Ecran noir ,Warning - Page 2

  1. Contributeur sécurité
    Desactive tes defences et telecharge sur ton BUREAU combofix http://download.bleepingcomputer.com/sUBs/ComboFix.exe

    Deconnecte toi d'internet et Ferme toutes tes applications

    lance le suit les instructions et ne touche + a rien et poste le rapport
    0
    1. il me marque (quand j'execute le fichier) vs ne pouvez pas renommer combofix en combofix (1)
      0
      1. Contributeur sécurité
        sa veut dire que tu l'as deja telechargé a ce moment la telecharge et au moment du telechargement tu le renomme en CF
        0
        1. Il est dans le lecteur de disque dur c mais quand je clique il y a un dossier av la lettre n et si je clique encore il me mets 11 fichiers
          0
          1. Contributeur sécurité
            va dans demarrer et executer et copie colle sa

            combofix /u puis entrée accepte la suite

            puis retelecharge combofix en le renommant comme tu veux et fait le scan
            0
            1. Putain ça m'enerve j'y arrive pas.quand je clique sur executer il me donne explore.exe c apres que je sais pas comment faire,en + ss fatiguée,c chiant d'etre nule.....
              0
              1. Contributeur sécurité
                calme toi :)

                pour faire du menage

                Pour supprimer toutes les traces des logiciels qui ont servi à traiter les infections spécifiques :

                * Télécharge Toolscleaner sur ton Bureau https://www.androidworld.fr/

                (c est le numéro 15 en bas de la page) :
                * Double-clique sur ToolsCleaner2.exe et laisse le travailler
                * Clique sur Recherche et laisse le scan se terminer.
                * Clique sur Suppression pour finaliser.
                * Tu peux, si tu le souhaites, te servir des Options facultatives.
                * Clique sur Quitter, pour que le rapport puisse se créer.
                * Le rapport (TCleaner.txt) se trouve à la racine de votre disque dur (C:\)...colle le dans ta prochaine réponse

                puis

                Télécharge Random's System Information Tool (RSIT) par random/random et sauvegarde-le sur ton Bureau.
                http://images.malwareremoval.com/random/RSIT.exe
                Clique sur Continue
                Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera et tu devras accepter la licence.
                Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront poste les 2 rapports SEPAREMENT
                0
                1. Logfile of random's system information tool 1.05 (written by random/random)
                  Run by sylk62 at 2009-03-10 00:03:02
                  Microsoft Windows XP Édition familiale Service Pack 3
                  System drive C: has 10 GB (32%) free of 31 GB
                  Total RAM: 1022 MB (33% free)

                  Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 00:03:07, on 10/03/2009
                  Platform: Windows XP SP3 (WinNT 5.01.2600)
                  MSIE: Internet Explorer v7.00 (7.00.6000.16791)
                  Boot mode: Normal

                  Running processes:
                  C:\WINDOWS\System32\smss.exe
                  C:\WINDOWS\system32\winlogon.exe
                  C:\WINDOWS\system32\services.exe
                  C:\WINDOWS\system32\lsass.exe
                  C:\WINDOWS\system32\Ati2evxx.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\system32\spoolsv.exe
                  C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
                  c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
                  c:\APPS\Powercinema\Kernel\CLML_NTService\CLMLServer.exe
                  C:\Program Files\SFR\Pack Sécurité\Anti-Virus\fsgk32st.exe
                  C:\Program Files\SFR\Pack Sécurité\Common\FSMA32.EXE
                  C:\Program Files\SFR\Pack Sécurité\Anti-Virus\FSGK32.EXE
                  C:\Program Files\Windows Live\Family Safety\fsssvc.exe
                  c:\APPS\HIDSERVICE\HIDSERVICE.exe
                  C:\Program Files\Java\jre6\bin\jqs.exe
                  C:\Apps\Softex\OmniPass\Omniserv.exe
                  C:\WINDOWS\system32\HPZipm12.exe
                  C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
                  c:\APPS\Powercinema\Kernel\TV\CLSched.exe
                  C:\Program Files\SFR\Pack Sécurité\Anti-Virus\fssm32.exe
                  C:\Apps\Softex\OmniPass\OPXPApp.exe
                  C:\WINDOWS\system32\Ati2evxx.exe
                  C:\WINDOWS\Explorer.EXE
                  C:\WINDOWS\system32\wbem\wmiapsrv.exe
                  C:\WINDOWS\RTHDCPL.EXE
                  C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
                  C:\Program Files\Java\jre6\bin\jusched.exe
                  C:\Apps\Softex\OmniPass\scureapp.exe
                  C:\Program Files\Fichiers communs\Ulead Systems\AutoDetector\monitor.exe
                  C:\APPS\Powercinema\PCMService.exe
                  C:\apps\ABoard\ABoard.exe
                  C:\Program Files\QuickTime\QTTask.exe
                  C:\apps\ABoard\AOSD.exe
                  C:\Program Files\Goto Software\Vade Retro\Vaderetro_Mgr.exe
                  C:\Program Files\Hercules\Deluxe Optical Glass\Camservice.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                  C:\Program Files\Windows Live\Family Safety\fsui.exe
                  C:\APPS\SMP\SmpSys.exe
                  C:\WINDOWS\system32\ctfmon.exe
                  C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                  C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                  C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
                  D:\Documents and Settings\sylk62\Application Data\Microsoft\Live Search\Notification-LiveSearch.exe
                  D:\Documents and Settings\sylk62\Application Data\Microsoft\Live Search\Mise-a-jour-LiveSearch.exe
                  C:\Program Files\OpenOffice.org 3\program\soffice.exe
                  C:\Program Files\OpenOffice.org 3\program\soffice.bin
                  C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
                  C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
                  C:\Program Files\Internet Explorer\IEXPLORE.EXE
                  C:\Program Files\Windows Live\Toolbar\wltuser.exe
                  C:\Program Files\SFR\Pack Sécurité\Common\FSLAUNCH.EXE
                  D:\Documents and Settings\sylk62\Local Settings\Temporary Internet Files\Content.IE5\NU21CLXF\RSIT[1].exe
                  C:\Program Files\trend micro\sylk62.exe

                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                  R3 - URLSearchHook: (no name) - {0BC6E3FA-78EF-4886-842C-5A1258C4455A} - (no file)
                  O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                  O2 - BHO: Windows Live Family Safety Browser Helper - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll
                  O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                  O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
                  O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
                  O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                  O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
                  O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
                  O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
                  O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                  O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                  O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
                  O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
                  O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                  O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
                  O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
                  O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
                  O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
                  O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
                  O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
                  O4 - HKLM\..\Run: [ATICCC] "c:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
                  O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                  O4 - HKLM\..\Run: [OmniPass] C:\Apps\Softex\OmniPass\scureapp.exe
                  O4 - HKLM\..\Run: [Ulead AutoDetector v2] C:\Program Files\Fichiers communs\Ulead Systems\AutoDetector\monitor.exe
                  O4 - HKLM\..\Run: [PCMService] "c:\APPS\Powercinema\PCMService.exe"
                  O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe
                  O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                  O4 - HKLM\..\Run: [VadeRetro Desktop] C:\Program Files\Goto Software\Vade Retro\Vaderetro_Mgr.exe
                  O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                  O4 - HKLM\..\Run: [CamserviceDeluxe2] C:\Program Files\Hercules\Deluxe Optical Glass\Camservice.exe /startup
                  O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                  O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\SFR\Pack Sécurité\Common\FSM32.EXE" /splash
                  O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\SFR\Pack Sécurité\FSGUI\TNBUtil.exe" /CHECKALL /WAITFORSW
                  O4 - HKLM\..\Run: [fssui] "C:\Program Files\Windows Live\Family Safety\fsui.exe" -autorun
                  O4 - HKCU\..\Run: [SmpcSys] C:\APPS\SMP\SmpSys.exe
                  O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                  O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                  O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                  O4 - HKCU\..\Run: [eMuleAutoStart] C:\Program Files\eMule\emule.exe -AutoStart
                  O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                  O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                  O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                  O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                  O4 - Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
                  O4 - Startup: Outil de notification Live Search.lnk = D:\Documents and Settings\sylk62\Application Data\Microsoft\Live Search\Notification-LiveSearch.exe
                  O4 - Global Startup: Démarrage rapide du logiciel HP Image Zone.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
                  O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                  O4 - Global Startup: xccstart.lnk = C:\WINDOWS\system\xccef090305.exe
                  O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
                  O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
                  O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                  O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                  O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                  O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                  O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
                  O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                  O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                  O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
                  O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
                  O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w3/resources/MSNPUpld.cab
                  O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://copainsdavant.linternaute.com/...
                  O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
                  O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game06.zylom.com/activex/zylomgamesplayer.cab
                  O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
                  O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
                  O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                  O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
                  O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLSched.exe
                  O23 - Service: CyberLink Media Library Service - Cyberlink - c:\APPS\Powercinema\Kernel\CLML_NTService\CLMLServer.exe
                  O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program Files\SFR\Pack Sécurité\Anti-Virus\fsgk32st.exe
                  O23 - Service: F-Secure Automatic Update Agent (FSAUA) - F-Secure Corporation - C:\Program Files\SFR\Pack Sécurité\FSAUA\program\fsaua.exe
                  O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\SFR\Pack Sécurité\FWES\Program\fsdfwd.exe
                  O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\SFR\Pack Sécurité\Common\FSMA32.EXE
                  O23 - Service: F-Secure ORSP Client (FSORSPClient) - F-Secure Corporation - C:\Program Files\SFR\Pack Sécurité\ORSP Client\fsorsp.exe
                  O23 - Service: Generic Service for HID Keyboard Input Collections (GenericHidService) - Unknown owner - c:\APPS\HIDSERVICE\HIDSERVICE.exe
                  O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
                  O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
                  O23 - Service: Softex OmniPass Service (omniserv) - Softex Inc. - C:\Apps\Softex\OmniPass\Omniserv.exe
                  O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
                  O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
                  0
                  1. Contributeur sécurité
                    non c'est pas bon tu as pa sfait dans l'ordre d'abord toolcleaner avec la suppression direct des elements et poste le rapport puis tu devras retelecharger RSIT et faire un scan
                    0
                    1. je v aller me coucher ss trop naze,si on px continuer dem ça serait cool,g retrouvée aussi combofix dans "mes documents" et g refais analyse av tcleaner mais toujours pas trouvé de rapport ca marqué qu'il avait trouvé combofix mais impossible de supprimer,la 1ère fois que je l'aie fait il avait trouvé tt les noms des fichiers mais moi g pas le rapport.
                      Je v te laisser merci bcp,ss creuvée demain je taf et g dormi que quelques heures depuis vendredi.
                      A +,bisous.
                      0
                      1. Contributeur sécurité
                        bonjour,

                        sur toolclaner tu as pas de rapport il faut que tu copie colle ce qu'il y a dans la fenetre

                        as tu deja lancé combofix une fois ? supprime toutes les traces de logiciels qui ne sont pas supprimé par toolcleaner et ensuite poste un RSIT

                        on va voir pour combofix si on peut pas s'en passer
                        0
                        1. salut,je n'aie pas été sur mon pc aujourd'hui et demain matin je travaille,là je repars sur toolclaner comme tu m'as dit et j'envoie le rapport
                          0
                          1. Bon ben il me télécharge toolclaener mais il me marque que ce n'est pas une application de je sais plus quoi et à la fin WIn32.
                            j'aie remarquée que mon antivirus (celui de SFR) bloque toujours "Backdoor.Win32.IRCBot.hym,chemin:c/windows.",il me dit que c'est un virus,j'aie mis en quarantaine!
                            0
                            Précédent
                            • 1
                            • 2