Aide lecture rapport hijackthis - Page 2

  1. j'ai trouvé une autre page pour SF
    0
    1. ========================= SF 1.0.0.3 - C_XX | 22:27:10,52

      Valeur(s) recherchée(s):

      msidvtld
      umpnpmgt

      ========================= Fichier(s)/Dossier(s):

      Aucun fichier/Dossier trouvé.

      ========================= Registre:

      [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e67dd5cb-c767-11dd-a47f-0023543720a0}\shell\open\Command]
      ""="rundll32.exe .\\msidvtld.dll,InstallM"

      [HKEY_USERS\S-1-5-21-1664007841-973385807-4058214226-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e67dd5cb-c767-11dd-a47f-0023543720a0}\shell\open\Command]
      ""="rundll32.exe .\\msidvtld.dll,InstallM"

      [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{fe45f4b3-1f8e-11de-8a7b-0023543720a0}\shell\open\Command]
      ""="rundll32.exe .\\umpnpmgt.dll,InstallM"

      [HKEY_USERS\S-1-5-21-1664007841-973385807-4058214226-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{fe45f4b3-1f8e-11de-8a7b-0023543720a0}\shell\open\Command]
      ""="rundll32.exe .\\umpnpmgt.dll,InstallM"

      ========================= E.O.F | 22:30:24,36
      0
      1. Modérateur
        Ok parfait.
        Comment as-tu trouvé cet outil (je te demande car il est nouveau :D)

        *****

        Par précaution :
        Télécharge et installe UsbFix de C_XX & Chiquitine29 :
        = = = = >>> En cliquant ici <<< = = = =

        Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptibles d’avoir été infectés sans les ouvrir !

        * Clique droit sur le raccourci UsbFix présent sur ton bureau et sélectionne "Exécuter en tant qu’administrateur".
        * Choisis ensuite l’option 1 (Recherche)
        * Laisse travailler l’outil.
        * Ensuite poste le rapport UsbFix.txt qui apparaîtra.

        Notes :
        - Le rapport UsbFix.txt est sauvegardé a la racine du disque. (C:\UsbFix.txt)
        (CTRL+A Pour tout sélectionner, CTRL+C pour copier et CTRL+V pour coller sur le forum).
        - "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool. Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus. Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.
        0
        1. J'ai seulement repris le nom et l'auteur de cet outil et j'ai fais une recherche sur le forum, et j'ai pu retrouvé l'outil avec un lien différent !

          Voila j'ai branché une clée USB et un ipod nano, les seuls sources de données externes que j'utilise régulièrement.

          ############################## | UsbFix V6.040 |

          User : Mathilde (Administrateurs) # MATHILDE
          Update on 10/10/2009 by Chiquitine29, C_XX & Chimay8
          Start at: 23:20:28 | 11/10/2009
          Website : http://pagesperso-orange.fr/NosTools/index.html

          Intel(R) Pentium(R) Dual CPU T3200 @ 2.00GHz
          Microsoft® Windows Vista™ Professionnel (6.0.6001 32-bit) # Service Pack 1
          Internet Explorer 8.0.6001.18813
          Windows Firewall Status : Enabled

          C:\ -> Disque fixe local # 74,52 Go (16,24 Go free) [VistaOS] # NTFS
          D:\ -> Disque fixe local # 64,76 Go (61,43 Go free) [DATA] # NTFS
          E:\ -> Disque CD-ROM
          F:\ -> Disque amovible # 3,72 Go (1,24 Go free) # FAT32
          H:\ -> Disque CD-ROM
          I:\ -> Disque amovible # 7,42 Go (6,99 Go free) [IPOD (MATHI] # FAT32

          ############################## | Processus actifs |

          C:\Windows\System32\smss.exe
          C:\Windows\system32\csrss.exe
          C:\Windows\system32\wininit.exe
          C:\Windows\system32\csrss.exe
          C:\Windows\system32\services.exe
          C:\Windows\system32\winlogon.exe
          C:\Windows\system32\lsass.exe
          C:\Windows\system32\lsm.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\System32\svchost.exe
          C:\Windows\System32\svchost.exe
          C:\Windows\System32\svchost.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\system32\SLsvc.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\system32\svchost.exe
          C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe
          C:\Program Files\ASUS\ATK Hotkey\ASLDRSrv.exe
          C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          C:\Program Files\ATKGFNEX\GFNEXSrv.exe
          C:\Program Files\Alwil Software\Avast4\ashServ.exe
          C:\Windows\system32\WLANExt.exe
          C:\Windows\system32\taskeng.exe
          C:\Windows\System32\spoolsv.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\system32\agrsmsvc.exe
          C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
          C:\Program Files\Bonjour\mDNSResponder.exe
          C:\Program Files\Common Files\LightScribe\LSSrvc.exe
          C:\Windows\system32\svchost.exe
          C:\Program Files\CyberLink\Shared Files\RichVideo.exe
          C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\System32\svchost.exe
          C:\Windows\system32\SearchIndexer.exe
          C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
          C:\Windows\system32\Dwm.exe
          C:\Windows\system32\taskeng.exe
          C:\Program Files\ASUS\ASUS Live Update\ALU.exe
          C:\Program Files\ASUS\ATK Hotkey\MsgTranAgt.exe
          C:\Program Files\ASUS\ATK Hotkey\HControl.exe
          C:\Program Files\P4G\BatteryLife.exe
          C:\Program Files\Wireless Console 2\wcourier.exe
          C:\Program Files\ASUS\Splendid\ACMON.exe
          C:\Windows\system32\wbem\wmiprvse.exe
          C:\Windows\System32\ACEngSvr.exe
          C:\Program Files\ASUS\ATK Hotkey\ATKOSD.exe
          C:\Program Files\ASUS\ATK Hotkey\KBFiltr.exe
          C:\Program Files\ASUS\ATK Hotkey\WDC.exe
          C:\Program Files\ASUSTek\ASUSDVD\PDVDServ.exe
          C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe
          C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe
          C:\Program Files\ASUS\ASUS Data Security Manager\ADSMTray.exe
          C:\Program Files\ATKOSD2\ATKOSD2.exe
          C:\Windows\System32\igfxtray.exe
          C:\Windows\System32\igfxpers.exe
          C:\Windows\system32\igfxsrvc.exe
          C:\Windows\RtHDVCpl.exe
          C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
          C:\Program Files\Alwil Software\Avast4\ashDisp.exe
          C:\Program Files\Java\jre6\bin\jusched.exe
          C:\Program Files\Windows Defender\MSASCui.exe
          C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
          C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe
          C:\Program Files\DAEMON Tools Lite\daemon.exe
          C:\Users\Mathilde\AppData\Roaming\Microsoft\Live Search\Notification-LiveSearch.exe
          C:\Program Files\Windows Media Player\wmpnscfg.exe
          C:\Program Files\Windows Media Player\wmpnetwk.exe
          C:\Users\Mathilde\AppData\Roaming\Microsoft\Live Search\Mise-a-jour-LiveSearch.exe
          C:\Windows\system32\wbem\unsecapp.exe
          C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
          C:\Windows\system32\wuauclt.exe
          C:\Windows\System32\rundll32.exe
          C:\Windows\explorer.exe
          C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
          C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
          C:\Program Files\Mozilla Firefox\firefox.exe
          C:\Windows\system32\WUDFHost.exe
          C:\Program Files\Microsoft Office\Office12\WINWORD.EXE
          C:\Program Files\Microsoft\Office Live\OfficeLiveSignIn.exe
          C:\Windows\system32\conime.exe
          C:\Windows\system32\SearchProtocolHost.exe
          C:\Program Files\Windows Live\Messenger\msnmsgr.exe
          C:\Program Files\Windows Live\Contacts\wlcomm.exe
          C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe
          C:\Windows\system32\taskeng.exe
          C:\Windows\system32\SearchFilterHost.exe
          C:\Windows\system32\msfeedssync.exe
          \\?\C:\Windows\system32\wbem\WMIADAP.EXE
          C:\Windows\system32\wbem\wmiprvse.exe

          ################## | Fichiers # Dossiers infectieux |

          F:\~WRD0000.tmp
          F:\~WRD0001.tmp
          F:\~WRD0002.tmp
          F:\~WRD0003.tmp
          F:\~WRD3259.tmp
          F:\~WRL0001.tmp

          ################## | Registre # Clés Run infectieuses |

          [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System] "DisableRegistryTools"
          [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoDrives"

          ################## | Registre # Mountpoints2 |

          HKCU\..\..\Explorer\MountPoints2\{dfd186b3-72f2-11de-b2b8-0023543720a0}
          shell\AutoRun\command =H:\Autorun.exe

          HKCU\..\..\Explorer\MountPoints2\{e67dd5cb-c767-11dd-a47f-0023543720a0}
          shell\AutoRun\command =G:\
          shell\open\Command =rundll32.exe .\\msidvtld.dll,InstallM

          HKCU\..\..\Explorer\MountPoints2\{e8ac9eb5-dd94-11dd-bbfc-0023543720a0}
          shell\AutoRun\command =G:\LaunchU3.exe -a

          HKCU\..\..\Explorer\MountPoints2\{fe45f4b3-1f8e-11de-8a7b-0023543720a0}
          shell\AutoRun\command =F:\
          shell\open\Command =rundll32.exe .\\umpnpmgt.dll,InstallM

          ################## | ! Fin du rapport # UsbFix V6.040 ! |
          0
          1. Modérateur
            Si tu as des documents Word d'ouverts, sauvegarde les et Ferme Word !

            Nettoyage avec UsbFix :

            Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) suceptibles d’avoir été infectés sans les ouvrir !

            * Relance UsbFix par un clic droit sur le raccourci UsbFix présent sur ton bureau et en sélectionnant "Exécuter en tant qu’administrateur".
            * Choisis l’option 2 (Suppression)
            * Ton bureau disparaîtra et le PC redémarrera.
            * Au redémarrage, UsbFix scannera ton PC. Laisse travailler l’outil.
            * Ensuite poste l’intégralité du rapport UsbFix.txt qui apparaîtra avec le bureau.

            Note :
            Le rapport UsbFix.txt est sauvegardé a la racine du disque. (C:\UsbFix.txt)

            ******

            Poste un nouveau rapport RSIT (on va bientôt terminer, ne t'inquiète pas ;-).
            0
            1. bonsoir,

              j'ai utilisé usbfix mais je l'ai interropmpu avant qu'il me dise que c'était terminé car j'avais beau appuyé sur n'importe quelle touche cela ne marchait pas, j'ai non plus réussi a envoyé le dossier zip sur leur site. Donc voila ce que j'ai trouvé j'espère que c'est ça !

              ps : j'ai encore des alertes me signalant un cheval de troie parfois quand je vais sur google.

              ############################## | UsbFix V6.040 |

              User : Mathilde (Administrateurs) # MATHILDE
              Update on 10/10/2009 by Chiquitine29, C_XX & Chimay8
              Start at: 23:37:38 | 12/10/2009
              Website : http://pagesperso-orange.fr/NosTools/index.html

              Intel(R) Pentium(R) Dual CPU T3200 @ 2.00GHz
              Microsoft® Windows Vista™ Professionnel (6.0.6001 32-bit) # Service Pack 1
              Internet Explorer 8.0.6001.18813
              Windows Firewall Status : Enabled

              C:\ -> Disque fixe local # 74,52 Go (19,24 Go free) [VistaOS] # NTFS
              D:\ -> Disque fixe local # 64,76 Go (61,43 Go free) [DATA] # NTFS
              E:\ -> Disque CD-ROM
              F:\ -> Disque amovible # 3,72 Go (2,27 Go free) # FAT32
              H:\ -> Disque CD-ROM
              I:\ -> Disque amovible # 7,42 Go (6,99 Go free) [IPOD (MATHI] # FAT32

              ############################## | Processus actifs |

              C:\Windows\System32\smss.exe
              C:\Windows\system32\csrss.exe
              C:\Windows\system32\wininit.exe
              C:\Windows\system32\csrss.exe
              C:\Windows\system32\services.exe
              C:\Windows\system32\winlogon.exe
              C:\Windows\system32\lsass.exe
              C:\Windows\system32\lsm.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\System32\svchost.exe
              C:\Windows\system32\LogonUI.exe
              C:\Windows\System32\svchost.exe
              C:\Windows\System32\svchost.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\system32\SLsvc.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\system32\svchost.exe
              C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe
              C:\Program Files\ASUS\ATK Hotkey\ASLDRSrv.exe
              C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
              C:\Program Files\ATKGFNEX\GFNEXSrv.exe
              C:\Program Files\Alwil Software\Avast4\ashServ.exe
              C:\Windows\system32\WLANExt.exe
              C:\Windows\System32\spoolsv.exe
              C:\Windows\system32\taskeng.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\system32\agrsmsvc.exe
              C:\Windows\System32\lpksetup.exe
              C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
              C:\Program Files\Bonjour\mDNSResponder.exe
              C:\Program Files\Common Files\LightScribe\LSSrvc.exe
              C:\Windows\system32\svchost.exe
              C:\Program Files\CyberLink\Shared Files\RichVideo.exe
              C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\System32\svchost.exe
              C:\Windows\system32\SearchIndexer.exe
              C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
              C:\Windows\system32\WUDFHost.exe
              C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
              C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
              C:\Windows\servicing\TrustedInstaller.exe
              C:\Windows\system32\wbem\wmiprvse.exe
              C:\Windows\system32\wbem\wmiprvse.exe
              C:\Windows\system32\userinit.exe
              C:\Windows\system32\Dwm.exe
              C:\Windows\system32\taskeng.exe
              C:\Program Files\ASUS\ASUS Live Update\ALU.exe
              C:\Windows\Explorer.EXE
              C:\Windows\system32\runonce.exe
              C:\Program Files\ASUS\ATK Hotkey\MsgTranAgt.exe
              C:\Program Files\ASUS\ATK Hotkey\HControl.exe
              C:\Program Files\P4G\BatteryLife.exe
              C:\Program Files\Wireless Console 2\wcourier.exe
              C:\Program Files\ASUS\Splendid\ACMON.exe
              C:\Windows\system32\conime.exe
              C:\Windows\System32\ACEngSvr.exe
              C:\Program Files\ASUS\ATK Hotkey\ATKOSD.exe
              C:\Program Files\ASUS\ATK Hotkey\KBFiltr.exe
              C:\Program Files\ASUS\ATK Hotkey\WDC.exe

              ################## | Fichiers # Dossiers infectieux |

              Supprimé ! F:\~WRD0000.tmp
              Supprimé ! F:\~WRD0001.tmp
              Supprimé ! F:\~WRD0002.tmp
              Supprimé ! F:\~WRD0003.tmp
              Supprimé ! F:\~WRD3259.tmp
              Supprimé ! F:\~WRL0001.tmp

              ################## | Registre # Clés Run infectieuses |

              Supprimé ! [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System] "DisableRegistryTools"
              Supprimé ! [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoDrives"

              ################## | Registre # Mountpoints2 |

              Supprimé ! HKCU\...\Explorer\MountPoints2\{dfd186b3-72f2-11de-b2b8-0023543720a0}\Shell\AutoRun\Command
              Supprimé ! HKCU\...\Explorer\MountPoints2\{e67dd5cb-c767-11dd-a47f-0023543720a0}\Shell\AutoRun\Command
              Supprimé ! HKCU\...\Explorer\MountPoints2\{e8ac9eb5-dd94-11dd-bbfc-0023543720a0}\Shell\AutoRun\Command
              Supprimé ! HKCU\...\Explorer\MountPoints2\{fe45f4b3-1f8e-11de-8a7b-0023543720a0}\Shell\AutoRun\Command

              ################## | Listing des fichiers présent |

              [11/10/2009 18:21|--a------|5306] C:\Ad-Report-CLEAN[1].log
              [10/10/2009 17:52|--a------|2723] C:\Ad-Report-SCAN[1].log
              [18/09/2006 23:43|--a------|24] C:\autoexec.bat
              [21/01/2008 04:25|-rahs----|333203] C:\bootmgr
              [16/04/2008 15:17|-ra-s----|8192] C:\BOOTSECT.BAK
              [10/10/2009 14:33|--a------|1300] C:\cleannavi.txt
              [01/03/2009 13:22|--a------|17366] C:\ComboFix.txt
              [18/09/2006 23:43|--a------|10] C:\config.sys
              [05/10/2008 07:25|--a------|19994] C:\devlist.txt
              [26/08/2008 01:30|--a------|24] C:\Driver.10
              [29/04/2008 09:12|--a------|30] C:\DVD.LOG
              [04/04/2007 21:01|--a------|19] C:\EA21.txt
              [28/02/2009 21:19|--a------|5007] C:\FindyKill.txt
              [05/10/2008 07:22|--a------|9] C:\Finish.log
              [08/08/2008 09:22|--a------|30] C:\NERO.LOG
              [04/07/2008 06:35|--a------|21] C:\NIS2008.TXT
              [16/03/2007 01:18|--a------|25] C:\OFFICE2007_A.TXT
              [?|?|?] C:\pagefile.sys
              [04/10/2008 18:20|--a------|105] C:\Pass.txt
              [18/08/2008 12:58|--a------|2561] C:\Patch.LOG
              [29/04/2008 16:30|--a------|20] C:\READER_A.TXT
              [09/08/2008 01:07|--a------|24] C:\RECOVERY.DAT
              [05/10/2008 06:49|--a------|646] C:\RHDSetup.log
              [05/10/2008 07:00|--a------|86] C:\setup.log
              [11/10/2009 22:30|--a------|1129] C:\SFlog.txt
              [16/05/2006 02:22|--a------|5] C:\store.log
              [05/10/2008 05:53|--a------|166] C:\SumHidd.txt
              [05/10/2008 05:52|--a------|98] C:\SumOS.txt
              [10/10/2009 01:34|--a------|1716] C:\TB.txt
              [12/10/2009 23:41|--a------|5696] C:\UsbFix.txt
              [01/08/2008 00:40|--a------|21] C:\V552.txt
              [27/02/2009 19:50|--a------|135] C:\VundoFix.txt
              [09/09/2008 05:43|--a------|1048576] C:\X51L.BIN
              [12/11/2006 14:42|--a------|710813696] D:\Antartica, prisonniers du froid Fr Dvdrip Super qualite.avi
              [17/08/2008 00:34|--a------|727017472] D:\Hancock.avi
              [02/01/2009 23:35|--a------|733693952] D:\Mesrine.L'ennemi.Public.NO.1.R5.FRENCH.XViD.K-SUAL.avi
              [23/03/2009 19:38|--a------|729350144] D:\Twilight.FRENCH.DVDRiP.REPACK.1CD.XViD-STS.avi
              [07/05/2009 01:44|--a------|23711] F:\synthese bouchard.docx
              [07/05/2009 01:43|--a------|13972] F:\BOU.docx
              [16/10/2008 01:45|--ahs----|60928] F:\ehthumbs_vista.db
              [?|?|?] F:\ReadyBoost.sfcache
              [07/07/2009 16:19|--a------|35840] F:\fiche_evaluation_cuisine_familale.doc
              [23/06/2009 15:54|--a------|853504] F:\LAROSE mathilde FichedeCorrespondance2.doc
              [19/05/2009 15:57|--ah-----|165] F:\~$Pr‚sentation10.pptx
              [16/07/2009 13:34|--a------|39424] F:\cuisine autonomie 29.06 au 3.07.09.doc
              [15/07/2009 16:05|--a------|1603584] F:\FichedeCorrespondances[1].doc
              [04/12/2008 13:57|--ah-----|165] F:\~$Pr‚sentation2.pptx
              [11/12/2008 11:28|--ah-----|165] F:\~$diapo Mathilde LAROSE.pptx
              [07/03/2009 13:08|--a------|11449] F:\Bonjour.docx
              [18/10/2063 00:27|---------|0] I:\.metadata_never_index

              ################## | Vaccination |

              # C:\autorun.inf -> Folder created by UsbFix.
              # D:\autorun.inf -> Folder created by UsbFix.
              # F:\autorun.inf -> Folder created by UsbFix.
              # I:\autorun.inf -> Folder created by UsbFix.

              ################## | Upload |

              Veuillez envoyer le fichier : C:\Users\Mathilde\Desktop\UsbFix_Upload_Me_MATHILDE.zip : https://www.androidworld.fr/
              Merci pour votre contribution .
              0
          2. Logfile of random's system information tool 1.06 (written by random/random)
            Run by Mathilde at 2009-10-14 19:01:17
            Microsoft® Windows Vista™ Professionnel Service Pack 2
            System drive C: has 26 GB (35%) free of 76 GB
            Total RAM: 3062 MB (48% free)

            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 19:01:39, on 14/10/2009
            Platform: Windows Vista SP2 (WinNT 6.00.1906)
            MSIE: Internet Explorer v8.00 (8.00.6001.18813)
            Boot mode: Normal

            Running processes:
            C:\Windows\system32\Dwm.exe
            C:\Windows\system32\taskeng.exe
            C:\Windows\Explorer.EXE
            C:\Program Files\ASUS\ASUS Live Update\ALU.exe
            C:\Windows\system32\taskeng.exe
            C:\Program Files\ASUSTek\ASUSDVD\PDVDServ.exe
            C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe
            C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe
            C:\Program Files\ASUS\ASUS Data Security Manager\ADSMTray.exe
            C:\Program Files\ATKOSD2\ATKOSD2.exe
            C:\Windows\System32\igfxtray.exe
            C:\Windows\System32\hkcmd.exe
            C:\Windows\System32\igfxpers.exe
            C:\Windows\RtHDVCpl.exe
            C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
            C:\Program Files\Alwil Software\Avast4\ashDisp.exe
            C:\Program Files\Java\jre6\bin\jusched.exe
            C:\Windows\system32\igfxsrvc.exe
            C:\Program Files\Windows Defender\MSASCui.exe
            C:\Program Files\Windows Sidebar\sidebar.exe
            C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
            C:\Program Files\Windows Live\Messenger\msnmsgr.exe
            C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe
            C:\Program Files\DAEMON Tools Lite\daemon.exe
            C:\Program Files\Windows Media Player\wmpnscfg.exe
            C:\Users\Mathilde\AppData\Roaming\Microsoft\Live Search\Notification-LiveSearch.exe
            C:\Windows\system32\wbem\unsecapp.exe
            C:\Users\Mathilde\AppData\Roaming\Microsoft\Live Search\Mise-a-jour-LiveSearch.exe
            C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
            C:\Program Files\Windows Live\Contacts\wlcomm.exe
            C:\Program Files\Mozilla Firefox\firefox.exe
            C:\Windows\system32\wuauclt.exe
            C:\Users\Mathilde\Downloads\RSIT.exe
            C:\Program Files\Trend Micro\HijackThis\Mathilde.exe

            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer
            R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
            R3 - URLSearchHook: (no name) - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - (no file)
            O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
            O2 - BHO: e-Carte Bleue Browser Helper Object - {2E03C0FD-4C48-43A7-9A54-00240C70FF16} - C:\Windows\system32\BhoECart.dll
            O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
            O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
            O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
            O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
            O3 - Toolbar: Veoh Web Player Video Finder - {0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - C:\Program Files\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll
            O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\ASUSTek\ASUSDVD\PDVDServ.exe"
            O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\ASUSTek\ASUSDVD\Language\Language.exe"
            O4 - HKLM\..\Run: [CLMLServer] "C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe"
            O4 - HKLM\..\Run: [P2Go_Menu] "C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
            O4 - HKLM\..\Run: [HControlUser] C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe
            O4 - HKLM\..\Run: [ADSMTray] C:\Program Files\ASUS\ASUS Data Security Manager\ADSMTray.exe
            O4 - HKLM\..\Run: [ATKOSD2] "C:\Program Files\ATKOSD2\ATKOSD2.exe"
            O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
            O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
            O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
            O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
            O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
            O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
            O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
            O4 - HKLM\..\Run: [Fnac] "C:\Program Files\Fnac\Fnac.exe" /check
            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
            O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
            O4 - HKLM\..\Run: [SystrayORAHSS] "C:\Program Files\Orange\Systray\SystrayApp.exe"
            O4 - HKLM\..\Run: [ORAHSSSessionManager] C:\Program Files\Orange\SessionManager\SessionManager.exe
            O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
            O4 - HKLM\..\Run: [Skytel] Skytel.exe
            O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
            O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
            O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
            O4 - HKCU\..\Run: [VeohPlugin] "C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe"
            O4 - HKCU\..\Run: [EPSON Stylus DX7400 Series] C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATICDE.EXE /FU "C:\Windows\TEMP\E_S6E1D.tmp" /EF "HKCU"
            O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
            O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
            O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
            O4 - Startup: Outil de notification Live Search.lnk = C:\Users\Mathilde\AppData\Roaming\Microsoft\Live Search\Notification-LiveSearch.exe
            O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
            O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
            O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
            O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
            O9 - Extra button: (no name) - cmdmapping - (no file) (HKCU)
            O13 - Gopher Prefix:
            O23 - Service: ADSM Service (ADSMService) - ASUSTek Computer Inc. - C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe
            O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
            O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
            O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files\ASUS\ATK Hotkey\ASLDRSrv.exe
            O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
            O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - Unknown owner - C:\Program Files\ATKGFNEX\GFNEXSrv.exe
            O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
            O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
            O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
            O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
            O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
            O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
            O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
            O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
            O23 - Service: spmgr - Unknown owner - C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
            0
            1. Modérateur
              J'aurais aimé comme demandé d'avoir le rapport USBFix...

              ***

              Comment va le PC ?
              0
              1. Modérateur
                Sur quels fichiers as-tu des alertes ?
                As-tu un rapport de fichiers infectés à me montrer (fais une analyse complète avec Avast mis à jour pour le moment).
                Poste moi le rapport.
                0
                Précédent
                • 1
                • 2