Précédent
- 1
- 2
-
############################## [ UsbFix V3.027 | Cleaning ]
# User : Salim (Administrateurs) # GRACE
# Update on 30/05/09 by Chiquitine29, C_XX & Chimay8
# WebSite : http://pagesperso-orange.fr/NosTools/usbfix.html
# Start at: 14:05:44 | 01/06/2009
# Intel(R) Core(TM)2 Duo CPU T8100 @ 2.10GHz
# Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6001 32-bit) # Service Pack 1
# Internet Explorer 7.0.6001.18000
# Windows Firewall Status : Disabled
# C:\ # Disque fixe local # 176,28 Go (95,13 Go free) # NTFS
# D:\ # Disque amovible
# E:\ # Disque amovible
# F:\ # Disque CD-ROM # 64,06 Mo (0 Mo free) [38th EMAC Conference] # UDF
# G:\ # Disque fixe local # 232,83 Go (193,34 Go free) [WD Passport] # FAT32
############################## [ Processus actifs ]
C:\Windows\System32\smss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\LogonUI.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Program Files\ArcSoft\Magic-i Visual Effects\uCamMonitor.exe
C:\Windows\system32\Ati2evxx.exe
C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
C:\Program Files\Sony\VAIO Event Service\VESMgrSub.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\userinit.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
C:\Windows\system32\runonce.exe
C:\Windows\system32\wbem\wmiprvse.exe
################## [ Fichiers # Dossiers infectieux ]
(!) Not Deleted ! F:\autorun.inf
Deleted ! G:\autorun.inf
################## [ Registre # Clés Run infectieuses ]
################## [ Registre # Mountpoints2 ]
Deleted ! HKCU\...\Explorer\MountPoints2\H\Shell\AutoRun\Command
Deleted ! HKCU\...\Explorer\MountPoints2\{250f9d65-1d21-11de-8480-001e3da63a32}\Shell\AutoRun\Command
Deleted ! HKCU\...\Explorer\MountPoints2\{57c6fc4c-de82-11dd-b180-001e3da63a32}\Shell\AutoRun\Command
Deleted ! HKCU\...\Explorer\MountPoints2\{85ab51c4-fec0-11dd-bb07-001e3da63a32}\Shell\AutoRun\Command
Deleted ! HKCU\...\Explorer\MountPoints2\{85ab51c6-fec0-11dd-bb07-001e3da63a32}\Shell\AutoRun\Command
Deleted ! HKCU\...\Explorer\MountPoints2\{e98d2369-80e2-11dd-9c62-806e6f6e6963}\Shell\AutoRun\Command
################## [ Listing des fichiers présent ]
[18/09/2006 23:43|--a------|24] - C:\autoexec.bat
[21/01/2008 04:24|-rahs----|333203] - C:\bootmgr
[07/04/2008 20:30|-ra-s----|8192] - C:\BOOTSECT.BAK
[18/09/2006 23:43|--a------|10] - C:\config.sys
[?|?|?] - C:\hiberfil.sys
[03/01/2005 06:37|--ah-----|17] - C:\initrd.pam
[30/09/2008 11:00|-rahs----|0] - C:\IO.SYS
[27/03/2007 14:33|--ah-----|67] - C:\kernel.pam
[15/09/2008 16:19|--a------|0] - C:\law.sp
[30/09/2008 11:00|-rahs----|0] - C:\MSDOS.SYS
[?|?|?] - C:\pagefile.sys
[01/06/2009 11:45|--a------|3224] - C:\TB.txt
[01/06/2009 14:06|--a------|4204] - C:\UsbFix.txt
[14/05/2009 16:33|-ra------|3827057] - F:\EMAC.exe
[11/05/2009 12:11|-ra------|26] - F:\autorun.inf
[15/05/2009 11:05|-ra------|223212] - F:\competitivePapers.xml
[06/05/2009 11:57|-ra------|647] - F:\doc_dflt.html
[13/05/2009 18:19|-ra------|1862] - F:\emac_arbo.xml
[14/05/2009 16:12|-ra------|2938] - F:\emac_sessions.xml
[16/11/2007 09:04|--a------|4805120] - G:\WDSync.exe
################## [ Vaccination ]
# C:\autorun.inf ( # Not infected ) -> Folder created by UsbFix.
# G:\autorun.inf ( # Not infected ) -> Folder created by UsbFix.
################## [ Informations # Fichier Suspect ]
################## [ Cracks # Keygens # Serials ]
# -> Nothing found !
################## [ ! Fin du rapport # UsbFix V3.027 ! ] -
C'est OK pour les supports mais n'oublie quand tu auras récupéré ta clé de faire cette manip avec USBFix.
Télécharge Ad-remover ( de C_XX ) sur ton bureau :
http://sd-1.archive-host.com/membres/up/16506160323759868/AD-R.exe
! Déconnecte toi et ferme toutes applications en cours !
• Double clique sur "Ad-R.exe" pour lancer l'installation et laisse les paramètres d'installation par défaut .
• Click droit sur le raccourci Ad-Remover puis choisis exécuter en tant qu'administrateur
• Au menu principal choisis l'option "L" et tape sur [entrée] .
• Laisse travailler l'outil et ne touche à rien ...
--> Poste le rapport qui apparait à la fin , sur le forum ...
( Le rapport est sauvegardé aussi sous C:\Ad-report.log )
( CTRL+A Pour tout sélectionner , CTRL+C pour copier et CTRL+V pour coller )
A+ -
.
======= RAPPORT D'AD-REMOVER 1.1.4.5_B | UNIQUEMENT XP/VISTA =======
.
Mit à jour part C_XX le 01/06/2009 à 11:50 AM
Contact: AdRemover.contact@gmail.com
Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html
.
Lancé à: 14:37:12, 01/06/2009 | Mode Normal | Option: SCAN
Exécuté de: C:\Program Files\Ad-remover\
Système d'exploitation: Microsoft® Windows Vista™ Home Premium Service Pack 1 v6.0.6001
Nom du PC: GRACE | Utilisateur actuel: Salim
.
Administrateur: Administrateur *Desactive*
N'est pas administrateur: Invité *Desactive*
Administrateur: Salim
.
============== ÉLÉMENT(S) TROUVÉ(S) ==============
.
.
HKCU\Software\AppDataLow\Software\MyWebSearch
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EA9-A523-4961-B6BB-170DE4475CCA}
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB}
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{63D0ED2C-B45B-4458-8B3B-60C69BBBD83C}
HKLM\Software\Trymedia Systems
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{07B18EA9-A523-4961-B6BB-170DE4475CCA}
.
C:\Users\Salim\AppData\LocalLow\FunWebProducts
C:\Users\Salim\AppData\LocalLow\MyWebSearch
C:\Program Files\MyWebSearch
C:\Program Files\Mozilla Firefox\chrome\m3ffxtbr.jar
C:\Program Files\Mozilla Firefox\chrome\m3ffxtbr.manifest
C:\Program Files\Windows Live\Messenger\Riched20.dll
C:\Program Files\Windows Live\Messenger\Msimg32.dll
.
============== Scan additionnel ==============
.
* Mozilla FireFox Version 3.0.8 *
Nom du profil: ab7i1ouu.default (Salim)
.
(Prefs.js) user_pref("browser.startup.homepage_override.mstone", "rv:1.9.0.8");
.
.
* Internet Explorer Version 7.0.6001.18000 *
[HKEY_CURRENT_USER\..\Internet Explorer\Main]
Default_Page_URL: hxxp://www.club-vaio.com
Search bar: hxxp://www.google.com/ie
Search Page: hxxp://www.google.com
Start Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
[HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]
Default_Page_URL: hxxp://fr.yahoo.com
Default_Search_URL: hxxp://go.microsoft.com/fwlink/?LinkId=54896
Search Page: hxxp://go.microsoft.com/fwlink/?LinkId=54896
Start Page: hxxp://fr.msn.com/
[HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]
Tabs: res://ieframe.dll/tabswelcome.htm
============== Suspect (Cracks, Serials ... ) ==============
.
+---------------------------------------------------------------------------+
2502 Octet(s) - C:\Ad-Report-SCAN.log
1 Fichier(s) - C:\Program Files\Ad-remover\BACKUP
0 Fichier(s) - C:\Program Files\Ad-remover\QUARANTINE
Fin à: 14:46:16 | 01/06/2009
.
============== E.O.F ==============
. -
OK,
Pour vérifier que ton PC est propre, tu vasun scan en ligne sur le site de Kaspersky:
https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
# Clique sur Demarrer Online-scanner ( en bas de page à droite ) pour commencer l'analyse.
# Il te sera demandé d'installer un logiciel de Kaspersky, accepte.
# A la fin de cette analyse, clique sur enregistrer le rapport.
Poste le contenu de ce rapport dans ton prochain message.
tuto à lire pour vérifier les réglages des activeX :
Internet explorer : https://forum.pcastuces.com/default.asp
Firefox : https://forum.pcastuces.com/kaspersky_online_scanner___firefox___tutoriel-f31s26.htm
A+
Précédent
- 1
- 2