Help rapport hijackthis !! J'comprends pas =(

Fermé
Moi - 13 mars 2009 à 21:24
jacques.gache Messages postés 33453 Date d'inscription mardi 13 novembre 2007 Statut Contributeur sécurité Dernière intervention 25 janvier 2016 - 18 mars 2009 à 18:06
Bonjour,
Je trouve ma connexion internet plutôt lente et j'ai voulu vérifier avec hijackthis si il n'y avait pas un problème. Le problème est que je n'y connais rien alors je voulais savoir si quelqu'un pouvait me dire s'il voit un problème ou non.
Merci à tous!

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:09:24, on 13/03/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\PRISMSVR.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Brother\ControlCenter3\brccMCtl.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\vsnpstd.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\ZSSnp211.exe
C:\WINDOWS\Domino.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\Sony Corporation\Picture Package\Picture Package Menu\SonyTray.exe
C:\Program Files\Sony Corporation\Picture Package\Picture Package Applications\Residence.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe
C:\Documents and Settings\Grégoire\Mes documents\firefox.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgwb.dat
C:\DOCUME~1\Fabienne\LOCALS~1\Temp\Rar$EX00.969\HijackThis.exe
C:\DOCUME~1\Fabienne\LOCALS~1\Temp\Rar$EX02.812\HijackThis.exe
C:\DOCUME~1\Fabienne\LOCALS~1\Temp\Rar$EX02.906\HijackThis.exe
C:\WINDOWS\system32\wuauclt.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = "C:\Program Files\Outlook Express\msimn.exe"
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: (no name) - {EEE6C35D-6118-11DC-9C72-001320C79847} - (no file)
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: dcads - {4da28b2d-8654-e6b6-3a33-2a9ed4813a92} - C:\WINDOWS\system32\nss128.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: dcads - {733716E1-76D2-4003-AC39-845281C0EF85} - C:\WINDOWS\system32\nsx10C.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: browser optimizer superiorads - {8E015787-B1E3-404a-95DE-3E71E1FA0305} - C:\WINDOWS\system32\spads.dll (file missing)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'Default user')
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Créer un favori mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1109867453062
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{C51946B8-4CB7-4CD8-9326-D153180C7BC6}: NameServer = 212.27.54.252,212.27.53.252
O17 - HKLM\System\CCS\Services\Tcpip\..\{E79FD5E2-DFA5-42CB-83C8-16257CE6A49B}: NameServer = 212.27.53.252,212.27.54.252
O20 - AppInit_DLLs: C:\WINDOWS\system32\rlai.dll
O20 - Winlogon Notify: RelevantKnowledge - C:\WINDOWS\system32\rlls.dll (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe

37 réponses

jacques.gache Messages postés 33453 Date d'inscription mardi 13 novembre 2007 Statut Contributeur sécurité Dernière intervention 25 janvier 2016 1 616
13 mars 2009 à 21:28
bonjour je fais des recherches consernant certaine lignes et je reviens
0
ok merci à toi !
0
T'es toujours la ?
0
jacques.gache Messages postés 33453 Date d'inscription mardi 13 novembre 2007 Statut Contributeur sécurité Dernière intervention 25 janvier 2016 1 616
13 mars 2009 à 21:40
bonjour, tu as encore le service symantec " norton " qui est actif il faudra l'arrêter on vèra après , la tu vas faire otmoveit et puis passer malwarebytes , Merci

1) Télécharge OTMoveIt3 de OldTimer sur ton Bureau en cliquant sur ce lien :

http://oldtimer.geekstogo.com/OTMoveIt3.exe

Double-clique sur OTMoveIt3.exe pour le lancer.

Vérifie que la case devant "Unregister Dll's and Ocx's est bien cochée.

Copie la liste qui se trouve en gras ci-dessous,

et colle-la dans le cadre de gauche de OTMoveIt : "Paste instructions for item to be moved".

:processes
explorer.exe

:files
c:\windows\system32\nss128.dll
c:\windows\system32\nsx10c.dll
c:\windows\system32\spads.dll
c:\windows\system32\rlai.dll
c:\windows\system32\rlls.dll


:Commands
[purity]
[emptytemp]
[start explorer]
[reboot]



Clique sur "MoveIt!" pour lancer la suppression.

Le résultat apparaitra dans le cadre "Results".

Clique sur "Exit" pour fermer.

Poste le rapport situé dans C:\_OTMoveIt\MovedFiles sous le nom xxxxxx_xxxxxxxxxx.log .

Il te sera peut-être demander de redémarrer le pc pour achever la suppression. Si c'est le cas accepte par Yes.




2) Télécharge Malwarebytes' Anti-Malware: https://www.malekal.com/tutoriel-malwarebyte-anti-malware/

. sur la page cliques sur Télécharger Malwarebyte's Anti-Malware
. enregistres le sur le bureau
. Double cliques sur le fichier téléchargé pour lancer le processus d'installation.
. si le pare-feu demande l'autorisation de se connecter pour malwarebytes, acceptes
. Il va se mettre à jour une fois faite
. rend-toi dans l'onglet, Recherche
. Sélectionnes Exécuter un examen complet
. Cliques sur Rechercher
. Le scan démarre.
. A la fin de l'analyse, un message s'affiche :
L'examen s'est terminé normalement. Cliquez sur 'Afficher les résultats' pour afficher tous les objets trouvés.
. Cliques sur Ok pour poursuivre.
. Si des malwares ont été détectés, cliques sur Afficher les résultats
. Sélectionnes tout (ou laisses cochés)

. cliques sur Supprimer la sélection

. Malwarebytes va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.
. Malwarebytes va ouvrir le bloc-notes et y copier le rapport d'analyse.
. redemarre le pc
. une fois redémarré double-cliques sur malwarebytes
. rends toi dans l'onglet rapport/log
. tu cliques dessus pour l'afficher une fois affiché
. tu cliques sur edition en haut du boc notes,et puis sur sélectionner tous
. tu recliques sur edition et puis sur copier et tu reviens sur le forum et dans ta réponse
. tu cliques droit dans le cadre de la reponse et coller


0
Merci jacques.gache pour ta réponse complète, j'en suis à la fin de la partie 1 (j'ai redémaré mon ordi mais je ne comprends pas cette étape:

Poste le rapport situé dans C:\_OTMoveIt\MovedFiles sous le nom xxxxxx_xxxxxxxxxx.log .

Pourrais-tu me la réexpliquer s'il te plait ?
Merci encore!
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
(J'en suis au scan de la partie 2) Sinon pour la partie 1 je crois avoir compris, tu veux que je poste ça ? :

========== PROCESSES ==========
Process explorer.exe killed successfully.
========== FILES ==========
File/Folder c:\windows\system32\nss128.dll not found.
File/Folder c:\windows\system32\nsx10c.dll not found.
File/Folder c:\windows\system32\spads.dll not found.
File/Folder c:\windows\system32\rlai.dll not found.
File/Folder c:\windows\system32\rlls.dll not found.
========== COMMANDS ==========
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\INDEX.DAT scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
Windows Temp folder emptied.
Java cache emptied.
File delete failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\XUL.mfl scheduled to be deleted on reboot.
FireFox cache emptied.
Temp folders emptied.
Explorer started successfully

OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 03132009_215455

Files moved on Reboot...
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\INDEX.DAT scheduled to be moved on reboot.
C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\_CACHE_001_ moved successfully.
C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\_CACHE_002_ moved successfully.
C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\_CACHE_003_ moved successfully.
C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\_CACHE_MAP_ moved successfully.
C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\urlclassifier3.sqlite moved successfully.
C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\XUL.mfl moved successfully.
0
jacques.gache Messages postés 33453 Date d'inscription mardi 13 novembre 2007 Statut Contributeur sécurité Dernière intervention 25 janvier 2016 1 616
13 mars 2009 à 22:27
C:\_OTMoveIt\MovedFiles sous le nom xxxxxx_xxxxxxxxxx.log est le chemin pour retrouver le rapport de otmoveit tu vas dans ton disque dur système qui est généralement C et tu cherches le dossier otmoveit que tu ouvres , et puis le dossier MovedFiles dans celui-ci tu dois avoir un document format texte "blocs notes" les xxxxxx_xxxxxxxxxx normalement correspondent à la date et heure de la création du rapport
0
C'est donc bien ce que j'ai posté ?
0
jacques.gache Messages postés 33453 Date d'inscription mardi 13 novembre 2007 Statut Contributeur sécurité Dernière intervention 25 janvier 2016 1 616
13 mars 2009 à 22:32
ok , je vois qu tu as trouvé le rapport donc ne tient pas compte de mon dernier message fais malwarebytes, car la je comprend pas le résultat
File/Folder c:\windows\system32\nss128.dll not found. 
File/Folder c:\windows\system32\nsx10c.dll not found. 
File/Folder c:\windows\system32\spads.dll not found. 
File/Folder c:\windows\system32\rlai.dll not found. 
File/Folder c:\windows\system32\rlls.dll not found. 

cela veut dire qu'il n'a rien trouver si malwarebytes ne les trouve pas ou si il ne les vire pa non plus on refera otmoveit mais en mode sans echec
0
Ok ba malwarebytes est en cours, j'en suis à 42300 éléments examinés, ce qui fait 25 minutes, et j'ai pour l'instant 20 éléments infectés.

=(
0
jacques.gache Messages postés 33453 Date d'inscription mardi 13 novembre 2007 Statut Contributeur sécurité Dernière intervention 25 janvier 2016 1 616
13 mars 2009 à 22:38
ok sois patient car cela peut prendre près de 2h mais surtout tu clique bien sur supprimer la sélection une fois l'examen terminé et poste le rapport si je te répond pas tout de suite c'est que je serais parti dormir et je regarderais demain
0
Ok merci pour ton aide!

Sinon, ca devrait être bon après avoir supprimé les éléments infectés ?
Ya pas d'autres logiciels à télécharger ?

Bon, je vais posté tout ça et je te laisse dormir si c'est trop long.
A tout à l'heure ou peut-être à demain ! =)
0
jacques.gache Messages postés 33453 Date d'inscription mardi 13 novembre 2007 Statut Contributeur sécurité Dernière intervention 25 janvier 2016 1 616
13 mars 2009 à 22:45
on va attendre de voir ce que malwarebytes va nous avoir trouver et supprimé et on avisera les outils à télécharger en proportion
0
J'ai oublié de préciser qqch qui est peut-être important : j'ai lancé deux fois OTMoveIt3.
Le rapport que j'ai posté vient du deuxième scan car j'ai eu un problème de lag de l'ordinateur avec le premier scan et j'ai donc recommencé une deuxième fois (les deux scans ont été réalisés en entier).
Peut-être que ça n'a aucune importance mais je tiens juste à le préciser.
0
jacques.gache Messages postés 33453 Date d'inscription mardi 13 novembre 2007 Statut Contributeur sécurité Dernière intervention 25 janvier 2016 1 616
13 mars 2009 à 23:13
ok la je comprends mieux pourquoi il n'a rien trouvé tu n'as pas le rapport du premier par hazard
0
Bon voila ça devrait être le premier:


========== PROCESSES ==========
Process explorer.exe killed successfully.
========== FILES ==========
c:\windows\system32\nss128.dll unregistered successfully.
c:\windows\system32\nss128.dll moved successfully.
c:\windows\system32\nsx10C.dll unregistered successfully.
c:\windows\system32\nsx10C.dll moved successfully.
File/Folder c:\windows\system32\spads.dll not found.
DllUnregisterServer procedure not found in c:\windows\system32\rlai.dll
c:\windows\system32\rlai.dll NOT unregistered.
c:\windows\system32\rlai.dll moved successfully.
File/Folder c:\windows\system32\rlls.dll not found.
========== COMMANDS ==========
File delete failed. C:\DOCUME~1\Fabienne\LOCALS~1\Temp\Rar$EX02.906\HijackThis.exe scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Fabienne\LOCALS~1\Temp\etilqs_2Id8nnINiLGPQ4ryeYF8 scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Fabienne\LOCALS~1\Temp\~DF147B.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Fabienne\LOCALS~1\Temp\~DF7AFC.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Fabienne\LOCALS~1\Temp\~DF7B07.tmp scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\INDEX.DAT scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
Windows Temp folder emptied.
Java cache emptied.
File delete failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\01889805d01 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\1A38215Ed01 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\264BB7B7d01 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\2A229243d01 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\44CB876Cd01 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\5C48EFCEd01 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\8845E8EBd01 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\8EFCD9B7d01 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\9455C282d01 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\BA0F876Dd01 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\BCCCC87Bd01 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\C0CD8E4Cd01 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\CC76BFA2d01 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\CD01889Bd01 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\D5FB611Dd01 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\XUL.mfl scheduled to be deleted on reboot.
FireFox cache emptied.
Temp folders emptied.
Explorer started successfully

OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 03132009_214422

Files moved on Reboot...
C:\DOCUME~1\Fabienne\LOCALS~1\Temp\Rar$EX02.906\HijackThis.exe moved successfully.
File C:\DOCUME~1\Fabienne\LOCALS~1\Temp\etilqs_2Id8nnINiLGPQ4ryeYF8 not found!
File C:\DOCUME~1\Fabienne\LOCALS~1\Temp\~DF147B.tmp not found!
File C:\DOCUME~1\Fabienne\LOCALS~1\Temp\~DF7AFC.tmp not found!
File C:\DOCUME~1\Fabienne\LOCALS~1\Temp\~DF7B07.tmp not found!
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\INDEX.DAT scheduled to be moved on reboot.
File C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\01889805d01 not found!
File C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\1A38215Ed01 not found!
File C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\264BB7B7d01 not found!
File C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\2A229243d01 not found!
File C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\44CB876Cd01 not found!
File C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\5C48EFCEd01 not found!
File C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\8845E8EBd01 not found!
File C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\8EFCD9B7d01 not found!
File C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\9455C282d01 not found!
File C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\BA0F876Dd01 not found!
File C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\BCCCC87Bd01 not found!
File C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\C0CD8E4Cd01 not found!
File C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\CC76BFA2d01 not found!
File C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\CD01889Bd01 not found!
File C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\D5FB611Dd01 not found!
File move failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\_CACHE_001_ scheduled to be moved on reboot.
File move failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\_CACHE_002_ scheduled to be moved on reboot.
File move failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\_CACHE_003_ scheduled to be moved on reboot.
File move failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\Cache\_CACHE_MAP_ scheduled to be moved on reboot.
File move failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\urlclassifier3.sqlite scheduled to be moved on reboot.
File move failed. C:\Documents and Settings\Fabienne\Local Settings\Application Data\Mozilla\Firefox\Profiles\dxe8uujr.default\XUL.mfl scheduled to be moved on reboot.
0
jacques.gache Messages postés 33453 Date d'inscription mardi 13 novembre 2007 Statut Contributeur sécurité Dernière intervention 25 janvier 2016 1 616
14 mars 2009 à 00:48
ok merci c'est bien le premier , je vais dormir je regarderais malwarebytes demain @+
0
Rebonjour jacques !!

Je me suis couché aussi je ne savais pas combien de temps ça allait prendre...
Le scan s'est terminé au bout de 2h45 et voici ce que ça donne:

Malwarebytes' Anti-Malware 1.34
Version de la base de données: 1845
Windows 5.1.2600 Service Pack 2

14/03/2009 07:14:13
mbam-log-2009-03-14 (07-14-13).txt

Type de recherche: Examen complet (C:\|)
Eléments examinés: 215775
Temps écoulé: 2 hour(s), 44 minute(s), 9 second(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 21
Valeur(s) du Registre infectée(s): 1
Elément(s) de données du Registre infecté(s): 1
Dossier(s) infecté(s): 5
Fichier(s) infecté(s): 40

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):
HKEY_CLASSES_ROOT\rotator.gizmo3 (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\rotator.gizmo3.1 (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{c1a6d8b8-93c3-4186-9dd1-13983f9f1d9b} (Adware.RightOnAds) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{8e015787-b1e3-404a-95de-3e71e1fa0305} (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{3160f356-e8c3-4de2-a698-92eeeb3d3400} (Adware.RightOnAds) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\{8d71eeb8-a1a7-4733-8fa2-1cac015c967d} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d8282e6-bc4f-469b-aaed-7e4ff077ad93} (Adware.RightOnAds) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{733716e1-76d2-4003-ac39-845281c0ef85} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{6fc3c36d-7635-4d43-ba62-0d9d2f2cd06e} (Adware.Fotomoto) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{8e015787-b1e3-404a-95de-3e71e1fa0305} (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{b64f4a7c-97c9-11da-8bde-f66bad1e3f3a} (Rogue.WinAntivirus) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{2178f3fb-2560-458f-bdee-631e2fe0dfe4} (Rogue.WinAntivirus) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{b5141620-c2b2-4d95-9f0f-134d99c87ab0} (Rogue.WinAntivirus) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8e015787-b1e3-404a-95de-3e71e1fa0305} (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2cbd1bb3-9ac7-4d7f-9023-8a3e8dfb841a} (Adware.RelevantKnowledge) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\messengerskinner (Adware.EGDAccess) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\Sidebar.DLL (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\superiorads (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\AdvRemoteDbg (Adware.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\MessengerSkinner (Rogue.MessengerSkinner) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\dcads (Adware.Dcads) -> Quarantined and deleted successfully.

Valeur(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\spa_start (Adware.BHO) -> Quarantined and deleted successfully.

Elément(s) de données du Registre infecté(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowHelp (Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.

Dossier(s) infecté(s):
C:\Documents and Settings\Fabienne\Application Data\DriveCleaner Free (Rogue.DriveCleaner) -> Quarantined and deleted successfully.
C:\Documents and Settings\Fabienne\Application Data\DriveCleaner Free\Logs (Rogue.DriveCleaner) -> Quarantined and deleted successfully.
C:\Program Files\MessengerSkinner (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\MessengerSkinner\download (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\MessengerSkinner\resources (Adware.EGDAccess) -> Quarantined and deleted successfully.

Fichier(s) infecté(s):
C:\Documents and Settings\Sylvain\Local Settings\Application Data\msiuakc_navps.dat (Adware.Navipromo.H) -> Quarantined and deleted successfully.
C:\Documents and Settings\Sylvain\Local Settings\Application Data\msiuakc_nav.dat (Adware.Navipromo.H) -> Quarantined and deleted successfully.
C:\Documents and Settings\Sylvain\Local Settings\Application Data\msiuakc.dat (Adware.Navipromo.H) -> Quarantined and deleted successfully.
C:\Documents and Settings\Sylvain\Local Settings\Application Data\msiuakc.exe (Adware.Navipromo.H) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jules\Application Data\MessengerSkinner\Userdata\defaultPack.cab (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Program Files\MessengerSkinner\MessengerSkinnerDll.dll (Rogue.MessengerSkinner) -> Quarantined and deleted successfully.
C:\WINDOWS\WinLockDll.dll (Malware.Tool) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\silc_dll.dll (Spyware.Marketscore) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\WhoisCL.exe (Adware.BHO) -> Quarantined and deleted successfully.
C:\_OTMoveIt\MovedFiles\03132009_214422\windows\system32\rlai.dll (Adware.BHO) -> Quarantined and deleted successfully.
C:\Documents and Settings\Fabienne\Application Data\DriveCleaner Free\Logs\update.log (Rogue.DriveCleaner) -> Quarantined and deleted successfully.
C:\Program Files\MessengerSkinner\MessengerSkinner.exe (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\MessengerSkinner\uninst.exe (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\MessengerSkinner\download\defaultPack.cab (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\MessengerSkinner\resources\appconfig.xml (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\MessengerSkinner\resources\btn.rgn (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\MessengerSkinner\resources\btnBnr.rgn (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\MessengerSkinner\resources\btnIn.rgn (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\MessengerSkinner\resources\btnInNormal.bmp (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\MessengerSkinner\resources\btnInOver.bmp (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\MessengerSkinner\resources\btnNormal.bmp (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\MessengerSkinner\resources\btnNormal.gif (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\MessengerSkinner\resources\btnNormalBnr.bmp (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\MessengerSkinner\resources\btnNormalBnr.gif (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\MessengerSkinner\resources\btnOver.bmp (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\MessengerSkinner\resources\btnOver.gif (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\MessengerSkinner\resources\btnOverBnr.bmp (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\MessengerSkinner\resources\btnOverBnr.gif (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\Program Files\MessengerSkinner\resources\languages_v2.xml (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\superiorads-uninst.exe (Adware.BHO) -> Quarantined and deleted successfully.
C:\Documents and Settings\Fabienne\Application Data\urlredir.cfg (Adware.RightOnAds) -> Quarantined and deleted successfully.
C:\Documents and Settings\Grégoire\Application Data\urlredir.cfg (Adware.RightOnAds) -> Quarantined and deleted successfully.
C:\Documents and Settings\Sylvain\Application Data\urlredir.cfg (Adware.RightOnAds) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\model.dat (Spyware.MarketScore) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\LDPackage.dll (Spyware.MarketScore) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\rlph.dll (Spyware.MarketScore) -> Quarantined and deleted successfully.
C:\WINDOWS\uid.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\tcydarcdh_navps.dat (Adware.NaviPromo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\tcydarcdh_nav.dat (Adware.NaviPromo) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\nvs2.inf (Adware.EGDAccess) -> Quarantined and deleted successfully.
0
jacques.gache Messages postés 33453 Date d'inscription mardi 13 novembre 2007 Statut Contributeur sécurité Dernière intervention 25 janvier 2016 1 616
14 mars 2009 à 17:53
bonjour, il a bien bossé , tu ouvres malwarebytes tu vides la quarantaine, ne retélécharge pas MessengerSkinner c'est une grosse merde .

tu vas passer AD-Remover et poster le rapport, Merci

Télécharge AD-Remover de C_XX sur ton Bureau :
http://sd-1.archive-host.com/membres/up/16506160323759868/AD-R.exe

Ferme toutes les applications en cours, y compris ton navigateur *.
Désactive ton antivirus.

Double-clique sur AD-R.exe et installe-le dans le répertoire par défaut. ( C:\Program files )

Double clique sur l'icône Ad-remover
https://i75.servimg.com/u/f75/11/05/93/83/ad-r10.jpg

Au menu principal choisis l'option A

Poste le rapport qui apparait à la fin du scan.
Il est sauvegardé ici : C:\Ad-report(date).log

* Process.exe, un composant de l'outil, est détecté par certains antivirus, (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
C'est pourquoi il faut désactiver provisoirement ton antivirus.

0
Bon j'ai suivi ce que tu as dis et voici le rapport:


------- LOGFILE OF AD-REMOVER 1.1.1.7 | ONLY XP/VISTA -------

Updated by C_XX on 11/03/2009 at 11:30

Start at: 18:10:07, Sam 14/03/2009 | Boot mode: Normal Boot
Option: SCAN | Executed from: C:\Program Files\Ad-remover\Ad-remover.bat
Operating System: Microsoft® Windows XP™ Service Pack 2 (version 5.1.2600)
Computer Name: MINILOUP
Current User: Fabienne - Administrator
Drive(s):
- C:\ (File System: NTFS)
- E:\ (File System: CDFS)
- F:\ (File System: FAT32)
System Drive: C:\
Windows Directory: C:\WINDOWS\
System Directory: C:\WINDOWS\System32\

--- Running Processes: 50

+-----------------| Boonty/Boonty Games Elements Found:

Service: Boonty Games
.
HKCU\Software\Boonty
HKLM\Software\Boonty
HKLM\System\ControlSet001\Services\Boonty Games
HKLM\System\CurrentControlSet\Services\Boonty Games
HKLM\System\ControlSet003\Services\Boonty Games
.
C:\Program Files\Boonty
C:\Program Files\BoontyGames
C:\Program Files\Fichiers communs\BOONTY Shared
C:\Documents and Settings\All Users\Application Data\BOONTY

+-----------------| Eorezo Elements Found:

.

+-----------------| Infected Poker Softwares Elements Found:

.
0
Je ne suis pas sur d'avoir bien réussi à arrêter l'antivirus, (c'est une version gratuite d'avg) mais je pense l'avoir fait vu que j'ai réussi à obtenir le scan.
0
jacques.gache Messages postés 33453 Date d'inscription mardi 13 novembre 2007 Statut Contributeur sécurité Dernière intervention 25 janvier 2016 1 616
14 mars 2009 à 18:34
bon tu vas relancer ad-remover pour faire la suppression tu postes le rapport suivi d'un nouveau hijackthis pour contrôler et finir le nettoyage , tu pourras en attendant la lecture de ton hijackthis faire la désinstallation de ad-remover

Fermes toutes les applications en cours, y compris ton navigateur
.
Relances "Ad-remover". tu choisis l'option B

et tu coches tout et tu le lances laisses le travailler en appuyant sur S

et postes le rapport générer


Il est sauvegardé ici : C:\Ad-report(date).log



désinstallation de ad-renover:


Via l'Explorateur Windows, ouvre le répertoire C:\Program Files\Ad-remover.
Double-clique sur le fichier Uninstal.exe.

Supprime les fichiers : C:\Ad-report(date).log
Supprime ensuite le répertoire C:\Program Files\AD-Remover qui sera vide.
0
Ok, tout est supprimé et voici le rapport: (je dois partir un moment et je reviendrai peut-être dans deux heures ou alors demain matin, encore merci de ton aide! )


------- LOGFILE OF AD-REMOVER 1.1.1.7 | ONLY XP/VISTA -------

Updated by C_XX on 11/03/2009 at 11:30

**** LIMITED TO ****

Boonty/BoontyGames
Eorezo
Infected Poker Softwares
FunWebProduct/MyWay/MyWebSearch
It's TV
Sweetim
Other Adwares

********************

Start at: 18:37:45, Sam 14/03/2009 | Boot mode: Normal Boot
Option: CLEAN | Executed from: C:\Program Files\Ad-remover\Ad-remover.bat
Operating System: Microsoft® Windows XP™ Service Pack 2 (version 5.1.2600)
Computer Name: MINILOUP
Current User: Fabienne - Administrator
Drive(s):
- C:\ (File System: NTFS)
- D:\ (File System: CDFS)
System Drive: C:\
Windows Directory: C:\WINDOWS\
System Directory: C:\WINDOWS\System32\

--- Running Processes: 49

(!) ---- IE start pages/Tabs reset

+-----------------| Boonty/Boonty Games Elements Deleted :

Service: "Boonty Games"
.
HKCU\Software\Boonty
HKLM\Software\Boonty
HKLM\System\ControlSet003\Services\Boonty Games
.
C:\Program Files\Boonty
C:\Program Files\BoontyGames
C:\Program Files\Fichiers communs\BOONTY Shared
C:\Documents and Settings\All Users\Application Data\BOONTY

+-----------------| Eorezo Elements Deleted :

.
0
jacques.gache Messages postés 33453 Date d'inscription mardi 13 novembre 2007 Statut Contributeur sécurité Dernière intervention 25 janvier 2016 1 616
14 mars 2009 à 19:17
ok je suis ce soir sur le pc jusqua minuit environ sinon demain je ne serais pas sur le pc donc si on fini pas ce soir cela sera pour lundi
0
C'est bon je suis la, je fais quoi maintenant ?
0