Suis-je infecté ?
aselmare
-
Utilisateur anonyme -
Utilisateur anonyme -
Bonjour,
En arrivant ce matin au boulot, je me suis rendu compte que mon PC était vérolé, et qu'aucun antivirus n'était activé (symantec auparavant). L'informaticien est en vacance pendant 2semaine, et personne n'est capable de me donner un coup de main. Après avoir installer antivir, fait 3 analyses, et un firewall (zone alarm), de nombreux virus sont supprimés. Cependant, mon PC est toujours terriblement lent, les pages web ne fonctionnent presque pas (j’ai l’impression que ca provient des applet flash), elle s’affichent en format texte, sans images. Ou lorsque je click sur un lien, il me met a la place du lien demander : http://windowsclick.com/go.php? …….
J’ai donc suivit la procedure suivante : http://www.commentcamarche.net/faq/sujet 3174 virus methode preliminaire de desinfection version fr
Je mets ci-dessous les trois rapports, pouvez vous me dire si mon PC est encore infecté
Merci a tous
PS : après avoir lancé CCcleaner, le PC ma semblé bcp plus « rapide ».
PS2 : je n’ai pas réussit à faire de maj pour AVG (probablement dernière version téléchargée)
PS3 : impossible de faire le scan online de bitdefender, erreur. J’ai téléchargé la version d’évaluation, et effectué le scan
---------------------------------------------------------
AVG Anti-Spyware - Rapport d'analyse
---------------------------------------------------------
+ Créé à: 09:58:02 23/02/2009
+ Résultat de l'analyse:
:mozilla.394:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.247realmedia : Aucune action entreprise.
:mozilla.395:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.247realmedia : Aucune action entreprise.
:mozilla.116:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.2o7 : Aucune action entreprise.
:mozilla.117:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.2o7 : Aucune action entreprise.
:mozilla.118:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.2o7 : Aucune action entreprise.
:mozilla.119:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.2o7 : Aucune action entreprise.
:mozilla.121:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.2o7 : Aucune action entreprise.
:mozilla.123:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.2o7 : Aucune action entreprise.
:mozilla.216:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.2o7 : Aucune action entreprise.
:mozilla.273:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.2o7 : Aucune action entreprise.
:mozilla.376:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.2o7 : Aucune action entreprise.
:mozilla.488:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.2o7 : Aucune action entreprise.
:mozilla.120:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Adtech : Aucune action entreprise.
:mozilla.122:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Adtech : Aucune action entreprise.
:mozilla.112:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Advertising : Aucune action entreprise.
:mozilla.113:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Advertising : Aucune action entreprise.
:mozilla.114:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Advertising : Aucune action entreprise.
:mozilla.115:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Advertising : Aucune action entreprise.
:mozilla.124:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Advertising : Aucune action entreprise.
:mozilla.140:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Atdmt : Aucune action entreprise.
:mozilla.148:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Bluestreak : Aucune action entreprise.
:mozilla.531:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Casalemedia : Aucune action entreprise.
:mozilla.125:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Comclick : Aucune action entreprise.
:mozilla.126:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Comclick : Aucune action entreprise.
:mozilla.127:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Comclick : Aucune action entreprise.
:mozilla.62:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Doubleclick : Aucune action entreprise.
:mozilla.195:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Estat : Aucune action entreprise.
:mozilla.448:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Euroclick : Aucune action entreprise.
:mozilla.289:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Fastclick : Aucune action entreprise.
:mozilla.290:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Fastclick : Aucune action entreprise.
:mozilla.213:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Hitbox : Aucune action entreprise.
:mozilla.214:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Hitbox : Aucune action entreprise.
:mozilla.315:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Hitbox : Aucune action entreprise.
:mozilla.384:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Hitslink : Aucune action entreprise.
:mozilla.63:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Imrworldwide : Aucune action entreprise.
:mozilla.64:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Imrworldwide : Aucune action entreprise.
:mozilla.458:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Information : Aucune action entreprise.
:mozilla.535:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Ivwbox : Aucune action entreprise.
:mozilla.68:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Liveperson : Aucune action entreprise.
:mozilla.69:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Liveperson : Aucune action entreprise.
:mozilla.70:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Liveperson : Aucune action entreprise.
:mozilla.91:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Mediaplex : Aucune action entreprise.
:mozilla.649:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Onestat : Aucune action entreprise.
:mozilla.650:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Onestat : Aucune action entreprise.
:mozilla.197:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Overture : Aucune action entreprise.
:mozilla.400:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Paypal : Aucune action entreprise.
:mozilla.451:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Pointroll : Aucune action entreprise.
:mozilla.452:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Pointroll : Aucune action entreprise.
:mozilla.453:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Pointroll : Aucune action entreprise.
:mozilla.454:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Pointroll : Aucune action entreprise.
:mozilla.455:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Pointroll : Aucune action entreprise.
:mozilla.456:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Pointroll : Aucune action entreprise.
:mozilla.457:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Pointroll : Aucune action entreprise.
:mozilla.392:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Realmedia : Aucune action entreprise.
:mozilla.141:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Serving-sys : Aucune action entreprise.
:mozilla.142:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Serving-sys : Aucune action entreprise.
:mozilla.143:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Serving-sys : Aucune action entreprise.
:mozilla.144:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Serving-sys : Aucune action entreprise.
:mozilla.145:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Serving-sys : Aucune action entreprise.
:mozilla.146:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Serving-sys : Aucune action entreprise.
:mozilla.147:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Serving-sys : Aucune action entreprise.
:mozilla.168:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Smartadserver : Aucune action entreprise.
:mozilla.169:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Smartadserver : Aucune action entreprise.
:mozilla.170:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Smartadserver : Aucune action entreprise.
:mozilla.171:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Smartadserver : Aucune action entreprise.
:mozilla.175:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Smartadserver : Aucune action entreprise.
:mozilla.176:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Smartadserver : Aucune action entreprise.
:mozilla.335:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Specificclick : Aucune action entreprise.
:mozilla.337:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Specificclick : Aucune action entreprise.
:mozilla.338:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Specificclick : Aucune action entreprise.
:mozilla.339:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Specificclick : Aucune action entreprise.
:mozilla.21:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Statcounter : Aucune action entreprise.
:mozilla.26:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Statcounter : Aucune action entreprise.
:mozilla.27:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Statcounter : Aucune action entreprise.
:mozilla.28:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Statcounter : Aucune action entreprise.
:mozilla.29:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Statcounter : Aucune action entreprise.
:mozilla.30:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Statcounter : Aucune action entreprise.
:mozilla.76:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Tacoda : Aucune action entreprise.
:mozilla.77:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Tacoda : Aucune action entreprise.
:mozilla.79:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Tacoda : Aucune action entreprise.
:mozilla.80:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Tacoda : Aucune action entreprise.
:mozilla.81:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Tacoda : Aucune action entreprise.
:mozilla.57:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Tradedoubler : Aucune action entreprise.
:mozilla.58:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Tradedoubler : Aucune action entreprise.
:mozilla.59:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Tradedoubler : Aucune action entreprise.
:mozilla.60:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Tradedoubler : Aucune action entreprise.
:mozilla.61:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Tradedoubler : Aucune action entreprise.
:mozilla.510:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Trafficmp : Aucune action entreprise.
:mozilla.511:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Trafficmp : Aucune action entreprise.
:mozilla.291:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Tribalfusion : Aucune action entreprise.
:mozilla.102:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Weborama : Aucune action entreprise.
:mozilla.103:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Weborama : Aucune action entreprise.
:mozilla.259:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Webtrends : Aucune action entreprise.
:mozilla.336:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Webtrendslive : Aucune action entreprise.
:mozilla.44:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Yieldmanager : Aucune action entreprise.
:mozilla.45:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Yieldmanager : Aucune action entreprise.
:mozilla.46:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Yieldmanager : Aucune action entreprise.
:mozilla.47:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Yieldmanager : Aucune action entreprise.
:mozilla.48:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Yieldmanager : Aucune action entreprise.
:mozilla.49:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Yieldmanager : Aucune action entreprise.
:mozilla.50:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Yieldmanager : Aucune action entreprise.
Fin du rapport
BitDefender - Fichier journal
Produit : BitDefender Total Security 2009
Version : BitDefender UIScanner v.12
Tâche d'analyse : Analyse complète
Date du journal : 11:05:04 23/02/2009
Chemin du journal : C:\Documents and Settings\All Users\Application Data\BitDefender\Desktop\Profiles\Logs\full_scan\1235383504_1_02.xml
Analyse des chemins :
Chemin 0000: C:\
Options d’analyse :
Détecter les virus : Oui
Détecter les adwares : Oui
Détecter les spywares : Oui
Analyser les applications : Oui
Détecter les dialers : Oui
Détecter les rootkits : Oui
Options de sélection de cible :
Analyser les clés du registre : Oui
Analyser les cookies : Oui
Analyser les secteurs de boot : Oui
Analyser les processus mémoire : Oui
Analyser les archives : Non
Analyser les fichiers enpaquetés : Oui
Analyser les e-mails : Non
Analyser tous les fichiers : Oui
Analyse heuristique : Oui
Extensions analysées :
Extensions exclues :
Traitement de la cible :
Action par défaut pour les objets infectés : Désinfecter
Action par défaut pour les objets suspects : Aucune
Action par défaut pour les objets camouflés : Aucune
Résumé de l'analyse
Nombre de signatures de virus : 2680880
Plugins archives : 45
Plugins e-mail : 6
Plugins d'analyse : 13
Plugins système : 5
Plugins de décompression : 7
Résumé de l'analyse générale
Eléments analysés : 58248
Eléments infectés : 12
Eléments suspects : 0
Eléments résolus : 7
Éléments non résolus : 5
Eléments protégés par mot de passe : 0
Virus individuels trouvés : 6
Répertoires analysés : 4296
Secteur de boot analysés : 3
Archives analysés : 3
Erreurs I/O : 31
Temps d'analyse : 00:33:19
Fichiers par seconde : 28
Résumé des processus analysés
Analysé : 40
Infecté : 0
Résumé des clés de registre analysées
Analysé : 857
Infecté : 0
Résumé des cookies analysés
Analysé : 857
Infecté : 0
Problèmes non résolus :
Nom de l'objet Nom de la menace État final
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\04980000.VBN=](Quarantine-PE) Backdoor.Bot.18029 Aucune action possible
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\04A00000.VBN=](Quarantine-PE) Backdoor.Bot.18029 Aucune action possible
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\04A40000.VBN=](Quarantine-PE) Backdoor.Bot.18029 Aucune action possible
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\04500002.VBN=](Quarantine-PE) Rootkit.Agent.AIUL Aucune action possible
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\04480000.VBN=](Quarantine-PE) Trojan.Downloader.JLQS Aucune action possible
Problèmes résolus
Nom de l'objet Nom de la menace État final
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\04600000.VBN=](Quarantine-PE) Backdoor.Bot.18029 Supprimé
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\047C0000.VBN=](Quarantine-PE) Rootkit.Agent.AIUL Supprimé
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\04800000.VBN=](Quarantine-PE) Rootkit.Agent.AIUL Supprimé
C:\Documents and Settings\Alexis\Local Settings\Temp\9874.tmp Trojan.Generic.1444242 Supprimé
C:\System Volume Information\_restore{340C3340-2EBB-4324-859A-C37E85627171}\RP237\A0014859.exe Trojan.Generic.296792 Supprimé
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\044C0001.VBN=](Quarantine-PE) Trojan.TDss.AU Supprimé
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\044C0002.VBN=](Quarantine-PE) Trojan.TDss.AU Supprimé
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:06:03, on 23/02/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Intel\ASF Agent\ASFAgent.exe
C:\Program Files\AskBarDis\bar\bin\AskService.exe
C:\Program Files\Intel\AMT\atchksrv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Program Files\Intel\AMT\LMS.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\Program Files\Intel\AMT\UNS.exe
C:\Program Files\BitDefender\BitDefender 2009\seccenter.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Intel\AMT\atchk.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\All Users\Application Data\Macrovision\FLEXnet Connect\6\ISUSPM.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
C:\Program Files\BitDefender\BitDefender 2009\uiscan.exe
C:\Program Files\BitDefender\BitDefender 2009\uiscan.exe
C:\Program Files\Microsoft Office\Office12\WINWORD.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.fr/ig/dell?hl=fr&client=dell-row-rel&channel=fr&ibd=3071214
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.speedbit.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.fr/ig/dell?hl=fr&client=dell-row-rel&channel=fr&ibd=3071214
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = https://www.dell.com/fr-fr?c=fr&l=fr&s=gen&redirect=1
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = ftp://neurochem.u-strasbg.fr/pub/transfert/Alexis/review.pdf
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\drivers\services.exe
O1 - Hosts: 195.245.119.131 browser-security.microsoft.com
O1 - Hosts: 195.245.119.131 browser-security.microsoft.com
O2 - BHO: C:\WINDOWS\system32\hsari3jndsbfi73.dll - {D5BF4552-94F1-42BD-F434-3604812C807D} - C:\WINDOWS\system32\hsari3jndsbfi73.dll
O3 - Toolbar: ZoneAlarm Spy Blocker Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2009\IEToolbar.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [atchk] "C:\Program Files\Intel\AMT\atchk.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe"
O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2009\IEShow.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ISUSPM] "C:\Documents and Settings\All Users\Application Data\Macrovision\FLEXnet Connect\6\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...
O17 - HKLM\System\CCS\Services\Tcpip\..\{C511F928-EA3C-451F-81B2-79FBF2E8302F}: Domain = u-strasbg.fr
O17 - HKLM\System\CCS\Services\Tcpip\..\{C511F928-EA3C-451F-81B2-79FBF2E8302F}: NameServer = 130.79.200.200
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = u-strasbg.fr
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = u-strasbg.fr
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = u-strasbg.fr
O20 - Winlogon Notify: crypt - crypts.dll (file missing)
O22 - SharedTaskScheduler: erajhsf8743kjrngjnf - {D5BF4552-94F1-42BD-F434-3604812C807D} - C:\WINDOWS\system32\hsari3jndsbfi73.dll
O23 - Service: Planificateur Avira AntiVir Personal - Free Antivirus (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: BitDefender Arrakis Server (Arrakis3) - BitDefender S.R.L. https://www.bitdefender.fr/ - C:\Program Files\Fichiers communs\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe
O23 - Service: ASF Agent (ASFAgent) - Intel Corporation - C:\Program Files\Intel\ASF Agent\ASFAgent.exe
O23 - Service: ASKService - Unknown owner - C:\Program Files\AskBarDis\bar\bin\AskService.exe
O23 - Service: Intel(R) Active Management Technology System Status Service (atchksrv) - Intel Corporation - C:\Program Files\Intel\AMT\atchksrv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
O23 - Service: Intel(R) Active Management Technology Local Management Service (LMS) - Intel - C:\Program Files\Intel\AMT\LMS.exe
O23 - Service: LPTRDC server (LPTRDCsrv) - Unknown owner - C:\WINDOWS\ctfmon.exe (file missing)
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: Planificateur de tâches (Schedule) - Unknown owner - C:\WINDOWS\system32\drivers\services.exe (file missing)
O23 - Service: Intel(R) Active Management Technology User Notification Service (UNS) - Intel - C:\Program Files\Intel\AMT\UNS.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S. R. L. - C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
En arrivant ce matin au boulot, je me suis rendu compte que mon PC était vérolé, et qu'aucun antivirus n'était activé (symantec auparavant). L'informaticien est en vacance pendant 2semaine, et personne n'est capable de me donner un coup de main. Après avoir installer antivir, fait 3 analyses, et un firewall (zone alarm), de nombreux virus sont supprimés. Cependant, mon PC est toujours terriblement lent, les pages web ne fonctionnent presque pas (j’ai l’impression que ca provient des applet flash), elle s’affichent en format texte, sans images. Ou lorsque je click sur un lien, il me met a la place du lien demander : http://windowsclick.com/go.php? …….
J’ai donc suivit la procedure suivante : http://www.commentcamarche.net/faq/sujet 3174 virus methode preliminaire de desinfection version fr
Je mets ci-dessous les trois rapports, pouvez vous me dire si mon PC est encore infecté
Merci a tous
PS : après avoir lancé CCcleaner, le PC ma semblé bcp plus « rapide ».
PS2 : je n’ai pas réussit à faire de maj pour AVG (probablement dernière version téléchargée)
PS3 : impossible de faire le scan online de bitdefender, erreur. J’ai téléchargé la version d’évaluation, et effectué le scan
---------------------------------------------------------
AVG Anti-Spyware - Rapport d'analyse
---------------------------------------------------------
+ Créé à: 09:58:02 23/02/2009
+ Résultat de l'analyse:
:mozilla.394:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.247realmedia : Aucune action entreprise.
:mozilla.395:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.247realmedia : Aucune action entreprise.
:mozilla.116:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.2o7 : Aucune action entreprise.
:mozilla.117:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.2o7 : Aucune action entreprise.
:mozilla.118:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.2o7 : Aucune action entreprise.
:mozilla.119:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.2o7 : Aucune action entreprise.
:mozilla.121:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.2o7 : Aucune action entreprise.
:mozilla.123:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.2o7 : Aucune action entreprise.
:mozilla.216:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.2o7 : Aucune action entreprise.
:mozilla.273:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.2o7 : Aucune action entreprise.
:mozilla.376:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.2o7 : Aucune action entreprise.
:mozilla.488:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.2o7 : Aucune action entreprise.
:mozilla.120:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Adtech : Aucune action entreprise.
:mozilla.122:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Adtech : Aucune action entreprise.
:mozilla.112:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Advertising : Aucune action entreprise.
:mozilla.113:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Advertising : Aucune action entreprise.
:mozilla.114:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Advertising : Aucune action entreprise.
:mozilla.115:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Advertising : Aucune action entreprise.
:mozilla.124:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Advertising : Aucune action entreprise.
:mozilla.140:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Atdmt : Aucune action entreprise.
:mozilla.148:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Bluestreak : Aucune action entreprise.
:mozilla.531:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Casalemedia : Aucune action entreprise.
:mozilla.125:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Comclick : Aucune action entreprise.
:mozilla.126:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Comclick : Aucune action entreprise.
:mozilla.127:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Comclick : Aucune action entreprise.
:mozilla.62:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Doubleclick : Aucune action entreprise.
:mozilla.195:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Estat : Aucune action entreprise.
:mozilla.448:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Euroclick : Aucune action entreprise.
:mozilla.289:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Fastclick : Aucune action entreprise.
:mozilla.290:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Fastclick : Aucune action entreprise.
:mozilla.213:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Hitbox : Aucune action entreprise.
:mozilla.214:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Hitbox : Aucune action entreprise.
:mozilla.315:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Hitbox : Aucune action entreprise.
:mozilla.384:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Hitslink : Aucune action entreprise.
:mozilla.63:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Imrworldwide : Aucune action entreprise.
:mozilla.64:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Imrworldwide : Aucune action entreprise.
:mozilla.458:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Information : Aucune action entreprise.
:mozilla.535:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Ivwbox : Aucune action entreprise.
:mozilla.68:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Liveperson : Aucune action entreprise.
:mozilla.69:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Liveperson : Aucune action entreprise.
:mozilla.70:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Liveperson : Aucune action entreprise.
:mozilla.91:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Mediaplex : Aucune action entreprise.
:mozilla.649:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Onestat : Aucune action entreprise.
:mozilla.650:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Onestat : Aucune action entreprise.
:mozilla.197:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Overture : Aucune action entreprise.
:mozilla.400:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Paypal : Aucune action entreprise.
:mozilla.451:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Pointroll : Aucune action entreprise.
:mozilla.452:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Pointroll : Aucune action entreprise.
:mozilla.453:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Pointroll : Aucune action entreprise.
:mozilla.454:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Pointroll : Aucune action entreprise.
:mozilla.455:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Pointroll : Aucune action entreprise.
:mozilla.456:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Pointroll : Aucune action entreprise.
:mozilla.457:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Pointroll : Aucune action entreprise.
:mozilla.392:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Realmedia : Aucune action entreprise.
:mozilla.141:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Serving-sys : Aucune action entreprise.
:mozilla.142:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Serving-sys : Aucune action entreprise.
:mozilla.143:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Serving-sys : Aucune action entreprise.
:mozilla.144:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Serving-sys : Aucune action entreprise.
:mozilla.145:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Serving-sys : Aucune action entreprise.
:mozilla.146:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Serving-sys : Aucune action entreprise.
:mozilla.147:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Serving-sys : Aucune action entreprise.
:mozilla.168:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Smartadserver : Aucune action entreprise.
:mozilla.169:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Smartadserver : Aucune action entreprise.
:mozilla.170:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Smartadserver : Aucune action entreprise.
:mozilla.171:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Smartadserver : Aucune action entreprise.
:mozilla.175:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Smartadserver : Aucune action entreprise.
:mozilla.176:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Smartadserver : Aucune action entreprise.
:mozilla.335:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Specificclick : Aucune action entreprise.
:mozilla.337:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Specificclick : Aucune action entreprise.
:mozilla.338:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Specificclick : Aucune action entreprise.
:mozilla.339:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Specificclick : Aucune action entreprise.
:mozilla.21:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Statcounter : Aucune action entreprise.
:mozilla.26:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Statcounter : Aucune action entreprise.
:mozilla.27:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Statcounter : Aucune action entreprise.
:mozilla.28:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Statcounter : Aucune action entreprise.
:mozilla.29:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Statcounter : Aucune action entreprise.
:mozilla.30:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Statcounter : Aucune action entreprise.
:mozilla.76:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Tacoda : Aucune action entreprise.
:mozilla.77:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Tacoda : Aucune action entreprise.
:mozilla.79:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Tacoda : Aucune action entreprise.
:mozilla.80:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Tacoda : Aucune action entreprise.
:mozilla.81:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Tacoda : Aucune action entreprise.
:mozilla.57:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Tradedoubler : Aucune action entreprise.
:mozilla.58:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Tradedoubler : Aucune action entreprise.
:mozilla.59:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Tradedoubler : Aucune action entreprise.
:mozilla.60:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Tradedoubler : Aucune action entreprise.
:mozilla.61:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Tradedoubler : Aucune action entreprise.
:mozilla.510:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Trafficmp : Aucune action entreprise.
:mozilla.511:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Trafficmp : Aucune action entreprise.
:mozilla.291:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Tribalfusion : Aucune action entreprise.
:mozilla.102:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Weborama : Aucune action entreprise.
:mozilla.103:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Weborama : Aucune action entreprise.
:mozilla.259:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Webtrends : Aucune action entreprise.
:mozilla.336:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Webtrendslive : Aucune action entreprise.
:mozilla.44:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Yieldmanager : Aucune action entreprise.
:mozilla.45:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Yieldmanager : Aucune action entreprise.
:mozilla.46:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Yieldmanager : Aucune action entreprise.
:mozilla.47:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Yieldmanager : Aucune action entreprise.
:mozilla.48:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Yieldmanager : Aucune action entreprise.
:mozilla.49:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Yieldmanager : Aucune action entreprise.
:mozilla.50:C:\WINDOWS\CSC\d4\800001DB -> TrackingCookie.Yieldmanager : Aucune action entreprise.
Fin du rapport
BitDefender - Fichier journal
Produit : BitDefender Total Security 2009
Version : BitDefender UIScanner v.12
Tâche d'analyse : Analyse complète
Date du journal : 11:05:04 23/02/2009
Chemin du journal : C:\Documents and Settings\All Users\Application Data\BitDefender\Desktop\Profiles\Logs\full_scan\1235383504_1_02.xml
Analyse des chemins :
Chemin 0000: C:\
Options d’analyse :
Détecter les virus : Oui
Détecter les adwares : Oui
Détecter les spywares : Oui
Analyser les applications : Oui
Détecter les dialers : Oui
Détecter les rootkits : Oui
Options de sélection de cible :
Analyser les clés du registre : Oui
Analyser les cookies : Oui
Analyser les secteurs de boot : Oui
Analyser les processus mémoire : Oui
Analyser les archives : Non
Analyser les fichiers enpaquetés : Oui
Analyser les e-mails : Non
Analyser tous les fichiers : Oui
Analyse heuristique : Oui
Extensions analysées :
Extensions exclues :
Traitement de la cible :
Action par défaut pour les objets infectés : Désinfecter
Action par défaut pour les objets suspects : Aucune
Action par défaut pour les objets camouflés : Aucune
Résumé de l'analyse
Nombre de signatures de virus : 2680880
Plugins archives : 45
Plugins e-mail : 6
Plugins d'analyse : 13
Plugins système : 5
Plugins de décompression : 7
Résumé de l'analyse générale
Eléments analysés : 58248
Eléments infectés : 12
Eléments suspects : 0
Eléments résolus : 7
Éléments non résolus : 5
Eléments protégés par mot de passe : 0
Virus individuels trouvés : 6
Répertoires analysés : 4296
Secteur de boot analysés : 3
Archives analysés : 3
Erreurs I/O : 31
Temps d'analyse : 00:33:19
Fichiers par seconde : 28
Résumé des processus analysés
Analysé : 40
Infecté : 0
Résumé des clés de registre analysées
Analysé : 857
Infecté : 0
Résumé des cookies analysés
Analysé : 857
Infecté : 0
Problèmes non résolus :
Nom de l'objet Nom de la menace État final
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\04980000.VBN=](Quarantine-PE) Backdoor.Bot.18029 Aucune action possible
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\04A00000.VBN=](Quarantine-PE) Backdoor.Bot.18029 Aucune action possible
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\04A40000.VBN=](Quarantine-PE) Backdoor.Bot.18029 Aucune action possible
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\04500002.VBN=](Quarantine-PE) Rootkit.Agent.AIUL Aucune action possible
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\04480000.VBN=](Quarantine-PE) Trojan.Downloader.JLQS Aucune action possible
Problèmes résolus
Nom de l'objet Nom de la menace État final
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\04600000.VBN=](Quarantine-PE) Backdoor.Bot.18029 Supprimé
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\047C0000.VBN=](Quarantine-PE) Rootkit.Agent.AIUL Supprimé
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\04800000.VBN=](Quarantine-PE) Rootkit.Agent.AIUL Supprimé
C:\Documents and Settings\Alexis\Local Settings\Temp\9874.tmp Trojan.Generic.1444242 Supprimé
C:\System Volume Information\_restore{340C3340-2EBB-4324-859A-C37E85627171}\RP237\A0014859.exe Trojan.Generic.296792 Supprimé
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\044C0001.VBN=](Quarantine-PE) Trojan.TDss.AU Supprimé
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\044C0002.VBN=](Quarantine-PE) Trojan.TDss.AU Supprimé
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:06:03, on 23/02/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Intel\ASF Agent\ASFAgent.exe
C:\Program Files\AskBarDis\bar\bin\AskService.exe
C:\Program Files\Intel\AMT\atchksrv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Program Files\Intel\AMT\LMS.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\Program Files\Intel\AMT\UNS.exe
C:\Program Files\BitDefender\BitDefender 2009\seccenter.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Intel\AMT\atchk.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\All Users\Application Data\Macrovision\FLEXnet Connect\6\ISUSPM.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
C:\Program Files\BitDefender\BitDefender 2009\uiscan.exe
C:\Program Files\BitDefender\BitDefender 2009\uiscan.exe
C:\Program Files\Microsoft Office\Office12\WINWORD.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.fr/ig/dell?hl=fr&client=dell-row-rel&channel=fr&ibd=3071214
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.speedbit.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.fr/ig/dell?hl=fr&client=dell-row-rel&channel=fr&ibd=3071214
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = https://www.dell.com/fr-fr?c=fr&l=fr&s=gen&redirect=1
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = ftp://neurochem.u-strasbg.fr/pub/transfert/Alexis/review.pdf
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\drivers\services.exe
O1 - Hosts: 195.245.119.131 browser-security.microsoft.com
O1 - Hosts: 195.245.119.131 browser-security.microsoft.com
O2 - BHO: C:\WINDOWS\system32\hsari3jndsbfi73.dll - {D5BF4552-94F1-42BD-F434-3604812C807D} - C:\WINDOWS\system32\hsari3jndsbfi73.dll
O3 - Toolbar: ZoneAlarm Spy Blocker Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2009\IEToolbar.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [atchk] "C:\Program Files\Intel\AMT\atchk.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe"
O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2009\IEShow.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ISUSPM] "C:\Documents and Settings\All Users\Application Data\Macrovision\FLEXnet Connect\6\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...
O17 - HKLM\System\CCS\Services\Tcpip\..\{C511F928-EA3C-451F-81B2-79FBF2E8302F}: Domain = u-strasbg.fr
O17 - HKLM\System\CCS\Services\Tcpip\..\{C511F928-EA3C-451F-81B2-79FBF2E8302F}: NameServer = 130.79.200.200
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = u-strasbg.fr
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = u-strasbg.fr
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = u-strasbg.fr
O20 - Winlogon Notify: crypt - crypts.dll (file missing)
O22 - SharedTaskScheduler: erajhsf8743kjrngjnf - {D5BF4552-94F1-42BD-F434-3604812C807D} - C:\WINDOWS\system32\hsari3jndsbfi73.dll
O23 - Service: Planificateur Avira AntiVir Personal - Free Antivirus (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: BitDefender Arrakis Server (Arrakis3) - BitDefender S.R.L. https://www.bitdefender.fr/ - C:\Program Files\Fichiers communs\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe
O23 - Service: ASF Agent (ASFAgent) - Intel Corporation - C:\Program Files\Intel\ASF Agent\ASFAgent.exe
O23 - Service: ASKService - Unknown owner - C:\Program Files\AskBarDis\bar\bin\AskService.exe
O23 - Service: Intel(R) Active Management Technology System Status Service (atchksrv) - Intel Corporation - C:\Program Files\Intel\AMT\atchksrv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
O23 - Service: Intel(R) Active Management Technology Local Management Service (LMS) - Intel - C:\Program Files\Intel\AMT\LMS.exe
O23 - Service: LPTRDC server (LPTRDCsrv) - Unknown owner - C:\WINDOWS\ctfmon.exe (file missing)
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: Planificateur de tâches (Schedule) - Unknown owner - C:\WINDOWS\system32\drivers\services.exe (file missing)
O23 - Service: Intel(R) Active Management Technology User Notification Service (UNS) - Intel - C:\Program Files\Intel\AMT\UNS.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S. R. L. - C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
A voir également:
- Suis-je infecté ?
- Alerte windows ordinateur infecté - Accueil - Arnaque
- L'ordinateur d'arthur a été infecté par un virus répertorié récemment ✓ - Forum Virus
- L'ordinateur de simon a été infecté par un virus répertorié récemment ✓ - Forum Virus
- L'ordinateur de mustapha a été infecté par un virus répertorié récemment - Forum Virus
- Infection par : ONLYPC Flow.co.in ✓ - Forum Virus
32 réponses
Voila
Logfile of random's system information tool 1.05 (written by random/random)
Run by Alexis at 2009-02-25 15:58:48
Microsoft Windows XP Professionnel Service Pack 3
System drive C: has 58 GB (77%) free of 76 GB
Total RAM: 997 MB (23% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:58:58, on 25/02/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Intel\ASF Agent\ASFAgent.exe
C:\Program Files\Intel\AMT\atchksrv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Program Files\Intel\AMT\LMS.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\Program Files\Intel\AMT\UNS.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Intel\AMT\atchk.exe
C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\All Users\Application Data\Macrovision\FLEXnet Connect\6\ISUSPM.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\BitDefender\BitDefender 2009\seccenter.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe
C:\Program Files\Fichiers communs\Adobe\Updater5\AdobeUpdater.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Microsoft Office\Office12\EXCEL.EXE
C:\PROGRA~1\Java\JRE15~1.0_0\bin\javaw.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Alexis\Bureau\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\Alexis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.fr/ig/dell?hl=fr&client=dell-row-rel&channel=fr&ibd=3071214
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.fr/ig/dell?hl=fr&client=dell-row-rel&channel=fr&ibd=3071214
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = https://www.dell.com/fr-fr?c=fr&l=fr&s=gen&redirect=1
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2009\IEToolbar.dll
O4 - HKLM\..\Run: [atchk] "C:\Program Files\Intel\AMT\atchk.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe"
O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2009\IEShow.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ISUSPM] "C:\Documents and Settings\All Users\Application Data\Macrovision\FLEXnet Connect\6\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...
O17 - HKLM\System\CCS\Services\Tcpip\..\{C511F928-EA3C-451F-81B2-79FBF2E8302F}: Domain = u-strasbg.fr
O17 - HKLM\System\CCS\Services\Tcpip\..\{C511F928-EA3C-451F-81B2-79FBF2E8302F}: NameServer = 130.79.200.200
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = u-strasbg.fr
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = u-strasbg.fr
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = u-strasbg.fr
O23 - Service: Planificateur Avira AntiVir Personal - Free Antivirus (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: BitDefender Arrakis Server (Arrakis3) - BitDefender S.R.L. https://www.bitdefender.fr/ - C:\Program Files\Fichiers communs\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe
O23 - Service: ASF Agent (ASFAgent) - Intel Corporation - C:\Program Files\Intel\ASF Agent\ASFAgent.exe
O23 - Service: Intel(R) Active Management Technology System Status Service (atchksrv) - Intel Corporation - C:\Program Files\Intel\AMT\atchksrv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
O23 - Service: Intel(R) Active Management Technology Local Management Service (LMS) - Intel - C:\Program Files\Intel\AMT\LMS.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: Planificateur de tâches (Schedule) - Unknown owner - C:\WINDOWS\system32\drivers\services.exe (file missing)
O23 - Service: Intel(R) Active Management Technology User Notification Service (UNS) - Intel - C:\Program Files\Intel\AMT\UNS.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S. R. L. - C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
Logfile of random's system information tool 1.05 (written by random/random)
Run by Alexis at 2009-02-25 15:58:48
Microsoft Windows XP Professionnel Service Pack 3
System drive C: has 58 GB (77%) free of 76 GB
Total RAM: 997 MB (23% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:58:58, on 25/02/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Intel\ASF Agent\ASFAgent.exe
C:\Program Files\Intel\AMT\atchksrv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Program Files\Intel\AMT\LMS.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\Program Files\Intel\AMT\UNS.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Intel\AMT\atchk.exe
C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\All Users\Application Data\Macrovision\FLEXnet Connect\6\ISUSPM.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\BitDefender\BitDefender 2009\seccenter.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe
C:\Program Files\Fichiers communs\Adobe\Updater5\AdobeUpdater.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Microsoft Office\Office12\EXCEL.EXE
C:\PROGRA~1\Java\JRE15~1.0_0\bin\javaw.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Alexis\Bureau\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\Alexis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.fr/ig/dell?hl=fr&client=dell-row-rel&channel=fr&ibd=3071214
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.fr/ig/dell?hl=fr&client=dell-row-rel&channel=fr&ibd=3071214
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = https://www.dell.com/fr-fr?c=fr&l=fr&s=gen&redirect=1
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2009\IEToolbar.dll
O4 - HKLM\..\Run: [atchk] "C:\Program Files\Intel\AMT\atchk.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe"
O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2009\IEShow.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ISUSPM] "C:\Documents and Settings\All Users\Application Data\Macrovision\FLEXnet Connect\6\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...
O17 - HKLM\System\CCS\Services\Tcpip\..\{C511F928-EA3C-451F-81B2-79FBF2E8302F}: Domain = u-strasbg.fr
O17 - HKLM\System\CCS\Services\Tcpip\..\{C511F928-EA3C-451F-81B2-79FBF2E8302F}: NameServer = 130.79.200.200
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = u-strasbg.fr
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = u-strasbg.fr
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = u-strasbg.fr
O23 - Service: Planificateur Avira AntiVir Personal - Free Antivirus (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: BitDefender Arrakis Server (Arrakis3) - BitDefender S.R.L. https://www.bitdefender.fr/ - C:\Program Files\Fichiers communs\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe
O23 - Service: ASF Agent (ASFAgent) - Intel Corporation - C:\Program Files\Intel\ASF Agent\ASFAgent.exe
O23 - Service: Intel(R) Active Management Technology System Status Service (atchksrv) - Intel Corporation - C:\Program Files\Intel\AMT\atchksrv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
O23 - Service: Intel(R) Active Management Technology Local Management Service (LMS) - Intel - C:\Program Files\Intel\AMT\LMS.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: Planificateur de tâches (Schedule) - Unknown owner - C:\WINDOWS\system32\drivers\services.exe (file missing)
O23 - Service: Intel(R) Active Management Technology User Notification Service (UNS) - Intel - C:\Program Files\Intel\AMT\UNS.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S. R. L. - C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
---> Double-clique sur OTMoveIt3.exe afin de le lancer.
---> Copie (Ctrl+C) le texte suivant ci-dessous :
:processes
explorer.exe
:services
snhuzhflkfxb
:files
C:\WINDOWS\system32\drivers\ekskfobvqywrzi.sys
:commands
[purity]
[emptytemp]
[start explorer]
[reboot]
---> Colle (Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.
---> Clique maintenant sur le bouton MoveIt! puis ferme OTMoveIt3.
Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
Accepte en cliquant sur YES.
---> Poste le rapport situé dans ce dossier : C:\_OTMoveIt\MovedFiles\
Le nom du rapport correspond au moment de sa création : date_heure.log
---> Copie (Ctrl+C) le texte suivant ci-dessous :
:processes
explorer.exe
:services
snhuzhflkfxb
:files
C:\WINDOWS\system32\drivers\ekskfobvqywrzi.sys
:commands
[purity]
[emptytemp]
[start explorer]
[reboot]
---> Colle (Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.
---> Clique maintenant sur le bouton MoveIt! puis ferme OTMoveIt3.
Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
Accepte en cliquant sur YES.
---> Poste le rapport situé dans ce dossier : C:\_OTMoveIt\MovedFiles\
Le nom du rapport correspond au moment de sa création : date_heure.log
========== PROCESSES ==========
Process explorer.exe killed successfully.
========== SERVICES/DRIVERS ==========
Service snhuzhflkfxb stopped successfully.
Service snhuzhflkfxb deleted successfully.
========== FILES ==========
File/Folder C:\WINDOWS\system32\drivers\ekskfobvqywrzi.sys not found.
========== COMMANDS ==========
File delete failed. C:\DOCUME~1\Alexis\LOCALS~1\Temp\RtmpAkxlVy\file3d6c4ae1 scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Alexis\LOCALS~1\Temp\hsperfdata_Alexis\7112 scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Alexis\LOCALS~1\Temp\AcrA79A.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Alexis\LOCALS~1\Temp\C2.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Alexis\LOCALS~1\Temp\etilqs_HeLORWXNnckQTQnnGdxi scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Alexis\LOCALS~1\Temp\Z@R74.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Alexis\LOCALS~1\Temp\Z@R77.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Alexis\LOCALS~1\Temp\Z@R7E.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Alexis\LOCALS~1\Temp\Z@R80.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Alexis\LOCALS~1\Temp\Z@R82.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Alexis\LOCALS~1\Temp\Z@R87.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Alexis\LOCALS~1\Temp\~DF82E2.tmp scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Fichiers Internet temporaires\Content.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be deleted on reboot.
Local Service Temp folder emptied.
Local Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\atchk.log scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\atchksrv.log scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
File delete failed. C:\Documents and Settings\Alexis\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxbc7y6r.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Alexis\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxbc7y6r.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Alexis\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxbc7y6r.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Alexis\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxbc7y6r.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Alexis\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxbc7y6r.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Alexis\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxbc7y6r.default\XUL.mfl scheduled to be deleted on reboot.
FireFox cache emptied.
Temp folders emptied.
Explorer started successfully
OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 02252009_163244
Files moved on Reboot...
C:\DOCUME~1\Alexis\LOCALS~1\Temp\RtmpAkxlVy\file3d6c4ae1 moved successfully.
File C:\DOCUME~1\Alexis\LOCALS~1\Temp\hsperfdata_Alexis\7112 not found!
File C:\DOCUME~1\Alexis\LOCALS~1\Temp\AcrA79A.tmp not found!
File C:\DOCUME~1\Alexis\LOCALS~1\Temp\C2.tmp not found!
File C:\DOCUME~1\Alexis\LOCALS~1\Temp\etilqs_HeLORWXNnckQTQnnGdxi not found!
File C:\DOCUME~1\Alexis\LOCALS~1\Temp\Z@R74.tmp not found!
File C:\DOCUME~1\Alexis\LOCALS~1\Temp\Z@R77.tmp not found!
File C:\DOCUME~1\Alexis\LOCALS~1\Temp\Z@R7E.tmp not found!
File C:\DOCUME~1\Alexis\LOCALS~1\Temp\Z@R80.tmp not found!
File C:\DOCUME~1\Alexis\LOCALS~1\Temp\Z@R82.tmp not found!
File C:\DOCUME~1\Alexis\LOCALS~1\Temp\Z@R87.tmp not found!
File C:\DOCUME~1\Alexis\LOCALS~1\Temp\~DF82E2.tmp not found!
C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat moved successfully.
C:\Documents and Settings\LocalService\Local Settings\Temp\Fichiers Internet temporaires\Content.IE5\index.dat moved successfully.
C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat moved successfully.
C:\WINDOWS\temp\atchk.log moved successfully.
C:\WINDOWS\temp\atchksrv.log moved successfully.
C:\Documents and Settings\Alexis\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxbc7y6r.default\Cache\_CACHE_001_ moved successfully.
C:\Documents and Settings\Alexis\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxbc7y6r.default\Cache\_CACHE_002_ moved successfully.
C:\Documents and Settings\Alexis\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxbc7y6r.default\Cache\_CACHE_003_ moved successfully.
C:\Documents and Settings\Alexis\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxbc7y6r.default\Cache\_CACHE_MAP_ moved successfully.
C:\Documents and Settings\Alexis\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxbc7y6r.default\urlclassifier3.sqlite moved successfully.
C:\Documents and Settings\Alexis\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxbc7y6r.default\XUL.mfl moved successfully.
Process explorer.exe killed successfully.
========== SERVICES/DRIVERS ==========
Service snhuzhflkfxb stopped successfully.
Service snhuzhflkfxb deleted successfully.
========== FILES ==========
File/Folder C:\WINDOWS\system32\drivers\ekskfobvqywrzi.sys not found.
========== COMMANDS ==========
File delete failed. C:\DOCUME~1\Alexis\LOCALS~1\Temp\RtmpAkxlVy\file3d6c4ae1 scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Alexis\LOCALS~1\Temp\hsperfdata_Alexis\7112 scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Alexis\LOCALS~1\Temp\AcrA79A.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Alexis\LOCALS~1\Temp\C2.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Alexis\LOCALS~1\Temp\etilqs_HeLORWXNnckQTQnnGdxi scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Alexis\LOCALS~1\Temp\Z@R74.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Alexis\LOCALS~1\Temp\Z@R77.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Alexis\LOCALS~1\Temp\Z@R7E.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Alexis\LOCALS~1\Temp\Z@R80.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Alexis\LOCALS~1\Temp\Z@R82.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Alexis\LOCALS~1\Temp\Z@R87.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Alexis\LOCALS~1\Temp\~DF82E2.tmp scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Fichiers Internet temporaires\Content.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be deleted on reboot.
Local Service Temp folder emptied.
Local Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\atchk.log scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\atchksrv.log scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
File delete failed. C:\Documents and Settings\Alexis\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxbc7y6r.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Alexis\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxbc7y6r.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Alexis\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxbc7y6r.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Alexis\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxbc7y6r.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Alexis\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxbc7y6r.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Alexis\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxbc7y6r.default\XUL.mfl scheduled to be deleted on reboot.
FireFox cache emptied.
Temp folders emptied.
Explorer started successfully
OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 02252009_163244
Files moved on Reboot...
C:\DOCUME~1\Alexis\LOCALS~1\Temp\RtmpAkxlVy\file3d6c4ae1 moved successfully.
File C:\DOCUME~1\Alexis\LOCALS~1\Temp\hsperfdata_Alexis\7112 not found!
File C:\DOCUME~1\Alexis\LOCALS~1\Temp\AcrA79A.tmp not found!
File C:\DOCUME~1\Alexis\LOCALS~1\Temp\C2.tmp not found!
File C:\DOCUME~1\Alexis\LOCALS~1\Temp\etilqs_HeLORWXNnckQTQnnGdxi not found!
File C:\DOCUME~1\Alexis\LOCALS~1\Temp\Z@R74.tmp not found!
File C:\DOCUME~1\Alexis\LOCALS~1\Temp\Z@R77.tmp not found!
File C:\DOCUME~1\Alexis\LOCALS~1\Temp\Z@R7E.tmp not found!
File C:\DOCUME~1\Alexis\LOCALS~1\Temp\Z@R80.tmp not found!
File C:\DOCUME~1\Alexis\LOCALS~1\Temp\Z@R82.tmp not found!
File C:\DOCUME~1\Alexis\LOCALS~1\Temp\Z@R87.tmp not found!
File C:\DOCUME~1\Alexis\LOCALS~1\Temp\~DF82E2.tmp not found!
C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat moved successfully.
C:\Documents and Settings\LocalService\Local Settings\Temp\Fichiers Internet temporaires\Content.IE5\index.dat moved successfully.
C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat moved successfully.
C:\WINDOWS\temp\atchk.log moved successfully.
C:\WINDOWS\temp\atchksrv.log moved successfully.
C:\Documents and Settings\Alexis\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxbc7y6r.default\Cache\_CACHE_001_ moved successfully.
C:\Documents and Settings\Alexis\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxbc7y6r.default\Cache\_CACHE_002_ moved successfully.
C:\Documents and Settings\Alexis\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxbc7y6r.default\Cache\_CACHE_003_ moved successfully.
C:\Documents and Settings\Alexis\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxbc7y6r.default\Cache\_CACHE_MAP_ moved successfully.
C:\Documents and Settings\Alexis\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxbc7y6r.default\urlclassifier3.sqlite moved successfully.
C:\Documents and Settings\Alexis\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxbc7y6r.default\XUL.mfl moved successfully.
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
Télécharge MalwareByte's :
Malwarebytes ou :
Malwarebytes
* Installe le ( choisis bien "francais" ; ne modifie pas les paramètres d'installe ) et mets le à jour .
(NB : S'il te manque "COMCTL32.OCX" lors de l'installe, alors télécharge le ici : COMCTL32.OCX
* Potasse le tuto pour te familiariser avec le prg :
Tuto
( cela dis, il est très simple d'utilisation ).
relance malwarebytes en suivant scrupuleusement ces consignes :
! Déconnecte toi et ferme toutes applications en cours !
* Lance Malwarebyte's .
Fais un examen dit "Complet" .
--> Laisse le programme travailler ( et ne rien faire d'autre avec le PC durant le scan ).
--> à la fin tu cliques sur "résultat" .
--> Vérifie que tous les objets infectés soient validés, puis clique sur " suppression " .
Note : si il faut redémarrer ton PC pour finir le nettoyage, fais le !
Poste le rapport sauvegardé après la suppression des objets infectés (dans l'onglet "rapport/log"de Malwarebytes, le dernier en date)
Malwarebytes ou :
Malwarebytes
* Installe le ( choisis bien "francais" ; ne modifie pas les paramètres d'installe ) et mets le à jour .
(NB : S'il te manque "COMCTL32.OCX" lors de l'installe, alors télécharge le ici : COMCTL32.OCX
* Potasse le tuto pour te familiariser avec le prg :
Tuto
( cela dis, il est très simple d'utilisation ).
relance malwarebytes en suivant scrupuleusement ces consignes :
! Déconnecte toi et ferme toutes applications en cours !
* Lance Malwarebyte's .
Fais un examen dit "Complet" .
--> Laisse le programme travailler ( et ne rien faire d'autre avec le PC durant le scan ).
--> à la fin tu cliques sur "résultat" .
--> Vérifie que tous les objets infectés soient validés, puis clique sur " suppression " .
Note : si il faut redémarrer ton PC pour finir le nettoyage, fais le !
Poste le rapport sauvegardé après la suppression des objets infectés (dans l'onglet "rapport/log"de Malwarebytes, le dernier en date)
zut alors comprends pas :(
essaie en mode sans echec :
Comment aller en Mode sans échec
1) Redémarres ton ordi
2) Tapote la touche F8 immédiatement, (F5 sur certains PC) juste après le "Bip"
3) Tu verras un écran avec options de démarrage apparaître
4) Choisis la première option : Sans Échec, et valide avec "Entrée"
5) Choisis ton compte habituel, et non Administrateur (si besoin ... )
essaie en mode sans echec :
Comment aller en Mode sans échec
1) Redémarres ton ordi
2) Tapote la touche F8 immédiatement, (F5 sur certains PC) juste après le "Bip"
3) Tu verras un écran avec options de démarrage apparaître
4) Choisis la première option : Sans Échec, et valide avec "Entrée"
5) Choisis ton compte habituel, et non Administrateur (si besoin ... )
Voila, entre temps, j'ai desinstal malwaresbyte, je l'ai reinstaller, tjrs rien a faire, j'ai aussi essayer avec une version antérieure.
Merci
Logfile of random's system information tool 1.05 (written by random/random)
Run by Alexis at 2009-02-25 18:49:23
Microsoft Windows XP Professionnel Service Pack 3
System drive C: has 59 GB (77%) free of 76 GB
Total RAM: 997 MB (47% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:49:27, on 25/02/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Intel\ASF Agent\ASFAgent.exe
C:\Program Files\Intel\AMT\atchksrv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Program Files\Intel\AMT\LMS.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\Program Files\Intel\AMT\UNS.exe
C:\Program Files\Intel\AMT\atchk.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\All Users\Application Data\Macrovision\FLEXnet Connect\6\ISUSPM.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Alexis\Bureau\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\Alexis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.fr/ig/dell?hl=fr&client=dell-row-rel&channel=fr&ibd=3071214
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.fr/ig/dell?hl=fr&client=dell-row-rel&channel=fr&ibd=3071214
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://www1.euro.dell.com/content/default.aspx?c=fr&l=fr&s=gen
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O4 - HKLM\..\Run: [atchk] "C:\Program Files\Intel\AMT\atchk.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ISUSPM] "C:\Documents and Settings\All Users\Application Data\Macrovision\FLEXnet Connect\6\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...
O17 - HKLM\System\CCS\Services\Tcpip\..\{C511F928-EA3C-451F-81B2-79FBF2E8302F}: Domain = u-strasbg.fr
O17 - HKLM\System\CCS\Services\Tcpip\..\{C511F928-EA3C-451F-81B2-79FBF2E8302F}: NameServer = 130.79.200.200
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = u-strasbg.fr
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = u-strasbg.fr
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = u-strasbg.fr
O23 - Service: Planificateur Avira AntiVir Personal - Free Antivirus (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: ASF Agent (ASFAgent) - Intel Corporation - C:\Program Files\Intel\ASF Agent\ASFAgent.exe
O23 - Service: Intel(R) Active Management Technology System Status Service (atchksrv) - Intel Corporation - C:\Program Files\Intel\AMT\atchksrv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: Intel(R) Active Management Technology Local Management Service (LMS) - Intel - C:\Program Files\Intel\AMT\LMS.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: Planificateur de tâches (Schedule) - Unknown owner - C:\WINDOWS\system32\drivers\services.exe (file missing)
O23 - Service: Intel(R) Active Management Technology User Notification Service (UNS) - Intel - C:\Program Files\Intel\AMT\UNS.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Merci
Logfile of random's system information tool 1.05 (written by random/random)
Run by Alexis at 2009-02-25 18:49:23
Microsoft Windows XP Professionnel Service Pack 3
System drive C: has 59 GB (77%) free of 76 GB
Total RAM: 997 MB (47% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:49:27, on 25/02/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Intel\ASF Agent\ASFAgent.exe
C:\Program Files\Intel\AMT\atchksrv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Program Files\Intel\AMT\LMS.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\Program Files\Intel\AMT\UNS.exe
C:\Program Files\Intel\AMT\atchk.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\All Users\Application Data\Macrovision\FLEXnet Connect\6\ISUSPM.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Alexis\Bureau\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\Alexis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.fr/ig/dell?hl=fr&client=dell-row-rel&channel=fr&ibd=3071214
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.fr/ig/dell?hl=fr&client=dell-row-rel&channel=fr&ibd=3071214
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://www1.euro.dell.com/content/default.aspx?c=fr&l=fr&s=gen
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O4 - HKLM\..\Run: [atchk] "C:\Program Files\Intel\AMT\atchk.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ISUSPM] "C:\Documents and Settings\All Users\Application Data\Macrovision\FLEXnet Connect\6\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...
O17 - HKLM\System\CCS\Services\Tcpip\..\{C511F928-EA3C-451F-81B2-79FBF2E8302F}: Domain = u-strasbg.fr
O17 - HKLM\System\CCS\Services\Tcpip\..\{C511F928-EA3C-451F-81B2-79FBF2E8302F}: NameServer = 130.79.200.200
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = u-strasbg.fr
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = u-strasbg.fr
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = u-strasbg.fr
O23 - Service: Planificateur Avira AntiVir Personal - Free Antivirus (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: ASF Agent (ASFAgent) - Intel Corporation - C:\Program Files\Intel\ASF Agent\ASFAgent.exe
O23 - Service: Intel(R) Active Management Technology System Status Service (atchksrv) - Intel Corporation - C:\Program Files\Intel\AMT\atchksrv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: Intel(R) Active Management Technology Local Management Service (LMS) - Intel - C:\Program Files\Intel\AMT\LMS.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: Planificateur de tâches (Schedule) - Unknown owner - C:\WINDOWS\system32\drivers\services.exe (file missing)
O23 - Service: Intel(R) Active Management Technology User Notification Service (UNS) - Intel - C:\Program Files\Intel\AMT\UNS.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
---> Double-clique sur OTMoveIt3.exe afin de le lancer.
---> Copie (Ctrl+C) le texte suivant ci-dessous :
:processes
explorer.exe
:files
C:\Documents and Settings\All Users\Application Data\SpeedBit
C:\PMN.txt
:reg
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"\\ultime.inserm575.local\Donnee\Documents\alexis laux\Mes documents\mIRC\mirc.exe"=-
"D:\Windows Utilities\Installer32\InstallationManager.exe"="D:\Windows Utilities\Installer32\InstallationManager.exe:*:Enabled:Xerox Windows Common Installer"
:commands
[purity]
[emptytemp]
[start explorer]
[reboot]
---> Colle (Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.
---> Clique maintenant sur le bouton MoveIt! puis ferme OTMoveIt3.
Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
Accepte en cliquant sur YES.
---> Poste le rapport situé dans ce dossier : C:\_OTMoveIt\MovedFiles\
Le nom du rapport correspond au moment de sa création : date_heure.log
ensuite connais-tu :
C:\Avenger
C:\Program Files\Minitab 15
C:\Program Files\Statistiklabor_Runtime
---> Copie (Ctrl+C) le texte suivant ci-dessous :
:processes
explorer.exe
:files
C:\Documents and Settings\All Users\Application Data\SpeedBit
C:\PMN.txt
:reg
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"\\ultime.inserm575.local\Donnee\Documents\alexis laux\Mes documents\mIRC\mirc.exe"=-
"D:\Windows Utilities\Installer32\InstallationManager.exe"="D:\Windows Utilities\Installer32\InstallationManager.exe:*:Enabled:Xerox Windows Common Installer"
:commands
[purity]
[emptytemp]
[start explorer]
[reboot]
---> Colle (Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.
---> Clique maintenant sur le bouton MoveIt! puis ferme OTMoveIt3.
Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
Accepte en cliquant sur YES.
---> Poste le rapport situé dans ce dossier : C:\_OTMoveIt\MovedFiles\
Le nom du rapport correspond au moment de sa création : date_heure.log
ensuite connais-tu :
C:\Avenger
C:\Program Files\Minitab 15
C:\Program Files\Statistiklabor_Runtime
Voila le rapport.
Je ne connais pas avenger
Minitab15 et statistiklabor je connais mais je les ai desinstallés il y a un bon bout de temps.
Merci
========== PROCESSES ==========
Process explorer.exe killed successfully.
========== FILES ==========
C:\Documents and Settings\All Users\Application Data\SpeedBit moved successfully.
C:\PMN.txt moved successfully.
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list\\\ultime.inserm575.local\Donnee\Documents\alexis laux\Mes documents\mIRC\mirc.exe not found.
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list\\"D:\Windows Utilities\Installer32\InstallationManager.exe"|"D:\Windows Utilities\Installer32\InstallationManager.exe:*:Enabled:Xerox Windows Common Installer" /E : value set successfully!
========== COMMANDS ==========
File delete failed. C:\DOCUME~1\Alexis\LOCALS~1\Temp\hsperfdata_Alexis\3660 scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Alexis\LOCALS~1\Temp\etilqs_K2IDn0eIbomKsYf4ecQI scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Alexis\LOCALS~1\Temp\~DF1DFC.tmp scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Fichiers Internet temporaires\Content.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be deleted on reboot.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\atchk.log scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\atchksrv.log scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\ZLT04261.TMP scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
File delete failed. C:\Documents and Settings\Alexis\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxbc7y6r.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Alexis\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxbc7y6r.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Alexis\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxbc7y6r.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Alexis\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxbc7y6r.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Alexis\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxbc7y6r.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Alexis\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxbc7y6r.default\XUL.mfl scheduled to be deleted on reboot.
FireFox cache emptied.
Temp folders emptied.
Explorer started successfully
OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 02262009_063632
Files moved on Reboot...
File C:\DOCUME~1\Alexis\LOCALS~1\Temp\hsperfdata_Alexis\3660 not found!
File C:\DOCUME~1\Alexis\LOCALS~1\Temp\etilqs_K2IDn0eIbomKsYf4ecQI not found!
C:\DOCUME~1\Alexis\LOCALS~1\Temp\~DF1DFC.tmp moved successfully.
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat scheduled to be moved on reboot.
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Fichiers Internet temporaires\Content.IE5\index.dat scheduled to be moved on reboot.
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be moved on reboot.
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.
C:\WINDOWS\temp\atchk.log moved successfully.
File move failed. C:\WINDOWS\temp\atchksrv.log scheduled to be moved on reboot.
File C:\WINDOWS\temp\ZLT04261.TMP not found!
C:\Documents and Settings\Alexis\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxbc7y6r.default\Cache\_CACHE_001_ moved successfully.
C:\Documents and Settings\Alexis\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxbc7y6r.default\Cache\_CACHE_002_ moved successfully.
C:\Documents and Settings\Alexis\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxbc7y6r.default\Cache\_CACHE_003_ moved successfully.
C:\Documents and Settings\Alexis\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxbc7y6r.default\Cache\_CACHE_MAP_ moved successfully.
C:\Documents and Settings\Alexis\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxbc7y6r.default\urlclassifier3.sqlite moved successfully.
C:\Documents and Settings\Alexis\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxbc7y6r.default\XUL.mfl moved successfully.
Je ne connais pas avenger
Minitab15 et statistiklabor je connais mais je les ai desinstallés il y a un bon bout de temps.
Merci
========== PROCESSES ==========
Process explorer.exe killed successfully.
========== FILES ==========
C:\Documents and Settings\All Users\Application Data\SpeedBit moved successfully.
C:\PMN.txt moved successfully.
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list\\\ultime.inserm575.local\Donnee\Documents\alexis laux\Mes documents\mIRC\mirc.exe not found.
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list\\"D:\Windows Utilities\Installer32\InstallationManager.exe"|"D:\Windows Utilities\Installer32\InstallationManager.exe:*:Enabled:Xerox Windows Common Installer" /E : value set successfully!
========== COMMANDS ==========
File delete failed. C:\DOCUME~1\Alexis\LOCALS~1\Temp\hsperfdata_Alexis\3660 scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Alexis\LOCALS~1\Temp\etilqs_K2IDn0eIbomKsYf4ecQI scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Alexis\LOCALS~1\Temp\~DF1DFC.tmp scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Fichiers Internet temporaires\Content.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be deleted on reboot.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\atchk.log scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\atchksrv.log scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\ZLT04261.TMP scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
File delete failed. C:\Documents and Settings\Alexis\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxbc7y6r.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Alexis\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxbc7y6r.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Alexis\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxbc7y6r.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Alexis\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxbc7y6r.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Alexis\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxbc7y6r.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Alexis\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxbc7y6r.default\XUL.mfl scheduled to be deleted on reboot.
FireFox cache emptied.
Temp folders emptied.
Explorer started successfully
OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 02262009_063632
Files moved on Reboot...
File C:\DOCUME~1\Alexis\LOCALS~1\Temp\hsperfdata_Alexis\3660 not found!
File C:\DOCUME~1\Alexis\LOCALS~1\Temp\etilqs_K2IDn0eIbomKsYf4ecQI not found!
C:\DOCUME~1\Alexis\LOCALS~1\Temp\~DF1DFC.tmp moved successfully.
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat scheduled to be moved on reboot.
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Fichiers Internet temporaires\Content.IE5\index.dat scheduled to be moved on reboot.
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be moved on reboot.
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.
C:\WINDOWS\temp\atchk.log moved successfully.
File move failed. C:\WINDOWS\temp\atchksrv.log scheduled to be moved on reboot.
File C:\WINDOWS\temp\ZLT04261.TMP not found!
C:\Documents and Settings\Alexis\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxbc7y6r.default\Cache\_CACHE_001_ moved successfully.
C:\Documents and Settings\Alexis\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxbc7y6r.default\Cache\_CACHE_002_ moved successfully.
C:\Documents and Settings\Alexis\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxbc7y6r.default\Cache\_CACHE_003_ moved successfully.
C:\Documents and Settings\Alexis\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxbc7y6r.default\Cache\_CACHE_MAP_ moved successfully.
C:\Documents and Settings\Alexis\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxbc7y6r.default\urlclassifier3.sqlite moved successfully.
C:\Documents and Settings\Alexis\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxbc7y6r.default\XUL.mfl moved successfully.
bien dans ce cas tu peux les supprimer
sinon je ne vois vraiment plus ce qui pourrait te causer souci :(
sinon je ne vois vraiment plus ce qui pourrait te causer souci :(
Voila c'est supprimé, je vais refaire kkl scans et je verais bien, si lundi ca ne va pas mieu, je ferais un format du pc (entre temps j'ai fait une sauvegarde de mes données).
En tout cas merci pour ton aide et pour le temps que as consacré a mon problème.
Si jamais il te viens une idée d'ici lundi n'hésite pas.
a+
En tout cas merci pour ton aide et pour le temps que as consacré a mon problème.
Si jamais il te viens une idée d'ici lundi n'hésite pas.
a+
bonsoir oui :
en examinant un peu il reste des trucs a virer et regler :
---> Double-clique sur OTMoveIt3.exe afin de le lancer.
---> Copie (Ctrl+C) le texte suivant ci-dessous :
:processes
explorer.exe
:Services
DefWatch
Symantec AntiVirus Client
:files
C:\PROGRA~1\SYMANT~1\SYMANT~1
:reg
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="http://www.google.fr/"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search]
"Default_Page_URL"="http://www.google.fr/"
:commands
[purity]
[emptytemp]
[start explorer]
[reboot]
---> Colle (Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.
---> Clique maintenant sur le bouton MoveIt! puis ferme OTMoveIt3.
Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
Accepte en cliquant sur YES.
---> Poste le rapport situé dans ce dossier : C:\_OTMoveIt\MovedFiles\
Le nom du rapport correspond au moment de sa création : date_heure.log
en examinant un peu il reste des trucs a virer et regler :
---> Double-clique sur OTMoveIt3.exe afin de le lancer.
---> Copie (Ctrl+C) le texte suivant ci-dessous :
:processes
explorer.exe
:Services
DefWatch
Symantec AntiVirus Client
:files
C:\PROGRA~1\SYMANT~1\SYMANT~1
:reg
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="http://www.google.fr/"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search]
"Default_Page_URL"="http://www.google.fr/"
:commands
[purity]
[emptytemp]
[start explorer]
[reboot]
---> Colle (Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.
---> Clique maintenant sur le bouton MoveIt! puis ferme OTMoveIt3.
Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
Accepte en cliquant sur YES.
---> Poste le rapport situé dans ce dossier : C:\_OTMoveIt\MovedFiles\
Le nom du rapport correspond au moment de sa création : date_heure.log
Voila, au passage, il me reste encore 2 symptomes génants : l'affichage de pages http://windowsclick.com lorsque je clique sur un lien a partir d'une page web (Url entré a la main fonctionne pourtant), et c'est alléatoire selon les site et le moment ou j'essaye. Le deuxiemme est l'impossibilité de me connecté a gmail par exemple, ou a tout site ou j'ai besoin de me loger. netvibes ne reconnais meme plus mon adresse email, lorsque je fait un request password, pourtant mon compte existe bien puisque je m'y connecte depuis chez moi.
Voila le log OTmoveIT
========== PROCESSES ==========
Process explorer.exe killed successfully.
========== SERVICES/DRIVERS ==========
Service DefWatch stopped successfully.
Service DefWatch deleted successfully.
Unable to stop service Symantec AntiVirus Client .
========== FILES ==========
Folder move failed. C:\PROGRA~1\SYMANT~1\Symantec AntiVirus scheduled to be moved on reboot.
========== REGISTRY ==========
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\"Default_Page_URL"|"https://www.google.fr/?gws_rd=ssl" /E : value set successfully!
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\\"Default_Page_URL"|"https://www.google.fr/?gws_rd=ssl" /E : value set successfully!
========== COMMANDS ==========
File delete failed. C:\DOCUME~1\Alexis\LOCALS~1\Temp\hsperfdata_Alexis\2432 scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Alexis\LOCALS~1\Temp\etilqs_THxm7gJFJQEZ0zdBF6dC scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Alexis\LOCALS~1\Temp\~DFFC52.tmp scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Fichiers Internet temporaires\Content.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be deleted on reboot.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\atchk.log scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\atchksrv.log scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\ZLT00f30.TMP scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
File delete failed. C:\Documents and Settings\Alexis\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxbc7y6r.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Alexis\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxbc7y6r.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Alexis\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxbc7y6r.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Alexis\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxbc7y6r.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Alexis\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxbc7y6r.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Alexis\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxbc7y6r.default\XUL.mfl scheduled to be deleted on reboot.
FireFox cache emptied.
Temp folders emptied.
Explorer started successfully
OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 02272009_075624
Files moved on Reboot...
C:\PROGRA~1\SYMANT~1\Symantec AntiVirus moved successfully.
File C:\DOCUME~1\Alexis\LOCALS~1\Temp\hsperfdata_Alexis\2432 not found!
File C:\DOCUME~1\Alexis\LOCALS~1\Temp\etilqs_THxm7gJFJQEZ0zdBF6dC not found!
C:\DOCUME~1\Alexis\LOCALS~1\Temp\~DFFC52.tmp moved successfully.
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat scheduled to be moved on reboot.
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Fichiers Internet temporaires\Content.IE5\index.dat scheduled to be moved on reboot.
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be moved on reboot.
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.
C:\WINDOWS\temp\atchk.log moved successfully.
File move failed. C:\WINDOWS\temp\atchksrv.log scheduled to be moved on reboot.
File C:\WINDOWS\temp\ZLT00f30.TMP not found!
C:\Documents and Settings\Alexis\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxbc7y6r.default\Cache\_CACHE_001_ moved successfully.
C:\Documents and Settings\Alexis\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxbc7y6r.default\Cache\_CACHE_002_ moved successfully.
C:\Documents and Settings\Alexis\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxbc7y6r.default\Cache\_CACHE_003_ moved successfully.
C:\Documents and Settings\Alexis\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxbc7y6r.default\Cache\_CACHE_MAP_ moved successfully.
C:\Documents and Settings\Alexis\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxbc7y6r.default\urlclassifier3.sqlite moved successfully.
C:\Documents and Settings\Alexis\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxbc7y6r.default\XUL.mfl moved successfully.
Voila le log OTmoveIT
========== PROCESSES ==========
Process explorer.exe killed successfully.
========== SERVICES/DRIVERS ==========
Service DefWatch stopped successfully.
Service DefWatch deleted successfully.
Unable to stop service Symantec AntiVirus Client .
========== FILES ==========
Folder move failed. C:\PROGRA~1\SYMANT~1\Symantec AntiVirus scheduled to be moved on reboot.
========== REGISTRY ==========
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\"Default_Page_URL"|"https://www.google.fr/?gws_rd=ssl" /E : value set successfully!
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\\"Default_Page_URL"|"https://www.google.fr/?gws_rd=ssl" /E : value set successfully!
========== COMMANDS ==========
File delete failed. C:\DOCUME~1\Alexis\LOCALS~1\Temp\hsperfdata_Alexis\2432 scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Alexis\LOCALS~1\Temp\etilqs_THxm7gJFJQEZ0zdBF6dC scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Alexis\LOCALS~1\Temp\~DFFC52.tmp scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Fichiers Internet temporaires\Content.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be deleted on reboot.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\atchk.log scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\atchksrv.log scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\ZLT00f30.TMP scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
File delete failed. C:\Documents and Settings\Alexis\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxbc7y6r.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Alexis\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxbc7y6r.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Alexis\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxbc7y6r.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Alexis\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxbc7y6r.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Alexis\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxbc7y6r.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Alexis\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxbc7y6r.default\XUL.mfl scheduled to be deleted on reboot.
FireFox cache emptied.
Temp folders emptied.
Explorer started successfully
OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 02272009_075624
Files moved on Reboot...
C:\PROGRA~1\SYMANT~1\Symantec AntiVirus moved successfully.
File C:\DOCUME~1\Alexis\LOCALS~1\Temp\hsperfdata_Alexis\2432 not found!
File C:\DOCUME~1\Alexis\LOCALS~1\Temp\etilqs_THxm7gJFJQEZ0zdBF6dC not found!
C:\DOCUME~1\Alexis\LOCALS~1\Temp\~DFFC52.tmp moved successfully.
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat scheduled to be moved on reboot.
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Fichiers Internet temporaires\Content.IE5\index.dat scheduled to be moved on reboot.
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be moved on reboot.
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.
C:\WINDOWS\temp\atchk.log moved successfully.
File move failed. C:\WINDOWS\temp\atchksrv.log scheduled to be moved on reboot.
File C:\WINDOWS\temp\ZLT00f30.TMP not found!
C:\Documents and Settings\Alexis\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxbc7y6r.default\Cache\_CACHE_001_ moved successfully.
C:\Documents and Settings\Alexis\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxbc7y6r.default\Cache\_CACHE_002_ moved successfully.
C:\Documents and Settings\Alexis\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxbc7y6r.default\Cache\_CACHE_003_ moved successfully.
C:\Documents and Settings\Alexis\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxbc7y6r.default\Cache\_CACHE_MAP_ moved successfully.
C:\Documents and Settings\Alexis\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxbc7y6r.default\urlclassifier3.sqlite moved successfully.
C:\Documents and Settings\Alexis\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxbc7y6r.default\XUL.mfl moved successfully.