Ouverture de site porno intempestive
Résolu
nelou_18
-
scander -
scander -
Bonjour,
dès que je me connecte à Internet ou à hotmail, j'ai une page de site porno "sexygirl" qui s'ouvre et ça m'énerve!!!
j'ai Avast comme anti virus mais je ne sais pas comment le programmer pour éviter ce genre de problème.
je suis sous windows vista. je ne vais quand même pas mettre un controle parental!!
si quelqu'un a une solution je suis preneuse...
merci
dès que je me connecte à Internet ou à hotmail, j'ai une page de site porno "sexygirl" qui s'ouvre et ça m'énerve!!!
j'ai Avast comme anti virus mais je ne sais pas comment le programmer pour éviter ce genre de problème.
je suis sous windows vista. je ne vais quand même pas mettre un controle parental!!
si quelqu'un a une solution je suis preneuse...
merci
A voir également:
- Ouverture de site porno intempestive
- Site de telechargement - Accueil - Outils
- Site comme coco - Accueil - Réseaux sociaux
- Site x - Guide
- Site de partage de photos - Guide
- Quel site remplace coco - Accueil - Réseaux sociaux
103 réponses
Il faut le lancer et ne plus rien toucher...
Il paraît ne plus répondre mais il travaille ;-)
Une fois que tu verras apparaître le bouton Suppression et la liste des outils, tu pourras reprendre ta souris en main et cliquer sur Suppression ;-)
Il paraît ne plus répondre mais il travaille ;-)
Une fois que tu verras apparaître le bouton Suppression et la liste des outils, tu pourras reprendre ta souris en main et cliquer sur Suppression ;-)
[ Rapport ToolsCleaner version 2.3.10 (par A.Rothstein & dj QUIOU) ]
--> Recherche:
C:\Combofix.txt: trouvé !
C:\Combofix: trouvé !
C:\Qoobox: trouvé !
C:\Program Files\Trend Micro\HijackThis: trouvé !
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: trouvé !
C:\Program Files\Trend Micro\HijackThis\hijackthis.log: trouvé !
C:\ProgramData\Microsoft\Windows\Start Menu\Programmes\HijackThis: trouvé !
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis: trouvé !
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis\HijackThis.lnk: trouvé !
C:\Qoobox\Quarantine\catchme.log: trouvé !
C:\Users\All Users\Microsoft\Windows\Start Menu\Programmes\HijackThis: trouvé !
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\HijackThis: trouvé !
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\HijackThis\HijackThis.lnk: trouvé !
C:\Users\Laure\AppData\Local\VirtualStore\Program Files\Trend Micro\HijackThis: trouvé !
C:\Users\Laure\AppData\Local\VirtualStore\Program Files\Trend Micro\HijackThis\hijackthis.log: trouvé !
C:\Users\Laure\Desktop\Nouveau dossier\ComboFix.exe: trouvé !
C:\Users\Laure\Desktop\Nouveau dossier\HJTInstall.exe: trouvé !
---------------------------------
--> Suppression:
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: supprimé !
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis\HijackThis.lnk: supprimé !
C:\Users\Laure\Desktop\Nouveau dossier\ComboFix.exe: ERREUR DE SUPPRESSION !!
C:\Users\Laure\Desktop\Nouveau dossier\HJTInstall.exe: supprimé !
C:\Combofix.txt: supprimé !
C:\Program Files\Trend Micro\HijackThis\hijackthis.log: supprimé !
C:\Qoobox\Quarantine\catchme.log: supprimé !
C:\Users\Laure\AppData\Local\VirtualStore\Program Files\Trend Micro\HijackThis\hijackthis.log: supprimé !
C:\Combofix: supprimé !
C:\Qoobox: supprimé !
C:\Program Files\Trend Micro\HijackThis: supprimé !
C:\ProgramData\Microsoft\Windows\Start Menu\Programmes\HijackThis: ERREUR DE SUPPRESSION !!
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis: supprimé !
C:\Users\Laure\AppData\Local\VirtualStore\Program Files\Trend Micro\HijackThis: supprimé !
Fichiers temporaires nettoyés !
Corbeille vidée!
--> Recherche:
C:\Combofix.txt: trouvé !
C:\Combofix: trouvé !
C:\Qoobox: trouvé !
C:\Program Files\Trend Micro\HijackThis: trouvé !
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: trouvé !
C:\Program Files\Trend Micro\HijackThis\hijackthis.log: trouvé !
C:\ProgramData\Microsoft\Windows\Start Menu\Programmes\HijackThis: trouvé !
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis: trouvé !
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis\HijackThis.lnk: trouvé !
C:\Qoobox\Quarantine\catchme.log: trouvé !
C:\Users\All Users\Microsoft\Windows\Start Menu\Programmes\HijackThis: trouvé !
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\HijackThis: trouvé !
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\HijackThis\HijackThis.lnk: trouvé !
C:\Users\Laure\AppData\Local\VirtualStore\Program Files\Trend Micro\HijackThis: trouvé !
C:\Users\Laure\AppData\Local\VirtualStore\Program Files\Trend Micro\HijackThis\hijackthis.log: trouvé !
C:\Users\Laure\Desktop\Nouveau dossier\ComboFix.exe: trouvé !
C:\Users\Laure\Desktop\Nouveau dossier\HJTInstall.exe: trouvé !
---------------------------------
--> Suppression:
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: supprimé !
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis\HijackThis.lnk: supprimé !
C:\Users\Laure\Desktop\Nouveau dossier\ComboFix.exe: ERREUR DE SUPPRESSION !!
C:\Users\Laure\Desktop\Nouveau dossier\HJTInstall.exe: supprimé !
C:\Combofix.txt: supprimé !
C:\Program Files\Trend Micro\HijackThis\hijackthis.log: supprimé !
C:\Qoobox\Quarantine\catchme.log: supprimé !
C:\Users\Laure\AppData\Local\VirtualStore\Program Files\Trend Micro\HijackThis\hijackthis.log: supprimé !
C:\Combofix: supprimé !
C:\Qoobox: supprimé !
C:\Program Files\Trend Micro\HijackThis: supprimé !
C:\ProgramData\Microsoft\Windows\Start Menu\Programmes\HijackThis: ERREUR DE SUPPRESSION !!
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis: supprimé !
C:\Users\Laure\AppData\Local\VirtualStore\Program Files\Trend Micro\HijackThis: supprimé !
Fichiers temporaires nettoyés !
Corbeille vidée!
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
Tu peux supprimer ComboFix et Hijackthis... CCleaner tu peux le garder pour nettoyer de temps en temps ;-)
Ainsi que Malwarebytes ;-)
Ainsi que Malwarebytes ;-)
bon en fait ça n'a rien changé, j'ai toujours cette fenêtre qui s'ouvre!!!! j'en ai marre qu'est ce que je peux faire???????
Re,
▶ Télécharger et enregistrer lopSD sur le Bureau
▶ Double-clic Lop S&D
▶ Faire l'installation
▶ Fermer toutes les applications
▶ Le lancer par un double-clic sur le raccourci qui est sur le bureau
▶ Avec VISTA => clic-droit et => Exécuter en tant qu'administrateur
▶ Taper F pour français , puis presser entrée
▶ Taper 1
▶ Presser Entrée
▶ Le PC va redémarrer
* Note : si l'antivirus annonce une infection dans TEMP , l'ignorer
▶ Attendre l'apparition du rapport
▶ Copier le rapport et le coller dans la réponse
* le rapport se trouve aussi à C:\lopR
▶ Télécharger et enregistrer lopSD sur le Bureau
▶ Double-clic Lop S&D
▶ Faire l'installation
▶ Fermer toutes les applications
▶ Le lancer par un double-clic sur le raccourci qui est sur le bureau
▶ Avec VISTA => clic-droit et => Exécuter en tant qu'administrateur
▶ Taper F pour français , puis presser entrée
▶ Taper 1
▶ Presser Entrée
▶ Le PC va redémarrer
* Note : si l'antivirus annonce une infection dans TEMP , l'ignorer
▶ Attendre l'apparition du rapport
▶ Copier le rapport et le coller dans la réponse
* le rapport se trouve aussi à C:\lopR
--------------------\\ Lop S&D 4.2.5-0 XP/Vista
Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6001 ) Service Pack 1
X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 Duo CPU T8100 @ 2.10GHz )
BIOS : ZD1 v1.3809 3H09
USER : Laure ( Administrator )
BOOT : Normal boot
C:\ (Local Disk) - NTFS - Total:144 Go (Free:51 Go)
D:\ (Local Disk) - NTFS - Total:140 Go (Free:120 Go)
E:\ (CD or DVD)
F:\ (Local Disk) - NTFS - Total:298 Go (Free:130 Go)
"C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
Option : [1] ( 23/08/2009|22:05 )
[ UAC => 1 ]
--------------------\\ Listing des dossiers dans Local
[29/08/2008|21:27] C:\Users\Laure\AppData\Local\Acer Arcade Deluxe
[29/08/2008|17:15] C:\Users\Laure\AppData\Local\acer eNM
[31/08/2008|21:42] C:\Users\Laure\AppData\Local\Adobe
[15/05/2009|21:35] C:\Users\Laure\AppData\Local\Apple
[12/07/2009|18:17] C:\Users\Laure\AppData\Local\Apple Computer
[29/08/2008|17:13] C:\Users\Laure\AppData\Local\Application Data
[29/08/2008|17:40] C:\Users\Laure\AppData\Local\Apps
[29/08/2008|17:41] C:\Users\Laure\AppData\Local\Citrix
[09/12/2008|16:56] C:\Users\Laure\AppData\Local\CyberLink
[23/08/2009|14:36] C:\Users\Laure\AppData\Local\d3d9caps.dat
[22/08/2009|10:51] C:\Users\Laure\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[18/04/2009|09:47] C:\Users\Laure\AppData\Local\Deployment
[23/08/2009|10:48] C:\Users\Laure\AppData\Local\eMule
[22/08/2009|09:34] C:\Users\Laure\AppData\Local\GDIPFONTCACHEV1.DAT
[23/08/2009|14:36] C:\Users\Laure\AppData\Local\Google
[29/08/2008|17:13] C:\Users\Laure\AppData\Local\Historique
[09/12/2008|16:56] C:\Users\Laure\AppData\Local\HomeMedia
[25/09/2008|16:12] C:\Users\Laure\AppData\Local\HP
[23/08/2009|13:00] C:\Users\Laure\AppData\Local\IconCache.db
[21/08/2009|21:41] C:\Users\Laure\AppData\Local\Microsoft
[28/01/2009|11:07] C:\Users\Laure\AppData\Local\Microsoft Games
[21/01/2009|18:49] C:\Users\Laure\AppData\Local\Microsoft Help
[09/12/2008|22:25] C:\Users\Laure\AppData\Local\PlayMovie
[29/08/2008|21:27] C:\Users\Laure\AppData\Local\PowerCinema
[23/08/2009|12:50] C:\Users\Laure\AppData\Local\Seven Zip
[23/08/2009|22:05] C:\Users\Laure\AppData\Local\temp
[29/08/2008|17:13] C:\Users\Laure\AppData\Local\Temporary Internet Files
[04/10/2008|11:55] C:\Users\Laure\AppData\Local\VirtualStore
--------------------\\ Tâches planifiées dans C:\Windows\tasks
[23/08/2009 16:36][--ah-----] C:\Windows\tasks\User_Feed_Synchronization-{AF4F5F6A-2000-4888-B9D6-108881533917}.job
[23/08/2009 13:01][--ah-----] C:\Windows\tasks\SA.DAT
[23/08/2009 13:00][--a------] C:\Windows\tasks\SCHEDLGU.TXT
--------------------\\ Listing des dossiers dans C:\ProgramData
[15/05/2009|21:37] C:\ProgramData\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[02/12/2008|14:23] C:\ProgramData\0C656BFCCF.sys
[15/03/2009|16:13] C:\ProgramData\Adobe
[15/05/2009|21:37] C:\ProgramData\Apple Computer
[02/11/2006|15:02] C:\ProgramData\Application Data
[21/08/2009|22:34] C:\ProgramData\Avira
[10/08/2009|11:12] C:\ProgramData\Babylon
[29/08/2008|17:09] C:\ProgramData\Bureau
[02/12/2008|14:27] C:\ProgramData\Corel
[09/12/2008|17:00] C:\ProgramData\CyberLink
[02/11/2006|15:02] C:\ProgramData\Desktop
[02/11/2006|15:02] C:\ProgramData\Documents
[29/08/2008|21:34] C:\ProgramData\Downloaded Installations
[26/02/2009|12:30] C:\ProgramData\eMule
[29/08/2008|17:09] C:\ProgramData\Favoris
[02/11/2006|15:02] C:\ProgramData\Favorites
[24/11/2008|11:02] C:\ProgramData\Forge of Games
[29/08/2008|17:59] C:\ProgramData\Hewlett-Packard
[19/01/2009|20:13] C:\ProgramData\HP
[14/04/2009|05:05] C:\ProgramData\HP Product Assistant
[28/05/2009|19:23] C:\ProgramData\hpzinstall.log
[02/12/2008|14:23] C:\ProgramData\KGyGaAvL.sys
[30/12/2008|16:58] C:\ProgramData\LightScribe
[20/08/2009|22:45] C:\ProgramData\Malwarebytes
[29/08/2008|17:09] C:\ProgramData\Menu D‚marrer
[27/03/2009|18:56] C:\ProgramData\Microsoft
[13/08/2009|20:03] C:\ProgramData\Microsoft Help
[29/08/2008|17:09] C:\ProgramData\ModŠles
[19/11/2008|18:12] C:\ProgramData\mwas
[30/12/2008|16:58] C:\ProgramData\NtiDvdCopy
[22/08/2009|00:05] C:\ProgramData\ntuser.pol
[21/08/2009|20:17] C:\ProgramData\NVIDIA
[03/06/2009|22:15] C:\ProgramData\Skyline
[28/01/2009|21:45] C:\ProgramData\Spybot - Search & Destroy
[02/11/2006|15:02] C:\ProgramData\Start Menu
[03/01/2009|17:10] C:\ProgramData\Symantec
[02/11/2006|15:02] C:\ProgramData\Templates
[29/08/2008|18:03] C:\ProgramData\WEBREG
[29/08/2008|21:38] C:\ProgramData\WLInstaller
[23/08/2009|12:56] C:\ProgramData\yahoo!
--------------------\\ Listing des dossiers dans C:\Program Files
[29/08/2008|17:26] C:\Program Files\ACER CrystalEye webcam
[03/01/2009|17:09] C:\Program Files\Acer GameZone
[29/08/2008|17:31] C:\Program Files\Acer Inc
[19/08/2009|18:54] C:\Program Files\Adobe
[31/10/2008|14:23] C:\Program Files\Alwil Software
[21/08/2009|22:34] C:\Program Files\Avira
[21/12/2007|05:58] C:\Program Files\Broadcom
[21/08/2009|22:37] C:\Program Files\CCleaner
[29/08/2008|17:41] C:\Program Files\Citrix
[25/09/2008|17:47] C:\Program Files\ColiPoste
[23/08/2009|12:55] C:\Program Files\Common Files
[21/12/2007|05:43] C:\Program Files\CONEXANT
[02/12/2008|14:28] C:\Program Files\Corel
[21/12/2007|07:19] C:\Program Files\CyberLink
[10/07/2009|17:31] C:\Program Files\DivX
[07/03/2009|14:40] C:\Program Files\eMule
[29/08/2008|17:09] C:\Program Files\Fichiers communs [C:\Program Files\Common Files]
[22/08/2009|20:18] C:\Program Files\FileHippo.com
[28/10/2008|20:05] C:\Program Files\Fnacmusic
[29/04/2009|21:25] C:\Program Files\Free Audio Pack
[10/08/2009|11:12] C:\Program Files\GIMP-2.0
[09/11/2008|18:02] C:\Program Files\Google
[19/01/2009|20:11] C:\Program Files\Hewlett-Packard
[29/08/2008|17:54] C:\Program Files\HP
[14/10/2008|19:25] C:\Program Files\Inkscape
[14/03/2009|20:11] C:\Program Files\InstallShield Installation Information
[29/07/2009|17:31] C:\Program Files\Internet Explorer
[15/04/2009|18:43] C:\Program Files\Java
[31/12/2008|11:45] C:\Program Files\JRE
[03/01/2009|17:09] C:\Program Files\KaraFun
[10/10/2008|19:22] C:\Program Files\KC Softwares
[23/11/2008|19:21] C:\Program Files\K-Lite Codec Pack
[29/08/2008|17:16] C:\Program Files\Launch Manager
[27/11/2008|18:08] C:\Program Files\MatchWare
[24/02/2009|14:43] C:\Program Files\Micro Application
[27/03/2009|18:58] C:\Program Files\Microsoft
[02/11/2006|14:37] C:\Program Files\Microsoft Games
[08/01/2009|19:41] C:\Program Files\Microsoft Office
[27/03/2009|18:57] C:\Program Files\Microsoft Office Outlook Connector
[01/08/2009|11:04] C:\Program Files\Microsoft Silverlight
[27/03/2009|18:55] C:\Program Files\Microsoft SQL Server Compact Edition
[27/03/2009|18:57] C:\Program Files\Microsoft Sync Framework
[08/01/2009|19:42] C:\Program Files\Microsoft Visual Studio
[08/01/2009|19:39] C:\Program Files\Microsoft Visual Studio 8
[10/06/2009|20:47] C:\Program Files\Microsoft Works
[21/12/2007|07:35] C:\Program Files\Microsoft.NET
[08/10/2008|20:19] C:\Program Files\Movie Maker
[08/01/2009|19:43] C:\Program Files\MSBuild
[16/10/2008|18:55] C:\Program Files\MSECache
[21/12/2007|06:29] C:\Program Files\MSXML 4.0
[29/04/2009|21:26] C:\Program Files\NetPumper
[21/12/2007|07:09] C:\Program Files\NewTech Infosystems
[31/12/2008|11:45] C:\Program Files\OpenOffice.org 3
[06/04/2009|18:56] C:\Program Files\pese_courrier
[15/05/2009|21:36] C:\Program Files\QuickTime
[29/08/2008|17:54] C:\Program Files\Realtek
[02/11/2006|14:37] C:\Program Files\Reference Assemblies
[14/03/2009|19:49] C:\Program Files\Samsung
[03/06/2009|22:15] C:\Program Files\Skyline
[28/01/2009|21:46] C:\Program Files\Spybot - Search & Destroy
[29/08/2008|17:26] C:\Program Files\SUYIN
[21/12/2007|06:01] C:\Program Files\Synaptics
[22/08/2009|22:34] C:\Program Files\Trend Micro
[02/11/2006|15:01] C:\Program Files\Uninstall Information
[09/12/2008|22:53] C:\Program Files\VideoLAN
[10/08/2009|11:13] C:\Program Files\WinApplication
[21/12/2007|06:04] C:\Program Files\Winbond Electronics
[08/10/2008|20:19] C:\Program Files\Windows Calendar
[08/10/2008|20:19] C:\Program Files\Windows Collaboration
[08/10/2008|20:19] C:\Program Files\Windows Defender
[08/10/2008|20:19] C:\Program Files\Windows Journal
[27/03/2009|18:57] C:\Program Files\Windows Live
[27/03/2009|18:53] C:\Program Files\Windows Live SkyDrive
[13/08/2009|20:02] C:\Program Files\Windows Mail
[13/08/2009|20:09] C:\Program Files\Windows Media Player
[29/08/2008|17:09] C:\Program Files\Windows NT
[08/10/2008|20:19] C:\Program Files\Windows Photo Gallery
[08/10/2008|20:19] C:\Program Files\Windows Sidebar
[23/08/2009|13:01] C:\Program Files\WinRAR
[22/08/2009|22:43] C:\Program Files\WOT
[23/08/2009|12:56] C:\Program Files\Yahoo!
--------------------\\ Listing des dossiers dans C:\Program Files\Common Files
[19/08/2009|18:54] C:\Program Files\Common Files\Adobe
[22/10/2008|18:52] C:\Program Files\Common Files\Corel
[22/10/2008|18:52] C:\Program Files\Common Files\DESIGNER
[10/07/2009|17:30] C:\Program Files\Common Files\DivX Shared
[29/08/2008|17:54] C:\Program Files\Common Files\Hewlett-Packard
[19/01/2009|20:11] C:\Program Files\Common Files\HP
[22/10/2008|18:52] C:\Program Files\Common Files\InstallShield
[21/12/2007|07:08] C:\Program Files\Common Files\LightScribe
[08/05/2009|19:34] C:\Program Files\Common Files\microsoft shared
[21/12/2007|07:08] C:\Program Files\Common Files\muvee Technologies
[21/12/2007|07:09] C:\Program Files\Common Files\NewTech Infosystems
[10/07/2009|17:31] C:\Program Files\Common Files\PX Storage Engine
[02/11/2006|13:18] C:\Program Files\Common Files\Services
[29/08/2008|17:24] C:\Program Files\Common Files\snp2uvc
[02/11/2006|13:18] C:\Program Files\Common Files\SpeechEngines
[03/01/2009|17:10] C:\Program Files\Common Files\Symantec Shared
[27/03/2009|18:57] C:\Program Files\Common Files\System
[26/03/2009|07:32] C:\Program Files\Common Files\Windows Live
[29/08/2008|21:34] C:\Program Files\Common Files\WindowsLiveInstaller
--------------------\\ Process
( 83 Processes )
iexplore.exe ~ [PID:5876]
iexplore.exe ~ [PID:4144]
iexplore.exe ~ [PID:5012]
--------------------\\ Recherche avec S_Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Recherche de Fichiers / Dossiers Lop
C:\Program Files\NetPumper
--------------------\\ Verification du Registre
..... OK !
--------------------\\ Verification du fichier Hosts
Fichier Hosts PROPRE
--------------------\\ Recherche de fichiers avec Catchme
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-23 22:05:32
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 1
--------------------\\ Recherche d'autres infections
Aucune autre infection trouvée !
[F:15][D:5]-> C:\Users\Laure\AppData\Local\Temp
[F:45][D:1]-> C:\Users\Laure\AppData\Roaming\MICROS~1\Windows\Cookies
[F:157][D:4]-> C:\Users\Laure\AppData\Local\MICROS~1\Windows\TEMPOR~1\content.IE5
[F:1][D:1]-> C:\$Recycle.Bin
1 - "C:\Lop SD\LopR_1.txt" - 23/08/2009|22:06 - Option : [1]
--------------------\\ Fin du rapport a 22:06:53
[ UAC => 1 ]
Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6001 ) Service Pack 1
X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 Duo CPU T8100 @ 2.10GHz )
BIOS : ZD1 v1.3809 3H09
USER : Laure ( Administrator )
BOOT : Normal boot
C:\ (Local Disk) - NTFS - Total:144 Go (Free:51 Go)
D:\ (Local Disk) - NTFS - Total:140 Go (Free:120 Go)
E:\ (CD or DVD)
F:\ (Local Disk) - NTFS - Total:298 Go (Free:130 Go)
"C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
Option : [1] ( 23/08/2009|22:05 )
[ UAC => 1 ]
--------------------\\ Listing des dossiers dans Local
[29/08/2008|21:27] C:\Users\Laure\AppData\Local\Acer Arcade Deluxe
[29/08/2008|17:15] C:\Users\Laure\AppData\Local\acer eNM
[31/08/2008|21:42] C:\Users\Laure\AppData\Local\Adobe
[15/05/2009|21:35] C:\Users\Laure\AppData\Local\Apple
[12/07/2009|18:17] C:\Users\Laure\AppData\Local\Apple Computer
[29/08/2008|17:13] C:\Users\Laure\AppData\Local\Application Data
[29/08/2008|17:40] C:\Users\Laure\AppData\Local\Apps
[29/08/2008|17:41] C:\Users\Laure\AppData\Local\Citrix
[09/12/2008|16:56] C:\Users\Laure\AppData\Local\CyberLink
[23/08/2009|14:36] C:\Users\Laure\AppData\Local\d3d9caps.dat
[22/08/2009|10:51] C:\Users\Laure\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[18/04/2009|09:47] C:\Users\Laure\AppData\Local\Deployment
[23/08/2009|10:48] C:\Users\Laure\AppData\Local\eMule
[22/08/2009|09:34] C:\Users\Laure\AppData\Local\GDIPFONTCACHEV1.DAT
[23/08/2009|14:36] C:\Users\Laure\AppData\Local\Google
[29/08/2008|17:13] C:\Users\Laure\AppData\Local\Historique
[09/12/2008|16:56] C:\Users\Laure\AppData\Local\HomeMedia
[25/09/2008|16:12] C:\Users\Laure\AppData\Local\HP
[23/08/2009|13:00] C:\Users\Laure\AppData\Local\IconCache.db
[21/08/2009|21:41] C:\Users\Laure\AppData\Local\Microsoft
[28/01/2009|11:07] C:\Users\Laure\AppData\Local\Microsoft Games
[21/01/2009|18:49] C:\Users\Laure\AppData\Local\Microsoft Help
[09/12/2008|22:25] C:\Users\Laure\AppData\Local\PlayMovie
[29/08/2008|21:27] C:\Users\Laure\AppData\Local\PowerCinema
[23/08/2009|12:50] C:\Users\Laure\AppData\Local\Seven Zip
[23/08/2009|22:05] C:\Users\Laure\AppData\Local\temp
[29/08/2008|17:13] C:\Users\Laure\AppData\Local\Temporary Internet Files
[04/10/2008|11:55] C:\Users\Laure\AppData\Local\VirtualStore
--------------------\\ Tâches planifiées dans C:\Windows\tasks
[23/08/2009 16:36][--ah-----] C:\Windows\tasks\User_Feed_Synchronization-{AF4F5F6A-2000-4888-B9D6-108881533917}.job
[23/08/2009 13:01][--ah-----] C:\Windows\tasks\SA.DAT
[23/08/2009 13:00][--a------] C:\Windows\tasks\SCHEDLGU.TXT
--------------------\\ Listing des dossiers dans C:\ProgramData
[15/05/2009|21:37] C:\ProgramData\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[02/12/2008|14:23] C:\ProgramData\0C656BFCCF.sys
[15/03/2009|16:13] C:\ProgramData\Adobe
[15/05/2009|21:37] C:\ProgramData\Apple Computer
[02/11/2006|15:02] C:\ProgramData\Application Data
[21/08/2009|22:34] C:\ProgramData\Avira
[10/08/2009|11:12] C:\ProgramData\Babylon
[29/08/2008|17:09] C:\ProgramData\Bureau
[02/12/2008|14:27] C:\ProgramData\Corel
[09/12/2008|17:00] C:\ProgramData\CyberLink
[02/11/2006|15:02] C:\ProgramData\Desktop
[02/11/2006|15:02] C:\ProgramData\Documents
[29/08/2008|21:34] C:\ProgramData\Downloaded Installations
[26/02/2009|12:30] C:\ProgramData\eMule
[29/08/2008|17:09] C:\ProgramData\Favoris
[02/11/2006|15:02] C:\ProgramData\Favorites
[24/11/2008|11:02] C:\ProgramData\Forge of Games
[29/08/2008|17:59] C:\ProgramData\Hewlett-Packard
[19/01/2009|20:13] C:\ProgramData\HP
[14/04/2009|05:05] C:\ProgramData\HP Product Assistant
[28/05/2009|19:23] C:\ProgramData\hpzinstall.log
[02/12/2008|14:23] C:\ProgramData\KGyGaAvL.sys
[30/12/2008|16:58] C:\ProgramData\LightScribe
[20/08/2009|22:45] C:\ProgramData\Malwarebytes
[29/08/2008|17:09] C:\ProgramData\Menu D‚marrer
[27/03/2009|18:56] C:\ProgramData\Microsoft
[13/08/2009|20:03] C:\ProgramData\Microsoft Help
[29/08/2008|17:09] C:\ProgramData\ModŠles
[19/11/2008|18:12] C:\ProgramData\mwas
[30/12/2008|16:58] C:\ProgramData\NtiDvdCopy
[22/08/2009|00:05] C:\ProgramData\ntuser.pol
[21/08/2009|20:17] C:\ProgramData\NVIDIA
[03/06/2009|22:15] C:\ProgramData\Skyline
[28/01/2009|21:45] C:\ProgramData\Spybot - Search & Destroy
[02/11/2006|15:02] C:\ProgramData\Start Menu
[03/01/2009|17:10] C:\ProgramData\Symantec
[02/11/2006|15:02] C:\ProgramData\Templates
[29/08/2008|18:03] C:\ProgramData\WEBREG
[29/08/2008|21:38] C:\ProgramData\WLInstaller
[23/08/2009|12:56] C:\ProgramData\yahoo!
--------------------\\ Listing des dossiers dans C:\Program Files
[29/08/2008|17:26] C:\Program Files\ACER CrystalEye webcam
[03/01/2009|17:09] C:\Program Files\Acer GameZone
[29/08/2008|17:31] C:\Program Files\Acer Inc
[19/08/2009|18:54] C:\Program Files\Adobe
[31/10/2008|14:23] C:\Program Files\Alwil Software
[21/08/2009|22:34] C:\Program Files\Avira
[21/12/2007|05:58] C:\Program Files\Broadcom
[21/08/2009|22:37] C:\Program Files\CCleaner
[29/08/2008|17:41] C:\Program Files\Citrix
[25/09/2008|17:47] C:\Program Files\ColiPoste
[23/08/2009|12:55] C:\Program Files\Common Files
[21/12/2007|05:43] C:\Program Files\CONEXANT
[02/12/2008|14:28] C:\Program Files\Corel
[21/12/2007|07:19] C:\Program Files\CyberLink
[10/07/2009|17:31] C:\Program Files\DivX
[07/03/2009|14:40] C:\Program Files\eMule
[29/08/2008|17:09] C:\Program Files\Fichiers communs [C:\Program Files\Common Files]
[22/08/2009|20:18] C:\Program Files\FileHippo.com
[28/10/2008|20:05] C:\Program Files\Fnacmusic
[29/04/2009|21:25] C:\Program Files\Free Audio Pack
[10/08/2009|11:12] C:\Program Files\GIMP-2.0
[09/11/2008|18:02] C:\Program Files\Google
[19/01/2009|20:11] C:\Program Files\Hewlett-Packard
[29/08/2008|17:54] C:\Program Files\HP
[14/10/2008|19:25] C:\Program Files\Inkscape
[14/03/2009|20:11] C:\Program Files\InstallShield Installation Information
[29/07/2009|17:31] C:\Program Files\Internet Explorer
[15/04/2009|18:43] C:\Program Files\Java
[31/12/2008|11:45] C:\Program Files\JRE
[03/01/2009|17:09] C:\Program Files\KaraFun
[10/10/2008|19:22] C:\Program Files\KC Softwares
[23/11/2008|19:21] C:\Program Files\K-Lite Codec Pack
[29/08/2008|17:16] C:\Program Files\Launch Manager
[27/11/2008|18:08] C:\Program Files\MatchWare
[24/02/2009|14:43] C:\Program Files\Micro Application
[27/03/2009|18:58] C:\Program Files\Microsoft
[02/11/2006|14:37] C:\Program Files\Microsoft Games
[08/01/2009|19:41] C:\Program Files\Microsoft Office
[27/03/2009|18:57] C:\Program Files\Microsoft Office Outlook Connector
[01/08/2009|11:04] C:\Program Files\Microsoft Silverlight
[27/03/2009|18:55] C:\Program Files\Microsoft SQL Server Compact Edition
[27/03/2009|18:57] C:\Program Files\Microsoft Sync Framework
[08/01/2009|19:42] C:\Program Files\Microsoft Visual Studio
[08/01/2009|19:39] C:\Program Files\Microsoft Visual Studio 8
[10/06/2009|20:47] C:\Program Files\Microsoft Works
[21/12/2007|07:35] C:\Program Files\Microsoft.NET
[08/10/2008|20:19] C:\Program Files\Movie Maker
[08/01/2009|19:43] C:\Program Files\MSBuild
[16/10/2008|18:55] C:\Program Files\MSECache
[21/12/2007|06:29] C:\Program Files\MSXML 4.0
[29/04/2009|21:26] C:\Program Files\NetPumper
[21/12/2007|07:09] C:\Program Files\NewTech Infosystems
[31/12/2008|11:45] C:\Program Files\OpenOffice.org 3
[06/04/2009|18:56] C:\Program Files\pese_courrier
[15/05/2009|21:36] C:\Program Files\QuickTime
[29/08/2008|17:54] C:\Program Files\Realtek
[02/11/2006|14:37] C:\Program Files\Reference Assemblies
[14/03/2009|19:49] C:\Program Files\Samsung
[03/06/2009|22:15] C:\Program Files\Skyline
[28/01/2009|21:46] C:\Program Files\Spybot - Search & Destroy
[29/08/2008|17:26] C:\Program Files\SUYIN
[21/12/2007|06:01] C:\Program Files\Synaptics
[22/08/2009|22:34] C:\Program Files\Trend Micro
[02/11/2006|15:01] C:\Program Files\Uninstall Information
[09/12/2008|22:53] C:\Program Files\VideoLAN
[10/08/2009|11:13] C:\Program Files\WinApplication
[21/12/2007|06:04] C:\Program Files\Winbond Electronics
[08/10/2008|20:19] C:\Program Files\Windows Calendar
[08/10/2008|20:19] C:\Program Files\Windows Collaboration
[08/10/2008|20:19] C:\Program Files\Windows Defender
[08/10/2008|20:19] C:\Program Files\Windows Journal
[27/03/2009|18:57] C:\Program Files\Windows Live
[27/03/2009|18:53] C:\Program Files\Windows Live SkyDrive
[13/08/2009|20:02] C:\Program Files\Windows Mail
[13/08/2009|20:09] C:\Program Files\Windows Media Player
[29/08/2008|17:09] C:\Program Files\Windows NT
[08/10/2008|20:19] C:\Program Files\Windows Photo Gallery
[08/10/2008|20:19] C:\Program Files\Windows Sidebar
[23/08/2009|13:01] C:\Program Files\WinRAR
[22/08/2009|22:43] C:\Program Files\WOT
[23/08/2009|12:56] C:\Program Files\Yahoo!
--------------------\\ Listing des dossiers dans C:\Program Files\Common Files
[19/08/2009|18:54] C:\Program Files\Common Files\Adobe
[22/10/2008|18:52] C:\Program Files\Common Files\Corel
[22/10/2008|18:52] C:\Program Files\Common Files\DESIGNER
[10/07/2009|17:30] C:\Program Files\Common Files\DivX Shared
[29/08/2008|17:54] C:\Program Files\Common Files\Hewlett-Packard
[19/01/2009|20:11] C:\Program Files\Common Files\HP
[22/10/2008|18:52] C:\Program Files\Common Files\InstallShield
[21/12/2007|07:08] C:\Program Files\Common Files\LightScribe
[08/05/2009|19:34] C:\Program Files\Common Files\microsoft shared
[21/12/2007|07:08] C:\Program Files\Common Files\muvee Technologies
[21/12/2007|07:09] C:\Program Files\Common Files\NewTech Infosystems
[10/07/2009|17:31] C:\Program Files\Common Files\PX Storage Engine
[02/11/2006|13:18] C:\Program Files\Common Files\Services
[29/08/2008|17:24] C:\Program Files\Common Files\snp2uvc
[02/11/2006|13:18] C:\Program Files\Common Files\SpeechEngines
[03/01/2009|17:10] C:\Program Files\Common Files\Symantec Shared
[27/03/2009|18:57] C:\Program Files\Common Files\System
[26/03/2009|07:32] C:\Program Files\Common Files\Windows Live
[29/08/2008|21:34] C:\Program Files\Common Files\WindowsLiveInstaller
--------------------\\ Process
( 83 Processes )
iexplore.exe ~ [PID:5876]
iexplore.exe ~ [PID:4144]
iexplore.exe ~ [PID:5012]
--------------------\\ Recherche avec S_Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Recherche de Fichiers / Dossiers Lop
C:\Program Files\NetPumper
--------------------\\ Verification du Registre
..... OK !
--------------------\\ Verification du fichier Hosts
Fichier Hosts PROPRE
--------------------\\ Recherche de fichiers avec Catchme
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-23 22:05:32
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 1
--------------------\\ Recherche d'autres infections
Aucune autre infection trouvée !
[F:15][D:5]-> C:\Users\Laure\AppData\Local\Temp
[F:45][D:1]-> C:\Users\Laure\AppData\Roaming\MICROS~1\Windows\Cookies
[F:157][D:4]-> C:\Users\Laure\AppData\Local\MICROS~1\Windows\TEMPOR~1\content.IE5
[F:1][D:1]-> C:\$Recycle.Bin
1 - "C:\Lop SD\LopR_1.txt" - 23/08/2009|22:06 - Option : [1]
--------------------\\ Fin du rapport a 22:06:53
[ UAC => 1 ]
▶ Relance Lop S&D
▶ Choisis cette fois-ci l'option 2 (Suppression)
▶ Ne ferme pas la fenêtre lors de la suppression !
▶ Poste le rapport généré (C:\lopR.txt)
* (Si le Bureau ne réapparait pas, presse Ctrl+Alt+Suppr, Onglet Fichier, Nouvelle tâche, tape explorer.exe et valide)
▶ Choisis cette fois-ci l'option 2 (Suppression)
▶ Ne ferme pas la fenêtre lors de la suppression !
▶ Poste le rapport généré (C:\lopR.txt)
* (Si le Bureau ne réapparait pas, presse Ctrl+Alt+Suppr, Onglet Fichier, Nouvelle tâche, tape explorer.exe et valide)
--------------------\\ Lop S&D 4.2.5-0 XP/Vista
Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6001 ) Service Pack 1
X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 Duo CPU T8100 @ 2.10GHz )
BIOS : ZD1 v1.3809 3H09
USER : Laure ( Administrator )
BOOT : Normal boot
C:\ (Local Disk) - NTFS - Total:144 Go (Free:51 Go)
D:\ (Local Disk) - NTFS - Total:140 Go (Free:120 Go)
E:\ (CD or DVD)
F:\ (Local Disk) - NTFS - Total:298 Go (Free:130 Go)
"C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
Option : [2] ( 23/08/2009|22:10 )
[ UAC => 1 ]
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ SUPPRESSION
Supprime! - C:\Program Files\NetPumper
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
--------------------\\ Listing des dossiers dans Local
[29/08/2008|21:27] C:\Users\Laure\AppData\Local\Acer Arcade Deluxe
[29/08/2008|17:15] C:\Users\Laure\AppData\Local\acer eNM
[31/08/2008|21:42] C:\Users\Laure\AppData\Local\Adobe
[15/05/2009|21:35] C:\Users\Laure\AppData\Local\Apple
[12/07/2009|18:17] C:\Users\Laure\AppData\Local\Apple Computer
[29/08/2008|17:13] C:\Users\Laure\AppData\Local\Application Data
[29/08/2008|17:40] C:\Users\Laure\AppData\Local\Apps
[29/08/2008|17:41] C:\Users\Laure\AppData\Local\Citrix
[09/12/2008|16:56] C:\Users\Laure\AppData\Local\CyberLink
[23/08/2009|14:36] C:\Users\Laure\AppData\Local\d3d9caps.dat
[22/08/2009|10:51] C:\Users\Laure\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[18/04/2009|09:47] C:\Users\Laure\AppData\Local\Deployment
[23/08/2009|10:48] C:\Users\Laure\AppData\Local\eMule
[22/08/2009|09:34] C:\Users\Laure\AppData\Local\GDIPFONTCACHEV1.DAT
[23/08/2009|14:36] C:\Users\Laure\AppData\Local\Google
[29/08/2008|17:13] C:\Users\Laure\AppData\Local\Historique
[09/12/2008|16:56] C:\Users\Laure\AppData\Local\HomeMedia
[25/09/2008|16:12] C:\Users\Laure\AppData\Local\HP
[23/08/2009|13:00] C:\Users\Laure\AppData\Local\IconCache.db
[21/08/2009|21:41] C:\Users\Laure\AppData\Local\Microsoft
[28/01/2009|11:07] C:\Users\Laure\AppData\Local\Microsoft Games
[21/01/2009|18:49] C:\Users\Laure\AppData\Local\Microsoft Help
[09/12/2008|22:25] C:\Users\Laure\AppData\Local\PlayMovie
[29/08/2008|21:27] C:\Users\Laure\AppData\Local\PowerCinema
[23/08/2009|12:50] C:\Users\Laure\AppData\Local\Seven Zip
[23/08/2009|22:10] C:\Users\Laure\AppData\Local\temp
[29/08/2008|17:13] C:\Users\Laure\AppData\Local\Temporary Internet Files
[04/10/2008|11:55] C:\Users\Laure\AppData\Local\VirtualStore
--------------------\\ Tâches planifiées dans C:\Windows\tasks
[23/08/2009 16:36][--ah-----] C:\Windows\tasks\User_Feed_Synchronization-{AF4F5F6A-2000-4888-B9D6-108881533917}.job
[23/08/2009 13:01][--ah-----] C:\Windows\tasks\SA.DAT
[23/08/2009 13:00][--a------] C:\Windows\tasks\SCHEDLGU.TXT
--------------------\\ Listing des dossiers dans C:\ProgramData
[15/05/2009|21:37] C:\ProgramData\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[02/12/2008|14:23] C:\ProgramData\0C656BFCCF.sys
[15/03/2009|16:13] C:\ProgramData\Adobe
[15/05/2009|21:37] C:\ProgramData\Apple Computer
[02/11/2006|15:02] C:\ProgramData\Application Data
[21/08/2009|22:34] C:\ProgramData\Avira
[10/08/2009|11:12] C:\ProgramData\Babylon
[29/08/2008|17:09] C:\ProgramData\Bureau
[02/12/2008|14:27] C:\ProgramData\Corel
[09/12/2008|17:00] C:\ProgramData\CyberLink
[02/11/2006|15:02] C:\ProgramData\Desktop
[02/11/2006|15:02] C:\ProgramData\Documents
[29/08/2008|21:34] C:\ProgramData\Downloaded Installations
[26/02/2009|12:30] C:\ProgramData\eMule
[29/08/2008|17:09] C:\ProgramData\Favoris
[02/11/2006|15:02] C:\ProgramData\Favorites
[24/11/2008|11:02] C:\ProgramData\Forge of Games
[29/08/2008|17:59] C:\ProgramData\Hewlett-Packard
[19/01/2009|20:13] C:\ProgramData\HP
[14/04/2009|05:05] C:\ProgramData\HP Product Assistant
[28/05/2009|19:23] C:\ProgramData\hpzinstall.log
[02/12/2008|14:23] C:\ProgramData\KGyGaAvL.sys
[30/12/2008|16:58] C:\ProgramData\LightScribe
[20/08/2009|22:45] C:\ProgramData\Malwarebytes
[29/08/2008|17:09] C:\ProgramData\Menu D‚marrer
[27/03/2009|18:56] C:\ProgramData\Microsoft
[13/08/2009|20:03] C:\ProgramData\Microsoft Help
[29/08/2008|17:09] C:\ProgramData\ModŠles
[19/11/2008|18:12] C:\ProgramData\mwas
[30/12/2008|16:58] C:\ProgramData\NtiDvdCopy
[22/08/2009|00:05] C:\ProgramData\ntuser.pol
[21/08/2009|20:17] C:\ProgramData\NVIDIA
[03/06/2009|22:15] C:\ProgramData\Skyline
[28/01/2009|21:45] C:\ProgramData\Spybot - Search & Destroy
[02/11/2006|15:02] C:\ProgramData\Start Menu
[03/01/2009|17:10] C:\ProgramData\Symantec
[02/11/2006|15:02] C:\ProgramData\Templates
[29/08/2008|18:03] C:\ProgramData\WEBREG
[29/08/2008|21:38] C:\ProgramData\WLInstaller
[23/08/2009|12:56] C:\ProgramData\yahoo!
--------------------\\ Listing des dossiers dans C:\Program Files
[29/08/2008|17:26] C:\Program Files\ACER CrystalEye webcam
[03/01/2009|17:09] C:\Program Files\Acer GameZone
[29/08/2008|17:31] C:\Program Files\Acer Inc
[19/08/2009|18:54] C:\Program Files\Adobe
[31/10/2008|14:23] C:\Program Files\Alwil Software
[21/08/2009|22:34] C:\Program Files\Avira
[21/12/2007|05:58] C:\Program Files\Broadcom
[21/08/2009|22:37] C:\Program Files\CCleaner
[29/08/2008|17:41] C:\Program Files\Citrix
[25/09/2008|17:47] C:\Program Files\ColiPoste
[23/08/2009|12:55] C:\Program Files\Common Files
[21/12/2007|05:43] C:\Program Files\CONEXANT
[02/12/2008|14:28] C:\Program Files\Corel
[21/12/2007|07:19] C:\Program Files\CyberLink
[10/07/2009|17:31] C:\Program Files\DivX
[07/03/2009|14:40] C:\Program Files\eMule
[29/08/2008|17:09] C:\Program Files\Fichiers communs [C:\Program Files\Common Files]
[22/08/2009|20:18] C:\Program Files\FileHippo.com
[28/10/2008|20:05] C:\Program Files\Fnacmusic
[29/04/2009|21:25] C:\Program Files\Free Audio Pack
[10/08/2009|11:12] C:\Program Files\GIMP-2.0
[09/11/2008|18:02] C:\Program Files\Google
[19/01/2009|20:11] C:\Program Files\Hewlett-Packard
[29/08/2008|17:54] C:\Program Files\HP
[14/10/2008|19:25] C:\Program Files\Inkscape
[14/03/2009|20:11] C:\Program Files\InstallShield Installation Information
[29/07/2009|17:31] C:\Program Files\Internet Explorer
[15/04/2009|18:43] C:\Program Files\Java
[31/12/2008|11:45] C:\Program Files\JRE
[03/01/2009|17:09] C:\Program Files\KaraFun
[10/10/2008|19:22] C:\Program Files\KC Softwares
[23/11/2008|19:21] C:\Program Files\K-Lite Codec Pack
[29/08/2008|17:16] C:\Program Files\Launch Manager
[27/11/2008|18:08] C:\Program Files\MatchWare
[24/02/2009|14:43] C:\Program Files\Micro Application
[27/03/2009|18:58] C:\Program Files\Microsoft
[02/11/2006|14:37] C:\Program Files\Microsoft Games
[08/01/2009|19:41] C:\Program Files\Microsoft Office
[27/03/2009|18:57] C:\Program Files\Microsoft Office Outlook Connector
[01/08/2009|11:04] C:\Program Files\Microsoft Silverlight
[27/03/2009|18:55] C:\Program Files\Microsoft SQL Server Compact Edition
[27/03/2009|18:57] C:\Program Files\Microsoft Sync Framework
[08/01/2009|19:42] C:\Program Files\Microsoft Visual Studio
[08/01/2009|19:39] C:\Program Files\Microsoft Visual Studio 8
[10/06/2009|20:47] C:\Program Files\Microsoft Works
[21/12/2007|07:35] C:\Program Files\Microsoft.NET
[08/10/2008|20:19] C:\Program Files\Movie Maker
[08/01/2009|19:43] C:\Program Files\MSBuild
[16/10/2008|18:55] C:\Program Files\MSECache
[21/12/2007|06:29] C:\Program Files\MSXML 4.0
[21/12/2007|07:09] C:\Program Files\NewTech Infosystems
[31/12/2008|11:45] C:\Program Files\OpenOffice.org 3
[06/04/2009|18:56] C:\Program Files\pese_courrier
[15/05/2009|21:36] C:\Program Files\QuickTime
[29/08/2008|17:54] C:\Program Files\Realtek
[02/11/2006|14:37] C:\Program Files\Reference Assemblies
[14/03/2009|19:49] C:\Program Files\Samsung
[03/06/2009|22:15] C:\Program Files\Skyline
[28/01/2009|21:46] C:\Program Files\Spybot - Search & Destroy
[29/08/2008|17:26] C:\Program Files\SUYIN
[21/12/2007|06:01] C:\Program Files\Synaptics
[22/08/2009|22:34] C:\Program Files\Trend Micro
[02/11/2006|15:01] C:\Program Files\Uninstall Information
[09/12/2008|22:53] C:\Program Files\VideoLAN
[10/08/2009|11:13] C:\Program Files\WinApplication
[21/12/2007|06:04] C:\Program Files\Winbond Electronics
[08/10/2008|20:19] C:\Program Files\Windows Calendar
[08/10/2008|20:19] C:\Program Files\Windows Collaboration
[08/10/2008|20:19] C:\Program Files\Windows Defender
[08/10/2008|20:19] C:\Program Files\Windows Journal
[27/03/2009|18:57] C:\Program Files\Windows Live
[27/03/2009|18:53] C:\Program Files\Windows Live SkyDrive
[13/08/2009|20:02] C:\Program Files\Windows Mail
[13/08/2009|20:09] C:\Program Files\Windows Media Player
[29/08/2008|17:09] C:\Program Files\Windows NT
[08/10/2008|20:19] C:\Program Files\Windows Photo Gallery
[08/10/2008|20:19] C:\Program Files\Windows Sidebar
[23/08/2009|13:01] C:\Program Files\WinRAR
[22/08/2009|22:43] C:\Program Files\WOT
[23/08/2009|12:56] C:\Program Files\Yahoo!
--------------------\\ Listing des dossiers dans C:\Program Files\Common Files
[19/08/2009|18:54] C:\Program Files\Common Files\Adobe
[22/10/2008|18:52] C:\Program Files\Common Files\Corel
[22/10/2008|18:52] C:\Program Files\Common Files\DESIGNER
[10/07/2009|17:30] C:\Program Files\Common Files\DivX Shared
[29/08/2008|17:54] C:\Program Files\Common Files\Hewlett-Packard
[19/01/2009|20:11] C:\Program Files\Common Files\HP
[22/10/2008|18:52] C:\Program Files\Common Files\InstallShield
[21/12/2007|07:08] C:\Program Files\Common Files\LightScribe
[08/05/2009|19:34] C:\Program Files\Common Files\microsoft shared
[21/12/2007|07:08] C:\Program Files\Common Files\muvee Technologies
[21/12/2007|07:09] C:\Program Files\Common Files\NewTech Infosystems
[10/07/2009|17:31] C:\Program Files\Common Files\PX Storage Engine
[02/11/2006|13:18] C:\Program Files\Common Files\Services
[29/08/2008|17:24] C:\Program Files\Common Files\snp2uvc
[02/11/2006|13:18] C:\Program Files\Common Files\SpeechEngines
[03/01/2009|17:10] C:\Program Files\Common Files\Symantec Shared
[27/03/2009|18:57] C:\Program Files\Common Files\System
[26/03/2009|07:32] C:\Program Files\Common Files\Windows Live
[29/08/2008|21:34] C:\Program Files\Common Files\WindowsLiveInstaller
--------------------\\ Process
( 80 Processes )
... OK !
--------------------\\ Recherche avec S_Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Recherche de Fichiers / Dossiers Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Verification du Registre
..... OK !
--------------------\\ Verification du fichier Hosts
Fichier Hosts PROPRE
--------------------\\ Recherche de fichiers avec Catchme
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-23 22:10:42
Windows 5.1.2600 Service Pack 2 NTFS
detected NTDLL code modification:
ZwEnumerateKey, ZwQueryKey, ZwOpenKey, ZwClose, ZwEnumerateValueKey, ZwQueryValueKey, ZwOpenFile, ZwQueryDirectoryFile, ZwQuerySystemInformation
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 1
--------------------\\ Recherche d'autres infections
Aucune autre infection trouvée !
[F:13][D:6]-> C:\Users\Laure\AppData\Local\Temp
[F:46][D:1]-> C:\Users\Laure\AppData\Roaming\MICROS~1\Windows\Cookies
[F:158][D:4]-> C:\Users\Laure\AppData\Local\MICROS~1\Windows\TEMPOR~1\content.IE5
[F:1][D:1]-> C:\$Recycle.Bin
1 - "C:\Lop SD\LopR_1.txt" - 23/08/2009|22:06 - Option : [1]
2 - "C:\Lop SD\LopR_2.txt" - 23/08/2009|22:11 - Option : [2]
--------------------\\ Fin du rapport a 22:11:50
[ UAC => 1 ]
Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6001 ) Service Pack 1
X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 Duo CPU T8100 @ 2.10GHz )
BIOS : ZD1 v1.3809 3H09
USER : Laure ( Administrator )
BOOT : Normal boot
C:\ (Local Disk) - NTFS - Total:144 Go (Free:51 Go)
D:\ (Local Disk) - NTFS - Total:140 Go (Free:120 Go)
E:\ (CD or DVD)
F:\ (Local Disk) - NTFS - Total:298 Go (Free:130 Go)
"C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
Option : [2] ( 23/08/2009|22:10 )
[ UAC => 1 ]
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ SUPPRESSION
Supprime! - C:\Program Files\NetPumper
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
--------------------\\ Listing des dossiers dans Local
[29/08/2008|21:27] C:\Users\Laure\AppData\Local\Acer Arcade Deluxe
[29/08/2008|17:15] C:\Users\Laure\AppData\Local\acer eNM
[31/08/2008|21:42] C:\Users\Laure\AppData\Local\Adobe
[15/05/2009|21:35] C:\Users\Laure\AppData\Local\Apple
[12/07/2009|18:17] C:\Users\Laure\AppData\Local\Apple Computer
[29/08/2008|17:13] C:\Users\Laure\AppData\Local\Application Data
[29/08/2008|17:40] C:\Users\Laure\AppData\Local\Apps
[29/08/2008|17:41] C:\Users\Laure\AppData\Local\Citrix
[09/12/2008|16:56] C:\Users\Laure\AppData\Local\CyberLink
[23/08/2009|14:36] C:\Users\Laure\AppData\Local\d3d9caps.dat
[22/08/2009|10:51] C:\Users\Laure\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[18/04/2009|09:47] C:\Users\Laure\AppData\Local\Deployment
[23/08/2009|10:48] C:\Users\Laure\AppData\Local\eMule
[22/08/2009|09:34] C:\Users\Laure\AppData\Local\GDIPFONTCACHEV1.DAT
[23/08/2009|14:36] C:\Users\Laure\AppData\Local\Google
[29/08/2008|17:13] C:\Users\Laure\AppData\Local\Historique
[09/12/2008|16:56] C:\Users\Laure\AppData\Local\HomeMedia
[25/09/2008|16:12] C:\Users\Laure\AppData\Local\HP
[23/08/2009|13:00] C:\Users\Laure\AppData\Local\IconCache.db
[21/08/2009|21:41] C:\Users\Laure\AppData\Local\Microsoft
[28/01/2009|11:07] C:\Users\Laure\AppData\Local\Microsoft Games
[21/01/2009|18:49] C:\Users\Laure\AppData\Local\Microsoft Help
[09/12/2008|22:25] C:\Users\Laure\AppData\Local\PlayMovie
[29/08/2008|21:27] C:\Users\Laure\AppData\Local\PowerCinema
[23/08/2009|12:50] C:\Users\Laure\AppData\Local\Seven Zip
[23/08/2009|22:10] C:\Users\Laure\AppData\Local\temp
[29/08/2008|17:13] C:\Users\Laure\AppData\Local\Temporary Internet Files
[04/10/2008|11:55] C:\Users\Laure\AppData\Local\VirtualStore
--------------------\\ Tâches planifiées dans C:\Windows\tasks
[23/08/2009 16:36][--ah-----] C:\Windows\tasks\User_Feed_Synchronization-{AF4F5F6A-2000-4888-B9D6-108881533917}.job
[23/08/2009 13:01][--ah-----] C:\Windows\tasks\SA.DAT
[23/08/2009 13:00][--a------] C:\Windows\tasks\SCHEDLGU.TXT
--------------------\\ Listing des dossiers dans C:\ProgramData
[15/05/2009|21:37] C:\ProgramData\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[02/12/2008|14:23] C:\ProgramData\0C656BFCCF.sys
[15/03/2009|16:13] C:\ProgramData\Adobe
[15/05/2009|21:37] C:\ProgramData\Apple Computer
[02/11/2006|15:02] C:\ProgramData\Application Data
[21/08/2009|22:34] C:\ProgramData\Avira
[10/08/2009|11:12] C:\ProgramData\Babylon
[29/08/2008|17:09] C:\ProgramData\Bureau
[02/12/2008|14:27] C:\ProgramData\Corel
[09/12/2008|17:00] C:\ProgramData\CyberLink
[02/11/2006|15:02] C:\ProgramData\Desktop
[02/11/2006|15:02] C:\ProgramData\Documents
[29/08/2008|21:34] C:\ProgramData\Downloaded Installations
[26/02/2009|12:30] C:\ProgramData\eMule
[29/08/2008|17:09] C:\ProgramData\Favoris
[02/11/2006|15:02] C:\ProgramData\Favorites
[24/11/2008|11:02] C:\ProgramData\Forge of Games
[29/08/2008|17:59] C:\ProgramData\Hewlett-Packard
[19/01/2009|20:13] C:\ProgramData\HP
[14/04/2009|05:05] C:\ProgramData\HP Product Assistant
[28/05/2009|19:23] C:\ProgramData\hpzinstall.log
[02/12/2008|14:23] C:\ProgramData\KGyGaAvL.sys
[30/12/2008|16:58] C:\ProgramData\LightScribe
[20/08/2009|22:45] C:\ProgramData\Malwarebytes
[29/08/2008|17:09] C:\ProgramData\Menu D‚marrer
[27/03/2009|18:56] C:\ProgramData\Microsoft
[13/08/2009|20:03] C:\ProgramData\Microsoft Help
[29/08/2008|17:09] C:\ProgramData\ModŠles
[19/11/2008|18:12] C:\ProgramData\mwas
[30/12/2008|16:58] C:\ProgramData\NtiDvdCopy
[22/08/2009|00:05] C:\ProgramData\ntuser.pol
[21/08/2009|20:17] C:\ProgramData\NVIDIA
[03/06/2009|22:15] C:\ProgramData\Skyline
[28/01/2009|21:45] C:\ProgramData\Spybot - Search & Destroy
[02/11/2006|15:02] C:\ProgramData\Start Menu
[03/01/2009|17:10] C:\ProgramData\Symantec
[02/11/2006|15:02] C:\ProgramData\Templates
[29/08/2008|18:03] C:\ProgramData\WEBREG
[29/08/2008|21:38] C:\ProgramData\WLInstaller
[23/08/2009|12:56] C:\ProgramData\yahoo!
--------------------\\ Listing des dossiers dans C:\Program Files
[29/08/2008|17:26] C:\Program Files\ACER CrystalEye webcam
[03/01/2009|17:09] C:\Program Files\Acer GameZone
[29/08/2008|17:31] C:\Program Files\Acer Inc
[19/08/2009|18:54] C:\Program Files\Adobe
[31/10/2008|14:23] C:\Program Files\Alwil Software
[21/08/2009|22:34] C:\Program Files\Avira
[21/12/2007|05:58] C:\Program Files\Broadcom
[21/08/2009|22:37] C:\Program Files\CCleaner
[29/08/2008|17:41] C:\Program Files\Citrix
[25/09/2008|17:47] C:\Program Files\ColiPoste
[23/08/2009|12:55] C:\Program Files\Common Files
[21/12/2007|05:43] C:\Program Files\CONEXANT
[02/12/2008|14:28] C:\Program Files\Corel
[21/12/2007|07:19] C:\Program Files\CyberLink
[10/07/2009|17:31] C:\Program Files\DivX
[07/03/2009|14:40] C:\Program Files\eMule
[29/08/2008|17:09] C:\Program Files\Fichiers communs [C:\Program Files\Common Files]
[22/08/2009|20:18] C:\Program Files\FileHippo.com
[28/10/2008|20:05] C:\Program Files\Fnacmusic
[29/04/2009|21:25] C:\Program Files\Free Audio Pack
[10/08/2009|11:12] C:\Program Files\GIMP-2.0
[09/11/2008|18:02] C:\Program Files\Google
[19/01/2009|20:11] C:\Program Files\Hewlett-Packard
[29/08/2008|17:54] C:\Program Files\HP
[14/10/2008|19:25] C:\Program Files\Inkscape
[14/03/2009|20:11] C:\Program Files\InstallShield Installation Information
[29/07/2009|17:31] C:\Program Files\Internet Explorer
[15/04/2009|18:43] C:\Program Files\Java
[31/12/2008|11:45] C:\Program Files\JRE
[03/01/2009|17:09] C:\Program Files\KaraFun
[10/10/2008|19:22] C:\Program Files\KC Softwares
[23/11/2008|19:21] C:\Program Files\K-Lite Codec Pack
[29/08/2008|17:16] C:\Program Files\Launch Manager
[27/11/2008|18:08] C:\Program Files\MatchWare
[24/02/2009|14:43] C:\Program Files\Micro Application
[27/03/2009|18:58] C:\Program Files\Microsoft
[02/11/2006|14:37] C:\Program Files\Microsoft Games
[08/01/2009|19:41] C:\Program Files\Microsoft Office
[27/03/2009|18:57] C:\Program Files\Microsoft Office Outlook Connector
[01/08/2009|11:04] C:\Program Files\Microsoft Silverlight
[27/03/2009|18:55] C:\Program Files\Microsoft SQL Server Compact Edition
[27/03/2009|18:57] C:\Program Files\Microsoft Sync Framework
[08/01/2009|19:42] C:\Program Files\Microsoft Visual Studio
[08/01/2009|19:39] C:\Program Files\Microsoft Visual Studio 8
[10/06/2009|20:47] C:\Program Files\Microsoft Works
[21/12/2007|07:35] C:\Program Files\Microsoft.NET
[08/10/2008|20:19] C:\Program Files\Movie Maker
[08/01/2009|19:43] C:\Program Files\MSBuild
[16/10/2008|18:55] C:\Program Files\MSECache
[21/12/2007|06:29] C:\Program Files\MSXML 4.0
[21/12/2007|07:09] C:\Program Files\NewTech Infosystems
[31/12/2008|11:45] C:\Program Files\OpenOffice.org 3
[06/04/2009|18:56] C:\Program Files\pese_courrier
[15/05/2009|21:36] C:\Program Files\QuickTime
[29/08/2008|17:54] C:\Program Files\Realtek
[02/11/2006|14:37] C:\Program Files\Reference Assemblies
[14/03/2009|19:49] C:\Program Files\Samsung
[03/06/2009|22:15] C:\Program Files\Skyline
[28/01/2009|21:46] C:\Program Files\Spybot - Search & Destroy
[29/08/2008|17:26] C:\Program Files\SUYIN
[21/12/2007|06:01] C:\Program Files\Synaptics
[22/08/2009|22:34] C:\Program Files\Trend Micro
[02/11/2006|15:01] C:\Program Files\Uninstall Information
[09/12/2008|22:53] C:\Program Files\VideoLAN
[10/08/2009|11:13] C:\Program Files\WinApplication
[21/12/2007|06:04] C:\Program Files\Winbond Electronics
[08/10/2008|20:19] C:\Program Files\Windows Calendar
[08/10/2008|20:19] C:\Program Files\Windows Collaboration
[08/10/2008|20:19] C:\Program Files\Windows Defender
[08/10/2008|20:19] C:\Program Files\Windows Journal
[27/03/2009|18:57] C:\Program Files\Windows Live
[27/03/2009|18:53] C:\Program Files\Windows Live SkyDrive
[13/08/2009|20:02] C:\Program Files\Windows Mail
[13/08/2009|20:09] C:\Program Files\Windows Media Player
[29/08/2008|17:09] C:\Program Files\Windows NT
[08/10/2008|20:19] C:\Program Files\Windows Photo Gallery
[08/10/2008|20:19] C:\Program Files\Windows Sidebar
[23/08/2009|13:01] C:\Program Files\WinRAR
[22/08/2009|22:43] C:\Program Files\WOT
[23/08/2009|12:56] C:\Program Files\Yahoo!
--------------------\\ Listing des dossiers dans C:\Program Files\Common Files
[19/08/2009|18:54] C:\Program Files\Common Files\Adobe
[22/10/2008|18:52] C:\Program Files\Common Files\Corel
[22/10/2008|18:52] C:\Program Files\Common Files\DESIGNER
[10/07/2009|17:30] C:\Program Files\Common Files\DivX Shared
[29/08/2008|17:54] C:\Program Files\Common Files\Hewlett-Packard
[19/01/2009|20:11] C:\Program Files\Common Files\HP
[22/10/2008|18:52] C:\Program Files\Common Files\InstallShield
[21/12/2007|07:08] C:\Program Files\Common Files\LightScribe
[08/05/2009|19:34] C:\Program Files\Common Files\microsoft shared
[21/12/2007|07:08] C:\Program Files\Common Files\muvee Technologies
[21/12/2007|07:09] C:\Program Files\Common Files\NewTech Infosystems
[10/07/2009|17:31] C:\Program Files\Common Files\PX Storage Engine
[02/11/2006|13:18] C:\Program Files\Common Files\Services
[29/08/2008|17:24] C:\Program Files\Common Files\snp2uvc
[02/11/2006|13:18] C:\Program Files\Common Files\SpeechEngines
[03/01/2009|17:10] C:\Program Files\Common Files\Symantec Shared
[27/03/2009|18:57] C:\Program Files\Common Files\System
[26/03/2009|07:32] C:\Program Files\Common Files\Windows Live
[29/08/2008|21:34] C:\Program Files\Common Files\WindowsLiveInstaller
--------------------\\ Process
( 80 Processes )
... OK !
--------------------\\ Recherche avec S_Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Recherche de Fichiers / Dossiers Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Verification du Registre
..... OK !
--------------------\\ Verification du fichier Hosts
Fichier Hosts PROPRE
--------------------\\ Recherche de fichiers avec Catchme
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-23 22:10:42
Windows 5.1.2600 Service Pack 2 NTFS
detected NTDLL code modification:
ZwEnumerateKey, ZwQueryKey, ZwOpenKey, ZwClose, ZwEnumerateValueKey, ZwQueryValueKey, ZwOpenFile, ZwQueryDirectoryFile, ZwQuerySystemInformation
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 1
--------------------\\ Recherche d'autres infections
Aucune autre infection trouvée !
[F:13][D:6]-> C:\Users\Laure\AppData\Local\Temp
[F:46][D:1]-> C:\Users\Laure\AppData\Roaming\MICROS~1\Windows\Cookies
[F:158][D:4]-> C:\Users\Laure\AppData\Local\MICROS~1\Windows\TEMPOR~1\content.IE5
[F:1][D:1]-> C:\$Recycle.Bin
1 - "C:\Lop SD\LopR_1.txt" - 23/08/2009|22:06 - Option : [1]
2 - "C:\Lop SD\LopR_2.txt" - 23/08/2009|22:11 - Option : [2]
--------------------\\ Fin du rapport a 22:11:50
[ UAC => 1 ]
est ce qu'il y a des logiciels que je peux supprimer? il y en a que je ne sais pas à quoi ils servent mais j'ose pas les supprimer de peur de faire une connerie!!
Ok maintenant :
▶ Télécharge mbr.exe de Gmer sur le Bureau : http://www2.gmer.net/mbr/mbr.exe
▶ Désactive toutes tes protections et coupe la connexion.
▶ Double clique sur mbr.exe et laisse l'outil travailler : un rapport nommé mbr.log sera généré
▶ Poste son rapport dans ta prochaine réponse stp
▶ Télécharge mbr.exe de Gmer sur le Bureau : http://www2.gmer.net/mbr/mbr.exe
▶ Désactive toutes tes protections et coupe la connexion.
▶ Double clique sur mbr.exe et laisse l'outil travailler : un rapport nommé mbr.log sera généré
▶ Poste son rapport dans ta prochaine réponse stp
Tout dépend quels programmes tu veux désinstaller
ça marche pas :
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.6 by Gmer, http://www.gmer.net
device: opened successfully
user: error reading MBR
kernel: error reading MBR
pourtant j'ai désactiver antivir
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.6 by Gmer, http://www.gmer.net
device: opened successfully
user: error reading MBR
kernel: error reading MBR
pourtant j'ai désactiver antivir
▶ Télécharge Rooter (créé par l'équipe IDN) sur ton bureau.
▶ /!\ Déconnecte toi d'internet et ferme toutes les applications en cours /!\
▶ Exécute Rooter et laisse le travailler jusqu'à l'apparition du rapport dans le bloc note
▶ Ensuite poste le rapport dans ta prochaine réponse
▶ /!\ Déconnecte toi d'internet et ferme toutes les applications en cours /!\
▶ Exécute Rooter et laisse le travailler jusqu'à l'apparition du rapport dans le bloc note
▶ Ensuite poste le rapport dans ta prochaine réponse
Rooter.exe (v1.0.2) by Eric_71
.
The token does not have the SeDebugPrivilege privilege ! (error:1300)
[b]Can not acquire SeDebugPrivilege !
Please run the tool as administrator ..[/b]
.
Windows Vista Home Edition (6.0.6001) Service Pack 1
[32_bits] - x86 Family 6 Model 23 Stepping 6, GenuineIntel
.
Error OpenService (wscsvc) : 6
Error OpenSCManager : 5
Error OpenService (MpsSvc) : 6
Windows Defender -> Enabled
User Account Control (UAC) -> Enabled
.
Internet Explorer 8.0.6001.18813
.
C:\ [Fixed-NTFS] .. ( Total:144 Go - Free:51 Go )
D:\ [Fixed-NTFS] .. ( Total:140 Go - Free:120 Go )
E:\ [CD_Rom]
F:\ [Fixed-NTFS] .. ( Total:298 Go - Free:130 Go )
Z:\ [Network] .. ( Total:0 Go - Free:0 Go )
.
Scan : 22:19.54
Path : C:\Users\Laure\Desktop\Rooter.exe
User : Laure ( Administrator -> YES )
.
----------------------\\ Processes
.
Locked [System Process] (0)
Locked System (4)
Locked smss.exe (528)
Locked csrss.exe (596)
Locked wininit.exe (648)
Locked csrss.exe (660)
Locked services.exe (696)
Locked lsass.exe (712)
Locked lsm.exe (720)
Locked winlogon.exe (864)
Locked svchost.exe (876)
Locked svchost.exe (972)
Locked svchost.exe (1012)
Locked svchost.exe (1076)
Locked rundll32.exe (1088)
Locked svchost.exe (1152)
Locked svchost.exe (1168)
Locked audiodg.exe (1220)
Locked svchost.exe (1240)
Locked SLsvc.exe (1256)
Locked svchost.exe (1296)
Locked svchost.exe (1432)
Locked spoolsv.exe (1724)
Locked sched.exe (1788)
Locked svchost.exe (1800)
Locked avguard.exe (568)
Locked eDSService.exe (520)
Locked eLockServ.exe (1384)
Locked eNet Service.exe (1940)
Locked svchost.exe (572)
Locked LSSrvc.exe (2056)
Locked MobilityService.exe (2124)
Locked svchost.exe (2232)
Locked SeaPort.exe (2252)
Locked svchost.exe (2320)
Locked svchost.exe (2352)
Locked SearchIndexer.exe (2388)
Locked XAudio.exe (2488)
Locked eRecoveryService.exe (2512)
Locked capuserv.exe (2588)
Locked ePowerSvc.exe (2676)
Locked WmiPrvSE.exe (2860)
Locked unsecapp.exe (2940)
Locked WmiPrvSE.exe (2952)
Locked taskeng.exe (3132)
Locked svchost.exe (3944)
______ C:\Windows\system32\taskeng.exe (4076)
______ C:\Windows\system32\Dwm.exe (2768)
______ C:\Windows\Explorer.EXE (3004)
______ C:\Program Files\Windows Defender\MSASCui.exe (2932)
______ C:\Program Files\Synaptics\SynTP\SynTPStart.exe (1548)
______ C:\Acer\Empowering Technology\eDataSecurity\eDSLoader.exe (3792)
______ C:\Acer\Empowering Technology\eAudio\eAudio.exe (2660)
______ C:\Windows\RtHDVCpl.exe (2424)
Locked QtZgAcer.EXE (2480)
Locked SynTPEnh.exe (3580)
______ C:\Windows\System32\rundll32.exe (3332)
______ C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe (3868)
______ C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (3824)
______ C:\Program Files\Java\jre6\bin\jusched.exe (1572)
______ C:\Program Files\Windows Live\Messenger\msnmsgr.exe (2888)
______ C:\Windows\ehome\ehtray.exe (2936)
______ C:\Program Files\Windows Sidebar\sidebar.exe (312)
______ C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (3364)
______ C:\Windows\System32\rundll32.exe (3372)
______ C:\Program Files\Windows Media Player\wmpnscfg.exe (3016)
Locked wmpnetwk.exe (4116)
______ C:\Users\Laure\AppData\Local\Temp\RtkBtMnt.exe (4412)
______ C:\Windows\ehome\ehmsas.exe (4452)
______ C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe (4844)
______ C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe (4900)
______ C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe (5108)
______ C:\Program Files\Windows Live\Contacts\wlcomm.exe (5780)
Locked UpdateChecker.exe (820)
Locked conime.exe (3348)
Locked svchost.exe (768)
Locked svchost.exe (4188)
Locked taskeng.exe (5188)
Locked SearchProtocolHost.exe (5256)
Locked SearchFilterHost.exe (4536)
______ C:\Windows\system32\SearchProtocolHost.exe (2696)
______ C:\Users\Laure\Desktop\Rooter.exe (4080)
.
----------------------\\ Device\Harddisk0\
.
\Device\Harddisk0 [Sectors : 63 x 512 Bytes]
.
\Device\Harddisk0\Partition1 (Start_Offset:32256 | Length:10478974464)
\Device\Harddisk0\Partition2 --[ MBR ]-- (Start_Offset:10479468544 | Length:154934444032)
\Device\Harddisk0\Partition3 (Start_Offset:165413912576 | Length:151176347648)
\Device\Harddisk0\Partition4 (Start_Offset:316590260224 | Length:3481272320)
.
----------------------\\ Scheduled Tasks
.
C:\Windows\Tasks\SA.DAT
C:\Windows\Tasks\SCHEDLGU.TXT
C:\Windows\Tasks\User_Feed_Synchronization-{AF4F5F6A-2000-4888-B9D6-108881533917}.job
.
----------------------\\ Registry
.
.
----------------------\\ Files & Folders
.
----------------------\\ Scan completed at 22:19.56
.
C:\Rooter$\Rooter_1.txt - (23/08/2009 | 22:19.56)
.
The token does not have the SeDebugPrivilege privilege ! (error:1300)
[b]Can not acquire SeDebugPrivilege !
Please run the tool as administrator ..[/b]
.
Windows Vista Home Edition (6.0.6001) Service Pack 1
[32_bits] - x86 Family 6 Model 23 Stepping 6, GenuineIntel
.
Error OpenService (wscsvc) : 6
Error OpenSCManager : 5
Error OpenService (MpsSvc) : 6
Windows Defender -> Enabled
User Account Control (UAC) -> Enabled
.
Internet Explorer 8.0.6001.18813
.
C:\ [Fixed-NTFS] .. ( Total:144 Go - Free:51 Go )
D:\ [Fixed-NTFS] .. ( Total:140 Go - Free:120 Go )
E:\ [CD_Rom]
F:\ [Fixed-NTFS] .. ( Total:298 Go - Free:130 Go )
Z:\ [Network] .. ( Total:0 Go - Free:0 Go )
.
Scan : 22:19.54
Path : C:\Users\Laure\Desktop\Rooter.exe
User : Laure ( Administrator -> YES )
.
----------------------\\ Processes
.
Locked [System Process] (0)
Locked System (4)
Locked smss.exe (528)
Locked csrss.exe (596)
Locked wininit.exe (648)
Locked csrss.exe (660)
Locked services.exe (696)
Locked lsass.exe (712)
Locked lsm.exe (720)
Locked winlogon.exe (864)
Locked svchost.exe (876)
Locked svchost.exe (972)
Locked svchost.exe (1012)
Locked svchost.exe (1076)
Locked rundll32.exe (1088)
Locked svchost.exe (1152)
Locked svchost.exe (1168)
Locked audiodg.exe (1220)
Locked svchost.exe (1240)
Locked SLsvc.exe (1256)
Locked svchost.exe (1296)
Locked svchost.exe (1432)
Locked spoolsv.exe (1724)
Locked sched.exe (1788)
Locked svchost.exe (1800)
Locked avguard.exe (568)
Locked eDSService.exe (520)
Locked eLockServ.exe (1384)
Locked eNet Service.exe (1940)
Locked svchost.exe (572)
Locked LSSrvc.exe (2056)
Locked MobilityService.exe (2124)
Locked svchost.exe (2232)
Locked SeaPort.exe (2252)
Locked svchost.exe (2320)
Locked svchost.exe (2352)
Locked SearchIndexer.exe (2388)
Locked XAudio.exe (2488)
Locked eRecoveryService.exe (2512)
Locked capuserv.exe (2588)
Locked ePowerSvc.exe (2676)
Locked WmiPrvSE.exe (2860)
Locked unsecapp.exe (2940)
Locked WmiPrvSE.exe (2952)
Locked taskeng.exe (3132)
Locked svchost.exe (3944)
______ C:\Windows\system32\taskeng.exe (4076)
______ C:\Windows\system32\Dwm.exe (2768)
______ C:\Windows\Explorer.EXE (3004)
______ C:\Program Files\Windows Defender\MSASCui.exe (2932)
______ C:\Program Files\Synaptics\SynTP\SynTPStart.exe (1548)
______ C:\Acer\Empowering Technology\eDataSecurity\eDSLoader.exe (3792)
______ C:\Acer\Empowering Technology\eAudio\eAudio.exe (2660)
______ C:\Windows\RtHDVCpl.exe (2424)
Locked QtZgAcer.EXE (2480)
Locked SynTPEnh.exe (3580)
______ C:\Windows\System32\rundll32.exe (3332)
______ C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe (3868)
______ C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (3824)
______ C:\Program Files\Java\jre6\bin\jusched.exe (1572)
______ C:\Program Files\Windows Live\Messenger\msnmsgr.exe (2888)
______ C:\Windows\ehome\ehtray.exe (2936)
______ C:\Program Files\Windows Sidebar\sidebar.exe (312)
______ C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (3364)
______ C:\Windows\System32\rundll32.exe (3372)
______ C:\Program Files\Windows Media Player\wmpnscfg.exe (3016)
Locked wmpnetwk.exe (4116)
______ C:\Users\Laure\AppData\Local\Temp\RtkBtMnt.exe (4412)
______ C:\Windows\ehome\ehmsas.exe (4452)
______ C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe (4844)
______ C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe (4900)
______ C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe (5108)
______ C:\Program Files\Windows Live\Contacts\wlcomm.exe (5780)
Locked UpdateChecker.exe (820)
Locked conime.exe (3348)
Locked svchost.exe (768)
Locked svchost.exe (4188)
Locked taskeng.exe (5188)
Locked SearchProtocolHost.exe (5256)
Locked SearchFilterHost.exe (4536)
______ C:\Windows\system32\SearchProtocolHost.exe (2696)
______ C:\Users\Laure\Desktop\Rooter.exe (4080)
.
----------------------\\ Device\Harddisk0\
.
\Device\Harddisk0 [Sectors : 63 x 512 Bytes]
.
\Device\Harddisk0\Partition1 (Start_Offset:32256 | Length:10478974464)
\Device\Harddisk0\Partition2 --[ MBR ]-- (Start_Offset:10479468544 | Length:154934444032)
\Device\Harddisk0\Partition3 (Start_Offset:165413912576 | Length:151176347648)
\Device\Harddisk0\Partition4 (Start_Offset:316590260224 | Length:3481272320)
.
----------------------\\ Scheduled Tasks
.
C:\Windows\Tasks\SA.DAT
C:\Windows\Tasks\SCHEDLGU.TXT
C:\Windows\Tasks\User_Feed_Synchronization-{AF4F5F6A-2000-4888-B9D6-108881533917}.job
.
----------------------\\ Registry
.
.
----------------------\\ Files & Folders
.
----------------------\\ Scan completed at 22:19.56
.
C:\Rooter$\Rooter_1.txt - (23/08/2009 | 22:19.56)
Oups... C'est de ma faute...
Tu es sous Vista... Il faut que tu désactives le contrôle des comptes utilisateurs et que tu l'exécute en tant qu'administrateur
Tu es sous Vista... Il faut que tu désactives le contrôle des comptes utilisateurs et que tu l'exécute en tant qu'administrateur
excuse
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.6 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
user & kernel MBR OK
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.6 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
user & kernel MBR OK
Je ne vois pourtant pas de traces de Navipromo dans les rapports mais fais quand même ceci pour s'assurer stp :
▶ Télécharge sur le bureau Navilog1
*Si ton antivirus s'affole , le désactiver
sous vista : Clic-droit sur le raccourci Navilog1 présent sur le bureau et choisis "Exécuter en tant qu'administrateur
sous XP : double-clic dessus pour l'installer et le lancer
▶ taper F
▶ Appuyer sur une touche jusqu' arriver aux options
▶ Choisir Recherche/désinfection automatique ( = taper 1 )
▶un rapport : fixnavi.txt dans ==> C:
▶le copier et le coller dans la réponse
▶ Télécharge sur le bureau Navilog1
*Si ton antivirus s'affole , le désactiver
sous vista : Clic-droit sur le raccourci Navilog1 présent sur le bureau et choisis "Exécuter en tant qu'administrateur
sous XP : double-clic dessus pour l'installer et le lancer
▶ taper F
▶ Appuyer sur une touche jusqu' arriver aux options
▶ Choisir Recherche/désinfection automatique ( = taper 1 )
▶un rapport : fixnavi.txt dans ==> C:
▶le copier et le coller dans la réponse
Y a la plupart que je ne connais mais je te conseille de ne pas y toucher... Vaut mieux pas quand on ne connais pas^^
Fix Navipromo version 4.0.1 commencé le 23/08/2009 22:38:35,37
!!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
!!! Postez ce rapport sur le forum pour le faire analyser !!!
Outil exécuté depuis C:\Program Files\navilog1
Mise à jour le 18.07.2009 à 11h00 par IL-MAFIOSO
Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6001 ) Service Pack 1
X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 Duo CPU T8100 @ 2.10GHz )
BIOS : ZD1 v1.3809 3H09
USER : Laure ( Administrator )
BOOT : Normal boot
C:\ (Local Disk) - NTFS - Total:144 Go (Free:51 Go)
D:\ (Local Disk) - NTFS - Total:140 Go (Free:120 Go)
E:\ (CD or DVD)
F:\ (Local Disk) - NTFS - Total:298 Go (Free:130 Go)
Z:\ (Network Disk)
Recherche executée en mode normal
[b]Aucune Infection Navipromo/Egdaccess trouvé/b
*** Scan terminé 23/08/2009 22:50:38,84 ***
!!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
!!! Postez ce rapport sur le forum pour le faire analyser !!!
Outil exécuté depuis C:\Program Files\navilog1
Mise à jour le 18.07.2009 à 11h00 par IL-MAFIOSO
Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6001 ) Service Pack 1
X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 Duo CPU T8100 @ 2.10GHz )
BIOS : ZD1 v1.3809 3H09
USER : Laure ( Administrator )
BOOT : Normal boot
C:\ (Local Disk) - NTFS - Total:144 Go (Free:51 Go)
D:\ (Local Disk) - NTFS - Total:140 Go (Free:120 Go)
E:\ (CD or DVD)
F:\ (Local Disk) - NTFS - Total:298 Go (Free:130 Go)
Z:\ (Network Disk)
Recherche executée en mode normal
[b]Aucune Infection Navipromo/Egdaccess trouvé/b
*** Scan terminé 23/08/2009 22:50:38,84 ***