Virus IS.526410 - Page 2
Résolu
Précédent
- 1
- 2
-
voici de quoi recuperer tes favoris de firefox pour pouvoir les y remettre apres reinstallation de ce dernier
https://www.google.fr/search?hl=fr&q=o%C3%B9+se+trouvent+les+favoris+dans+firefox&btnG=Recherche+Google&meta=&aq=f&oq=&gws_rd=ssl -
-
ah, oui ...lol
Télécharge :ATF Cleaner par Atribune
Double-clique ATF-Cleaner.exe afin de lancer le programme.
Sous l'onglet Main, choisis : Select All
Clique sur le bouton Empty Selected
Si tu utilises le navigateur Firefox :
Clique Firefox au haut et choisis : Select All
Clique le bouton Empty Selected a
NOTE : Si tu veux conserver tes mots de passe sauvegardés, clique No à l'invité.
Si tu utilises le navigateur Opera :
Clique Opera au haut et choisis : Select All
Clique le bouton Empty Selected
NOTE : Si tu veux conserver tes mots de passe sauvegardés, clique No à l'invité.
Clique Exit, du menu prinicipal, afin de fermer le programme.
Pour obtenir du Support technique, double-clique l'adresse électronique située au bas de chacun des menus.
__________________________________________________
Tu peux garder ATF pour d'eventuels netttoyages un peu plus poussés
__________________________________________________
https://www.commentcamarche.net/telecharger/securite/22061-toolscleaner/
---> Télécharge ToolsCleaner2 sur ton Bureau.
* Double-clique sur ToolsCleaner2.exe pour le lancer.
* Clique sur Recherche et laisse le scan agir.
* Clique sur Suppression pour finaliser.
* Tu peux, si tu le souhaites, te servir des Options Facultatives.
* Clique sur Quitter pour obtenir le rapport.
* Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).
________________________________________________
Tu peux supprimer ToolCleaner
_________________________________________________
---> Télécharge et installe CCleaner (N'installe pas la Yahoo Toolbar) :
* Lance-le. Va dans Options puis Avancé et décoche la case Effacer uniquement les fichiers etc....
* Va dans Nettoyeur, choisis Analyse. Une fois terminé, lance le nettoyage.
* Ensuite, choisis Registre, puis Chercher des erreurs. Une fois terminé, répare toutes les erreurs tant de fois qu il en trouve a l analyse
* Veille a ce que dans les options le reglage soit au demarrage de windows et réglé sur "effacement securisé" 35 passes (guttman)
__________________________________________________
Attention : ne pas toucher au PC pendant qu'il travaille !
B-Nettoyage et Défragmentation de tes Disques
*Nettoyage :
Clic droit sur "poste de travail"(ordinateur pour vista) ==>"ouvrir" ==>clic droit sur le disque C ==>Propriétés ==>onglet "Général"
Cliques sur le bouton "nettoyage de disque", OK
tu le fais pour chacun de tes disques
________________________________________________
*Vérifications des erreurs :
Clic droit sur "poste de travail"(ordinateur pour vista) ==>"ouvrir" ==>clic droit sur le disque C ==>Propriétés ==>onglet "Outil"
"Vérifier maintenant", une boîte s'ouvre, cocher les cases :
-réparer automatiquement les erreurs...
-rechercher et tenter une récupération...
--->Démarrer, ok
Note : s'il te dis de redémarrer ton Pc pour le faire , tu redémarres et tu laisses faire, cela prend un peu de temps c'est normal
tu le fais pour chacun de tes disques
________________________________________________
ensuite toujours dans le même onglet tu choisis :
*Défragmentation :
"défragmenter maintenant", OK
une boîte s'ouvre, tu sélectionnes le disque à défragmenter, et tu cliques sur "analyser", puis après l'analyse, "défragmenter" . OK
tu le fais pour chacun de tes disques
_______________________________________________
Note : si tu as un utilitaire pour défragmenter , utilises le à la place
pour ce faire Defraggler est proposé
_________________________________________________
> Peux-tu vérifier Console Java ? :
et installer la nouvelle version si besoin est (dans ce cas désinstalle avant l'ancienne version).
Tuto
voici pour desinstaller :
JavaRa
Décompresse le fichier sur le Bureau (Clic droit > Extraire tout).
* Double-clique sur le répertoire JavaRa.
* Puis double-clique sur le fichier JavaRa.exe (le exe peut ne pas s'afficher).
* Choisis Français puis clique sur Select.
* Clique sur Recherche de mises à jour.
* Sélectionne Mettre à jour via jucheck.exe puis clique sur Rechercher.
* Autorise le processus à se connecter s'il le demande, clique sur Installer et suis les instructions d'installation qui prennent quelques minutes.
* L'installation est terminée, reviens à l'écran de JavaRa et clique sur Effacer les anciennes versions.
* Clique sur Oui pour confirmer. Laisse travailler et clique ensuite sur OK, puis une deuxième fois sur OK.
* Un rapport va s'ouvrir. Poste-le dans ta prochaine réponse.
* Ferme l'application.
Note : le rapport se trouve aussi dans C:\ sous le nom JavaRa.log.
_________________________________________________
> Mets à jour Adobe Reader si ce n'est pas le cas (désinstalle avant la version antérieure)
__________________________________________________
Je te conseille si tu n en as pas , afin de mieux securiser ton pc , d'installer un parefeu :
Online armor ou KERIO ou JETICO ou ZONE ALARM (mettre que le parefeu gratuit) ou COMODO
https://www.commentcamarche.net/telecharger/securite/16545-online-armor-personal-firewall/
https://www.01net.com/telecharger/windows/Securite/firewall/fiches/39911.html
https://forum.pcastuces.com/sujet.asp?f=25&s=35606
https://www.clubic.com/telecharger-fiche11071-sunbelt-personal-firewall-ex-kerio.html
https://manuelsdaide.com/contact/
http://www.open-files.com/forum/index.php?showtopic=29277
https://www.commentcamarche.net/telecharger/securite/24863-zonealarm/
___________________________________________________
> Tu peux aussi vider ta corbeille,quoi que Ccleaner le fasse tout seul
_____________________________________________________
> Si nous avons utilisé MalwareByte's Anti-Malware : vide sa quarantaine.
- Lance le programme puis clique sur <Quarantaine>.
- Sélectionne tous les éléments puis clique sur <supprimer>.
- Quitte le programme.
______________________________________________________
>si tu as installé Antivir :
Configuration
________________________________________________________
> Idem pour ton antivirus : vide sa quarantaine si ce n'est pas déjà fait
______________________________________________________
> Désactive et réactive la restauration de système, pour cela : suis les instructions du lien :
Lien XP
Lien Vista
Sitôt fait , recrées un point de restoration dit "sain" pour parer à quelques eventuels problêmes dans le futur
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Quelques conseils et recommandations pour l'avenir :
> Passe un coup de MalwareByte's Anti-Malware de temps en temps (1 fois par semaine , suivant l'utilisation que tu fais de ton PC.
- Utilise aussi tes autres logiciels de protection (scannes antivirus, antispywares...). N'oublie pas de faire les mises à jour avant de les utiliser.
- Pense aussi à faire une défragmentation de tes disques durs de temps en temps (garde suffisamment d'espace sur C:\ (1/3 de libre pour être à l'aise))
_____________
> Pour bien protéger ton PC :
[1 seul Antivirus] + [1 seul Pare feu (/!\ les routeurs et box en possèdent un)] + [Un bon Antispyware avec immunisation] + [Mises à Jour récentes Windows et Logiciels de Protection] + [Utilisation de Firefox -ou autres- (Internet Explorer présente des failles de sécurité qui mettent longtemps avant d'être corrigées mais il faut absolument le conserver pour les mises à jour Windows et Windows live Messenger)]
Je te conseille d'installer cette extension pour Firefox pour securiser ton surf : WOT
PS : En fait la meilleure des protections c'est toi même : ce que tu fais avec ton PC : où tu surfes, télécharges...ect....
Les virus utilisent les failles de ton PC pour infecter un système
dans le souhait de vouloir desinstaller un antivirus au profit d'un autre , voici quelques liens :
Desinstaller Avast
Desinstaller BitDefender
Desinstaller Norton
Desinstaller Kaspersky
Desinstaller AVG
ou tout en un :
Désinstallation Antivirus , Parefeu , Antispyware
_____________
>lien utile
>SpywareBlaster = petit logiciel qui bloque l'installation d'activeX nuisibles au PC.(Fonctionne en arrière plan)
____________
Si tu as Vista n'oublie pas de réactiver le controle des comptes des utilisateurs(UAC)
___________
Si tu as Spybot S&D et que nous avons desactive le "Tea-timer" tu peux le réactiver
___________
si nous avons affiché les fichiers cachés , n'oublies pas de les remettre en attribut "caché"
____________
Voila,
Bonne lecture, à bientot,une fois tout ceci fait tu peux mettre le topic en resolu
-
Merci pour tout. Je continue les manips.En attendant, je te transmets le rapport de ToolsCleaner2:
[ Rapport ToolsCleaner version 2.3.5 (par A.Rothstein & dj QUIOU) ]
--> Recherche:
C:\SDFIX: trouvé !
C:\Rsit: trouvé !
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis: trouvé !
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis\HijackThis.lnk: trouvé !
C:\Documents and Settings\K\Bureau\SdFix.exe: trouvé !
C:\Documents and Settings\K\Bureau\HijackThis.lnk: trouvé !
C:\Program Files\Ad-remover: trouvé !
C:\Program Files\Trend Micro\HijackThis: trouvé !
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: trouvé !
C:\Program Files\Trend Micro\HijackThis\hijackthis.log: trouvé !
C:\WINDOWS\ERUNT\SDFIX: trouvé !
---------------------------------
--> Suppression:
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis\HijackThis.lnk: supprimé !
C:\Documents and Settings\K\Bureau\SdFix.exe: supprimé !
C:\Documents and Settings\K\Bureau\HijackThis.lnk: supprimé !
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: supprimé !
C:\Program Files\Trend Micro\HijackThis\hijackthis.log: supprimé !
C:\SDFIX: supprimé !
C:\Rsit: supprimé !
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis: supprimé !
C:\Program Files\Ad-remover: supprimé !
C:\Program Files\Trend Micro\HijackThis: supprimé !
C:\WINDOWS\ERUNT\SDFIX: supprimé ! -
A propos de:
"Attention : ne pas toucher au PC pendant qu'il travaille !
B-Nettoyage et Défragmentation de tes Disques
*Nettoyage :
Clic droit sur "poste de travail"(ordinateur pour vista) ==>"ouvrir" ==>clic droit sur le disque C ==>Propriétés ==>onglet "Général"
Cliques sur le bouton "nettoyage de disque", OK
tu le fais pour chacun de tes disques "
Pour le poste C:
J'ai cliqué sur "nettoyage de disque" une fenêtre s'est ouverte me demandant de supprimer "compression des fichiers non-utilisés 27ko" dois-je cliquer sur OK?
Pour le poste E:
la fenêtre qui s'ouvre me propose de supprimer:
"Anciens fichiers Chkdsk" 372932 K.
Dois-je, stp, les supprimer?
Merci.
-
-
-
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question -
-
...merci je pensais qu'un logiciel ne pouvait pas être supprimer de cette manière...
A propos de ta proposition:
"Note : si tu as un utilitaire pour défragmenter , utilises le à la place
pour ce faire Defraggler est proposé"
Je possède le défragmenteur intégré à windows et on m'a déjà demandé de télécharger JKDefrag.
Que me conseilles-tu entre les 3 (jldefrag, défragmenteur windows, defragler), s'il te plaît?
Merci.
-
-
merci je pensais qu'un logiciel ne pouvait pas être supprimer de cette manière...
tu as certes raison mais ToolsCleaner2 n'est pas un logiciel , c'est une simple application sans installation :)
JKDefrag est bien utilise-le
celui de windows est pas terrible -
-
Pour la défragmentation je la ferai ce soir parce qu'elles sont très longues en général...
Je me suis occupée de JAVA.
Voilà le rapport:
JavaRa 1.15 Removal Log.
Report follows after line.
------------------------------------
The JavaRa removal process was started on Fri Jul 31 18:07:57 2009
Found and removed: C:\Documents and Settings\K\Application Data\Sun\Java\jre1.6.0_11
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA}
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_02
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_03
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_04
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2
Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2.0_01
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBB}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBA}
Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBB}
Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.6.0_07
Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.6.0_07
Found and removed: SOFTWARE\Microsoft\Active Setup\Installed Components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500}
Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACBB9B2318A96D117A58000B0D610007
Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3248F0A8-6813-11D6-A77B-00B0D0160070}
------------------------------------
Finished reporting.
-
-
-
Bonsoir,
Je te transmets le log de la défragmentation faite par JKDefrag:
17:02:45 JkDefrag v3.36
17:02:45 Date: 2009/08/03
17:02:45 Windows version: v5.1 build 2600 Service Pack 3
17:02:45 NtfsDisableLastAccessUpdate is inactive, using LastAccessTime for SpaceHogs.
17:02:45 Analyzing volume 'C:\'
17:02:45 Processing 'C:\*'
17:02:45 Opening volume '\\?\Volume{552abb47-16ad-11dd-8de7-806d6172696f}' at mountpoint 'C:'
17:02:45 Input mask: C:\*
17:02:46 Phase 1: Analyze
17:02:46 This is an NTFS disk.
17:02:58 Phase 2: Defragment
19:21:28 Phase 3: Fixup
19:55:17 Zone 1: Fast Optimize
19:55:57 Zone 2: Fast Optimize
20:20:28 Zone 3: Fast Optimize
20:30:44 Phase 3: Fixup
20:30:45 Finished.
20:30:45 - Total disk space: 74402975744 bytes (69.2932 gigabytes), 18164789 clusters
20:30:45 - Bytes per cluster: 4096 bytes
20:30:45 - Number of files: 70858
20:30:45 - Number of directories: 9443
20:30:45 - Total size of analyzed items: 28798517248 bytes (26.8207 gigabytes), 7030888 clusters
20:30:45 - Number of fragmented items: 3 (0.0037% of all items)
20:30:45 - Total size of fragmented items: 143204352 bytes, 34962 clusters, 0.4973% of all items, 0.1925% of disk
20:30:45 - Free disk space: 44796735488 bytes, 10936703 clusters, 60.2083% of disk
20:30:45 - Number of gaps: 354
20:30:45 - Number of small gaps: 178 (50.2825% of all gaps)
20:30:45 - Size of small gaps: 4100096 bytes, 1001 clusters, 0.0092% of free disk space
20:30:45 - Number of big gaps: 176 (49.7175% of all gaps)
20:30:45 - Size of big gaps: 44792635392 bytes, 10935702 clusters, 99.9908% of free disk space
20:30:45 - Average gap size: 30894.6412 clusters
20:30:45 - Biggest gap: 15183224832 bytes, 3706842 clusters, 33.8936% of free disk space
20:30:45 - Average end-begin distance: 1835871 clusters, 10.1068% of volume size
20:30:45 These items could not be moved:
20:30:45 Fragments Bytes Clusters Name
20:30:45 1 8532 3 C:\Documents and Settings\K\Local Settings\Application Data\Microsoft\CardSpace\CardSpace.db
20:30:45 1 67108864 16384 C:\$LogFile
20:30:45 4 13192 4 C:\$MFT::$BITMAP
20:30:45 2 108052480 26380 C:\$MFT
20:30:45 68 7987853240 8578 C:\$Extend\$UsnJrnl:$J:$DATA
20:30:45 1 4096 1 C:\$MFTMirr
20:30:45 1 4144 2 C:\.::$SECURITY_DESCRIPTOR
20:30:45 1 2270600 555 C:\$Bitmap
20:30:45 1 805306368 196608 C:\pagefile.sys
20:30:45 1 12288 3 C:\.
20:30:45 --------- ----------- --------- -----
20:30:45 81 8970633804 248518 Total
20:30:45 These items are still fragmented:
20:30:45 Fragments Bytes Clusters Name
20:30:45 4 13192 4 C:\$MFT::$BITMAP
20:30:45 2 108052480 26380 C:\$MFT
20:30:45 68 7987853240 8578 C:\$Extend\$UsnJrnl:$J:$DATA
20:30:45 --------- ----------- --------- -----
20:30:45 74 8095918912 34962 Total
20:30:45 The 25 largest items on disk:
20:30:45 Fragments Bytes Clusters Name
20:30:45 1 805306368 196608 C:\pagefile.sys
20:30:45 1 439560496 107315 C:\Documents and Settings\All Users\Documents\Mes vidéos\MAD MEN Saison 2 Episode 8 - Une soirée inoubliable (vod_11448).wmv
20:30:45 1 438368442 107024 C:\Documents and Settings\All Users\Documents\Mes vidéos\MAD MEN Saison 2 Episode 9 - Cruelle absence (vod_11449).wmv
20:30:45 1 433480298 105831 C:\Documents and Settings\All Users\Documents\Mes vidéos\MAD MEN Saison 2 Episode 13 - Crise de conscience (vod_11665).wmv
20:30:45 1 432688244 105637 C:\Documents and Settings\All Users\Documents\Mes vidéos\Mad Men Saison 2 Episode 11 - Jet-set (vod_11576).wmv
20:30:45 1 432656226 105629 C:\Documents and Settings\All Users\Documents\Mes vidéos\MAD MEN Saison 2 Episode 7 - Le violon d'or (vod_11334).wmv
20:30:45 1 431488196 105344 C:\Documents and Settings\All Users\Documents\Mes vidéos\MAD MEN Saison 2 Episode 12 - Dans l'antre du roi de la montagne (vod_11664).wmv
20:30:45 1 429856118 104946 C:\Documents and Settings\All Users\Documents\Mes vidéos\Mad Men Saison 2 Episode 10 - Héritage (vod_11575).wmv
20:30:45 1 389302576 95045 C:\Documents and Settings\All Users\Documents\Mes vidéos\The Starter Wife Saison 2 Episode 4 - Mollywood (vod_11391).wmv
20:30:45 1 389126558 95002 C:\Documents and Settings\All Users\Documents\Mes vidéos\The Starter Wife Saison 2 Episode 6 - Ex Files (vod_11499).wmv
20:30:45 1 388822564 94928 C:\Documents and Settings\All Users\Documents\Mes vidéos\The Starter Wife Saison 2 Episode 10 - Une femme sous influence (vod_11668).wmv
20:30:45 1 388182522 94772 C:\Documents and Settings\All Users\Documents\Mes vidéos\The Starter Wife Saison 2 Episode 3 - Indiscrétions (vod_11390).wmv
20:30:45 1 387494528 94604 C:\Documents and Settings\All Users\Documents\Mes vidéos\The Starter Wife Saison 2 Episode 5 - Liaison dangereuse (vod_11498).wmv
20:30:45 1 387326510 94563 C:\Documents and Settings\All Users\Documents\Mes vidéos\The Starter Wife Saison 2 Episode 9 - La femme volontaire (vod_11667).wmv
20:30:45 1 384958432 93984 C:\Documents and Settings\All Users\Documents\Mes vidéos\The Starter Wife Saison 2 Episode 7 - French Déconnection (vod_11577).wmv
20:30:45 1 379798240 92725 C:\Documents and Settings\All Users\Documents\Mes vidéos\The Starter Wife Episode 8 - Harcèlement (vod_11578).wmv
20:30:45 1 255609344 62405 C:\Documents and Settings\K\Local Settings\Application Data\Downloaded Installations\{018E1978-2583-43DB-A60A-8F33C20133A9}\setup.msi
20:30:45 1 252671600 61688 C:\Documents and Settings\K\Bureau\Set Up Installation Logiciels\G DATA 2008.exe
20:30:45 1 252671600 61688 C:\Documents and Settings\K\Bureau\Set Up Installation Logiciels\GDTC2008.exe
20:30:45 1 242743296 59264 C:\Documents and Settings\K\Bureau\2 dotnetfx35.exe
20:30:45 1 242743296 59264 C:\WINDOWS\SoftwareDistribution\Download\3dce66bae0dd71284ac7a971baed07030a186918
20:30:45 1 135083008 32980 C:\WINDOWS\Installer\a28662.msp
20:30:45 1 121957877 29775 C:\Documents and Settings\K\Bureau\Set Up Installation Logiciels\Programme d'installation d'Adobe Reader 9\Data1.cab
20:30:45 1 121957877 29775 C:\Program Files\Adobe\Reader 9.0\Reader\Data1.cab
20:30:45 1 121859183 29751 C:\Documents and Settings\K\Bureau\Set Up Installation Logiciels\Adobe Reader 9 Installer\Data1.cab
20:30:45 Analyzing volume 'D:\'
20:30:45 Volume '\\?\Volume{eba584c9-16db-11dd-b6a8-806d6172696f}' at mountpoint 'D:\' is not mounted.
20:30:45 Analyzing volume 'E:\'
20:30:45 Processing 'E:\*'
20:30:45 Opening volume '\\?\Volume{eba584c8-16db-11dd-b6a8-806d6172696f}' at mountpoint 'E:'
20:30:45 Input mask: E:\*
20:30:46 Phase 1: Analyze
20:30:46 This is not a FAT or NTFS disk, using the slow scanner.
20:30:49 Phase 2: Defragment
20:30:49 Phase 3: Fixup
20:30:50 Zone 1: Fast Optimize
20:30:52 Zone 2: Fast Optimize
20:34:04 Zone 3: Fast Optimize
20:40:12 Phase 3: Fixup
20:40:12 Finished.
20:40:12 - Total disk space: 0 bytes (0.0000 gigabytes), 1369453 clusters
20:40:12 - Bytes per cluster: 0 bytes
20:40:12 - Number of files: 5351
20:40:12 - Number of directories: 162
20:40:12 - Total size of analyzed items: 0 bytes (0.0000 gigabytes), 866039 clusters
20:40:12 - Number of fragmented items: 6 (0.1088% of all items)
20:40:12 - Total size of fragmented items: 0 bytes, 63 clusters, 0.0073% of all items, 0.0046% of disk
20:40:12 - Free disk space: 0 bytes, 503407 clusters, 36.7597% of disk
20:40:12 - Number of gaps: 122
20:40:12 - Number of small gaps: 43 (35.2459% of all gaps)
20:40:12 - Size of small gaps: 0 bytes, 171 clusters, 0.0340% of free disk space
20:40:12 - Number of big gaps: 79 (64.7541% of all gaps)
20:40:12 - Size of big gaps: 0 bytes, 503236 clusters, 99.9660% of free disk space
20:40:12 - Average gap size: 4126.2869 clusters
20:40:12 - Biggest gap: 0 bytes, 163669 clusters, 32.5123% of free disk space
20:40:12 - Average end-begin distance: 145420 clusters, 10.6189% of volume size
20:40:12 The 25 largest items on disk:
20:40:12 Fragments Bytes Clusters Name
20:40:12 1 163891031 40013 E:\TOOLS\windows\CREATOR\Tool CD.INP
20:40:12 1 114636288 27988 E:\I386\Apps\APP09894\App09894.exe
20:40:12 1 108023594 26373 E:\PRELOAD\BASE_11.INP
20:40:12 1 107078089 26143 E:\PRELOAD\BASE_19.INP
20:40:12 1 106560401 26016 E:\PRELOAD\BASE_09.INP
20:40:12 1 103805507 25344 E:\PRELOAD\BASE_16.INP
20:40:12 1 102821289 25103 E:\PRELOAD\BASE_17.INP
20:40:12 1 102148080 24939 E:\PRELOAD\BASE_15.INP
20:40:12 1 99262895 24235 E:\PRELOAD\BASE_18.INP
20:40:12 1 99258368 24233 E:\I386\Apps\APP26299\App26299.exe
20:40:12 1 91664864 22380 E:\PRELOAD\BASE_14.INP
20:40:12 1 90325233 22053 E:\PRELOAD\BASE_04.INP
20:40:12 1 88648704 21643 E:\I386\Apps\APP23811\App23811.exe
20:40:12 1 80216684 19585 E:\PRELOAD\DATA9.INP
20:40:12 1 76451905 18666 E:\PRELOAD\BASE_12.INP
20:40:12 1 75880323 18526 E:\PRELOAD\DATA2.INP
20:40:12 1 73285020 17892 E:\PRELOAD\BASE_20.INP
20:40:12 1 70337860 17173 E:\PRELOAD\BASE_06.INP
20:40:12 1 67013473 16361 E:\PRELOAD\BASE_02.INP
20:40:12 1 63161024 15421 E:\I386\DRIVER.CAB
20:40:12 1 61052958 14906 E:\PRELOAD\BASE_05.INP
20:40:12 1 58641177 14317 E:\PRELOAD\BASE_08.INP
20:40:12 1 56909538 13894 E:\PRELOAD\BASE_13.INP
20:40:12 1 54854144 13393 E:\I386\Apps\APP14771\App14771.exe
20:40:12 1 54838204 13389 E:\PRELOAD\BASE.INP
20:40:12 Analyzing volume 'F:\'
20:40:12 Ignoring volume 'F:\' because it has removable media.
20:40:12 Analyzing volume 'G:\'
20:40:12 Ignoring volume 'G:\' because there is no volume mounted.
20:40:12 Analyzing volume 'H:\'
20:40:12 Processing 'H:\*'
20:40:12 Opening volume '\\?\Volume{552abb46-16ad-11dd-8de7-806d6172696f}' at mountpoint 'H:'
20:40:12 Input mask: H:\*
20:40:13 Phase 1: Analyze
20:40:13 This is a FAT32 disk.
20:40:14 Phase 2: Defragment
20:40:14 Phase 3: Fixup
20:40:19 Zone 1: Fast Optimize
20:40:21 Zone 2: Fast Optimize
20:40:22 Zone 3: Fast Optimize
20:40:26 Phase 3: Fixup
20:40:26 Finished.
20:40:26 - Total disk space: 5609279488 bytes (5.2240 gigabytes), 1369453 clusters
20:40:26 - Bytes per cluster: 4096 bytes
20:40:26 - Number of files: 8306
20:40:26 - Number of directories: 206
20:40:26 - Total size of analyzed items: 3942248448 bytes (3.6715 gigabytes), 962463 clusters
20:40:26 - Number of fragmented items: 8 (0.0940% of all items)
20:40:26 - Total size of fragmented items: 286720 bytes, 70 clusters, 0.0073% of all items, 0.0051% of disk
20:40:26 - Free disk space: 1667006464 bytes, 406984 clusters, 29.7187% of disk
20:40:26 - Number of gaps: 84
20:40:26 - Number of small gaps: 36 (42.8571% of all gaps)
20:40:26 - Size of small gaps: 737280 bytes, 180 clusters, 0.0442% of free disk space
20:40:26 - Number of big gaps: 48 (57.1429% of all gaps)
20:40:26 - Size of big gaps: 1666269184 bytes, 406804 clusters, 99.9558% of free disk space
20:40:26 - Average gap size: 4845.0476 clusters
20:40:26 - Biggest gap: 1157586944 bytes, 282614 clusters, 69.4411% of free disk space
20:40:26 - Average end-begin distance: 257167 clusters, 18.7788% of volume size
20:40:26 The 25 largest items on disk:
20:40:26 Fragments Bytes Clusters Name
20:40:26 1 163891031 40013 H:\TOOLS\WINDOWS\CREATOR\Tool CD.INP
20:40:26 1 114636288 27988 H:\I386\Apps\APP09894\App09894.exe
20:40:26 1 108023594 26373 H:\PRELOAD\BASE_11.INP
20:40:26 1 107078089 26143 H:\PRELOAD\BASE_19.INP
20:40:26 1 106560401 26016 H:\PRELOAD\BASE_09.INP
20:40:26 1 103805507 25344 H:\PRELOAD\BASE_16.INP
20:40:26 1 102821289 25103 H:\PRELOAD\BASE_17.INP
20:40:26 1 102148080 24939 H:\PRELOAD\BASE_15.INP
20:40:26 1 99262895 24235 H:\PRELOAD\BASE_18.INP
20:40:26 1 99258368 24233 H:\I386\Apps\APP26299\App26299.exe
20:40:26 1 96126976 23469 H:\I386\BOOT.IMG
20:40:26 1 91664864 22380 H:\PRELOAD\BASE_14.INP
20:40:26 1 90325233 22053 H:\PRELOAD\BASE_04.INP
20:40:26 1 88648704 21643 H:\I386\Apps\APP23811\App23811.exe
20:40:26 1 80216684 19585 H:\PRELOAD\DATA9.INP
20:40:26 1 76451905 18666 H:\PRELOAD\BASE_12.INP
20:40:26 1 75880323 18526 H:\PRELOAD\DATA2.INP
20:40:26 1 73285020 17892 H:\PRELOAD\BASE_20.INP
20:40:26 1 70337860 17173 H:\PRELOAD\BASE_06.INP
20:40:26 1 67013473 16361 H:\PRELOAD\BASE_02.INP
20:40:26 1 63161024 15421 H:\I386\DRIVER.CAB
20:40:26 1 61052958 14906 H:\PRELOAD\BASE_05.INP
20:40:26 1 58641177 14317 H:\PRELOAD\BASE_08.INP
20:40:26 1 56909538 13894 H:\PRELOAD\BASE_13.INP
20:40:26 1 54854144 13393 H:\I386\Apps\APP14771\App14771.exe
20:40:26 Analyzing volume 'I:\'
20:40:26 Ignoring volume 'I:\' because it is a CD-ROM drive.
20:40:26 Analyzing volume 'J:\'
20:40:26 Ignoring volume 'J:\' because it is a CD-ROM drive.
20:40:26 Analyzing volume 'K:\'
20:40:26 Ignoring volume 'K:\' because it has removable media.
20:40:26 Analyzing volume 'L:\'
20:40:26 Ignoring volume 'L:\' because it has removable media.
20:40:26 Analyzing volume 'P:\'
20:40:26 Ignoring volume 'P:\' because it has removable media.
20:40:26 Finished.
Merci et douce nuit.
-
-
desinstalle Ad-Remover
ensuite :
Télécharge Zeb-Restore http://telechargement.zebulon.fr/zeb-restore.html enregistre ce fichier sur le bureau.
-Clic droit Zeb-Restore.zip ==> Extraire tout choisis comme lieu d'enregistrement le bureau.
-Ouvre le dossier ZR_1.0.0.37 ==> double clic sur Zeb-Restore.exe
- Coche la case devant :sites de confiance
- Ne coche aucune autre case
-Clique sur Restaurer
-Redémarre ton PC
ensuite :
Double clic sur OTL.exe pour le lancer.
Copie la liste qui se trouve en gras ci-dessous,
et colle-la dans la zone sous Customs Scans/Fixes
:processes
explorer.exe
iexplore.exe
firefox.exe
msnmsgr.exe
TeaTimer.exe
:OTL
O3 - HKU\S-1-5-21-1644491937-117609710-839522115-1004\..\Toolbar\WebBrowser: (no name) - {34EA1C70-42CC-42C5-AA29-EC58B95A343E} - No CLSID value found.
O3 - HKU\S-1-5-21-1644491937-117609710-839522115-1004\..\Toolbar\WebBrowser: (WOT) - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\msdaipp - No CLSID value found
@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
@Alternate Data Stream - 103 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
:files
C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
:commands
[emptytemp]
[start explorer]
[reboot]
Clique sur RunFix pour lancer la suppression.
Poste le rapport.
==========
-
J'ai eu très peur...
Après avoir collé la liste en gras j'ai cliqué sur RunFix; mon bureau a immédiatement disparu j'ai eu un écran bleu et cela pendant une demie-heure...j'ai alors coupé l'alimentation électrique du PC pour l'éteindre...
Mon bureau a mis plus d'un quart d'heure à s'afficher...Aucun rapport n'a été crée...
Je ne sais pas si la dernière manip a été menée à bien...
Comment dois-je procéder, s'il te plaît?
Dois-je relancer OTL.exe?
Merci.
-
-
-
regarde dans :
C:\_OTL\un rapport txt avec la date et l heure comme nom
le plus recent si plusieurs -
-
-
-
Bonjour,
J'ai refait toute la manip.
Le même sénario s'est reproduit. Écran bleu sans rien de mentionné pendant 25mn. J'ai éteins électriquement l'ordi. une fois de plus.
J'ai cherché dans C et n'ai pas trouvé de rapport de OLT...
Une chose à te préciser qd j'ai ouvert Firefox j'ai reçu une bonne dizaine d'alertes de GData internet sécurity 2009; toutes mentionnaient la même chose:
Connexion sortante
Modules inconnus !
Application: Firefox.exe
Démarré depuis: Explorer.EXE.
Réseau: Connexion au réseau local.
Journal: UDP
Port: dns (53)
Adresse IP: HSIB. home.
Voulez-vous autoriser ?
A chaque fois j'ai cliqué sur "toujours autoriser".
Qu'en penses-tu?
As-tu une idée des problèmes que rencontre l'ordi?
Dois-je recommencé en mode sans échec comme tu me l'as suggéré? (J'ai oublié de le faire de cette manière cette fois).
Bonne journée.
-
-
-
bien il doit y avoir une clé qui nous emm************
passe ce logiciel de diagnostic stp :
Télécharge Random's System Information Tool (RSIT) de random/random et enregistre l'exécutable sur ton Bureau.
! Déconnecte toi et ferme toutes tes applications en cours !
Double-clique sur " RSIT.exe " pour le lancer .
-> Une première fenêtre s'ouvre avec en titre : " Disclaimer of warranty " .
* Devant l'option "List files/folders created ..." , tu choisis : 2 months
* clique ensuite sur " Continue " pour lancer l'analyse ...
-> laisse faire le scan et ne touche pas au PC ...
Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront (probablement avec le bloc-note).
Poste le contenu de " log.txt " (c'est celui qui apparait à l'écran), ainsi que de " info.txt " (que tu verras dans la barre des tâches), pour analyse et attends la suite ...
Important : poste un rapport, puis l'autre dans la réponse suivante
Si tu essaies de poster les deux en même temps, cela risque d'être trop long pour le forum
( Note : les rapports seront en outre sauvegardés dans ce dossier -> C:\rsit )
-
Je te transmets ce que j'ai obtenu.
J'ai cliqué sur 3 months car j'ai eu recours à ce site et au site malekal depuis avril...
Je suis allée ds C:\rsit je n'ai trouvé qu'un seul rapport
Je recommence en cliquant sur 2 months.
Je n'ai obtenu qu'un seul rapport celui-ci:
Logfile of random's system information tool 1.05 (written by random/random)
Run by K at 2009-07-27 19:33:53
Microsoft Windows XP Édition familiale Service Pack 3
System drive C: has 46 GB (66%) free of 71 GB
Total RAM: 511 MB (32% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:34:09, on 27/07/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Fichiers communs\G DATA\AVKProxy\AVKProxy.exe
C:\Program Files\G DATA\InternetSecurity\AVK\AVKService.exe
C:\Program Files\G DATA\InternetSecurity\AVK\AVKWCtl.exe
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\G DATA\InternetSecurity\Firewall\GDFwSvc.exe
C:\Program Files\G DATA\InternetSecurity\Firewall\GDFirewallTray.exe
C:\Program Files\G DATA\InternetSecurity\AVKTray\AVKTray.exe
C:\Documents and Settings\K\Bureau\Random'sSystemInformationTool.exe
C:\Program Files\Trend Micro\HijackThis\K.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\Orange\SearchURLHook\SearchPageURL.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: QFX Software KeyScrambler - {2B9F5787-88A5-4945-90E7-C4B18563BC5E} - C:\Program Files\KeyScrambler\KeyScramblerIE.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: WOT Helper - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: MEDIADICO Familial - {CEDDA62B-5FBE-4AB2-AE2E-5E069F444444} - C:\Program Files\LAventure\MDToolbar\MdToolbar.dll
O3 - Toolbar: WOT - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll
O4 - HKLM\..\Run: [GDFirewallTray] C:\Program Files\G DATA\InternetSecurity\Firewall\GDFirewallTray.exe
O4 - HKLM\..\Run: [G DATA AntiVirus Trayapplication] C:\Program Files\G DATA\InternetSecurity\AVKTray\AVKTray.exe
O9 - Extra button: (no name) - {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - C:\Program Files\KeyScrambler\KeyScramblerIE.dll
O9 - Extra 'Tools' menuitem: &KeyScrambler... - {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - C:\Program Files\KeyScrambler\KeyScramblerIE.dll
O15 - ProtocolDefaults: '@ivt' protocol is in My Computer Zone, should be Intranet Zone
O15 - ProtocolDefaults: 'file' protocol is in My Computer Zone, should be Internet Zone
O15 - ProtocolDefaults: 'ftp' protocol is in My Computer Zone, should be Internet Zone
O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should be Internet Zone
O15 - ProtocolDefaults: 'https' protocol is in My Computer Zone, should be Internet Zone
O15 - ProtocolDefaults: '@ivt' protocol is in My Computer Zone, should be Intranet Zone (HKLM)
O15 - ProtocolDefaults: 'file' protocol is in My Computer Zone, should be Internet Zone (HKLM)
O15 - ProtocolDefaults: 'ftp' protocol is in My Computer Zone, should be Internet Zone (HKLM)
O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should be Internet Zone (HKLM)
O15 - ProtocolDefaults: 'https' protocol is in My Computer Zone, should be Internet Zone (HKLM)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Program Files\LSI SoftModem\agrsmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: G DATA AntiVirus Proxy (AVKProxy) - G DATA Software AG - C:\Program Files\Fichiers communs\G DATA\AVKProxy\AVKProxy.exe
O23 - Service: Planificateur G DATA (AVKService) - G DATA Software AG - C:\Program Files\G DATA\InternetSecurity\AVK\AVKService.exe
O23 - Service: Gardien d'AntiVirus (AVKWCtl) - G DATA Software AG - C:\Program Files\G DATA\InternetSecurity\AVK\AVKWCtl.exe
O23 - Service: CanalPlus.VOD - Canal+ Active - C:\Program Files\Canal\Canal Widget\VOD\CanalPlus.VOD.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
O23 - Service: Pare-feu personnel G DATA (GDFwSvc) - G DATA Software AG - C:\Program Files\G DATA\InternetSecurity\Firewall\GDFwSvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
-
Je ne comprends pas je n'obtiens pas "info.txt"
J'ai à nouveau obtenu un log-txt que je te transmets.
J'ai bien choisi l'option 2 months.
J'ai désactivé l'anti-virus et le pare-feu.
Logfile of random's system information tool 1.05 (written by random/random)
Run by K at 2009-07-27 19:55:24
Microsoft Windows XP Édition familiale Service Pack 3
System drive C: has 46 GB (66%) free of 71 GB
Total RAM: 511 MB (28% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:55:29, on 27/07/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Fichiers communs\G DATA\AVKProxy\AVKProxy.exe
C:\Program Files\G DATA\InternetSecurity\AVK\AVKService.exe
C:\Program Files\G DATA\InternetSecurity\AVK\AVKWCtl.exe
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\G DATA\InternetSecurity\Firewall\GDFwSvc.exe
C:\Program Files\G DATA\InternetSecurity\Firewall\GDFirewallTray.exe
C:\Program Files\G DATA\InternetSecurity\AVKTray\AVKTray.exe
C:\Documents and Settings\K\Bureau\Random'sSystemInformationTool.exe
C:\Program Files\Trend Micro\HijackThis\K.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\Orange\SearchURLHook\SearchPageURL.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: QFX Software KeyScrambler - {2B9F5787-88A5-4945-90E7-C4B18563BC5E} - C:\Program Files\KeyScrambler\KeyScramblerIE.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: WOT Helper - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: MEDIADICO Familial - {CEDDA62B-5FBE-4AB2-AE2E-5E069F444444} - C:\Program Files\LAventure\MDToolbar\MdToolbar.dll
O3 - Toolbar: WOT - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll
O4 - HKLM\..\Run: [GDFirewallTray] C:\Program Files\G DATA\InternetSecurity\Firewall\GDFirewallTray.exe
O4 - HKLM\..\Run: [G DATA AntiVirus Trayapplication] C:\Program Files\G DATA\InternetSecurity\AVKTray\AVKTray.exe
O9 - Extra button: (no name) - {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - C:\Program Files\KeyScrambler\KeyScramblerIE.dll
O9 - Extra 'Tools' menuitem: &KeyScrambler... - {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - C:\Program Files\KeyScrambler\KeyScramblerIE.dll
O15 - ProtocolDefaults: '@ivt' protocol is in My Computer Zone, should be Intranet Zone
O15 - ProtocolDefaults: 'file' protocol is in My Computer Zone, should be Internet Zone
O15 - ProtocolDefaults: 'ftp' protocol is in My Computer Zone, should be Internet Zone
O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should be Internet Zone
O15 - ProtocolDefaults: 'https' protocol is in My Computer Zone, should be Internet Zone
O15 - ProtocolDefaults: '@ivt' protocol is in My Computer Zone, should be Intranet Zone (HKLM)
O15 - ProtocolDefaults: 'file' protocol is in My Computer Zone, should be Internet Zone (HKLM)
O15 - ProtocolDefaults: 'ftp' protocol is in My Computer Zone, should be Internet Zone (HKLM)
O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should be Internet Zone (HKLM)
O15 - ProtocolDefaults: 'https' protocol is in My Computer Zone, should be Internet Zone (HKLM)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Program Files\LSI SoftModem\agrsmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: G DATA AntiVirus Proxy (AVKProxy) - G DATA Software AG - C:\Program Files\Fichiers communs\G DATA\AVKProxy\AVKProxy.exe
O23 - Service: Planificateur G DATA (AVKService) - G DATA Software AG - C:\Program Files\G DATA\InternetSecurity\AVK\AVKService.exe
O23 - Service: Gardien d'AntiVirus (AVKWCtl) - G DATA Software AG - C:\Program Files\G DATA\InternetSecurity\AVK\AVKWCtl.exe
O23 - Service: CanalPlus.VOD - Canal+ Active - C:\Program Files\Canal\Canal Widget\VOD\CanalPlus.VOD.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
O23 - Service: Pare-feu personnel G DATA (GDFwSvc) - G DATA Software AG - C:\Program Files\G DATA\InternetSecurity\Firewall\GDFwSvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
-
-
♦ Desactive ton Anti-virus le temps de la manip car il est detecte a tort comme infection puis :
♦ Télécharge List_All (de g3n-h@ckm@n)
et enregistre-le sur ton bureau et pas ailleurs
♦ Execute-le en double clic (clic droit et "en tant qu'administrateur" sous vista) pour le lancer.
♦ choisis la langue d'utilisation
♦ choisis l'option en gras ci-dessous :
1 : Elements du panneau de configuration (cpl)
2 : Liste des .dll systeme
3 : Listes des executables (.exe)
4 : Liste des fichiers systeme (Drivers)
5 : Liste du system32
6 : Liste de tout le systeme
7 : Liste des fichiers .tmp
8 : Liste des fichiers racine
9 : Liste des fichiers cachés
0 : Liste des Processus Console
puis "entrée"
♦ rends-toi récupérer le rapport où il t'est indiqué ,
♦ envoie-le sur : http://www.cijoint.fr/ , fais-toi parcourir ,
puis envoie le fichier.
♦ un lien de cette forme va apparaitre :
http://www.cijoint.fr/cjlink.php?file=cjge368/cijSKAP5fU.txt
♦ renvoie le lien tout frais dans ta prochaine reponse . -
Précédent
- 1
- 2