Infection system guard 2009 et autre - Page 2

Résolu
Précédent
  • 1
  • 2
  1. plopus Messages postés 49 Date d'inscription   Statut Contributeur sécurité Dernière intervention   293
     
    ok fait le poste 29 et poste
    0
  2. evyndar
     
    oui j'ai du redémarrer l'ordi et j'ai donc eu un autre rapport que je te poste

    ========== PROCESSES ==========
    Process explorer.exe killed successfully.
    Unable to kill process: systemguard.exe
    ========== FILES ==========
    C:\Program Files\System Guard 2009\systemguard.exe moved successfully.
    C:\Program Files\System Guard 2009\quarantine moved successfully.
    C:\Program Files\System Guard 2009 moved successfully.
    ========== COMMANDS ==========
    User's Temp folder emptied.
    User's Temporary Internet Files folder emptied.
    User's Internet Explorer cache folder emptied.
    Local Service Temp folder emptied.
    File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
    Local Service Temporary Internet Files folder emptied.
    File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_4f8.dat scheduled to be deleted on reboot.
    Windows Temp folder emptied.
    Java cache emptied.
    Temp folders emptied.
    Explorer started successfully

    OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 02012009_201317

    Files moved on Reboot...
    C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat moved successfully.
    File C:\WINDOWS\temp\Perflib_Perfdata_4f8.dat not found!
    0
    1. evyndar
       
      désolé j'ai posté 2 fois la même chose je croyais que je ne l'avais pas fait sinon voici les 2 rapports

      info.txt logfile of random's system information tool 1.05 2009-02-01 20:30:41

      ======Uninstall list======

      -->C:\Program Files\System Guard 2009\uninstall.exe
      -->C:\WINDOWS\IsUn040c.exe -fC:\WINDOWS\orun32.isu
      -->MsiExec.exe /I{8A42F680-2DD6-11D4-9A8C-0040F6982C20}
      -->MsiExec.exe /I{A2529672-574A-4A99-86A5-C1770A0E31FE}
      -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9B5AAC6D-AF21-4034-AF1D-A28274180BA6}\setup.exe" -l0x40c anything
      -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
      Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
      Adobe Reader 7.0 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A70000000000}
      Agere Systems AC'97 Modem v2141D-->agrsmdel
      Assistant de connexion Windows Live-->MsiExec.exe /I{D6E592B3-67DA-4BBB-9783-E1838FB253A2}
      avast! Antivirus-->C:\Program Files\Alwil Software\Avast4\aswRunDll.exe "C:\Program Files\Alwil Software\Avast4\Setup\setiface.dll",RunSetup
      Barre d'outils Outlook de Windows Live (Windows Live Toolbar)-->MsiExec.exe /X{4002F73D-EBB3-4EA1-A2FF-DBCB4529759E}
      Belkin Wireless Utility-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{49C090F0-4D03-4DD2-87BA-BF6AA53B9735}\setup.exe" -l0x40c
      Bloqueur de fenêtres pop-up (Windows Live Toolbar)-->MsiExec.exe /X{51F366F4-C2E4-429A-866A-59C885ED42FD}
      Brother MFL-Pro Suite-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BB9AC6BF-71B6-42A4-9689-C17D9F44E79A}\Setup.exe" -l0x40c Brunin03.dllBrunin03.dll
      CA eTrust Antivirus-->MsiExec.exe /X{6A120E99-3123-4CB2-9A02-D24784F4BC8C}
      Choice Guard-->MsiExec.exe /I{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}
      Correctif pour Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
      Détecteur de flux Windows Live Toolbar (Windows Live Toolbar)-->MsiExec.exe /X{175B7C4A-CAF8-437A-B597-73E0D2D970FE}
      eTrust Registration-->MsiExec.exe /X{6BFF4534-7608-41F0-85F7-31A0569D8960}
      Extension de Windows Live Toolbar (Windows Live Toolbar)-->MsiExec.exe /X{D518AD32-C710-4616-BA0D-D4B1FA5F82E8}
      Extension HighMAT pour l'Assistant Graver un CD de Microsoft Windows XP-->MsiExec.exe /X{FCE65C4E-B0E8-4FBD-AD16-EDCBE6CD591F}
      Google Earth-->MsiExec.exe /I{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}
      Google Toolbar for Internet Explorer-->"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_0531C63A913CC9D1.exe" /uninstall
      HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
      Informations sur votre PC-->MsiExec.exe /I{36D6F663-DF15-45BD-B0C6-4B909308E3B6}
      Intel(R) Graphics Media Accelerator Driver for Mobile-->RUNDLL32.EXE C:\WINDOWS\system32\ialmrem.dll,UninstallW2KIGfx2ID PCI\VEN_8086&DEV_2792 PCI\VEN_8086&DEV_2592
      J2SE Runtime Environment 5.0 Update 3-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150030}
      Lecteur Windows Media 10-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
      Macromedia Shockwave Player-->C:\WINDOWS\system32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~1\Install.log
      Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
      Microsoft .NET Framework 1.1 French Language Pack-->MsiExec.exe /X{9A394342-4A68-4EBA-85A6-55B559F4E700}
      Microsoft .NET Framework 1.1 Hotfix (KB928366)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
      Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
      Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
      Microsoft .NET Framework 2.0-->C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.exe
      Microsoft LifeCam-->MsiExec.exe /X{3C137BCF-8ADC-430D-B01C-A45593AC512B}
      Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
      Mise à jour de sécurité pour Lecteur Windows Media (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Lecteur Windows Media 10 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP10$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Step by Step Interactive Training (KB898458)-->"C:\WINDOWS\$NtUninstallKB898458$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Step by Step Interactive Training (KB923723)-->"C:\WINDOWS\$NtUninstallKB923723$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB956390)-->"C:\WINDOWS\$NtUninstallKB956390$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB957095)-->"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB958215)-->"C:\WINDOWS\$NtUninstallKB958215$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB960714)-->"C:\WINDOWS\$NtUninstallKB960714$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
      MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
      MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
      Navigation par onglets (Windows Live Toolbar)-->MsiExec.exe /X{E74559C2-BB47-45AD-83DD-0D66B67E7811}
      PaperPort-->MsiExec.exe /I{A17EABB6-D0C6-44E5-820C-72DC7F495064}
      Realtek AC'97 Audio-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FB08F381-6533-4108-B7DD-039E11FBC27E}\setup.exe" -l0x40c -removeonly
      REALTEK Gigabit and Fast Ethernet NIC Driver-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{94FB906A-CF42-4128-A509-D353026A607E}\Setup.exe" -l0x40c REMOVE
      System Control Manager-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{ED9C5D25-55DF-48D8-9328-2AC0D75DE5D8}\Setup.exe"
      Unity Web Player-->C:\Program Files\Unity\WebPlayer\Uninstall.exe
      Utilitaire de sauvegarde Windows-->MsiExec.exe /I{76EFFC7C-17A6-479D-9E47-8E658C1695AE}
      VLC media player 0.9.6-->C:\Program Files\VideoLAN\VLC\uninstall.exe
      Windows Genuine Advantage v1.3.0254.0-->MsiExec.exe /I{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}
      Windows Live Messenger-->MsiExec.exe /I{F6326B60-1B1D-4ABF-BFCD-7B7404F44411}
      Windows Live Sync-->MsiExec.exe /X{67D0313C-4F15-437D-9A2D-C1564088A26A}
      Windows Media Connect-->msiexec.exe /I {F6869CD2-3DB4-476D-A4C7-B3AE7C3ACF7B}
      Windows Media Connect-->MsiExec.exe /I{F6869CD2-3DB4-476D-A4C7-B3AE7C3ACF7B}
      Windows Media Format Runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
      Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"

      ======Security center information======

      AV: avast! antivirus 4.8.1296 [VPS 090115-0] (disabled) (outdated)

      System event log

      Computer Name: EKER
      Event Code: 7036
      Message: Le service NLA (Network Location Awareness) est entré dans l'état : en cours d'exécution.

      Record Number: 19943
      Source Name: Service Control Manager
      Time Written: 20090127090219.000000+060
      Event Type: Informations
      User:

      Computer Name: EKER
      Event Code: 7035
      Message: Un contrôle Démarrer a correctement été envoyé au service MGHwCtrl.

      Record Number: 19942
      Source Name: Service Control Manager
      Time Written: 20090127090219.000000+060
      Event Type: Informations
      User: EKER\ekere

      Computer Name: EKER
      Event Code: 7035
      Message: Un contrôle Démarrer a correctement été envoyé au service NLA (Network Location Awareness).

      Record Number: 19941
      Source Name: Service Control Manager
      Time Written: 20090127090219.000000+060
      Event Type: Informations
      User: AUTORITE NT\SYSTEM

      Computer Name: EKER
      Event Code: 7035
      Message: Un contrôle Démarrer a correctement été envoyé au service Gestionnaire de connexions d'accès distant.

      Record Number: 19940
      Source Name: Service Control Manager
      Time Written: 20090127090219.000000+060
      Event Type: Informations
      User: EKER\ekere

      Computer Name: EKER
      Event Code: 7036
      Message: Le service Compatibilité avec le Changement rapide d'utilisateur est entré dans l'état : en cours d'exécution.

      Record Number: 19939
      Source Name: Service Control Manager
      Time Written: 20090127090219.000000+060
      Event Type: Informations
      User:

      Application event log

      Computer Name: EKER
      Event Code: 0
      Message:
      Record Number: 4950
      Source Name: MSCamSvc
      Time Written: 20090128224739.000000+060
      Event Type: Informations
      User:

      Computer Name: EKER
      Event Code: 1517
      Message: Windows a sauvegardé le Registre utilisateur EKER\ekere alors qu'une application ou un service utilisait toujours le Registre pendant la fermeture de la session. La mémoire utilisée par le Registre de l'utilisateur n'a pas été libérée. le Registre sera déchargé lorsqu'il ne sera plus utilisé.


      Cela est souvent causé par des services s'exécutant en tant que compte d'utilisateur, essayez de configurer les services pour s'exécuter dans le compte service réseau ou service local.

      Record Number: 4949
      Source Name: Userenv
      Time Written: 20090128215827.000000+060
      Event Type: Avertissement
      User: AUTORITE NT\SYSTEM

      Computer Name: EKER
      Event Code: 1800
      Message: Le service Centre de sécurité Windows a démarré.

      Record Number: 4948
      Source Name: SecurityCenter
      Time Written: 20090128205959.000000+060
      Event Type: Informations
      User:

      Computer Name: EKER
      Event Code: 0
      Message:

      Record Number: 4947
      Source Name: MSCamSvc
      Time Written: 20090128205950.000000+060
      Event Type: Informations
      User:

      Computer Name: EKER
      Event Code: 0
      Message:
      Record Number: 4946
      Source Name: MSCamSvc
      Time Written: 20090128205950.000000+060
      Event Type: Informations
      User:

      ======Environment variables======

      "ComSpec"=%SystemRoot%\system32\cmd.exe
      "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\PROGRA~1\CA\SHARED~1\SCANEN~1;C:\PROGRA~1\CA\ETRUST~1
      "windir"=%SystemRoot%
      "FP_NO_HOST_CHECK"=NO
      "OS"=Windows_NT
      "PROCESSOR_ARCHITECTURE"=x86
      "PROCESSOR_LEVEL"=6
      "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 13 Stepping 8, GenuineIntel
      "PROCESSOR_REVISION"=0d08
      "NUMBER_OF_PROCESSORS"=1
      "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
      "TEMP"=%SystemRoot%\TEMP
      "TMP"=%SystemRoot%\TEMP
      "AVENGINE"=C:\PROGRA~1\CA\SHARED~1\SCANEN~1
      "INOCULAN"=C:\PROGRA~1\CA\ETRUST~1

      -----------------EOF-----------------




      Logfile of random's system information tool 1.05 (written by random/random)
      Run by ekere at 2009-02-01 20:30:34
      Microsoft Windows XP Édition familiale Service Pack 3
      System drive C: has 10 GB (36%) free of 29 GB
      Total RAM: 503 MB (52% free)

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 20:30:38, on 01/02/2009
      Platform: Windows XP SP3 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\System32\wltrysvc.exe
      C:\WINDOWS\System32\bcmwltry.exe
      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      C:\Program Files\Alwil Software\Avast4\ashServ.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\system32\brss01a.exe
      C:\Program Files\CA\eTrust Antivirus\InoRpc.exe
      C:\Program Files\CA\eTrust Antivirus\InoRT.exe
      C:\Program Files\Microsoft LifeCam\MSCamS32.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\AGRSMMSG.exe
      C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
      C:\WINDOWS\system32\hkcmd.exe
      C:\WINDOWS\system32\igfxpers.exe
      C:\WINDOWS\system32\wltray.exe
      C:\WINDOWS\vVX6000.exe
      C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
      C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      C:\WINDOWS\system32\wscntfy.exe
      C:\Documents and Settings\ekere\Bureau\RSIT.exe
      C:\Program Files\Trend Micro\HijackThis\ekere.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
      O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
      O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
      O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
      O4 - HKLM\..\Run: [AntivirusRegistration] C:\Program Files\CA\Etrust Antivirus\Register.exe
      O4 - HKLM\..\Run: [Realtime Monitor] C:\PROGRA~1\CA\ETRUST~1\realmon.exe -s
      O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
      O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
      O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
      O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
      O4 - HKLM\..\Run: [MGSysCtrl] C:\Program Files\System Control Manager\MGSysCtrl.exe
      O4 - HKLM\..\Run: [wltray.exe] C:\WINDOWS\system32\wltray.exe
      O4 - HKLM\..\Run: [VX6000] C:\WINDOWS\vVX6000.exe
      O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
      O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
      O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
      O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
      O4 - HKLM\..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl05a\BrStDvPt.exe
      O4 - HKLM\..\Run: [ControlCenter2.0] C:\Program Files\Brother\ControlCenter2\brctrcen.exe /autorun
      O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      O4 - HKLM\..\Run: [systemguard] C:\Program Files\System Guard 2009\systemguard.exe
      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
      O4 - Global Startup: Contrôleur d’état.lnk = C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
      O8 - Extra context menu item: &Recherche AOL Toolbar - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
      O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
      O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?1f59d8c160694a6eb61d1f674c12d5e9
      O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?1f59d8c160694a6eb61d1f674c12d5e9
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_03\bin\npjpi150_03.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_03\bin\npjpi150_03.dll
      O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
      O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://copainsdavant.linternaute.com/...
      O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
      O22 - SharedTaskScheduler: IPC Configuration Utility - IPC Configuration Utility - (no file)
      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: eTrust Antivirus RPC Server (InoRPC) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoRpc.exe
      O23 - Service: eTrust Antivirus Realtime Server (InoRT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoRT.exe
      O23 - Service: eTrust Antivirus Job Server (InoTask) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoTask.exe
      O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
      O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
      0
  3. plopus Messages postés 49 Date d'inscription   Statut Contributeur sécurité Dernière intervention   293
     
    en attendant que je regarde :

    d'abord

    Télécharge JavaRa.zip de Paul 'Prm753' McLain et Fred de Vries.

    http://raproducts.org/click/click.php?id=1

    * Décompresse le fichier sur le bureau (clic droit > Extraire tout)
    * Double-cliquer sur le répertoire JavaRa.
    * Puis double-cliquer sur le fichier JavaRa.exe (le exe peut ne pas s'afficher)
    * Clique sur Search For Updates.
    * Sélectionner Update Using jucheck.exe puis cliquer sur Search.
    * Autorise le processus à se connecter s'il le demande, cliquer sur Install et suivre les instructions d'installation qui prennent quelques minutes.
    * L'installation est terminée, revenez à l'écran de JavaRa et clique sur Remove Older Versions.
    * Clique sur Oui pour confirmer. Laisse travailler et cliquez ensuite sur Ok, puis une deuxième fois sur Ok.
    * Un rapport va s'ouvrir à copier-coller dans la prochaine réponse.
    * Fermer l'application

    Note : le rapport se trouve aussi à la racine de la partition système, en général C:\ sous le nom JavaRa.log .

    puis mise a jour de tes logiciel :
    via windows update
    via ce site https://www.flexera.com/products/operations/software-vulnerability-management.html (clic start scan accepte l'active X) et met a jour tous les logiciels avec des croix rouge en desinstallant avant les ancienne versions

    puis telecharge CCleaner ici
    https://www.01net.com/telecharger/windows/Utilitaire/nettoyeurs_et_installeurs/fiches/32599.html
    ouvre CCleaner va dans option/avanvé et decoche la premier ligne
    et nettoie ton registre et tes fichier temporaire au moins 2fois jusqu'a trouver 0erreur
    0
    1. evyndar
       
      impossible de télécharger javara le lien ne doit plus être bon
      mise à jour effectuée et ccleaner également
      0
  4. plopus Messages postés 49 Date d'inscription   Statut Contributeur sécurité Dernière intervention   293
     
    ok chez moi sa marche on verra a la fin tu le refera

    petite verif

    / !\ Déconnecte-toi et désactive ton antivirus et antispyware résident pour que le programme puisse s'exécuter normalement. /!\

    telecharge combofix http://download.bleepingcomputer.com/sUBs/ComboFix.exe sur ton bureau

    lance le et ne fait rien pendant le scan, touche meme pas a ta souris et poste le rapport à la fin
    0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. plopus Messages postés 49 Date d'inscription   Statut Contributeur sécurité Dernière intervention   293
     
    Bon...

    telecharge GENPROC Ouvre ce lien d'aide < < http://www.alt-shift-return.org/Info/GenProc-HowTo.html >
    , et le téléchargement est dedans < http://www.alt-shift-return.org/Info/Fichiers/GenProc.zip > repond oui à la question à la fin et poste le rapport stp
    0
    1. evyndar
       
      c'est normal que cela mette autant de temps car c'est marqué 30 secondes à 1mn30 et là çà va faire au moins 15mn
      0
  7. plopus Messages postés 49 Date d'inscription   Statut Contributeur sécurité Dernière intervention   293
     
    re

    tu as lu le premier lien de conseil d'installation car au bout de 15 min c'est pas normal non, recommence stp
    0
    1. evyndar
       
      Rapport GenProc 2.351 [1] - 01/02/2009 - Windows XP

      GenProc n'a détecté aucune infection caractéristique et suggère de suivre la procédure suivante :


      Poste un rapport Nod32 https://www.eset.com/ (il faut utiliser Internet Explorer)
      - coche toutes les cases à chaque fois, et lorsque c'est terminé, colle le rapport :
      - C:\Program Files\EsetOnlineScanner\log.txt

      __________________________________________________________________________________________________________

      Sites officiels GenProc : www.alt-shift-return.org et www.genproc.com
      0
  8. plopus Messages postés 49 Date d'inscription   Statut Contributeur sécurité Dernière intervention   293
     
    re

    fait ce qu'il dit et poste les rapports
    0
    1. evyndar
       
      Bonjour,

      je n'ai pas pu faire ce qui était demandé car l'ordi rame pour aller sur internet c'est beaucoup trop long.
      0
  9. plopus Messages postés 49 Date d'inscription   Statut Contributeur sécurité Dernière intervention   293
     
    bonjour

    ok dans ce relance malwarebyte en scan RAPIDE c'est 10min et supprime tous et poste le rapport
    0
    1. evyndar
       
      Malwarebytes' Anti-Malware 1.33
      Version de la base de données: 1654
      Windows 5.1.2600 Service Pack 3

      02/02/2009 17:20:51
      mbam-log-2009-02-02 (17-20-51).txt

      Type de recherche: Examen rapide
      Eléments examinés: 60955
      Temps écoulé: 10 minute(s), 45 second(s)

      Processus mémoire infecté(s): 0
      Module(s) mémoire infecté(s): 0
      Clé(s) du Registre infectée(s): 0
      Valeur(s) du Registre infectée(s): 0
      Elément(s) de données du Registre infecté(s): 0
      Dossier(s) infecté(s): 0
      Fichier(s) infecté(s): 0

      Processus mémoire infecté(s):
      (Aucun élément nuisible détecté)

      Module(s) mémoire infecté(s):
      (Aucun élément nuisible détecté)

      Clé(s) du Registre infectée(s):
      (Aucun élément nuisible détecté)

      Valeur(s) du Registre infectée(s):
      (Aucun élément nuisible détecté)

      Elément(s) de données du Registre infecté(s):
      (Aucun élément nuisible détecté)

      Dossier(s) infecté(s):
      (Aucun élément nuisible détecté)

      Fichier(s) infecté(s):
      (Aucun élément nuisible détecté)
      0
  10. plopus Messages postés 49 Date d'inscription   Statut Contributeur sécurité Dernière intervention   293
     
    re

    oui donc deja j'avais pas fait attention mais
    CA®eTrust Antivirus c'est un antivirus pas un antispyware

    et tu as aussi avast en antivirus

    c'est 1 antivirus par PC sinon sa rame beaucoup, et en + tu es moins proteger car ils rentrent en conflit

    donc desinstalle eTrust via ajout et suppression de programme

    puis un conseil pour etre bien protegé desinstalle avast et insatlle antivir

    pourquoi desinsatlle avast et mettre antivir http://forum.malekal.com/ftopic3528.php
    pour bien desinsatlle avast suit cela :
    http://www.commentcamarche.net/forum/affich 6356821 desinstaller avast proprement

    puis telecharge CCleaner ici
    https://www.01net.com/telecharger/windows/Utilitaire/nettoyeurs_et_installeurs/fiches/32599.html
    ouvre CCleaner va dans option/avanvé et decoche la premier ligne
    et nettoie ton registre et tes fichier temporaire au moins 2fois jusqu'a trouver 0erreur

    si tu le souhaite donc insatlle antivir en francais maintenant
    http://www.commentcamarche.net/telecharger/telecharger 55 antivir
    ensuite double clic sur le parapluie rouge dans la barre des tache en bas a droite :
    - a l'ecran d'accueil clic sur F8 (ou menu configuration)
    - ensuite coche en haut a gauche "expert mode"
    - ensuite selectionne dessous SCANNER
    - ensuite dans le cadre de droite tu coche "tous les fichiers" et " Rech.rootkit au dem. de la recherche" puis met ok

    une fois antivir installé et CONFIGURER lance un scan de ton PC et supprime tout ce qu'il trouve et poste le rapport
    0
    1. evyndar
       
      j'ai désinstallé e trust par contre j'ai garder avast car ce n'est pas mon ordi et je préfère laisser la personne concernée faire son choix.
      0
  11. plopus Messages postés 49 Date d'inscription   Statut Contributeur sécurité Dernière intervention   293
     
    ok je comprends donc après desinstallation de etrust tu as redemarré ton PC ?

    si non fait le, puis après fait CCleaner comme expliqué + haut

    et fait un scan en ligne ici et poste le rapport
    http://www.bitdefender.fr/scan_fr/scan8/ie.html

    ou si sa ne marche pas ici
    https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
    0
    1. evyndar
       
      BitDefender Online Scanner



      Rapport d'analyse généré à: Mon, Feb 02, 2009 - 18:30:56





      Voie d'analyse: C:\;D:\;E:\;F:\;G:\;







      Statistiques

      Temps
      00:26:21

      Fichiers
      47900

      Directoires
      4677

      Secteurs de boot
      0

      Archives
      1065

      Paquets programmes
      2608




      Résultats

      Virus identifiés
      7

      Fichiers infectés
      41

      Fichiers suspects
      0

      Avertissements
      0

      Désinfectés
      0

      Fichiers effacés
      41




      Info sur les moteurs

      Définition virus
      2638759

      Version des moteurs
      AVCORE v1.7 (build 8314.19) (i386) (Sep 29 2008 17:19:14)

      Analyse des plugins
      17

      Archive des plugins
      45

      Unpack des plugins
      7

      E-mail plugins
      6

      Système plugins
      4




      Paramètres d'analyse

      Première action
      Désinfecté

      Seconde Action
      Supprimé

      Heuristique
      Oui

      Acceptez les avertissements
      Oui

      Extensions analysées
      exe;com;dll;ocx;scr;bin;dat;386;vxd;sys;wdm;cla;class;ovl;ole;hlp;doc;dot;xls;ppt;wbk;wiz;pot;ppa;xla;xlt;vbs;vbe;mdb;rtf;htm;hta;html;xml;xtp;php;asp;js;shs;chm;lnk;pif;prc;url;smm;pfd;msi;ini;csc;cmd;bas;

      Excludez les extensions


      Analyse d'emails
      Oui

      Analyse des Archives
      Oui

      Analyser paquets programmes
      Oui

      Analyse des fichiers
      Oui

      Analyse de boot
      Oui




      Fichier analysé
      Statut

      C:\0xf9.exe
      Infecté par: BehavesLike:Trojan.TaskDisabler

      C:\0xf9.exe
      Echec de la désinfection

      C:\0xf9.exe
      Supprimé

      C:\Documents and Settings\All Users\Application Data\Microsoft\Network\DLLs\lfqjbkpyze.dll
      Infecté par: Rootkit.12603

      C:\Documents and Settings\All Users\Application Data\Microsoft\Network\DLLs\lfqjbkpyze.dll
      Supprimé

      C:\Documents and Settings\All Users\Application Data\Microsoft\Network\svchost.exe
      Infecté par: Rootkit.12568

      C:\Documents and Settings\All Users\Application Data\Microsoft\Network\svchost.exe
      Supprimé

      C:\System Volume Information\_restore{7A7830DC-AA84-41CB-A0E7-270655EB3CFB}\RP102\A0035011.dll
      Infecté par: Rootkit.12626

      C:\System Volume Information\_restore{7A7830DC-AA84-41CB-A0E7-270655EB3CFB}\RP102\A0035011.dll
      Supprimé

      C:\System Volume Information\_restore{7A7830DC-AA84-41CB-A0E7-270655EB3CFB}\RP102\A0035016.exe
      Infecté par: Rootkit.12440

      C:\System Volume Information\_restore{7A7830DC-AA84-41CB-A0E7-270655EB3CFB}\RP102\A0035016.exe
      Supprimé

      C:\System Volume Information\_restore{7A7830DC-AA84-41CB-A0E7-270655EB3CFB}\RP102\A0035038.dll
      Infecté par: Rootkit.12626

      C:\System Volume Information\_restore{7A7830DC-AA84-41CB-A0E7-270655EB3CFB}\RP102\A0035038.dll
      Supprimé

      C:\System Volume Information\_restore{7A7830DC-AA84-41CB-A0E7-270655EB3CFB}\RP103\A0036142.dll
      Infecté par: Rootkit.12626

      C:\System Volume Information\_restore{7A7830DC-AA84-41CB-A0E7-270655EB3CFB}\RP103\A0036142.dll
      Supprimé

      C:\System Volume Information\_restore{7A7830DC-AA84-41CB-A0E7-270655EB3CFB}\RP103\A0036179.dll
      Infecté par: Rootkit.12626

      C:\System Volume Information\_restore{7A7830DC-AA84-41CB-A0E7-270655EB3CFB}\RP103\A0036179.dll
      Supprimé

      C:\System Volume Information\_restore{7A7830DC-AA84-41CB-A0E7-270655EB3CFB}\RP103\A0036200.dll
      Infecté par: Rootkit.12626

      C:\System Volume Information\_restore{7A7830DC-AA84-41CB-A0E7-270655EB3CFB}\RP103\A0036200.dll
      Supprimé

      C:\System Volume Information\_restore{7A7830DC-AA84-41CB-A0E7-270655EB3CFB}\RP103\A0036227.dll
      Infecté par: Rootkit.12626

      C:\System Volume Information\_restore{7A7830DC-AA84-41CB-A0E7-270655EB3CFB}\RP103\A0036227.dll
      Supprimé

      C:\System Volume Information\_restore{7A7830DC-AA84-41CB-A0E7-270655EB3CFB}\RP103\A0036247.dll
      Infecté par: Rootkit.12626

      C:\System Volume Information\_restore{7A7830DC-AA84-41CB-A0E7-270655EB3CFB}\RP103\A0036247.dll
      Supprimé

      C:\System Volume Information\_restore{7A7830DC-AA84-41CB-A0E7-270655EB3CFB}\RP103\A0036268.dll
      Infecté par: Rootkit.12626

      C:\System Volume Information\_restore{7A7830DC-AA84-41CB-A0E7-270655EB3CFB}\RP103\A0036268.dll
      Supprimé

      C:\System Volume Information\_restore{7A7830DC-AA84-41CB-A0E7-270655EB3CFB}\RP103\A0036297.dll
      Infecté par: Rootkit.12626

      C:\System Volume Information\_restore{7A7830DC-AA84-41CB-A0E7-270655EB3CFB}\RP103\A0036297.dll
      Supprimé

      C:\System Volume Information\_restore{7A7830DC-AA84-41CB-A0E7-270655EB3CFB}\RP103\A0037296.dll
      Infecté par: Rootkit.12626

      C:\System Volume Information\_restore{7A7830DC-AA84-41CB-A0E7-270655EB3CFB}\RP103\A0037296.dll
      Supprimé

      C:\System Volume Information\_restore{7A7830DC-AA84-41CB-A0E7-270655EB3CFB}\RP103\A0037322.dll
      Infecté par: Rootkit.12626

      C:\System Volume Information\_restore{7A7830DC-AA84-41CB-A0E7-270655EB3CFB}\RP103\A0037322.dll
      Supprimé

      C:\System Volume Information\_restore{7A7830DC-AA84-41CB-A0E7-270655EB3CFB}\RP103\A0037347.dll
      Infecté par: Rootkit.12626

      C:\System Volume Information\_restore{7A7830DC-AA84-41CB-A0E7-270655EB3CFB}\RP103\A0037347.dll
      Supprimé

      C:\System Volume Information\_restore{7A7830DC-AA84-41CB-A0E7-270655EB3CFB}\RP104\A0037368.dll
      Infecté par: Rootkit.12626

      C:\System Volume Information\_restore{7A7830DC-AA84-41CB-A0E7-270655EB3CFB}\RP104\A0037368.dll
      Supprimé

      C:\System Volume Information\_restore{7A7830DC-AA84-41CB-A0E7-270655EB3CFB}\RP104\A0037388.dll
      Infecté par: Rootkit.12626

      C:\System Volume Information\_restore{7A7830DC-AA84-41CB-A0E7-270655EB3CFB}\RP104\A0037388.dll
      Supprimé

      C:\System Volume Information\_restore{7A7830DC-AA84-41CB-A0E7-270655EB3CFB}\RP104\A0037406.dll
      Infecté par: Rootkit.12626

      C:\System Volume Information\_restore{7A7830DC-AA84-41CB-A0E7-270655EB3CFB}\RP104\A0037406.dll
      Supprimé

      C:\System Volume Information\_restore{7A7830DC-AA84-41CB-A0E7-270655EB3CFB}\RP104\A0037422.dll
      Infecté par: Rootkit.12626

      C:\System Volume Information\_restore{7A7830DC-AA84-41CB-A0E7-270655EB3CFB}\RP104\A0037422.dll
      Supprimé

      C:\System Volume Information\_restore{7A7830DC-AA84-41CB-A0E7-270655EB3CFB}\RP104\A0037442.dll
      Infecté par: Rootkit.12626

      C:\System Volume Information\_restore{7A7830DC-AA84-41CB-A0E7-270655EB3CFB}\RP104\A0037442.dll
      Supprimé

      C:\System Volume Information\_restore{7A7830DC-AA84-41CB-A0E7-270655EB3CFB}\RP104\A0037464.dll
      Infecté par: Rootkit.12626

      C:\System Volume Information\_restore{7A7830DC-AA84-41CB-A0E7-270655EB3CFB}\RP104\A0037464.dll
      Supprimé

      C:\System Volume Information\_restore{7A7830DC-AA84-41CB-A0E7-270655EB3CFB}\RP104\A0037480.exe
      Infecté par: Rootkit.12423

      C:\System Volume Information\_restore{7A7830DC-AA84-41CB-A0E7-270655EB3CFB}\RP104\A0037480.exe
      Supprimé

      C:\System Volume Information\_restore{7A7830DC-AA84-41CB-A0E7-270655EB3CFB}\RP104\A0037491.dll
      Infecté par: Rootkit.12626

      C:\System Volume Information\_restore{7A7830DC-AA84-41CB-A0E7-270655EB3CFB}\RP104\A0037491.dll
      Supprimé

      C:\System Volume Information\_restore{7A7830DC-AA84-41CB-A0E7-270655EB3CFB}\RP104\A0037512.dll
      Infecté par: Rootkit.12626

      C:\System Volume Information\_restore{7A7830DC-AA84-41CB-A0E7-270655EB3CFB}\RP104\A0037512.dll
      Supprimé

      C:\System Volume Information\_restore{7A7830DC-AA84-41CB-A0E7-270655EB3CFB}\RP104\A0037531.dll
      Infecté par: Rootkit.12626

      C:\System Volume Information\_restore{7A7830DC-AA84-41CB-A0E7-270655EB3CFB}\RP104\A0037531.dll
      Supprimé

      C:\System Volume Information\_restore{7A7830DC-AA84-41CB-A0E7-270655EB3CFB}\RP104\A0037553.dll
      Infecté par: Rootkit.12626

      C:\System Volume Information\_restore{7A7830DC-AA84-41CB-A0E7-270655EB3CFB}\RP104\A0037553.dll
      Supprimé

      C:\System Volume Information\_restore{7A7830DC-AA84-41CB-A0E7-270655EB3CFB}\RP104\A0037573.dll
      Infecté par: Rootkit.12626

      C:\System Volume Information\_restore{7A7830DC-AA84-41CB-A0E7-270655EB3CFB}\RP104\A0037573.dll
      Supprimé

      C:\System Volume Information\_restore{7A7830DC-AA84-41CB-A0E7-270655EB3CFB}\RP104\A0037589.dll
      Infecté par: Rootkit.12626

      C:\System Volume Information\_restore{7A7830DC-AA84-41CB-A0E7-270655EB3CFB}\RP104\A0037589.dll
      Supprimé

      C:\System Volume Information\_restore{7A7830DC-AA84-41CB-A0E7-270655EB3CFB}\RP104\A0038627.dll
      Infecté par: Rootkit.12626

      C:\System Volume Information\_restore{7A7830DC-AA84-41CB-A0E7-270655EB3CFB}\RP104\A0038627.dll
      Supprimé

      C:\System Volume Information\_restore{7A7830DC-AA84-41CB-A0E7-270655EB3CFB}\RP104\A0038647.dll
      Infecté par: Rootkit.12626

      C:\System Volume Information\_restore{7A7830DC-AA84-41CB-A0E7-270655EB3CFB}\RP104\A0038647.dll
      Supprimé

      C:\System Volume Information\_restore{7A7830DC-AA84-41CB-A0E7-270655EB3CFB}\RP104\A0038691.dll
      Infecté par: Rootkit.12626

      C:\System Volume Information\_restore{7A7830DC-AA84-41CB-A0E7-270655EB3CFB}\RP104\A0038691.dll
      Supprimé

      C:\System Volume Information\_restore{7A7830DC-AA84-41CB-A0E7-270655EB3CFB}\RP104\A0038707.dll
      Infecté par: Rootkit.12626

      C:\System Volume Information\_restore{7A7830DC-AA84-41CB-A0E7-270655EB3CFB}\RP104\A0038707.dll
      Supprimé

      C:\System Volume Information\_restore{7A7830DC-AA84-41CB-A0E7-270655EB3CFB}\RP104\A0038727.dll
      Infecté par: Rootkit.12626

      C:\System Volume Information\_restore{7A7830DC-AA84-41CB-A0E7-270655EB3CFB}\RP104\A0038727.dll
      Supprimé

      C:\System Volume Information\_restore{7A7830DC-AA84-41CB-A0E7-270655EB3CFB}\RP104\A0038783.dll
      Infecté par: Rootkit.12626

      C:\System Volume Information\_restore{7A7830DC-AA84-41CB-A0E7-270655EB3CFB}\RP104\A0038783.dll
      Supprimé

      C:\System Volume Information\_restore{7A7830DC-AA84-41CB-A0E7-270655EB3CFB}\RP104\A0038803.dll
      Infecté par: Rootkit.12626

      C:\System Volume Information\_restore{7A7830DC-AA84-41CB-A0E7-270655EB3CFB}\RP104\A0038803.dll
      Supprimé

      C:\System Volume Information\_restore{7A7830DC-AA84-41CB-A0E7-270655EB3CFB}\RP104\A0039082.dll
      Infecté par: Rootkit.12626

      C:\System Volume Information\_restore{7A7830DC-AA84-41CB-A0E7-270655EB3CFB}\RP104\A0039082.dll
      Supprimé

      C:\System Volume Information\_restore{7A7830DC-AA84-41CB-A0E7-270655EB3CFB}\RP105\A0041220.exe
      Infecté par: BehavesLike:Trojan.TaskDisabler

      C:\System Volume Information\_restore{7A7830DC-AA84-41CB-A0E7-270655EB3CFB}\RP105\A0041220.exe
      Echec de la désinfection

      C:\System Volume Information\_restore{7A7830DC-AA84-41CB-A0E7-270655EB3CFB}\RP105\A0041220.exe
      Supprimé

      C:\System Volume Information\_restore{7A7830DC-AA84-41CB-A0E7-270655EB3CFB}\RP105\A0041221.dll
      Infecté par: Rootkit.12603

      C:\System Volume Information\_restore{7A7830DC-AA84-41CB-A0E7-270655EB3CFB}\RP105\A0041221.dll
      Supprimé

      C:\System Volume Information\_restore{7A7830DC-AA84-41CB-A0E7-270655EB3CFB}\RP105\A0041222.exe
      Infecté par: Rootkit.12568

      C:\System Volume Information\_restore{7A7830DC-AA84-41CB-A0E7-270655EB3CFB}\RP105\A0041222.exe
      Supprimé

      C:\_OTMoveIt\MovedFiles\02012009_201317\Program Files\System Guard 2009\systemguard.exe
      Infecté par: Trojan.FakeAlert.AKV

      C:\_OTMoveIt\MovedFiles\02012009_201317\Program Files\System Guard 2009\systemguard.exe
      Echec de la désinfection

      C:\_OTMoveIt\MovedFiles\02012009_201317\Program Files\System Guard 2009\systemguard.exe
      Supprimé
      0
  12. plopus Messages postés 49 Date d'inscription   Statut Contributeur sécurité Dernière intervention   293
     
    reposte un rapport RSIT

    le PC va mieux ? tu as encore des problemes, si oui lesquels ?
    0
    1. evyndar
       
      Oui le pc va beaucoup mieux je ne vois plus de prolème apparement

      Logfile of random's system information tool 1.05 (written by random/random)
      Run by ekere at 2009-02-02 21:16:47
      Microsoft Windows XP Édition familiale Service Pack 3
      System drive C: has 11 GB (37%) free of 29 GB
      Total RAM: 503 MB (63% free)

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 21:16:51, on 02/02/2009
      Platform: Windows XP SP3 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\System32\wltrysvc.exe
      C:\WINDOWS\System32\bcmwltry.exe
      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      C:\Program Files\Alwil Software\Avast4\ashServ.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\AGRSMMSG.exe
      C:\WINDOWS\system32\hkcmd.exe
      C:\WINDOWS\system32\igfxpers.exe
      C:\WINDOWS\system32\wltray.exe
      C:\WINDOWS\vVX6000.exe
      C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
      C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      C:\WINDOWS\system32\brsvc01a.exe
      C:\WINDOWS\system32\brss01a.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Microsoft LifeCam\MSCamS32.exe
      C:\WINDOWS\system32\svchost.exe
      C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
      C:\WINDOWS\system32\wscntfy.exe
      C:\Documents and Settings\ekere\Bureau\RSIT.exe
      C:\Program Files\Trend Micro\HijackThis\ekere.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
      O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
      O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
      O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
      O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
      O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
      O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
      O4 - HKLM\..\Run: [AntivirusRegistration] C:\Program Files\CA\Etrust Antivirus\Register.exe
      O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
      O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
      O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
      O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
      O4 - HKLM\..\Run: [MGSysCtrl] C:\Program Files\System Control Manager\MGSysCtrl.exe
      O4 - HKLM\..\Run: [wltray.exe] C:\WINDOWS\system32\wltray.exe
      O4 - HKLM\..\Run: [VX6000] C:\WINDOWS\vVX6000.exe
      O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
      O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
      O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
      O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
      O4 - HKLM\..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl05a\BrStDvPt.exe
      O4 - HKLM\..\Run: [ControlCenter2.0] C:\Program Files\Brother\ControlCenter2\brctrcen.exe /autorun
      O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
      O4 - Global Startup: Contrôleur d’état.lnk = C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
      O8 - Extra context menu item: &Recherche AOL Toolbar - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
      O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
      O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?1f59d8c160694a6eb61d1f674c12d5e9
      O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?1f59d8c160694a6eb61d1f674c12d5e9
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_03\bin\npjpi150_03.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_03\bin\npjpi150_03.dll
      O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
      O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
      O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
      O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://copainsdavant.linternaute.com/...
      O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
      O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
      O22 - SharedTaskScheduler: IPC Configuration Utility - IPC Configuration Utility - (no file)
      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
      O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
      0
  13. plopus Messages postés 49 Date d'inscription   Statut Contributeur sécurité Dernière intervention   293
     
    deja relance hijackthis choisit do a scan only et coche les cases a gauche des lignes :

    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
    O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
    O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
    O4 - HKLM\..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl05a\BrStDvPt.exe
    O4 - HKLM\..\Run: [ControlCenter2.0] C:\Program Files\Brother\ControlCenter2\brctrcen.exe /autorun
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - Global Startup: Contrôleur d’état.lnk = C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O22 - SharedTaskScheduler: IPC Configuration Utility - IPC Configuration Utility - (no file)

    puis clic sur fix checked

    ensuite

    Télécharge JavaRa.zip de Paul 'Prm753' McLain et Fred de Vries.

    http://raproducts.org/click/click.php?id=1

    * Décompresse le fichier sur le bureau (clic droit > Extraire tout)
    * Double-cliquer sur le répertoire JavaRa.
    * Puis double-cliquer sur le fichier JavaRa.exe (le exe peut ne pas s'afficher)
    * Clique sur Search For Updates.
    * Sélectionner Update Using jucheck.exe puis cliquer sur Search.
    * Autorise le processus à se connecter s'il le demande, cliquer sur Install et suivre les instructions d'installation qui prennent quelques minutes.
    * L'installation est terminée, revenez à l'écran de JavaRa et clique sur Remove Older Versions.
    * Clique sur Oui pour confirmer. Laisse travailler et cliquez ensuite sur Ok, puis une deuxième fois sur Ok.
    * Un rapport va s'ouvrir à copier-coller dans la prochaine réponse.
    * Fermer l'application

    Note : le rapport se trouve aussi à la racine de la partition système, en général C:\ sous le nom JavaRa.log .

    puis

    MET INTERNET EXPLORER A JOUR la version 7 tres IMPORTANT

    puis

    puis mise a jour de tes logiciel :
    via windows update
    via ce site https://www.flexera.com/products/operations/software-vulnerability-management.html (clic start scan accepte l'active X) et met a jour tous les logiciels avec des croix rouge en desinstallant avant les ancienne versions
    0
  14. plopus Messages postés 49 Date d'inscription   Statut Contributeur sécurité Dernière intervention   293
     
    regarde si tu trouve ce dossier, (il apparait sur ton log ??)
    si tu le vois supprime le, si sa te met accés refusé passe par le mode sans echec

    C:\Program Files\System Guard 2009\

    puis clic ici https://www.virustotal.com/gui/ et clic sur parcourir et va chercher ce fichier te fait le analyser et poste le rapport

    C:\DOCUME~1\ekere\LOCALS~1\Temp\ pinnew.exe
    0
    1. evyndar
       
      tout est ok le dossier system guard n'apparait pas sur le log par contre il est toujours présent dans mes programmes, le fichier pinnew exe je ne l'ai pas trouvé et sinon voici le rapport javara


      JavaRa 1.13 Removal Log.

      Report follows after line.

      ------------------------------------

      The JavaRa removal process was started on Mon Feb 02 21:54:02 2009

      Found and removed: C:\Program Files\Java\jre1.5.0_03

      Found and removed: Software\JavaSoft\Java2D\1.5.0_03

      Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0003-ABCDEFFEDCBA}

      Found and removed: SOFTWARE\Classes\Installer\Features\8A0F842331866D117AB7000B0D510003

      Found and removed: SOFTWARE\Classes\Installer\Products\8A0F842331866D117AB7000B0D510003

      Found and removed: SOFTWARE\Classes\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D510003

      Found and removed: SOFTWARE\Classes\JavaPlugin.150_03

      Found and removed: SOFTWARE\Classes\JavaWebStart.isInstalled.1.5.0.0

      Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.5.0_03

      Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.5

      Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.5.0_03

      Found and removed: SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0015-0000-0003-ABCDEFFEDCBA}

      Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACBB9B2318A96D117A58000B0D510003

      Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F842331866D117AB7000B0D510003

      Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3248F0A8-6813-11D6-A77B-00B0D0150030}

      Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.5.0_03

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA}

      Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1

      Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_02

      Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_03

      Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_04

      Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2

      Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2.0_01

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBA}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBB}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBA}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBB}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBA}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBB}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBA}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBB}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBA}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBB}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBA}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBB}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBA}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBB}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBA}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBB}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBA}

      Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBB}

      Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.5.0_03\

      ------------------------------------

      Finished reporting.
      0
  15. plopus Messages postés 49 Date d'inscription   Statut Contributeur sécurité Dernière intervention   293
     
    Bon ok si tu as + de probleme alors :

    tu peut passer Toolscleaner pour nettoyer les outils que tu as telecharge
    http://www.commentcamarche.net/telecharger/telecharger 34055291 toolscleaner
    clik sur recherche laisse le scanner ton pc et après clik sur suppression et poste le rapport

    ensuite tu purgera ta restauration systeme à l'aide sa : http://www.sophos.fr/support/knowledgebase/article/10386.html
    puis creer un nouveau point de restauration avec sa : http://www.commentcamarche.net/faq/sujet 740 windows points de restauration

    et met ton sujet en resolu
    0
    1. evyndar
       
      Merci beaucoup pour l'aide et les indications qui étaient très bien expliquées. Bonne journée. Voici le rapport:


      [ Rapport ToolsCleaner version 2.3.0 (par A.Rothstein & dj QUIOU) ]

      -->- Recherche:

      C:\_OtMoveIt: trouvé !
      C:\Rsit: trouvé !
      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis: trouvé !
      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis\HijackThis.lnk: trouvé !
      C:\Documents and Settings\ekere\Bureau\pouelle\HijackThis.lnk: trouvé !
      C:\Documents and Settings\ekere\Bureau\pouelle\GenProc.zip: trouvé !
      C:\Documents and Settings\ekere\Bureau\pouelle\ComboFix.exe: trouvé !
      C:\Documents and Settings\ekere\Bureau\pouelle\HJTInstall.exe: trouvé !
      C:\Documents and Settings\ekere\Bureau\pouelle\hijackthis.log: trouvé !
      C:\Documents and Settings\ekere\Bureau\pouelle\OTMoveIt3.exe: trouvé !
      C:\Documents and Settings\ekere\Bureau\pouelle\Rsit.exe: trouvé !
      C:\Documents and Settings\ekere\Bureau\pouelle\gen\GenProc: trouvé !
      C:\Documents and Settings\ekere\Bureau\pouelle\gen\GenProc\Page\GenProc[*].html: trouvé !
      C:\Program Files\Trend Micro\HijackThis: trouvé !
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: trouvé !
      C:\Program Files\Trend Micro\HijackThis\hijackthis.log: trouvé !

      ---------------------------------
      -->- Suppression:

      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis\HijackThis.lnk: supprimé !
      C:\Documents and Settings\ekere\Bureau\pouelle\HijackThis.lnk: supprimé !
      C:\Documents and Settings\ekere\Bureau\pouelle\GenProc.zip: supprimé !
      C:\Documents and Settings\ekere\Bureau\pouelle\ComboFix.exe: supprimé !
      C:\Documents and Settings\ekere\Bureau\pouelle\HJTInstall.exe: supprimé !
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: supprimé !
      C:\Documents and Settings\ekere\Bureau\pouelle\hijackthis.log: supprimé !
      C:\Documents and Settings\ekere\Bureau\pouelle\OTMoveIt3.exe: supprimé !
      C:\Documents and Settings\ekere\Bureau\pouelle\Rsit.exe: supprimé !
      C:\Documents and Settings\ekere\Bureau\pouelle\gen\GenProc\Page\GenProc[*].html: ERREUR DE SUPPRESSION !!
      C:\Program Files\Trend Micro\HijackThis\hijackthis.log: supprimé !
      C:\_OtMoveIt: supprimé !
      C:\Rsit: supprimé !
      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis: supprimé !
      C:\Documents and Settings\ekere\Bureau\pouelle\gen\GenProc: supprimé !
      C:\Program Files\Trend Micro\HijackThis: supprimé !
      0
  16. plopus Messages postés 49 Date d'inscription   Statut Contributeur sécurité Dernière intervention   293
     
    re

    juste une chose

    tu as dit : par contre il est toujours présent dans mes programmes (systeme guard)

    ou sa dans tes programmes ?
    0
    1. evyndar
       
      bonsoir,
      il était dans mes programmes via le menu démarrer, j'ai essayé de le désinstaller mais il ne trouvais pas je l'ai donc supprimé et aucun problème. Par contre je voulais savoir comment on fait pour mettre en résolu je ne sais plus.
      0
  17. plopus Messages postés 49 Date d'inscription   Statut Contributeur sécurité Dernière intervention   293
     
    ok supprime tous les fichiers concernant systemeguard

    ensuite dans ton prochain poste tu met :

    RESOLU

    car si tu n'es pas inscrit je crois que tu peux pas faire sinon sa ce trouve en haut du topic la ou, il y a le nombre de page

    bonne soirée a+
    0
Précédent
  • 1
  • 2