Impssible de supprimé une ligne avec hijak

asus02 Messages postés 215 Statut Membre -  
Ced_King Messages postés 3519 Date d'inscription   Statut Contributeur Dernière intervention   -
Bonjour,
petit soucis avec hijak et vista, je n'arrive pas a supprimer une ligne 020\dll
voici la ligne

O20 - AppInit_DLLs: C:\Windows\System32\dot3gpclnt32.dll

merci
Configuration: Windows Vista
Firefox 2.0.0.20

5 réponses

  1. Ced_King Messages postés 3519 Date d'inscription   Statut Contributeur Dernière intervention   667
     
    Salut,

    * Tu ne supprimeras pas l'infection en fixant les lignes sur hijackthis

    - Sous vista, desactives le controle des comptes utilisateurs --> panneau de config --> comptes utilisateur --> desactiver le controle des comptes utilisateurs

    Telecharges RSIT " Random's System Information Tool " sur ton bureau : http://images.malwareremoval.com/random/RSIT.exe

    - Fermes toutes les applications en cours et clic-droit ( executer en tant qu'admin.) sur RSIT.exe
    - Selectionnes " Continue " à l'ecran >> RSIT va analyser le pc et verifier si l'outil hijackthis ( version à jour) est present sur le pc, si ce n'est pas le cas, RSIT le telechargera >> acceptes la license
    - Une fois l'analyse terminée, 2 rapports.txt s'ouvrent, log.txt à l'écran et info.txt dans la barre des taches
    - Postes le contenu des 2 rapports
    0
  2. asus02 Messages postés 215 Statut Membre 13
     
    merci pour ta rapidité

    -------------------------------------------------------------------------------------------
    info.txt logfile of random's system information tool 1.06 2009-04-30 20:57:42

    ======Uninstall list======

    -->"C:\Program Files\HP Games\Bejeweled 2 Deluxe\Uninstall.exe"
    -->"C:\Program Files\HP Games\Blasterball 3\Uninstall.exe"
    -->"C:\Program Files\HP Games\Bricks of Egypt\Uninstall.exe"
    -->"C:\Program Files\HP Games\Chuzzle Deluxe\Uninstall.exe"
    -->"C:\Program Files\HP Games\Crystal Maze\Uninstall.exe"
    -->"C:\Program Files\HP Games\Digby's Donuts\Uninstall.exe"
    -->"C:\Program Files\HP Games\Diner Dash 2 Restaurant Rescue\Uninstall.exe"
    -->"C:\Program Files\HP Games\Diner Dash\Uninstall.exe"
    -->"C:\Program Files\HP Games\FATE\Uninstall.exe"
    -->"C:\Program Files\HP Games\Fish Tycoon\Uninstall.exe"
    -->"C:\Program Files\HP Games\Gem Shop\Uninstall.exe"
    -->"C:\Program Files\HP Games\Insaniquarium Deluxe\Uninstall.exe"
    -->"C:\Program Files\HP Games\Magic Academy\Uninstall.exe"
    -->"C:\Program Files\HP Games\Mah Jong Quest\Uninstall.exe"
    -->"C:\Program Files\HP Games\My HP Game Console\Uninstall.exe"
    -->"C:\Program Files\HP Games\Ocean Express\Uninstall.exe"
    -->"C:\Program Files\HP Games\Peggle\Uninstall.exe"
    -->"C:\Program Files\HP Games\Penguins!\Uninstall.exe"
    -->"C:\Program Files\HP Games\Polar Bowler\Uninstall.exe"
    -->"C:\Program Files\HP Games\Polar Golfer Pineapple Cup\Uninstall.exe"
    -->"C:\Program Files\HP Games\Polar Golfer\Uninstall.exe"
    -->"C:\Program Files\HP Games\Puzzle Express\Uninstall.exe"
    -->"C:\Program Files\HP Games\Ricochet Lost Worlds\Uninstall.exe"
    -->"C:\Program Files\HP Games\Slingo Deluxe\Uninstall.exe"
    -->"C:\Program Files\HP Games\Sudoku Quest\Uninstall.exe"
    -->"C:\Program Files\HP Games\Super Granny\Uninstall.exe"
    -->"C:\Program Files\HP Games\Tradewinds\Uninstall.exe"
    -->"C:\Program Files\HP Games\Treasure Island\Uninstall.exe"
    -->"C:\Program Files\HP Games\Virtual Villagers - A New Home\Uninstall.exe"
    -->"C:\Program Files\HP Games\Zuma Deluxe\Uninstall.exe"
    Adobe Flash Player 10 ActiveX-->C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
    Adobe Flash Player 10 Plugin-->C:\Windows\system32\Macromed\Flash\uninstall_plugin.exe
    Adobe Reader 8.1.2 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A81200000003}
    Adobe Shockwave Player 11.5-->C:\Windows\system32\Adobe\uninstaller.exe
    Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
    avast! Antivirus-->C:\Program Files\Alwil Software\Avast4\aswRunDll.exe "C:\Program Files\Alwil Software\Avast4\Setup\setiface.dll",RunSetup
    Brother MFL-Pro Suite-->"C:\Program Files\InstallShield Installation Information\{9A912C12-A7DA-44D7-BD57-5CA85E2F33E1}\Setup.exe" -runfromtemp -l0x040c Brunin03.dll -removeonly
    Cartoonist 1.3-->"C:\Program Files\Cartoonist\unins000.exe"
    Catalyst Control Center - Branding-->MsiExec.exe /I{2E4609A3-F5AF-4408-B0C4-B8B84BC753DF}
    CrazyTalk v5.0 PRO Trial-->C:\Program Files\InstallShield Installation Information\{2EB3B0AB-4FEB-4548-B7E7-7A0E73F69125}\setup.exe -runfromtemp -l0x0009 -removeonly /remove
    CyberLink DVD Suite Deluxe-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}\Setup.exe" -uninstall
    CyberLink PowerDirector-->"C:\Program Files\InstallShield Installation Information\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}\setup.exe" /z-uninstall
    DjaSoft ! Stocks & Commercial (Standard) - version 1.8.0 A du -->"C:\Program Files\DjaSoft\unins000.exe"
    eMule-->"C:\Program Files\eMule\Uninstall.exe"
    FastStone Capture 6.3-->C:\Program Files\FastStone Capture\uninst.exe
    FlashGet 1.9.6.1073-->C:\Program Files\FlashGet\uninst.exe
    Google Toolbar for Internet Explorer-->"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_0531C63A913CC9D1.exe" /uninstall
    Google Update Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
    Google Earth-->MsiExec.exe /X{548EAC70-EE00-11DD-908C-005056806466}
    Hewlett-Packard Active Check for Health Check-->MsiExec.exe /X{254C37AA-6B72-4300-84F6-98A82419187E}
    Hewlett-Packard Asset Agent for Health Check-->MsiExec.exe /X{669D4A35-146B-4314-89F1-1AC3D7B88367}
    Hidden Secrets The Nightmare fr-->"C:\Program Files\BoontyGames\Hidden Secrets The Nightmare\unins000.exe"
    HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
    HP Active Support Library-->C:\Program Files\InstallShield Installation Information\{E0810CC2-4B5B-4439-B1D0-452306AF2D64}\setup.exe -runfromtemp -l0x0409
    HP Customer Experience Enhancements-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C27C82E4-9C53-4D76-9ED3-A01A3D5EE679}\setup.exe" -l0x9 -removeonly
    HP Customer Feedback-->MsiExec.exe /I{9DBA770F-BF73-4D39-B1DF-6035D95268FC}
    HP Easy Setup - Frontend-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E1476612-02D6-42A3-BDC1-E292B4115738}\setup.exe" -l0x9 -removeonly
    HP Picasso Media Center Add-In-->MsiExec.exe /I{55979C41-7D6A-49CC-B591-64AC1BBE2C8B}
    HP Total Care Advisor-->MsiExec.exe /X{f32502b5-5b64-4882-bf61-77f23edcac4f}
    HP Update-->MsiExec.exe /X{11B83AD3-7A46-4C2E-A568-9505981D4C6F}
    Java(TM) SE Runtime Environment 6 Update 1-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160010}
    LabelPrint-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C59C179C-668D-49A9-B6EA-0121CCFC1243}\Setup.exe" -uninstall
    LightScribe System Software 1.12.37.1-->MsiExec.exe /X{004C5DA2-2051-4D25-94BA-51CF810C91EB}
    Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
    MessenPass-->C:\Windows\zipinst.exe /uninst "C:\Program Files\MessenPass\uninst1~.nsu"
    Microsoft Office PowerPoint Viewer 2003-->MsiExec.exe /X{90AF040C-6000-11D3-8CFE-0150048383C9}
    Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
    Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
    Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{A49F249F-0C91-497F-86DF-B2585E8E76B7}
    Microsoft Works-->MsiExec.exe /I{3B160861-7250-451E-B5EE-8B92BF30A710}
    Mozilla Firefox (2.0.0.20)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
    muvee autoProducer 6.1-->C:\Program Files\InstallShield Installation Information\{FDDB69BB-2F9A-4830-A579-ABBB7C5AF9A8}\muveesetup.exe -removeonly -runfromtemp
    My HP Games-->"C:\Program Files\HP Games\Uninstall.exe"
    neroxml-->MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
    NVIDIA Drivers-->C:\Windows\system32\nvuninst.exe UninstallGUI
    Orange - Logiciels Internet-->C:\Program Files\OrangeHSS\installation\core\Installgui.exe -u
    Orange Plug-in messagerie vocale 888-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{16E79B1D-D1C2-4CA6-8B23-F4D890E0DCB9}\Setup.exe" -l0x40c --AddRemove
    Outils de diagnostic du matériel-->C:\Program Files\PC-Doctor 5 for Windows\uninst.exe
    Photo! Web Album 1.2-->"C:\Program Files\Photo!\Photo! Web Album\unins000.exe"
    PokerStars.net-->"C:\Program Files\PokerStars.NET\PokerStarsUninstall.exe" /u:PokerStars.net
    Power2Go-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{40BF1E83-20EB-11D8-97C5-0009C5020658}\Setup.exe" -uninstall
    Python 2.5-->MsiExec.exe /I{0A2C5854-557E-48C8-835A-3B9F074BDCAA}
    RadLight MPC DirectShow Filter (remove only)-->"C:\Windows\system32\RadLightMPCUninstall.exe"
    Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -removeonly
    Satsuki Decoder Pack 4000-->C:\Program Files\Satsuki Decoder Pack\Uninstall.exe
    Shareaza 2.4.0.0-->"C:\Program Files\Shareaza\Uninstall\unins000.exe"
    Skype™ 4.0-->MsiExec.exe /X{24D753CA-6AE9-4E30-8F5F-EFC93E08BF3D}
    SoftwareUpdate 1.0-->"C:\Users\janegreg\AppData\Roaming\eoRezo\SoftwareUpdate\unins000.exe"
    Solution de clavier multimédia amélioré-->C:\HP\KBD\Install.exe /u
    SYSTRAN Web Translator 5.0-->MsiExec.exe /I{E0B38894-0E4D-4AE1-B17E-CFBC3692E86A}
    Téléchargeur de Sonic Adventure DX fr-->"C:\Program Files\Téléchargeur de Sonic Adventure DX\unins000.exe"
    VLC media player 0.9.4-->C:\Program Files\VideoLAN\VLC\uninstall.exe
    Windows Live installer-->MsiExec.exe /X{FD44E544-E7D0-4DBA-9FA0-8AE1A1300390}
    Windows Live Messenger-->MsiExec.exe /I{F6326B60-1B1D-4ABF-BFCD-7B7404F44411}
    Windows Live Sign-in Assistant-->MsiExec.exe /I{49672EC2-171B-47B4-8CE7-50D7806360D7}
    Windows Live Toolbar-->"C:\Program Files\Windows Live Toolbar\UnInstall.exe" {05AE605F-3146-46ED-BC52-0A14EBF57962}
    Windows Live Toolbar-->MsiExec.exe /X{05AE605F-3146-46ED-BC52-0A14EBF57962}
    Windows Media Player Firefox Plugin-->MsiExec.exe /I{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}
    Yahoo! Messenger-->C:\PROGRA~1\Yahoo!\MESSEN~1\UNWISE.EXE /U C:\PROGRA~1\Yahoo!\MESSEN~1\INSTALL.LOG

    =====HijackThis Backups=====

    O20 - AppInit_DLLs: C:\Windows\System32\dot3gpclnt32.dll [2009-04-30]
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll [2009-04-30]
    O2 - BHO: ShareazaPlus Web Download Hook - {57E8CB3A-36CE-4a0c-BE27-95E1196372CC} - C:\Program Files\ShareazaPlus\plugins\RazaWebHook.dll (file missing) [2009-04-30]
    O20 - AppInit_DLLs: C:\Windows\System32\dot3gpclnt32.dll [2009-04-30]
    O20 - AppInit_DLLs: C:\Windows\System32\dot3gpclnt32.dll [2009-04-30]
    O20 - AppInit_DLLs: C:\Windows\System32\dot3gpclnt32.dll [2009-04-30]

    ======Hosts File======

    127.0.0.1 www.007guard.com
    127.0.0.1 007guard.com
    127.0.0.1 008i.com
    127.0.0.1 www.008k.com
    127.0.0.1 008k.com
    127.0.0.1 www.00hq.com
    127.0.0.1 00hq.com
    127.0.0.1 010402.com
    127.0.0.1 www.032439.com
    127.0.0.1 032439.com

    ======Security center information======

    AS: Windows Defender

    ======System event log======

    Computer Name: PC-de-janegreg
    Event Code: 20
    Message: Impossible de régler les diodes indicatrices du clavier.
    Record Number: 51266
    Source Name: i8042prt
    Time Written: 20090429214406.389200-000
    Event Type: Avertissement
    User:

    Computer Name: PC-de-janegreg
    Event Code: 4226
    Message: TCP/IP a atteint la limite de sécurité imposée sur le nombre de tentatives de connexion TCP simultanées.
    Record Number: 51274
    Source Name: Tcpip
    Time Written: 20090429215631.004200-000
    Event Type: Avertissement
    User:

    Computer Name: PC-de-janegreg
    Event Code: 4226
    Message: TCP/IP a atteint la limite de sécurité imposée sur le nombre de tentatives de connexion TCP simultanées.
    Record Number: 51290
    Source Name: Tcpip
    Time Written: 20090430101929.153800-000
    Event Type: Avertissement
    User:

    Computer Name: PC-de-janegreg
    Event Code: 15016
    Message: Impossible d’initialiser le package de sécurité Kerberos pour l’authentification côté serveur. Le champ de données contient le numéro de l’erreur.
    Record Number: 51365
    Source Name: Microsoft-Windows-HttpEvent
    Time Written: 20090430181242.309939-000
    Event Type: Erreur
    User:

    Computer Name: PC-de-janegreg
    Event Code: 7000
    Message: Le service Security Driver n'a pas pu démarrer en raison de l'erreur :
    Security Driver n'est pas une application Win32 valide.
    Record Number: 51408
    Source Name: Service Control Manager
    Time Written: 20090430181304.000000-000
    Event Type: Erreur
    User:

    =====Application event log=====

    Computer Name: PC-de-janegreg
    Event Code: 10
    Message: Le filtre d’événement avec la requête « SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99 » n’a pas pu être réactivé dans l’espace de noms « //./root/CIMV2 » à cause de l’erreur 0x80041003. Les événements ne peuvent pas être délivrés à travers ce filtre tant que le problème ne sera pas corrigé.
    Record Number: 12116
    Source Name: Microsoft-Windows-WMI
    Time Written: 20090429155344.000000-000
    Event Type: Erreur
    User:

    Computer Name: PC-de-janegreg
    Event Code: 1000
    Message: Application défaillante setup.exe_unknown, version 0.0.0.0, horodatage 0x49f5abe1, module défaillant setup.exe, version 0.0.0.0, horodatage 0x49f5abe1, code d’exception 0xc0000005, décalage d’erreur 0x00001dc6, ID du processus 0xb44, heure de début de l’application 0x01c9c99186440398.
    Record Number: 12155
    Source Name: Application Error
    Time Written: 20090430124524.000000-000
    Event Type: Erreur
    User:

    Computer Name: PC-de-janegreg
    Event Code: 1530
    Message: Windows a détecté que votre fichier de Registre est toujours utilisé par d'autres applications ou services. Le fichier va être déchargé. Les applications ou services qui ont accès à votre Registre risquent de ne pas fonctionner correctement après cela.

    DÉTAIL -
    1 user registry handles leaked from \Registry\User\S-1-5-21-1485561155-4169337654-4053709484-1000:
    Process 968 (\Device\HarddiskVolume1\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1485561155-4169337654-4053709484-1000

    Record Number: 12163
    Source Name: Microsoft-Windows-User Profiles Service
    Time Written: 20090430181129.000000-000
    Event Type: Avertissement
    User: AUTORITE NT\SYSTEM

    Computer Name: PC-de-janegreg
    Event Code: 1530
    Message: Windows a détecté que votre fichier de Registre est toujours utilisé par d'autres applications ou services. Le fichier va être déchargé. Les applications ou services qui ont accès à votre Registre risquent de ne pas fonctionner correctement après cela.

    DÉTAIL -
    1 user registry handles leaked from \Registry\User\S-1-5-21-1485561155-4169337654-4053709484-1000_Classes:
    Process 968 (\Device\HarddiskVolume1\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1485561155-4169337654-4053709484-1000_CLASSES

    Record Number: 12164
    Source Name: Microsoft-Windows-User Profiles Service
    Time Written: 20090430181129.000000-000
    Event Type: Avertissement
    User: AUTORITE NT\SYSTEM

    Computer Name: PC-de-janegreg
    Event Code: 10
    Message: Le filtre d’événement avec la requête « SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99 » n’a pas pu être réactivé dans l’espace de noms « //./root/CIMV2 » à cause de l’erreur 0x80041003. Les événements ne peuvent pas être délivrés à travers ce filtre tant que le problème ne sera pas corrigé.
    Record Number: 12182
    Source Name: Microsoft-Windows-WMI
    Time Written: 20090430181303.000000-000
    Event Type: Erreur
    User:

    =====Security event log=====

    Computer Name: PC-de-janegreg
    Event Code: 5038
    Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

    Nom du fichier : \Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys
    Record Number: 17805
    Source Name: Microsoft-Windows-Security-Auditing
    Time Written: 20090430185741.134039-000
    Event Type: Échec de l'audit
    User:

    Computer Name: PC-de-janegreg
    Event Code: 5038
    Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

    Nom du fichier : \Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys
    Record Number: 17806
    Source Name: Microsoft-Windows-Security-Auditing
    Time Written: 20090430185741.165239-000
    Event Type: Échec de l'audit
    User:

    Computer Name: PC-de-janegreg
    Event Code: 5038
    Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

    Nom du fichier : \Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys
    Record Number: 17807
    Source Name: Microsoft-Windows-Security-Auditing
    Time Written: 20090430185741.180839-000
    Event Type: Échec de l'audit
    User:

    Computer Name: PC-de-janegreg
    Event Code: 5038
    Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

    Nom du fichier : \Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys
    Record Number: 17808
    Source Name: Microsoft-Windows-Security-Auditing
    Time Written: 20090430185741.212039-000
    Event Type: Échec de l'audit
    User:

    Computer Name: PC-de-janegreg
    Event Code: 5038
    Message: L’intégrité du code a déterminé que le hachage de l’image d’un fichier n’est pas valide. Le fichier peut être endommagé en raison d’une modification non autorisée ou le hachage non valide peut indiquer une erreur d’unité de disque potentielle.

    Nom du fichier : \Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys
    Record Number: 17809
    Source Name: Microsoft-Windows-Security-Auditing
    Time Written: 20090430185741.243239-000
    Event Type: Échec de l'audit
    User:

    ======Environment variables======

    "ComSpec"=%SystemRoot%\system32\cmd.exe
    "FP_NO_HOST_CHECK"=NO
    "OS"=Windows_NT
    "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\hp\bin\Python;c:\Program Files\ATI Technologies\ATI.ACE\Core-Static
    "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
    "PROCESSOR_ARCHITECTURE"=x86
    "TEMP"=%SystemRoot%\TEMP
    "TMP"=%SystemRoot%\TEMP
    "USERNAME"=SYSTEM
    "windir"=%SystemRoot%
    "PROCESSOR_LEVEL"=15
    "PROCESSOR_IDENTIFIER"=x86 Family 15 Model 107 Stepping 2, AuthenticAMD
    "PROCESSOR_REVISION"=6b02
    "NUMBER_OF_PROCESSORS"=2
    "TRACE_FORMAT_SEARCH_PATH"=\\NTREL202.ntdev.corp.microsoft.com\4F18C3A5-CA09-4DBD-B6FC-219FDD4C6BE0\TraceFormat
    "DFSTRACINGON"=FALSE
    "OnlineServices"=Online Services
    "Platform"=HPD
    "PCBRAND"=Pavilion
    "MSWorksProductCode"={3B160861-7250-451E-B5EE-8B92BF30A710}

    -----------------EOF-----------------
    -----------------------------------------------------------------------------------------------------------------------
    Logfile of random's system information tool 1.06 (written by random/random)
    Run by janegreg at 2009-04-30 20:57:37
    Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 1
    System drive C: has 165 GB (56%) free of 294 GB
    Total RAM: 3070 MB (72% free)

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 20:57:41, on 30/04/2009
    Platform: Windows Vista SP1 (WinNT 6.00.1905)
    MSIE: Internet Explorer v7.00 (7.00.6001.18226)
    Boot mode: Normal

    Running processes:
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Users\janegreg\AppData\Roaming\eoRezo\SoftwareUpdate\SoftwareUpdateHP.exe
    C:\Program Files\Alwil Software\Avast4\ashDisp.exe
    C:\Program Files\Brother\ControlCenter3\brccMCtl.exe
    C:\Windows\system32\wbem\unsecapp.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Windows\system32\SearchFilterHost.exe
    C:\Users\janegreg\Documents\Mes téléchargements\RSIT(2).exe
    C:\Program Files\Trend Micro\HijackThis\janegreg.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.trooner.com/
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O1 - Hosts: ::1 localhost
    O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (file missing)
    O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (file missing)
    O3 - Toolbar: SYSTRAN Web Translator 5.0 - {A5899B52-3AF9-4F56-85FE-AD7B3BE8490F} - C:\Program Files\SYSTRAN\5.0\Personal\IEPlugIn.dll
    O4 - HKLM\..\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
    O4 - HKLM\..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\RunOnce: [SoftwareHelper] C:\Users\janegreg\AppData\Roaming\eoRezo\SoftwareUpdate\SoftwareUpdateHP.exe -runonce
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
    O8 - Extra context menu item: Download with &ShareazaPlus - res://C:\Program Files\ShareazaPlus\plugins\RazaWebHook.dll/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll (file missing)
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll (file missing)
    O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
    O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
    O9 - Extra button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Program Files\PokerStars.NET\PokerStarsUpdate.exe
    O13 - Gopher Prefix:
    O20 - AppInit_DLLs: C:\Windows\System32\dot3gpclnt32.dll
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: Boonty Games - BOONTY - C:\Program Files\Common Files\BOONTY Shared\Service\Boonty.exe
    O23 - Service: Service Google Update (gupdate1c9a8aac4c5f868) (gupdate1c9a8aac4c5f868) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    0
  3. Ced_King Messages postés 3519 Date d'inscription   Statut Contributeur Dernière intervention   667
     
    Telecharges et installes ccleaner :

    - Durant l'installation, n'installe pas la barre d'outils yahoo et decoche la case " ajouter l'option des mises à jour"

    - Une fois installé, fermes toutes les applications en cours et lance ccleaner

    - clic >> option >> avancé et decoches " effacer les fichiers etc... plus vieux que 48h

    - Selectionne " nettoyeur " >> clic sur Analyse puis nettoyage, puis referme le programme...
    ---------------------------
    Avant, pour desactiver le Tea-timer de Spybot ( ne le remets pas tant que la desinfection n'est pas terminé..) :

    Desactiver le Tea-Timer Spybot

    -----------------------------

    Puis,Telecharges Combofix et enregistres le sur ton bureau

    - Attention : Ce programme étant trés puissant, je te demanderais de bien suivre les manipulations.

    /!\ Desactives ton antivirus et la garde de ton antispyware ( si tu en as un) /!\

    - Deconnectes toi et fermes toutes les applications en cours

    - cliques droit ( executer en tant qu'admin.)sur Combofix.exe >> un message apparait > réponds " oui "

    - ( Il est conseillé d'installer la console de recuperations)

    - Selectionnes la langue et presse la touche 1 ( yes) pour lancer le scan

    /!\ Ne touche ni à la souris, ni au clavier durant le scan, cela pourrait figer l'ordi /!\

    - A la fin du scan, Combofix aura besoin de redemarrer pour finir la desinfection, laisses le faire

    - Une fois terminé, un rapport s'affiche, poste son contenu que tu peux aussi trouver à c:\combofix.txt

    0
  4. asus02 Messages postés 215 Statut Membre 13
     
    salut, voici le rapport de combofix
    ------------------------------------------------------------------------------------------------------------
    ComboFix 09-04-30.05 - janegreg 01/05/2009 10:24.1 - NTFSx86
    Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.33.1036.18.3070.2194 [GMT 2:00]
    Lancé depuis: c:\users\janegreg\Documents\Mes téléchargements\ComboFix.exe
    * Un nouveau point de restauration a été créé
    .

    (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\users\janegreg\AppData\Roaming\[u]0/u2000000447ec554579C.manifest
    c:\users\janegreg\AppData\Roaming\[u]0/u2000000447ec554579O.manifest
    c:\users\janegreg\AppData\Roaming\[u]0/u2000000447ec554579P.manifest
    c:\users\janegreg\AppData\Roaming\[u]0/u2000000447ec554579S.manifest
    c:\users\janegreg\AppData\Roaming\[u]0/u2000000447ec554583C.manifest
    c:\users\janegreg\AppData\Roaming\[u]0/u2000000447ec554583O.manifest
    c:\users\janegreg\AppData\Roaming\[u]0/u2000000447ec554583P.manifest
    c:\users\janegreg\AppData\Roaming\[u]0/u2000000447ec554583S.manifest
    c:\windows\system32\GroupPolicy000.dat

    .
    ((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    -------\Service_Boonty Games

    ((((((((((((((((((((((((((((( Fichiers créés du 2009-04-01 au 2009-05-01 ))))))))))))))))))))))))))))))))))))
    .

    2009-04-30 19:35 . 2009-04-30 19:35 -------- d-----w c:\program files\filehippo.com
    2009-04-30 19:12 . 2009-04-30 19:12 -------- d-sh--w c:\windows\system32\SystemService32
    2009-04-30 18:57 . 2009-04-30 18:57 -------- d-----w C:\rsit
    2009-04-30 12:48 . 2009-04-30 12:48 1372 ----a-w c:\windows\system32\3y715rV.vbs
    2009-04-30 12:47 . 2009-04-30 12:47 1372 ----a-w c:\windows\system32\jkjSa.vbs
    2009-04-30 12:47 . 2009-04-30 12:47 1372 ----a-w c:\windows\system32\KCGZ9HJgL8sSj17.vbs
    2009-04-30 12:46 . 2009-04-30 12:46 1372 ----a-w c:\windows\system32\bp4Ts.vbs
    2009-04-30 12:46 . 2009-04-30 12:46 1372 ----a-w c:\windows\system32\TCSu1zSFNUpfh.vbs
    2009-04-30 12:45 . 2009-04-30 12:45 1372 ----a-w c:\windows\system32\Ny4b1NO.vbs
    2009-04-30 12:45 . 2009-04-30 12:45 1372 ----a-w c:\windows\system32\nlhw2Hxwc9p70.vbs
    2009-04-30 10:37 . 2009-04-30 10:37 -------- d-----w c:\users\janegreg\AppData\Roaming\CyberLink
    2009-04-30 10:37 . 2009-04-30 10:37 -------- d-----w c:\programdata\CyberLink
    2009-04-30 10:37 . 2009-04-30 10:37 -------- d-----w c:\users\All Users\CyberLink
    2009-04-30 10:37 . 2009-04-30 10:37 -------- d-----w c:\users\Public\CyberLink
    2009-04-24 15:38 . 2009-04-24 15:39 -------- d-----w c:\program files\Satsuki Decoder Pack
    2009-04-24 15:23 . 2009-04-24 15:23 -------- d-----w c:\users\janegreg\AppData\Roaming\Shareaza
    2009-04-24 15:23 . 2009-04-24 15:23 -------- d-----w c:\program files\Shareaza
    2009-04-24 15:16 . 2009-04-24 15:21 -------- d-----w c:\users\janegreg\AppData\Roaming\ShareazaPlus
    2009-04-24 13:51 . 2009-04-24 13:51 39424 ----a-w c:\windows\zipinst.exe
    2009-04-24 13:51 . 2009-04-24 15:23 -------- d-----w c:\program files\MessenPass
    2009-04-24 13:19 . 2009-04-24 13:19 -------- d-----w c:\program files\Trend Micro
    2009-04-24 11:56 . 2009-02-05 20:06 51792 ----a-w c:\windows\system32\drivers\aswMonFlt.sys
    2009-04-24 11:43 . 2009-04-24 11:43 -------- d-----w c:\users\janegreg\AppData\Roaming\Malwarebytes
    2009-04-24 11:43 . 2008-10-16 18:25 15504 ----a-w c:\windows\system32\drivers\mbam.sys
    2009-04-24 11:43 . 2008-10-16 18:25 38496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
    2009-04-24 11:43 . 2009-04-24 11:43 -------- d-----w c:\programdata\Malwarebytes
    2009-04-24 11:43 . 2009-04-24 11:43 -------- d-----w c:\users\All Users\Malwarebytes
    2009-04-24 11:43 . 2009-04-24 11:43 -------- d-----w c:\program files\Malwarebytes' Anti-Malware
    2009-04-23 03:54 . 2009-04-23 03:54 1372 ----a-w c:\windows\system32\56aV9.vbs
    2009-04-23 03:54 . 2009-04-23 03:54 1372 ----a-w c:\windows\system32\9ZqPRcjaLJehi.vbs
    2009-04-22 20:39 . 2009-04-22 20:39 -------- d-----w c:\users\janegreg\AppData\Roaming\Media Player Classic
    2009-04-22 19:10 . 2009-04-22 19:10 -------- d-----w c:\users\janegreg\AppData\Local\Shareaza
    2009-04-22 18:54 . 2009-04-22 18:54 -------- d-----w c:\program files\eMule
    2009-04-22 17:54 . 2009-04-22 17:54 -------- d-----w c:\windows\system32\Adobe
    2009-04-20 12:23 . 2009-04-20 12:23 -------- d-----w c:\users\janegreg\AppData\Roaming\FastStone
    2009-04-20 12:23 . 2009-04-20 12:23 -------- d-----w c:\program files\FastStone Capture
    2009-04-20 12:05 . 2009-04-20 12:05 -------- d-----w c:\users\janegreg\AppData\Roaming\muvee Technologies
    2009-04-20 12:05 . 2009-04-20 12:05 -------- d-----w c:\programdata\TEMP
    2009-04-20 12:05 . 2009-04-20 12:05 -------- d-----w c:\users\All Users\TEMP
    2009-04-20 12:04 . 2009-04-20 12:04 50 ----a-w c:\windows\system32\bridf06a.dat
    2009-04-20 12:04 . 2006-10-31 07:49 56832 ----a-w c:\windows\system32\brinsstr.dll
    2009-04-20 12:04 . 2009-04-20 12:04 -------- d-----w c:\program files\Brother
    2009-04-20 12:03 . 2006-08-09 12:02 39424 ----a-w c:\windows\system32\BrUsi06c.dll
    2009-04-20 12:03 . 2006-09-22 14:58 1519616 ----a-w c:\windows\system32\BrWia06c.dll
    2009-04-20 12:03 . 2004-12-10 14:35 147456 ----a-w c:\windows\brunin03.dll
    2009-04-20 11:47 . 2009-04-20 11:47 -------- d-----w c:\program files\SYSTRAN
    2009-04-20 11:40 . 2009-04-20 11:40 -------- d-----w c:\programdata\Brother
    2009-04-20 11:40 . 2009-04-20 11:40 -------- d-----w c:\users\All Users\Brother
    2009-04-09 11:55 . 2009-04-09 11:55 -------- d-----w c:\program files\Orange

    .
    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-05-01 08:17 . 2009-05-01 08:17 -------- d-----w c:\program files\CCleaner
    2009-05-01 08:12 . 2008-05-26 15:36 669328 ----a-w c:\windows\system32\perfh00C.dat
    2009-05-01 08:12 . 2008-05-26 15:36 123350 ----a-w c:\windows\system32\perfc00C.dat
    2009-04-24 13:16 . 2009-03-20 16:25 -------- d-----w c:\program files\FlashGet
    2009-04-24 11:46 . 2008-05-26 06:17 -------- d-----w c:\program files\Common Files\Symantec Shared
    2009-04-23 22:35 . 2008-10-22 15:10 -------- d-----w c:\program files\Spybot - Search & Destroy
    2009-04-20 12:05 . 2008-10-04 20:40 78808 ----a-w c:\users\janegreg\AppData\Local\GDIPFONTCACHEV1.DAT
    2009-04-20 12:04 . 2006-11-02 10:25 86016 ----a-w c:\windows\inf\infstor.dat
    2009-04-20 12:04 . 2006-11-02 10:25 51200 ----a-w c:\windows\inf\infpub.dat
    2009-04-20 12:04 . 2006-11-02 10:25 143360 ----a-w c:\windows\inf\infstrng.dat
    2009-04-20 12:03 . 2008-05-26 05:55 -------- d--h--w c:\program files\InstallShield Installation Information
    2009-04-19 01:07 . 2006-11-02 11:18 -------- d-----w c:\program files\Windows Mail
    2009-03-28 00:50 . 2009-03-28 00:50 -------- d-----w c:\program files\BoontyGames
    2009-03-28 00:46 . 2009-03-28 00:45 -------- d-----w c:\program files\Téléchargeur de Sonic Adventure DX
    2009-03-28 00:45 . 2009-03-28 00:45 -------- d-----w c:\program files\Common Files\BOONTY Shared
    2009-03-24 18:54 . 2009-03-24 18:54 -------- d-----w c:\program files\Photo!
    2009-03-24 18:54 . 2009-03-24 18:51 -------- d-----w c:\program files\Web Photo Album
    2009-03-24 18:51 . 2009-03-24 18:51 -------- d-----w c:\program files\Cartoonist
    2009-03-24 18:29 . 2009-03-24 18:29 -------- d-----w c:\program files\Reallusion
    2009-03-22 23:30 . 2009-03-22 23:20 -------- d-----w c:\program files\easyMule
    2009-03-21 15:28 . 2009-03-19 15:52 -------- d-----w c:\program files\Google
    2009-03-20 16:39 . 2009-03-20 16:29 -------- d-----w c:\program files\DjaSoft
    2009-03-20 16:29 . 2009-03-20 16:29 -------- d-----w c:\program files\Common Files\Borland Shared
    2009-03-20 16:16 . 2009-03-20 16:16 -------- d-----w c:\program files\FACTOURE
    2009-03-17 03:38 . 2009-04-18 15:38 40960 ----a-w c:\windows\AppPatch\apihex86.dll
    2009-03-17 03:38 . 2009-04-18 15:38 13824 ----a-w c:\windows\system32\apilogen.dll
    2009-03-17 03:38 . 2009-04-18 15:38 24064 ----a-w c:\windows\system32\amxread.dll
    2009-03-12 18:35 . 2009-03-12 18:35 -------- d-----r c:\program files\Skype
    2009-03-06 17:57 . 2009-02-14 00:49 -------- d-----w c:\program files\PokerStars.NET
    2009-03-03 04:46 . 2009-04-18 15:38 3599328 ----a-w c:\windows\system32\ntkrnlpa.exe
    2009-03-03 04:46 . 2009-04-18 15:38 3547632 ----a-w c:\windows\system32\ntoskrnl.exe
    2009-03-03 04:40 . 2009-04-18 15:38 827392 ----a-w c:\windows\system32\wininet.dll
    2009-03-03 04:39 . 2009-04-18 15:38 183296 ----a-w c:\windows\system32\sdohlp.dll
    2009-03-03 04:39 . 2009-04-18 15:38 551424 ----a-w c:\windows\system32\rpcss.dll
    2009-03-03 04:39 . 2009-04-18 15:38 26112 ----a-w c:\windows\system32\printfilterpipelineprxy.dll
    2009-03-03 04:37 . 2009-04-18 15:38 78336 ----a-w c:\windows\system32\ieencode.dll
    2009-03-03 04:37 . 2009-04-18 15:38 98304 ----a-w c:\windows\system32\iasrecst.dll
    2009-03-03 04:37 . 2009-04-18 15:38 54784 ----a-w c:\windows\system32\iasads.dll
    2009-03-03 04:37 . 2009-04-18 15:38 44032 ----a-w c:\windows\system32\iasdatastore.dll
    2009-03-03 03:04 . 2009-04-18 15:38 666624 ----a-w c:\windows\system32\printfilterpipelinesvc.exe
    2009-03-03 02:38 . 2009-04-18 15:38 17408 ----a-w c:\windows\system32\iashost.exe
    2009-03-03 02:28 . 2009-04-18 15:38 26624 ----a-w c:\windows\system32\ieUnatt.exe
    2009-03-01 15:10 . 2009-03-01 15:10 80063 ----a-w c:\windows\Internet Logs\vsmon_2nd_2009_03_01_15_58_03_small.dmp.zip
    2009-02-14 00:49 . 2008-10-08 13:41 680 ----a-w c:\users\janegreg\AppData\Local\d3d9caps.dat
    2009-02-13 08:49 . 2009-04-18 15:38 72704 ----a-w c:\windows\system32\secur32.dll
    2009-02-13 08:49 . 2009-04-18 15:38 1255936 ----a-w c:\windows\system32\lsasrv.dll
    2009-02-09 03:10 . 2009-03-11 01:07 2033152 ----a-w c:\windows\system32\win32k.sys
    2008-01-21 02:43 . 2006-11-02 12:50 174 --sha-w c:\program files\desktop.ini
    2008-12-17 23:04 . 2009-03-06 17:11 67688 ----a-w c:\program files\mozilla firefox\components\jar50.dll
    2008-12-17 23:04 . 2009-03-06 17:11 54368 ----a-w c:\program files\mozilla firefox\components\jsd3250.dll
    2008-12-17 23:04 . 2009-03-06 17:11 34944 ----a-w c:\program files\mozilla firefox\components\myspell.dll
    2008-12-17 23:04 . 2009-03-06 17:11 46712 ----a-w c:\program files\mozilla firefox\components\spellchk.dll
    2008-12-17 23:04 . 2009-03-06 17:11 172136 ----a-w c:\program files\mozilla firefox\components\xpinstal.dll
    .

    ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "EnableUIADesktopToggle"= 0 (0x0)

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
    "AppInit_DLLs"=c:\windows\System32\dot3gpclnt32.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-1485561155-4169337654-4053709484-1000]
    "EnableNotifications"=dword:00000001
    "EnableNotificationsRef"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
    "{9B9589C0-0E7B-463D-BB50-63D3E52A65AE}"= Profile=Private|c:\program files\Cyberlink\PowerDirector\PDR.EXE:CyberLink PowerDirector
    "{93C6C3E4-3F42-4C36-BE0A-70F98ED33154}"= Profile=Private|c:\program files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)
    "{FA64AC26-2B4A-40BC-BE1F-F1A3F3E0DA27}"= Disabled:c:\program files\Cyberlink\PowerDirector\PDR.EXE:CyberLink PowerDirector
    "{0EFC9AE5-0EEF-4290-9883-AC77BF819869}"= Disabled:c:\program files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)
    "{6502C1F1-C1DF-46D2-A1FE-4AFE5B383BCC}"= Disabled:UDP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
    "{BE3471A2-84F6-4423-9678-BA1B41B8BAA6}"= Disabled:TCP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
    "{7DBEF7C7-A8A9-4C0A-9B98-C84C3FF07845}"= c:\program files\Skype\Phone\Skype.exe:Skype
    "TCP Query User{A74D2B02-00CA-4B6C-A0A4-F5CBCD80EF7A}c:\\program files\\flashget\\flashget.exe"= UDP:c:\program files\flashget\flashget.exe:FlashGet
    "UDP Query User{C5965902-8895-458A-81D5-B3570D20ED7D}c:\\program files\\flashget\\flashget.exe"= TCP:c:\program files\flashget\flashget.exe:FlashGet
    "TCP Query User{0948554F-1F34-4E05-AA0E-B7CD63108959}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
    "UDP Query User{6166AEDC-22C1-4B20-9D29-FA441ECADD17}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
    "{2D0E74CC-7326-48AD-A202-EA8CAB9F7B29}"= Disabled:UDP:57623:tcp emule
    "{115CF749-3CAF-428F-A423-11ABEBF58B9F}"= Disabled:TCP:63234:udp emule
    "{790ADC27-7C8D-4AB6-A94E-C6108D96A8AC}"= Disabled:UDP:4662:emule
    "{221F94BE-27A9-4F46-B89D-E1F45EF80BE2}"= Disabled:TCP:4672:emule
    "{1016EBFF-89F2-4A44-A72E-A14B6AB419EB}"= UDP:6446:sherazade
    "{B74F7B63-7D80-45CE-8762-5CEF7D3A4C35}"= TCP:6446:sherazade
    "TCP Query User{3EB9509A-0079-46AD-8E94-C0A78146BF5E}c:\\program files\\easymule\\emule.exe"= Disabled:UDP:c:\program files\easymule\emule.exe:easyMule
    "UDP Query User{F3B6530C-BB17-461B-A693-0444D1093B9C}c:\\program files\\easymule\\emule.exe"= Disabled:TCP:c:\program files\easymule\emule.exe:easyMule
    "TCP Query User{BB52E910-A4D9-495A-8707-A5C1A57D2A0C}c:\\program files\\emule\\emule.exe"= Disabled:UDP:c:\program files\emule\emule.exe:eMule
    "UDP Query User{A3C8F990-CD13-4EB5-8251-E7A79395FDC7}c:\\program files\\emule\\emule.exe"= Disabled:TCP:c:\program files\emule\emule.exe:eMule
    "TCP Query User{132F20B6-2FE0-4B5A-8AC5-CF9F3F916671}c:\\program files\\shareaza\\shareaza.exe"= UDP:c:\program files\shareaza\shareaza.exe:Shareaza Ultimate File Sharing
    "UDP Query User{CC0F2D97-D5E6-4CF6-80D2-080AC21953BB}c:\\program files\\shareaza\\shareaza.exe"= TCP:c:\program files\shareaza\shareaza.exe:Shareaza Ultimate File Sharing
    "TCP Query User{545126AF-E07C-4074-84DF-A2E2BCC883E7}c:\\program files\\mozilla firefox\\firefox.exe"= UDP:c:\program files\mozilla firefox\firefox.exe:Firefox
    "UDP Query User{3B7B1DC5-4BB2-477F-8250-0B692B4B36D6}c:\\program files\\mozilla firefox\\firefox.exe"= TCP:c:\program files\mozilla firefox\firefox.exe:Firefox

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
    "c:\\Program Files\\OrangeHSS\\Connectivity\\ConnectivityManager.exe"= c:\program files\OrangeHSS\Connectivity\ConnectivityManager.exe:*:enabled:CSS

    R2 gupdate1c9a8aac4c5f868;Service Google Update (gupdate1c9a8aac4c5f868);c:\program files\Google\Update\GoogleUpdate.exe [2009-03-19 133104]
    R3 PCAMp50;PCAMp50 NDIS Protocol Driver;c:\windows\system32\Drivers\PCAMp50.sys [2006-11-28 28224]
    S1 aswSP;avast! Self Protection; [x]
    S2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2009-02-05 20560]
    S2 aswMonFlt;aswMonFlt;c:\windows\system32\DRIVERS\aswMonFlt.sys [2009-02-05 51792]
    S2 ezSharedSvc;Easybits Shared Services for Windows;c:\windows\system32\svchost.exe [2008-01-21 21504]

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
    ezSharedSvc
    .
    Contenu du dossier 'Tâches planifiées'

    2009-05-01 c:\windows\Tasks\GoogleUpdateTaskMachine.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2009-03-19 15:52]

    2009-04-30 c:\windows\Tasks\User_Feed_Synchronization-{C4166262-CB91-4ABF-A1F1-D0A25DB63157}.job
    - c:\windows\system32\msfeedssync.exe [2008-01-21 02:24]

    2009-05-01 c:\windows\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job
    - c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2006-09-27 16:39]
    .
    - - - - ORPHELINS SUPPRIMES - - - -

    HKLM-Run-EoEngine - (no file)

    .
    ------- Examen supplémentaire -------
    .
    uStart Page = hxxp://orange.fr/
    mStart Page = hxxp://www.trooner.com/
    IE: Download with &ShareazaPlus - c:\program files\ShareazaPlus\plugins\RazaWebHook.dll/3000
    IE: {{FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - c:\program files\PokerStars.NET\PokerStarsUpdate.exe
    FF - ProfilePath - c:\users\janegreg\AppData\Roaming\Mozilla\Firefox\Profiles\azx56cx0.default\
    FF - prefs.js: browser.startup.homepage - hxxp://google.fr
    FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
    FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll

    ---- PARAMETRES FIREFOX ----
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.allow_platform_file_picker", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.cookie.p3plevel", 1); // 0=low, 1=medium, 2=high, 3=custom
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.enablePad", false); // Allow client to do proxy autodiscovery
    c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.hideGoButton", false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.search.param.Google.1.default", "chrome://branding/content/searchconfig.properties");
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.search.param.Google.1.custom", "chrome://branding/content/searchconfig.properties");
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("signon.prefillForms", true);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.enabled", false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.remoteLookups", false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.provider.0.updateURL", "http://sb.google.com/safebrowsing/update?client={moz:client}&appver={moz:version}&");
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.provider.0.lookupURL", "http://sb.google.com/safebrowsing/lookup?sourceid=firefox-antiphish&features=TrustRank&client={moz:client}&appver={moz:version}&");
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.provider.0.reportURL", "http://sb.google.com/safebrowsing/report?");
    c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("pref.browser.homepage.disable_button.bookmark_page", false);
    c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("pref.browser.homepage.disable_button.current_page", false);
    c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("pref.browser.homepage.disable_button.restore_default", false);
    c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("browser.places.importBookmarksHTML", true);
    c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("browser.places.importDefaults", false);
    c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("browser.search.selectedEngine", "xeoo.com");
    c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("keyword.URL", "http://xeoo.com/?p=url&a=firefox&k=");
    c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("browser.startup.homepage", "http://www.xeoo.com/?p=h&a=firefox");
    .

    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-05-01 10:29
    Windows 6.0.6001 Service Pack 1 NTFS

    Recherche de processus cachés ...

    Recherche d'éléments en démarrage automatique cachés ...

    Recherche de fichiers cachés ...

    Scan terminé avec succès
    Fichiers cachés: 0

    **************************************************************************
    .
    --------------------- CLES DE REGISTRE BLOQUEES ---------------------

    [HKEY_USERS\SYSTEM\ControlSet001\Services\Tcpip6\Parameters\Interfaces\{5ccab8b6-ede3-4827-8697-92a1d8a71ab4}]
    @DACL=(02 0000)
    "Dhcpv6Iaid"=dword:0f001e90
    "Dhcpv6State"=dword:00000000

    [HKEY_USERS\SYSTEM\ControlSet001\Services\Tcpip6\Parameters\Interfaces\{8a93352d-34cd-479e-9354-7acab034c56e}]
    @DACL=(02 0000)
    "Dhcpv6Iaid"=dword:11020054
    "Dhcpv6State"=dword:00000000

    [HKEY_USERS\SYSTEM\ControlSet001\Services\Tcpip6\Parameters\Interfaces\{9c642153-bfe0-4511-a0b6-e778ddd5ea9e}]
    @DACL=(02 0000)
    "Dhcpv6Iaid"=dword:07001422
    "Dhcpv6State"=dword:00000000

    [HKEY_USERS\SYSTEM\ControlSet001\Services\Tcpip6\Parameters\Interfaces\{ba32a50a-3d27-4fae-8591-5916311409be}]
    @DACL=(02 0000)
    "Dhcpv6Iaid"=dword:0c001422
    "Dhcpv6State"=dword:00000000

    [HKEY_USERS\SYSTEM\ControlSet001\Services\Tcpip6\Parameters\Interfaces\{f50c0996-5b4a-4c6a-a322-6e991d4caa0e}]
    @DACL=(02 0000)
    "Dhcpv6Iaid"=dword:06001422
    "Dhcpv6State"=dword:00000000

    [HKEY_USERS\SYSTEM\ControlSet001\Services\Tcpip6\Parameters\Interfaces\{f70a361f-6437-4fcc-91a4-cd88d468d91b}]
    @DACL=(02 0000)
    "Dhcpv6Iaid"=dword:0e001422
    "Dhcpv6State"=dword:00000000

    [HKEY_USERS\SYSTEM\ControlSet003\Services\Tcpip6\Parameters\Interfaces\{5ccab8b6-ede3-4827-8697-92a1d8a71ab4}]
    @DACL=(02 0000)
    "Dhcpv6Iaid"=dword:0f001e90
    "Dhcpv6State"=dword:00000000

    [HKEY_USERS\SYSTEM\ControlSet003\Services\Tcpip6\Parameters\Interfaces\{8a93352d-34cd-479e-9354-7acab034c56e}]
    @DACL=(02 0000)
    "Dhcpv6Iaid"=dword:11020054
    "Dhcpv6State"=dword:00000000

    [HKEY_USERS\SYSTEM\ControlSet003\Services\Tcpip6\Parameters\Interfaces\{9c642153-bfe0-4511-a0b6-e778ddd5ea9e}]
    @DACL=(02 0000)
    "Dhcpv6Iaid"=dword:07001422
    "Dhcpv6State"=dword:00000000

    [HKEY_USERS\SYSTEM\ControlSet003\Services\Tcpip6\Parameters\Interfaces\{ba32a50a-3d27-4fae-8591-5916311409be}]
    @DACL=(02 0000)
    "Dhcpv6Iaid"=dword:0c001422
    "Dhcpv6State"=dword:00000000

    [HKEY_USERS\SYSTEM\ControlSet003\Services\Tcpip6\Parameters\Interfaces\{f50c0996-5b4a-4c6a-a322-6e991d4caa0e}]
    @DACL=(02 0000)
    "Dhcpv6Iaid"=dword:06001422
    "Dhcpv6State"=dword:00000000

    [HKEY_USERS\SYSTEM\ControlSet003\Services\Tcpip6\Parameters\Interfaces\{f70a361f-6437-4fcc-91a4-cd88d468d91b}]
    @DACL=(02 0000)
    "Dhcpv6Iaid"=dword:0e001422
    "Dhcpv6State"=dword:00000000
    .
    ------------------------ Autres processus actifs ------------------------
    .
    c:\windows\System32\audiodg.exe
    c:\program files\Alwil Software\Avast4\aswUpdSv.exe
    c:\program files\Alwil Software\Avast4\ashServ.exe
    c:\windows\System32\WUDFHost.exe
    c:\program files\Alwil Software\Avast4\ashMaiSv.exe
    c:\program files\Alwil Software\Avast4\ashWebSv.exe
    c:\program files\Alwil Software\Avast4\ashDisp.exe
    c:\windows\System32\wbem\unsecapp.exe
    c:\program files\MSN Messenger\usnsvc.exe
    .
    **************************************************************************
    .
    Heure de fin: 2009-05-01 10:32 - La machine a redémarré
    ComboFix-quarantined-files.txt 2009-05-01 08:31

    Avant-CF: 178 401 411 072 octets libres
    Après-CF: 178 181 939 200 octets libres

    360 --- E O F --- 2009-04-23 22:26
    ------------------------------------------------------------------------------------------------------------------

    mais quand je reverifie avec hijak la ligne reste presente et avast me detect le virus.

    O20 - AppInit_DLLs: C:\Windows\System32\dot3gpclnt32.dll

    merci
    0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. Ced_King Messages postés 3519 Date d'inscription   Statut Contributeur Dernière intervention   667
     
    Télécharges ATF Cleaner par Atribune sur ton bureau :

    - Démarres ATF-Cleaner et coches toutes les cases.

    - Cliques sur <Empty Selected> et au message "Done Cleaning" sur <Ok>
    NB : Si tu utilises Firefox ou Opera :

    - Cliques sur Firefox ou Opera en haut puis choisis <Select All>.

    - Cliques sur le bouton <Empty Selected> (NB : Si tu veux conserver tes mots de passe sauvegardés alors cliques sur <No> à l'invite).

    - Cliques sur <Main> pour revenir à menu principal

    - Cliques sur <Exit>, du menu prinicipal, pour quitter ATFcleaner.

    *NB : Si le prefetch est nettoyé le redémarrage du PC sera plus lent.

    -----------------------------

    > Avec Combofix :
    - Crées un nouveau document texte : clic droit de souris sur le bureau => Nouveau => Document Texte, et copies/colles à l'interieur les lignes " en gras " suivantes :

    KILLALL::

    Registry::
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
    "AppInit_DLLs"=-
    [-HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-1485561155-4169337654-4053709484-1000]
    "EnableNotifications"=-
    "EnableNotificationsRef"=-

    Files::
    c:\windows\System32\dot3gpclnt32.dll
    c:\windows\system32\3y715rV.vbs
    c:\windows\system32\jkjSa.vbs
    c:\windows\system32\KCGZ9HJgL8sSj17.vbs
    c:\windows\system32\bp4Ts.vbs
    c:\windows\system32\TCSu1zSFNUpfh.vbs
    c:\windows\system32\Ny4b1NO.vbs
    c:\windows\system32\nlhw2Hxwc9p70.vbs
    c:\windows\system32\56aV9.vbs
    c:\windows\system32\9ZqPRcjaLJehi.vbs


    - Enregistres ce fichier sous le nom CFScript (Type du fichier : tous les fichiers)

    - Fermes tous tes navigateurs web (donc copie ou imprime les instructions suivantes avant si besoin est).

    /!\ Désactives ton antivirus et tes autres protections résidentes (ex : Spybot) si tu en as (c'est important). /!\

    - Fais un glissé/déposé de ce fichier CFScript sur le programme ComboFix.exe comme CECI :

    *( Cliques sur le fichier CFScript, maintiens le doigt enfoncé et fais glisser la souris pour que l'icône du CFScript vienne recouvrir l'icône de Combofix. Relâches alors le bouton de la souris).

    - Combofix va démarrer puis une fenêtre bleue va apparaître. Valides

    - Patientes le temps du scan. Le bureau va disparaître à plusieurs reprises: c'est normal !

    - Ne touches à rien tant que le scan n'est pas terminé sinon le PC peut planter !

    - Une fois le scan achevé, un rapport va s'afficher: postes le stp.

    --------------------------

    0