServer=205.151.67.6 205.151.67.2
HKLM\SYSTEM\CS3\Services\Tcpip\..\{9520F61C-51A6-4E10-A8A9-6CA04DA521CB}: DhcpNameServer=205.151.67.6 205.151.67.2
HKLM\SYSTEM\CS3\Services\Tcpip\..\{B2531025-54CE-420B-8F6A-C0C0E924D39B}: DhcpNameServer=205.151.67.6 205.151.67.2
HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=205.151.67.6 205.151.67.2

»»»»»»»»»»»»»»»»»»»»»»»» Suppression Fichiers Temporaires

»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""

»»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre

Nettoyage terminé.

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Après SmitFraudFix
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4}"="STS"

[HKEY_CLASSES_ROOT\CLSID\{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4}\InProcServer32]
@="c:\windows\system32\nosunilo.dll"

[HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4}\InProcServer32]
@="c:\windows\system32\nosunilo.dll"

»»»»»»»»»»»»»»»»»»»»»»»» Fin

Plus

ogfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:45:50, on 2009-01-11
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
C:\Acer\Empowering Technology\ePresentation\ePresentation.exe
C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
C:\Program Files\Fichiers communs\Logitech\QCDriver3\LVCOMS.EXE
C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\rundll32.exe
C:\Acer\Empowering Technology\eLock\LockServ.exe
C:\PROGRA~1\LAUNCH~1\LManager.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\NCLAUNCH.EXe
C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\program files\steam\steam.exe
C:\Acer\Empowering Technology\Acer.Empowering.Framework.Launcher.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
C:\Acer\Empowering Technology\eLock\Monitor\LockMon.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Logitech\ImageStudio\LowLight.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
C:\DOCUME~1\SERGEL~1\LOCALS~1\Temp\RtkBtMnt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;*.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {01c543da-fed5-4b54-ac92-ba63c42f2c52} - C:\WINDOWS\system32\gotumuda.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll (file missing)
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O2 - BHO: VisualTool - {F3A54897-9E68-B11E-A37A-4D1422CE9CAA} - C:\Program Files\VisualTool\VisualTool-3.dll (file missing)
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\WINDOWS\system32\eDStoolbar.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ntiMUI] C:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [ePower_DMC] C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
O4 - HKLM\..\Run: [Boot] C:\Acer\Empowering Technology\ePower\Boot.exe
O4 - HKLM\..\Run: [Acer ePresentation HPD] C:\Acer\Empowering Technology\ePresentation\ePresentation.exe
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe 0
O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Fichiers communs\Logitech\QCDriver3\LVCOMS.EXE
O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Program Files\Logitech\ImageStudio\ISStart.exe
O4 - HKLM\..\Run: [Microsoft] C:\WINDOWS\wuauclt.exe
O4 - HKLM\..\Run: [Ulead AutoDetector] C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [diwodakefa] Rundll32.exe "C:\WINDOWS\system32\lozugava.dll",s
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [0b790604] rundll32.exe "C:\WINDOWS\system32\likizedo.dll",b
O4 - HKLM\..\Run: [CPM084a3598] Rundll32.exe "c:\windows\system32\nosunilo.dll",a
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [LogitechImageStudioTray] C:\Program Files\Logitech\ImageStudio\LogiTray.exe
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
O4 - HKLM\..\Run: [eLockMonitor] C:\Acer\Empowering Technology\eLock\Monitor\LaunchMonitor.exe
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [NCLaunch] C:\WINDOWS\NCLAUNCH.EXe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\MSNMSGR.EXE" /background
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_1_0 -reboot 1
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [diwodakefa] Rundll32.exe "C:\WINDOWS\system32\lozugava.dll",s (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Acer Empowering Technology.lnk = ?
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - https://www.nvidia.com/content/DriverDownload/srl/3.0.0.0/srl_bin/sysreqlab3.cab
O16 - DPF: {56393399-041A-4650-94C7-13DFCB1F4665} (PSFormX Control) - http://www.ca.com/us/securityadvisor/pestscan/pestscan.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-CA/a-UNO1/GAME_UNO1.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/ractrl.cab?lmi=100
O20 - AppInit_DLLs: c:\windows\system32\diwosama.dll C:\WINDOWS\system32\gelilawe.dll c:\windows\system32\nosunilo.dll
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\nosunilo.dll
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\nosunilo.dll
O23 - Service: Memory Check Service (AcerMemUsageCheckService) - Acer Inc. - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
O23 - Service: LockServ - Unknown owner - C:\Acer\Empowering Technology\eLock\LockServ.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files\Fichiers communs\SolidWorks Shared\Service\SolidWorksLicensing.exe
0
darkpoet Messages postés 1696 Statut Contributeur sécurité 62
 
bon pas le choix
attentio ce programme est tres puissant suis a la lettre les consignes etregarde les tuto

Télécharge Combofix sUBs : http://download.bleepingcomputer.com/sUBs/ComboFix.exe
et sauvegarde le sur ton bureau et pas ailleurs!

https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix

**Désactive les logiciels de protection** (Antivirus, Antispywares) puis :
deconnecte toi d'internet,ferme tout les programmes

Double-clique sur combofix, Il va te poser une question, réponds par la touche 1 et entrée pour valider.
ne touche plus à rien, même pas ta souris!!
Attends que combofix ait terminé, un rapport sera créé. Poste le rapport.

Copie/colle un nouveau rapport HiJackThis avec.

-----------------------------------------------------

installer la Console de Récupération sur ton pc(cela permettra de réparer ton système au cas où le pc ne redémarrerait plus suite à la désinfection.)

Clique sur le lien ci-dessous pour aller sur le site Web de Microsoft:

https://support.microsoft.com/en-us/help/310994

descend jusqu'à "Téléchargement du fichier programme des disquettes d'installation" et clique sur le téléchargement correspondant à ta version de Windows XP (Édition familiale ou Professionnel) et au Service Pack que tu as installé.
**note: pour le SP3 charge le Service Pack 2
pour Windows XP Media Center charge XP Pro Service Pack 2.

enregistre le sur ton bureau.

0