Comment Faire Pour Arreter Que L'Ordi Rame ? - Page 2

Précédent
  • 1
  • 2
  1. RoMey974 Messages postés 38 Statut Membre
     
    Nan C Bon ! J'me suis trompé dsl !
    0
  2. RoMey974 Messages postés 38 Statut Membre
     
    ############################## | UsbFix V6.039 |

    User : Romey (Administrateurs) # PC-SSIYANKAI
    Update on 08/10/2009 by Chiquitine29, C_XX & Chimay8
    Start at: 19:26:34 | 09/10/2009
    Website : http://pagesperso-orange.fr/NosTools/index.html

    Intel(R) Pentium(R) 4 CPU 3.00GHz
    Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
    Internet Explorer 6.0.2900.5512
    Windows Firewall Status : Enabled
    AV : avast! antivirus 4.8.1351 [VPS 091008-0] 4.8.1351 [ Enabled | Updated ]

    A:\ -> Lecteur de disquettes 3 ½ pouces
    C:\ -> Disque fixe local # 78,13 Go (16,79 Go free) # NTFS
    D:\ -> Disque fixe local
    E:\ -> Disque CD-ROM
    F:\ -> Disque amovible # 3,81 Go (831,54 Mo free) [ROMEY] # FAT32

    ############################## | Processus actifs |

    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
    C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
    C:\Program Files\SPAMfighter\sfus.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\WINDOWS\System32\alg.exe
    C:\WINDOWS\System32\wbem\wmiapsrv.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\VTTimer.exe
    C:\WINDOWS\system32\VTtrayp.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Fichiers communs\LightScribe\LightScribeControlPanel.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
    C:\Program Files\McAfee Security Scan\1.0.150\SSScheduler.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Windows Live\Contacts\wlcomm.exe
    c:\windows\system32\ping.exe
    C:\WINDOWS\system32\wbem\wmiprvse.exe

    ################## | Fichiers # Dossiers infectieux |

    Supprimé ! C:\WINDOWS\admintxt.txt
    Supprimé ! C:\WINDOWS\system32\svchost64.exe

    ################## | Registre # Clés Run infectieuses |

    Supprimé ! [HKLM\Software\Microsoft\Windows\CurrentVersion\Run] "FrameWorkService"
    Supprimé ! [HKLM\Software\Microsoft\Windows\CurrentVersion\Run] "svchost64.exe"
    Supprimé ! [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "amva"
    Supprimé ! [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "FrameWorkService"
    Supprimé ! [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System] "DisableRegistryTools"
    Supprimé ! [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System] "DisableTaskMgr"
    Supprimé ! [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoFind"
    Supprimé ! [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoFolderOptions"
    Supprimé ! [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoRun"

    ################## | Registre # Mountpoints2 |

    Supprimé ! HKCU\...\Explorer\MountPoints2\{12f6553a-bde2-11dd-b0f5-00138f26818f}\Shell\AutoRun\Command
    Supprimé ! HKCU\...\Explorer\MountPoints2\{14002703-8bcd-11dd-8a4f-00138f26818f}\Shell\AutoRun\Command
    Supprimé ! HKCU\...\Explorer\MountPoints2\{17506f49-9157-11dd-8a59-00138f26818f}\Shell\AutoRun\Command
    Supprimé ! HKCU\...\Explorer\MountPoints2\{253811df-4e95-11de-bb5e-00138f26818f}\Shell\AutoRun\Command
    Supprimé ! HKCU\...\Explorer\MountPoints2\{30c0b350-22f5-11dd-8997-00138f26818f}\Shell\Auto\Command
    Supprimé ! HKCU\...\Explorer\MountPoints2\{3357d3e9-4f7d-11de-bb65-00138f26818f}\Shell\AutoRun\Command
    Supprimé ! HKCU\...\Explorer\MountPoints2\{35fdc139-d9ad-11dd-b13e-00138f26818f}\Shell\AutoRun\Command
    Supprimé ! HKCU\...\Explorer\MountPoints2\{37dad583-972a-11dc-882c-00138f26818f}\Shell\AutoRun\Command
    Supprimé ! HKCU\...\Explorer\MountPoints2\{3a86813c-469c-11dd-89f9-00138f26818f}\Shell\AutoRun\Command
    Supprimé ! HKCU\...\Explorer\MountPoints2\{4793ca9e-d916-11db-8606-00138f26818f}\Shell\AutoRun\Command
    Supprimé ! HKCU\...\Explorer\MountPoints2\{52d54f4b-f9de-11dd-89dc-00138f26818f}\Shell\AutoRun\Command
    Supprimé ! HKCU\...\Explorer\MountPoints2\{546402f1-9aa7-11de-abdb-00138f26818f}\Shell\AutoRun\Command
    Supprimé ! HKCU\...\Explorer\MountPoints2\{5be7583c-8d1e-11dd-8a53-00138f26818f}\Shell\AutoRun\Command
    Supprimé ! HKCU\...\Explorer\MountPoints2\{5d152dec-1097-11de-bad1-00138f26818f}\Shell\AutoRun\Command
    Supprimé ! HKCU\...\Explorer\MountPoints2\{7d446dd5-da2f-11dd-b141-00138f26818f}\Shell\AutoRun\Command
    Supprimé ! HKCU\...\Explorer\MountPoints2\{7f240f80-7033-11de-8c13-00138f26818f}\Shell\AutoRun\Command
    Supprimé ! HKCU\...\Explorer\MountPoints2\{7f61e04f-50f0-11de-bb68-00138f26818f}\Shell\AutoRun\Command
    Supprimé ! HKCU\...\Explorer\MountPoints2\{7f61e050-50f0-11de-bb68-00138f26818f}\Shell\AutoRun\Command
    Supprimé ! HKCU\...\Explorer\MountPoints2\{836e5f73-c5a7-11dc-88a0-00138f26818f}\Shell\AutoRun\Command
    Supprimé ! HKCU\...\Explorer\MountPoints2\{a484f9b4-d023-11dd-b124-00138f26818f}\Shell\AutoRun\Command
    Supprimé ! HKCU\...\Explorer\MountPoints2\{b2de486e-cf16-11dd-b120-00138f26818f}\Shell\AutoRun\Command
    Supprimé ! HKCU\...\Explorer\MountPoints2\{be27ed54-2e66-11dd-89ae-00138f26818f}\Shell\AutoRun\Command
    Supprimé ! HKCU\...\Explorer\MountPoints2\{c2101021-48cc-11dd-8a01-00138f26818f}\Shell\AutoRun\Command
    Supprimé ! HKCU\...\Explorer\MountPoints2\{c3f5cb68-1d07-11dd-8987-00138f26818f}\Shell\AutoRun\Command
    Supprimé ! HKCU\...\Explorer\MountPoints2\{c42182df-073c-11de-89ff-00138f26818f}\Shell\AutoRun\Command
    Supprimé ! HKCU\...\Explorer\MountPoints2\{c616b952-78b6-11dc-87da-00138f26818f}\Shell\AutoRun\Command
    Supprimé ! HKCU\...\Explorer\MountPoints2\{c7fe4eff-dca4-11dd-b147-00138f26818f}\Shell\AutoRun\Command
    Supprimé ! HKCU\...\Explorer\MountPoints2\{ccd05b85-9ceb-11dd-8a73-00138f26818f}\Shell\AutoRun\Command
    Supprimé ! HKCU\...\Explorer\MountPoints2\{e8d6dca8-ad9b-11de-ac14-00138f26818f}\Shell\Auto\Command
    Supprimé ! HKCU\...\Explorer\MountPoints2\{f0d87865-905b-11dd-8a58-00138f26818f}\Shell\AutoRun\Command
    Supprimé ! HKCU\...\Explorer\MountPoints2\{fe270b82-cea6-11dd-b11f-00138f26818f}\Shell\AutoRun\Command
    Supprimé ! HKCU\...\Explorer\MountPoints2\{fe270b83-cea6-11dd-b11f-00138f26818f}\Shell\AutoRun\Command

    ################## | Listing des fichiers présent |

    [09/04/2009 18:18|--a------|760384] C:\02 Piste 2.wma.MP4
    [03/09/2009 18:58|--a------|2083840] C:\AppleSoftwareUpdate.msi
    [21/03/2007 10:30|--a------|0] C:\AUTOEXEC.BAT
    [02/01/2008 15:26|-rahs----|216] C:\boot.ini
    [24/04/2003 16:00|-rahs----|4952] C:\Bootfont.bin
    [20/07/2009 11:37|--a------|74] C:\CMLoader.log
    [21/03/2007 10:30|--a------|0] C:\CONFIG.SYS
    [01/06/2009 09:44|--a------|280] C:\dirtreelog.txt
    [14/07/2009 10:14|--a------|7782] C:\dump.txt
    [01/06/2009 09:44|--a------|2220] C:\fmodlog.txt
    [30/03/2007 08:43|--a------|1260] C:\INSTALL.LOG
    [21/03/2007 10:30|-rahs----|0] C:\IO.SYS
    [31/03/2007 08:42|--a------|13632] C:\mediamp3.dat
    [21/03/2007 10:30|-rahs----|0] C:\MSDOS.SYS
    [21/03/2007 11:22|-rahs----|47564] C:\NTDETECT.COM
    [21/08/2009 18:08|-rahs----|252240] C:\ntldr
    [?|?|?] C:\pagefile.sys
    [10/01/2001 11:23|--a------|162304] C:\UNWISE.EXE
    [09/10/2009 19:29|--a------|8089] C:\UsbFix.txt
    [25/06/2008 11:25|--a------|1865] C:\VirtualDJ Local Database v5.xml

    ################## | Vaccination |

    # C:\autorun.inf -> Folder created by UsbFix.
    # F:\autorun.inf -> Folder created by UsbFix.

    ################## | ! Fin du rapport # UsbFix V6.039 ! |
    0
  3. Trying2 Messages postés 7096 Date d'inscription   Statut Contributeur sécurité Dernière intervention   236
     
    1/
    Es tu sûr que tu n'avais pas d'autres supports USB que cette clé de 4 Go?

    2/
    Fais analyser ce fichier (celui en gras) sur virus total:

    C:\WINDOWS\system32\tempBatFile.bat

    Tuto.
    Fais moi un copier/coller du lien menant vers le rapport dans ta prochaine réponse.

    Si besoin est:
    Affiche les fichiers et les dossiers cachés de cette manière.
    le rapport dans ta prochaine réponse.

    3/
    Télécharge Malwarebytes' Anti-Malware (MBAM)

    * Double clique sur le fichier téléchargé pour lancer le processus d'installation.
    * Dans l'onglet "Mise à jour", clique sur le bouton "Recherche de mise à jour": si le pare-feu demande l'autorisation à MBAM de se connecter, accepte.
    * Une fois la mise à jour terminée, rends-toi dans l'onglet "Recherche".
    * Sélectionne "Exécuter un examen rapide"
    * Clique sur "Rechercher"
    * L'analyse démarre, le scan est relativement long, c'est normal.
    * A la fin de l'analyse, un message s'affiche :

    "L'examen s'est terminé normalement. "

    Clique sur "Afficher les résultats" pour afficher tous les objets trouvés.

    Clique sur "Ok" pour poursuivre. Si MBAM n'a rien trouvé, il te le dira aussi.

    * Ferme tes navigateurs. (Internet Explorer/ Firefox...)
    * Si des malwares ont été détectés, clique sur Afficher les résultats.
    Sélectionne tout (ou laisse coché) et clique sur Supprimer la sélection, MBAM va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.
    * MBAM va ouvrir le Bloc-notes et y copier le rapport d'analyse. Copie-colle ce rapport et poste-le dans ta prochaine réponse.

    4/ Va falloir songer à arrêter les bêtises sur Lime Wire :)

    @+
    0
  4. RoMey974 Messages postés 38 Statut Membre
     
    1/ Celui Là C La Mienne Mais Les Autres Non ! Ils sont a mes potes
    3/ En fait je n'ai pas Lime Wire
    0
    1. Trying2 Messages postés 7096 Date d'inscription   Statut Contributeur sécurité Dernière intervention   236
       
      Tu n'as ni LimeWire ni Ares et pourtant leurs dossiers sont présents sur ton PC :-)

      Je ne te fais pas la morale, juste de la prévention.

      Ils sont a mes potes
      Tes potes ont des supports USB infectés, et leur PC aussi doivent l'être.
      https://forum.malekal.com/viewtopic.php?t=3350&start=
      0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. RoMey974 Messages postés 38 Statut Membre
     
    2/ Je sais pas c'est quel fichier
    0
    1. Trying2 Messages postés 7096 Date d'inscription   Statut Contributeur sécurité Dernière intervention   236
       
      Affiche les fichiers et les dossiers cachés de cette manière.

      Clique ici.


      Ton fichier à analyser sur Virus total est celui ci: "tempBatFile.bat"
      Il se trouve sur ton disque "C:/" dans le dossier "system32" qui lui même se trouve dans le dossier "Windows", ton fichier est donc situé ici ainsi: C:\WINDOWS\system32\tempBatFile.bat
      0
  7. RoMey974 Messages postés 38 Statut Membre
     
    Mais dans " system32 " il y a bcp d'autres fichier aussi
    0
    1. Trying2 Messages postés 7096 Date d'inscription   Statut Contributeur sécurité Dernière intervention   236
       
      Oui, mais tu n'en a qu'un qui s'appelle: "tempBatFile.bat"

      Trie les par ordre alphabétique (par nom), tu le trouveras rapidement.
      0
  8. RoMey974 Messages postés 38 Statut Membre
     
    J'ai cherché mais il n'y a pas :(
    0
  9. RoMey974 Messages postés 38 Statut Membre
     
    Mici Pr Ta PréVention ! ^ ^
    0
    1. Trying2 Messages postés 7096 Date d'inscription   Statut Contributeur sécurité Dernière intervention   236
       
      Pourtant, c'est le dernier fichier créé avant que tu me passes ton rapport Rsit:
      2009-10-07 13:37:28 ----A---- C:\WINDOWS\system32\tempBatFile.bat

      Mais ce n'est pas grave: Passe à MBAM.

      @+
      0
  10. RoMey974 Messages postés 38 Statut Membre
     
    OK (^_^)
    0
    1. Trying2 Messages postés 7096 Date d'inscription   Statut Contributeur sécurité Dernière intervention   236
       
      MBAM , c'est l'étape" 3/" de ce message : J'attends le rapport.
      @+
      0
  11. RoMey974 Messages postés 38 Statut Membre
     
    Malwarebytes' Anti-Malware 1.41
    Version de la base de données: 2935
    Windows 5.1.2600 Service Pack 3

    10/10/2009 13:04:43
    mbam-log-2009-10-10 (13-04-32).txt

    Type de recherche: Examen rapide
    Eléments examinés: 113481
    Temps écoulé: 1 hour(s), 23 minute(s), 12 second(s)

    Processus mémoire infecté(s): 0
    Module(s) mémoire infecté(s): 0
    Clé(s) du Registre infectée(s): 0
    Valeur(s) du Registre infectée(s): 2
    Elément(s) de données du Registre infecté(s): 0
    Dossier(s) infecté(s): 0
    Fichier(s) infecté(s): 0

    Processus mémoire infecté(s):
    (Aucun élément nuisible détecté)

    Module(s) mémoire infecté(s):
    (Aucun élément nuisible détecté)

    Clé(s) du Registre infectée(s):
    (Aucun élément nuisible détecté)

    Valeur(s) du Registre infectée(s):
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\FrameWorkService (Trojan.Delf) -> No action taken.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\svchost64.exe (Backdoor.Bot) -> No action taken.

    Elément(s) de données du Registre infecté(s):
    (Aucun élément nuisible détecté)

    Dossier(s) infecté(s):
    (Aucun élément nuisible détecté)

    Fichier(s) infecté(s):
    (Aucun élément nuisible détecté)
    0
  12. crapoulou Messages postés 28002 Date d'inscription   Statut Modérateur, Contributeur sécurité Dernière intervention   8 046
     
    Salut,
    Ton souci est-il toujours d'actualité ?
    0
    1. RoMey974 Messages postés 38 Statut Membre
       
      Salut, bein Oui ! =(
      0
  13. crapoulou Messages postés 28002 Date d'inscription   Statut Modérateur, Contributeur sécurité Dernière intervention   8 046
     
    lol il n'est jamais trop tard...
    Poste un nouveau rapport RSIT et trying ou moi viendront voir ça ...
    0
  14. RoMey974 Messages postés 38 Statut Membre
     
    Logfile of random's system information tool 1.06 (written by random/random)
    Run by Romey at 2009-12-29 16:26:38
    Microsoft Windows XP Édition familiale Service Pack 3
    System drive C: has 26 GB (32%) free of 80 GB
    Total RAM: 447 MB (14% free)

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 16:27:38, on 29/12/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\VTTimer.exe
    C:\WINDOWS\system32\VTtrayp.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
    C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
    C:\Program Files\Fichiers communs\LightScribe\LightScribeControlPanel.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
    C:\Program Files\McAfee Security Scan\1.0.150\SSScheduler.exe
    C:\Program Files\SPAMfighter\sfus.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
    C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
    C:\WINDOWS\System32\wbem\wmiapsrv.exe
    C:\Program Files\Windows Live\Contacts\wlcomm.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Documents and Settings\Romey.PC-SSIYANKAI\Bureau\RSIT.exe
    C:\Program Files\trend micro\Romey.exe
    C:\WINDOWS\system32\wuauclt.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ask.com?o=15015&l=dis
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: (no name) - {346de098-61f9-4b42-89da-6dfba7091bb6} - (no file)
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
    O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
    O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O3 - Toolbar: (no name) - {346de098-61f9-4b42-89da-6dfba7091bb6} - (no file)
    O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
    O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
    O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
    O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
    O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [mmtask] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe"
    O4 - HKLM\..\Run: [svchost64.exe] c:\windows\system32\svchost64.exe
    O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
    O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Fichiers communs\LightScribe\LightScribeControlPanel.exe -hidden
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKCU\..\RunOnce: [Shockwave Updater] C:\WINDOWS\system32\Adobe\Shockwave 11\SwHelper_1151601.exe -Update -1151601 -"Mozilla/5.0_(Windows;_U;_Windows_NT_5.1;_fr;_rv:1.9.1.6)_Gecko/20091201_Firefox/3.5.6_GTB6_(.NET_CLR_3.5.30729)" -"http://games.adultswim.com/iron-and-flame-adventure-online-game.html"
    O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
    O4 - Global Startup: McAfee Security Scan.lnk = ?
    O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
    O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
    O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
    O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/...
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
    O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
    O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
    O23 - Service: SPAMfighter Update Service - SPAMfighter ApS - C:\Program Files\SPAMfighter\sfus.exe
    0
  15. crapoulou Messages postés 28002 Date d'inscription   Statut Modérateur, Contributeur sécurité Dernière intervention   8 046
     
    Télécharge ToolBar S&D ( de Eric_71 )
    = = = = >>> En cliquant ici <<< = = = =

    /!\ Déconnectes toi et fermes toute tes applications en cours le temps de la manipulation /!\
    * Double-cliques sur l’exécutable pour lancer l’outil
    * Une fois fait, tape F pour sélectionner le Français
    * Choisis l’option 1 (Recherche) et tape sur Entrée.
    * Une fois le scan finit, un rapport va apparaître au format .txt.
    * Copie-colle l’intégralité de son contenu dans ta prochaine réponse ...
    Note :
    Le rapport est sauvegardé ici : C:\TB.txt
    Tuto si besoin ICI
    0
Précédent
  • 1
  • 2