Analyse ToolBar S&D 1.2.8 XP/Vista

miosotis -  
 miosotis -
Bonjour,

Voici un rapport d'analyse suite à mon PC qui rame beaucoup merci de m'aider, j'aimerai bien que Kevin05 me donne son avis!

-----------\\ ToolBar S&D 1.2.8 XP/Vista

Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
X86-based PC ( Uniprocessor Free : Intel(R) Pentium(R) 4 CPU 2.00GHz )
BIOS : Version 1.00
USER : KS ( Administrator )
BOOT : Normal boot
Antivirus : Avira AntiVir PersonalEdition 8.0.1.30 (Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total:55 Go (Free:17 Go)
D:\ (CD or DVD)
E:\ (CD or DVD)

"C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
Option : [1] ( 26/06/2009|12:13 )

-----------\\ Recherche de Fichiers / Dossiers ...

C:\Program Files\KaZaA
C:\Program Files\KaZaA\BGP2P
C:\Program Files\KaZaA\Db
C:\Program Files\KaZaA\My Shared Folder
C:\Program Files\KaZaA\BGP2P\bdupd.dll
C:\Program Files\KaZaA\BGP2P\plugins
C:\Program Files\KaZaA\BGP2P\plugins.htm
C:\Program Files\KaZaA\BGP2P\versions.dat
C:\Program Files\KaZaA\BGP2P\plugins\ace.xmd
C:\Program Files\KaZaA\BGP2P\plugins\adsntfs.xmd
C:\Program Files\KaZaA\BGP2P\plugins\alz.xmd
C:\Program Files\KaZaA\BGP2P\plugins\arc.xmd
C:\Program Files\KaZaA\BGP2P\plugins\arj.xmd
C:\Program Files\KaZaA\BGP2P\plugins\bach.xmd
C:\Program Files\KaZaA\BGP2P\plugins\bzip2.xmd
C:\Program Files\KaZaA\BGP2P\plugins\cab.xmd
C:\Program Files\KaZaA\BGP2P\plugins\cevakrnl.cvd
C:\Program Files\KaZaA\BGP2P\plugins\cevakrnl.ivd
C:\Program Files\KaZaA\BGP2P\plugins\cevakrnl.rvd
C:\Program Files\KaZaA\BGP2P\plugins\cevakrnl.xmd
C:\Program Files\KaZaA\BGP2P\plugins\ceva_dll.cvd
C:\Program Files\KaZaA\BGP2P\plugins\ceva_emu.cvd
C:\Program Files\KaZaA\BGP2P\plugins\ceva_vfs.cvd
C:\Program Files\KaZaA\BGP2P\plugins\chm.xmd
C:\Program Files\KaZaA\BGP2P\plugins\cpio.xmd
C:\Program Files\KaZaA\BGP2P\plugins\cran.cvd
C:\Program Files\KaZaA\BGP2P\plugins\cran.ivd
C:\Program Files\KaZaA\BGP2P\plugins\cran.xmd
C:\Program Files\KaZaA\BGP2P\plugins\dbx.xmd
C:\Program Files\KaZaA\BGP2P\plugins\docfile.xmd
C:\Program Files\KaZaA\BGP2P\plugins\emalware.cvd
C:\Program Files\KaZaA\BGP2P\plugins\emalware.ivd
C:\Program Files\KaZaA\BGP2P\plugins\emalware.xmd
C:\Program Files\KaZaA\BGP2P\plugins\epoc.xmd
C:\Program Files\KaZaA\BGP2P\plugins\e_spyw.ivd
C:\Program Files\KaZaA\BGP2P\plugins\gzip.xmd
C:\Program Files\KaZaA\BGP2P\plugins\ha.xmd
C:\Program Files\KaZaA\BGP2P\plugins\hlp.xmd
C:\Program Files\KaZaA\BGP2P\plugins\hpe.cvd
C:\Program Files\KaZaA\BGP2P\plugins\hpe.xmd
C:\Program Files\KaZaA\BGP2P\plugins\hqx.xmd
C:\Program Files\KaZaA\BGP2P\plugins\html.xmd
C:\Program Files\KaZaA\BGP2P\plugins\imp.xmd
C:\Program Files\KaZaA\BGP2P\plugins\inno.xmd
C:\Program Files\KaZaA\BGP2P\plugins\instyler.xmd
C:\Program Files\KaZaA\BGP2P\plugins\iso.xmd
C:\Program Files\KaZaA\BGP2P\plugins\java.cvd
C:\Program Files\KaZaA\BGP2P\plugins\java.xmd
C:\Program Files\KaZaA\BGP2P\plugins\jpeg.xmd
C:\Program Files\KaZaA\BGP2P\plugins\lha.xmd
C:\Program Files\KaZaA\BGP2P\plugins\lnk.xmd
C:\Program Files\KaZaA\BGP2P\plugins\mbox.xmd
C:\Program Files\KaZaA\BGP2P\plugins\mbx.xmd
C:\Program Files\KaZaA\BGP2P\plugins\mdx.xmd
C:\Program Files\KaZaA\BGP2P\plugins\mdx_97.cvd
C:\Program Files\KaZaA\BGP2P\plugins\mdx_97.ivd
C:\Program Files\KaZaA\BGP2P\plugins\mdx_w95.cvd
C:\Program Files\KaZaA\BGP2P\plugins\mdx_x95.cvd
C:\Program Files\KaZaA\BGP2P\plugins\mdx_xf.cvd
C:\Program Files\KaZaA\BGP2P\plugins\mime.xmd
C:\Program Files\KaZaA\BGP2P\plugins\mso.xmd
C:\Program Files\KaZaA\BGP2P\plugins\na.cvd
C:\Program Files\KaZaA\BGP2P\plugins\na.xmd
C:\Program Files\KaZaA\BGP2P\plugins\nelf.cvd
C:\Program Files\KaZaA\BGP2P\plugins\nelf.xmd
C:\Program Files\KaZaA\BGP2P\plugins\nsis.xmd
C:\Program Files\KaZaA\BGP2P\plugins\objd.xmd
C:\Program Files\KaZaA\BGP2P\plugins\pdf.xmd
C:\Program Files\KaZaA\BGP2P\plugins\pst.xmd
C:\Program Files\KaZaA\BGP2P\plugins\rar.xmd
C:\Program Files\KaZaA\BGP2P\plugins\regscan.cvd
C:\Program Files\KaZaA\BGP2P\plugins\rpm.xmd
C:\Program Files\KaZaA\BGP2P\plugins\rtf.xmd
C:\Program Files\KaZaA\BGP2P\plugins\rup.cvd
C:\Program Files\KaZaA\BGP2P\plugins\rup.xmd
C:\Program Files\KaZaA\BGP2P\plugins\sdx.cvd
C:\Program Files\KaZaA\BGP2P\plugins\sdx.ivd
C:\Program Files\KaZaA\BGP2P\plugins\sdx.xmd
C:\Program Files\KaZaA\BGP2P\plugins\sfx.xmd
C:\Program Files\KaZaA\BGP2P\plugins\swf.xmd
C:\Program Files\KaZaA\BGP2P\plugins\tar.xmd
C:\Program Files\KaZaA\BGP2P\plugins\td0.xmd
C:\Program Files\KaZaA\BGP2P\plugins\thebat.xmd
C:\Program Files\KaZaA\BGP2P\plugins\tnef.xmd
C:\Program Files\KaZaA\BGP2P\plugins\unpack.cvd
C:\Program Files\KaZaA\BGP2P\plugins\unpack.ivd
C:\Program Files\KaZaA\BGP2P\plugins\unpack.xmd
C:\Program Files\KaZaA\BGP2P\plugins\update.txt
C:\Program Files\KaZaA\BGP2P\plugins\uudecode.xmd
C:\Program Files\KaZaA\BGP2P\plugins\ve.cvd
C:\Program Files\KaZaA\BGP2P\plugins\ve.ivd
C:\Program Files\KaZaA\BGP2P\plugins\ve.xmd
C:\Program Files\KaZaA\BGP2P\plugins\vedata.cvd
C:\Program Files\KaZaA\BGP2P\plugins\viza.xmd
C:\Program Files\KaZaA\BGP2P\plugins\wise.xmd
C:\Program Files\KaZaA\BGP2P\plugins\xishield.xmd
C:\Program Files\KaZaA\BGP2P\plugins\z.xmd
C:\Program Files\KaZaA\BGP2P\plugins\zip.xmd
C:\Program Files\KaZaA\BGP2P\plugins\zoo.xmd
C:\Program Files\KaZaA\Db\ctx4-060124.cab
C:\Program Files\KaZaA\Db\data1024.dbb
C:\Program Files\KaZaA\Db\data256.dbb
C:\Program Files\KaZaA\Db\k7tqkgkk_tssv125.dat
C:\Program Files\KaZaA\Db\np.tmp
C:\Program Files\KaZaA\Db\ova4-060412.cab
C:\Program Files\KaZaA\Db\tsi4-060404a.cab
C:\Program Files\KaZaA\Db\tsi4-060404b.cab
C:\Program Files\KaZaA\Db\tss4.cab
C:\Program Files\Need2Find
C:\Program Files\Need2Find\bar
C:\Program Files\Need2Find\bar\1.bin
C:\Program Files\Need2Find\bar\Cache
C:\Program Files\Need2Find\bar\History
C:\Program Files\Need2Find\bar\Settings
C:\Program Files\Need2Find\bar\1.bin\N2FFXTBR.JAR
C:\Program Files\Need2Find\bar\1.bin\N2NTSTBR.JAR
C:\Program Files\Need2Find\bar\1.bin\PARTNER.DAT
C:\Program Files\Need2Find\bar\Cache\0252BDD8
C:\Program Files\Need2Find\bar\Cache\0254C735
C:\Program Files\Need2Find\bar\Cache\files.ini
C:\Program Files\Need2Find\bar\History\search
C:\Program Files\Need2Find\bar\Settings\prevcfg.htm
C:\DOCUME~1\AS\APPLIC~1\ShopperReports
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156232420.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156232481.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156233430.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156234704.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156234765.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156234826.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156234891.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156234952.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156235013.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156235093.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156235154.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156237582.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\shprrprt_1156341467.log
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\Config.xml
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\db
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\dwld
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\persist.dbs
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\report
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\res1
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\res2
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\db\Aliases.dbs
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\db\Sites.dbs
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\dwld\WhiteList.xip
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\report\aggr_storage.xml
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\report\send_storage.xml
C:\DOCUME~1\AS\APPLIC~1\ShopperReports\cs\res1\WhiteList.dbs
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\shprrprt.log
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\shprrprt_1156216961.log
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\shprrprt_1156217024.log
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs\Config.xml
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs\db
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs\dwld
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs\persist.dbs
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs\report
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs\res2
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs\db\Aliases.dbs
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs\db\Sites.dbs
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs\dwld\WhiteList.xip
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs\report\aggr_storage.xml
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs\report\send_storage.xml
C:\DOCUME~1\JPS\APPLIC~1\ShopperReports\cs\res2\WhiteList.dbs
C:\DOCUME~1\KS\APPLIC~1\ShopperReports
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt.log
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt_1156267763.log
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt_1156318114.log
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt_1156318178.log
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt_1156318239.log
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt_1156318300.log
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt_1156318361.log
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\shprrprt_1156319047.log
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\Application Data
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\Config.xml
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\db
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\dwld
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\persist.dbs
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\report
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\res1
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\res2
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\db\Aliases.dbs
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\db\Sites.dbs
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\dwld\WhiteList.xip
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\report\aggr_storage.xml
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\report\send_storage.xml
C:\DOCUME~1\KS\APPLIC~1\ShopperReports\cs\res2\WhiteList.dbs
C:\DOCUME~1\MS\APPLIC~1\ShopperReports
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\shprrprt.log
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\shprrprt_1155748521.log
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\shprrprt_1155748790.log
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\shprrprt_1155748852.log
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\shprrprt_1155748914.log
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\shprrprt_1155748975.log
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\shprrprt_1155751143.log
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\Config.xml
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\db
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\dwld
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\persist.dbs
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\report
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\res1
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\res2
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\db\Aliases.dbs
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\db\Sites.dbs
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\dwld\WhiteList.xip
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\report\aggr_storage.xml
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\report\send_storage.xml
C:\DOCUME~1\MS\APPLIC~1\ShopperReports\cs\res1\WhiteList.dbs
C:\Program Files\ShopperReports
C:\Program Files\ShopperReports\Bin
C:\Program Files\ShopperReports\cs
C:\Program Files\ShopperReports\Bin\2.0.0
C:\Program Files\ShopperReports\cs\persist.dbs
C:\DOCUME~1\KS\MENUDM~1\PROGRA~1\WhenUSearch
C:\WINDOWS\Fonts\acrsec.fon

-----------\\ Extensions

(AS) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar

(JPS) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
(JPS) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar

(KS) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar

-----------\\ [..\Internet Explorer\Main]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Local Page"="C:\\WINDOWS\\system32\\blank.htm"
"Search Page"="https://www.google.com/?gws_rd=ssl"
"Search Bar"="http://www.google.com/toolbar/ie8/sidebar.html"
"SearchMigratedDefaultURL"="https://www.google.com/webhp?gws_rd=ssl{searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8"
"Start Page"="http://www.plusnetwork.com"
"Default_Search_URL"="http://www.google.com/toolbar/ie8/sidebar.html"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Start Page"="https://www.msn.com/fr-fr/?ocid=iehp"
"Default_Page_URL"="http://home.neuf.fr"

--------------------\\ Recherche d'autres infections

C:\WINDOWS\Pack.epk
[b]==> EGDACCESS <==/b

C:\WINDOWS\system32\22389_up.exe
C:\WINDOWS\system32\27806_up.exe
[b]==> SASSER <==/b

--------------------\\ ROGUES ..

C:\PROGRA~1\SpamBlockerUtility_Icons

1 - "C:\ToolBar SD\TB_1.txt" - 26/06/2009|12:22 - Option : [1]

-----------\\ Fin du rapport a 12:22:31,42
A voir également:

6 réponses

Utilisateur anonyme
 
Reste sur ton premier sujet, les rapport y sont !? peut-etre qu'ils avaient été bloqués car un mot etaient blacklisté.

Un moderateur va fermer le sujet ici.

1
Utilisateur anonyme
 
Salut,

Ouf, tu es bien infecté !

Un rogue, du navipromo et en plus du sasser !!

Ton pc ne s'eteint pas tout seul ?

Car sasser est une infection pouvant eteindre l'ordianteur avec un compte a rebours ...

Pourquoi parle-tu de Kevin05 ? il t'a deja aidé auparavant ? ou tu as deja un sujet en cours avec lui ?

EDIT : je viens de voir que c'est un doublon :

reste sur ce sujet stp :

http://www.commentcamarche.net/forum/affich 13060124 analyse malwarebytes anti malware mbam

0
miosotis
 
Non mon Pc ne s'éteind pas tout seul.

Kevin05, c'est la personne qui m'a demandé de faire cette analyse, et je n'est pas pu poster le résultat sur le sujet en cours avec lui.

Maintenant si mon PC est si infecté, j'aimerai savoir la méthode à employer, j'ai avira antivir personnal actif sur mon PC et je suis loin d'être une pro en informatique, je ne sais que réaliser ce que l'on m'explique de faire

Merci
0
anthony5151 Messages postés 10927 Statut Contributeur sécurité 790
 
Bonjour,

Merci de rester dans ce sujet.

Si tu n'arrives pas à poster un rapport trop long, tu peux l'héberger ailleurs et poster le lien (en suivant ce tuto par exemple)

Et pour t'aider à avancer, tu peux relancer ToolbarS&D, passer à l'option 2 (Suppression), et poster le rapport dans le sujet où Kevin t'aide ;)

0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
miosotis
 
Super merci je vais continuer ici, excuse moi je suis un peu novice!
0
miosotis
 
je suis bête j'arrête ici! lol
0