Différents problèmes qui s'accumulent... - Page 3

Résolu
  1. Voila le rapport d'usbfix :

    ############################## | UsbFix V6.040 |

    User : Quentin (Administrateurs) # UNICORNI-D76A60
    Update on 10/10/2009 by Chiquitine29, C_XX & Chimay8
    Start at: 20:07:05 | 10/10/2009
    Website : http://pagesperso-orange.fr/NosTools/index.html

    Processeur Intel Pentium III Xeon
    Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 2
    Internet Explorer 8.0.6001.18702
    Windows Firewall Status : Enabled
    AV : AntiVir Desktop 9.0.1.32 [ Enabled | Updated ]

    A:\ -> Lecteur de disquettes 3 ½ pouces
    C:\ -> Disque fixe local # 232,88 Go (66,02 Go free) # NTFS
    D:\ -> Disque CD-ROM
    E:\ -> Disque CD-ROM
    F:\ -> Disque fixe local # 298,08 Go (31,92 Go free) [Macgyver] # NTFS

    ############################## | Processus actifs |

    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\logonui.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Avira\AntiVir Desktop\sched.exe
    C:\Program Files\Glary Utilities\initialize.exe
    C:\Program Files\Avira\AntiVir Desktop\avguard.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Google\Update\GoogleUpdate.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\WINDOWS\system32\gearsec.exe
    C:\Program Files\Google\Update\GoogleUpdate.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Google\Update\GoogleUpdate.exe
    C:\Program Files\Keyboard & Mouse Driver\KMWDSrv.exe
    C:\WINDOWS\system32\PnkBstrA.exe
    C:\WINDOWS\system32\PnkBstrB.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\wbem\wmiprvse.exe
    C:\WINDOWS\system32\wbem\wmiapsrv.exe
    C:\WINDOWS\System32\alg.exe
    C:\WINDOWS\system32\wbem\wmiprvse.exe

    ################## | Fichiers # Dossiers infectieux |

    ################## | Registre # Clés Run infectieuses |

    Supprimé ! [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System] "DisableRegistryTools"
    Supprimé ! [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoDrives"
    Supprimé ! [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoDrives"

    ################## | Registre # Mountpoints2 |

    ################## | Listing des fichiers présent |

    [27/12/2008 01:31|--a------|0] C:\AUTOEXEC.BAT
    [03/08/2009 10:44|--a------|53] C:\biosinfo
    [28/07/2009 11:45|--a------|212] C:\Boot.bak
    [03/10/2009 13:00|-rahs----|282] C:\boot.ini
    [24/08/2001 14:00|-rahs----|4952] C:\Bootfont.bin
    [03/08/2004 23:00|--a------|263488] C:\cmldr
    [27/12/2008 01:31|--a------|0] C:\CONFIG.SYS
    [04/02/2009 11:24|--a------|197] C:\csb.log
    [27/12/2008 01:31|-rahs----|0] C:\IO.SYS
    [27/12/2008 01:31|-rahs----|0] C:\MSDOS.SYS
    [03/08/2004 22:38|-rahs----|47564] C:\NTDETECT.COM
    [25/01/2009 20:07|-rahs----|252240] C:\ntldr
    [?|?|?] C:\pagefile.sys
    [04/02/2009 11:22|--a------|429] C:\RHDSetup.log
    [01/02/2009 17:00|--a------|1449987] C:\service.log
    [05/10/2009 09:36|--a------|968] C:\TCleaner.txt
    [10/10/2009 20:14|--a------|3284] C:\UsbFix.txt
    [02/10/2009 22:12|--a------|246050] F:\buro.jpg
    [20/05/2008 23:38|--a------|219166] F:\favo.JPG
    [20/05/2008 23:39|--a------|170606] F:\favo1.JPG
    [20/05/2008 23:39|--a------|174302] F:\favo2.JPG
    [03/07/2008 01:38|--a------|164913] F:\log.JPG
    [22/05/2008 19:09|--a------|803] F:\log.txt
    [03/07/2008 01:37|--a------|153660] F:\marques pages.JPG
    [02/10/2009 22:12|--ahs----|117760] F:\Thumbs.db
    [26/12/2008 21:43|--a------|1146] F:\Tu ne me vois pas.doc
    [19/06/2009 22:35|--a------|2077781] F:\VirtualDJ Local Database v5.xml

    ################## | Vaccination |

    # C:\autorun.inf -> Folder created by UsbFix.
    # F:\autorun.inf -> Folder created by UsbFix.

    ################## | ! Fin du rapport # UsbFix V6.040 ! |

    On peut en passer un coup de temps en temps histoire de nettoyer l'ordi, comme malwarebyte ?

    Merci beaucoup, à bientôt
    0
    1. Contributeur sécurité
      re

      non rien a voir avec malwarebyte ni un programme de securité habituel c'est un fix specifique au infection USB qui evolue trés rapidement donc sa ne serta rien de garder les fix qui sont obsolete au bout d'1 semaine

      par contre apparament il n'as pas detecté la clefs MP2.

      reposte un NOUVEAU RSIT
      0
      1. ah ok mais j'ai pris usbfix au hazard sur le net, donc il est possible que j'ai pris une version obsolète non ?

        Logfile of random's system information tool 1.06 (written by random/random)
        Run by Quentin at 2009-10-10 20:40:56
        Microsoft Windows XP Professionnel Service Pack 2
        System drive C: has 68 GB (29%) free of 238 GB
        Total RAM: 3326 MB (75% free)

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 20:41:10, on 10/10/2009
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v8.00 (8.00.6001.18702)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\nvsvc32.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\Program Files\Avira\AntiVir Desktop\sched.exe
        C:\Program Files\Avira\AntiVir Desktop\avguard.exe
        C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
        C:\Program Files\Bonjour\mDNSResponder.exe
        C:\WINDOWS\system32\gearsec.exe
        C:\Program Files\Java\jre6\bin\jqs.exe
        C:\Program Files\Keyboard & Mouse Driver\KMWDSrv.exe
        C:\WINDOWS\system32\PnkBstrA.exe
        C:\WINDOWS\system32\PnkBstrB.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\system32\wbem\wmiapsrv.exe
        C:\WINDOWS\SOUNDMAN.EXE
        C:\WINDOWS\explorer.exe
        C:\Program Files\Mozilla Firefox\firefox.exe
        C:\Program Files\MSI\US54SE_Utility\ZDWlan.exe
        C:\WINDOWS\system32\wuauclt.exe
        F:\Incoming\Emule extrem\emule.exe
        C:\Program Files\Windows Media Player\wmplayer.exe
        C:\Program Files\Windows Live\Messenger\msnmsgr.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\Windows Live\Contacts\wlcomm.exe
        C:\WINDOWS\system32\wuauclt.exe
        F:\Mes téléchargements\RSIT.exe
        F:\Mes téléchargements\Quentin.exe
        C:\Program Files\Skype\Toolbars\Shared\SkypeNames.exe

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer
        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
        R3 - URLSearchHook: DeviceVM Url Search Hook - {0063BF63-BFFF-4B8F-9D26-4267DF7F17DD} - C:\WINDOWS\system32\dvmurl.dll
        O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Downloads\IDM-Internet-Download-Manager-v.5.17\IDMIECC.dll
        O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
        O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll
        O2 - BHO: Videoraptor_WebRipPlugin Class - {3C0372C2-04C3-4100-BAB1-1D42C552BC48} - C:\Program Files\RapidSolution Software AG\Videoraptor\plugins\IE\VR_WebRipIePlugin.dll
        O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
        O2 - BHO: Babylon IE plugin - {9CFACCB6-2F3F-4177-94EA-0D2B72D384C1} - C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll
        O2 - BHO: Tunebite_WebRipPlugin Class - {AA102584-3B97-47e7-B9BC-75D54C110A7D} - C:\Program Files\RapidSolution\AudialsOne\Tunebite\plugins\IE\TB_WebRipIePlugin.dll
        O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
        O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
        O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
        O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
        O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
        O4 - HKLM\..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe /install
        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
        O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
        O4 - HKLM\..\Run: [KMCONFIG] C:\Program Files\Keyboard & Mouse Driver\StartAutorun.exe KMConfig.exe
        O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
        O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
        O4 - Global Startup: MSI US54SE 802.11b+g USB Stick Utility.lnk = C:\Program Files\MSI\US54SE_Utility\ZDWlan.exe
        O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
        O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
        O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
        O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000
        O8 - Extra context menu item: Translate this web page with Babylon - res://C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/ActionTU.htm
        O8 - Extra context menu item: Translate with Babylon - res://C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Action.htm
        O8 - Extra context menu item: Télécharger avec IDM - C:\Downloads\IDM-Internet-Download-Manager-v.5.17\IEExt.htm
        O8 - Extra context menu item: Télécharger le contenu de video FLV avec IDM - C:\Downloads\IDM-Internet-Download-Manager-v.5.17\IEGetVL.htm
        O8 - Extra context menu item: Télécharger tous les liens avec IDM - C:\Downloads\IDM-Internet-Download-Manager-v.5.17\IEGetAll.htm
        O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL
        O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll/206 (file missing)
        O9 - Extra button: Translate this web page with Babylon - {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll
        O9 - Extra 'Tools' menuitem: Translate this web page with Babylon - {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O14 - IERESET.INF: START_PAGE_URL=http://www.files-ftp.com/~unicorni/phpBB2/index.php
        O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
        O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
        O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
        O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
        O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
        O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
        O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - MAGIX® - C:\MAGIX\Common\Database\bin\fbserver.exe
        O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
        O23 - Service: gearsec - GEAR Software - C:\WINDOWS\system32\gearsec.exe
        O23 - Service: Google Update Service (gupdate1c9bc9162b38fbb) (gupdate1c9bc9162b38fbb) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
        O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
        O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
        O23 - Service: Keyboard And Mouse Communication Service (KMWDSERVICE) - UASSOFT.COM - C:\Program Files\Keyboard & Mouse Driver\KMWDSrv.exe
        O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
        O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
        O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
        O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
        0
        1. Contributeur sécurité
          fait sa deja :

          * Télécharge Toolscleaner sur ton Bureau

          https://www.commentcamarche.net/telecharger/securite/22061-toolscleaner/
          * Double-clique sur ToolsCleaner2.exe et laisse le travailler
          * Clique sur Recherche et laisse le scan se terminer.
          * Clique sur Suppression pour finaliser.
          * Tu peux, si tu le souhaites, te servir des Options facultatives.
          * Clique sur Quitter, pour que le rapport puisse se créer.
          * Le rapport (TCleaner.txt) se trouve à la racine de votre disque dur (C:\)...colle le dans ta prochaine réponse
          0
          1. Contributeur sécurité
            ok c'est bon

            tu peux faire le reste les mises a jour

            supprime aussi ce dossier C:\Program Files\DAEMON Tools Toolbar

            si tu y arrive pas redemarre ton PC au bip tapote F8 et choisit mode sans echec puis supprime le et vide ta corbeille

            puis si tu n'as pas utlise CCleaner https://www.01net.com/telecharger/windows/Utilitaire/nettoyeurs_et_installeurs/fiches/32599.html
            va dans option/avancé et decoche la 1er case et nettoie plusieurs ton regsitre et dans l'onglet nettoyeur jusqu' atrouver 0erreur

            dit moi si + de probleme et si c'est le cas met en resolu

            @+
            0
            1. C'est tout bon, dossier supprimé et avec Ccleaner comme l'autre jour il y a juste une erreur "extension de fichier non utilisée" qui reste à chaque fois.

              Merci ! a+
              0
              1. Contributeur sécurité
                tu as pas passer toolcleaner pour supprimer les quarantaine et les logs des fix etc... poste le rapport ensuite
                0
                1. apparemment il arrive pas à supprimer un des trucs :

                  [ Rapport ToolsCleaner version 2.3.11 (par A.Rothstein & dj QUIOU) ]

                  --> Recherche:

                  C:\UsbFix: trouvé !

                  ---------------------------------
                  --> Suppression:

                  C:\UsbFix: ERREUR DE SUPPRESSION !!
                  0
                  1. Contributeur sécurité
                    pas grave supprime toi ce dossier

                    C:\UsbFix
                    0
                    1. Bon ben c'est tout bon alors cette fois, merci !
                      0
                      1. Contributeur sécurité
                        re

                        de rien ;)

                        si les problemes reviennent hesite pas a faire remonter ce topic

                        @+
                        0
                        Précédent
                        • 1
                        • 2
                        • 3