Log HijackThis

Résolu
Bonjour,
pourriez vous me dire si le log est bon je pense avoir trop de 04 merci

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 09:44:07, on 19/11/2009
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18828)
Boot mode: Normal

Running processes:
C:\Windows\Explorer.EXE
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Acer\Acer PowerSmart Manager\ePowerTray.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\igfxext.exe
C:\Windows\system32\igfxsrvc.exe
C:\Users\regis\AppData\Local\Temp\RtkBtMnt.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Users\regis\Desktop\securité\HiJackThis.exe
C:\Program Files\Microsoft Office\Office\WINWORD.EXE
C:\Windows\system32\DllHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://actus.sfr.fr
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = https://actus.sfr.fr
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb128\SearchSettings.dll
O1 - Hosts: ::1 localhost
O2 - BHO: Dealio Toolbar - {01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} - C:\Program Files\Dealio Toolbar\DealioToolbarIE.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb128\SearchSettings.dll
O3 - Toolbar: Dealio Toolbar - {01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} - C:\Program Files\Dealio Toolbar\DealioToolbarIE.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
O4 - HKLM\..\Run: [BackupManagerTray] "C:\Program Files\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe" -k
O4 - HKLM\..\Run: [Acer ePower Management] C:\Program Files\Acer\Acer PowerSmart Manager\ePowerTrayLauncher.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [SearchSettings] C:\Program Files\Search Settings\SearchSettings.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O13 - Gopher Prefix:
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe

--
End of file - 5111 bytes
Configuration: Windows Vista Internet Explorer 7.0

21 réponses

  1. Contributeur sécurité
    Bonjour

    Tu as des barres d'outils infectées

    Désactive le contrôle des comptes utilisateurs
    (tu le réactiveras après ta désinfection):

    * Va dans démarrer puis panneau de configuration
    * Double Clique sur l'icône "Comptes d'utilisateurs"
    * Clique ensuite sur désactiver et valide.

    Tuto : https://forum.malekal.com/viewtopic.php?f=59&t=6517

    https://forum.pcastuces.com/navilog_de_il_mafioso_pour_vista-f31s12.htm

    Télécharge Toolbar-S&D (Team IDN) sur ton Bureau.

    https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/ToolBarSD.exe?attachauth=ANoY7cpVobGk5bHnxrhQ4yaoEUDJvOYNnEGyYjgqHZz5GqZLfutR3fMFPlsC3-CGIilfupPAguYATNyua3csodN_frdMK8sSzUpit10Yac-QJCOkMqJKkbdKcP6ySs8trWPgoNVIq4TGGWCe6o0txXQv-ZueJF9vZzw3RXsGwFYIqN2lvF2LPdQzS8mE1d5kWOVOz6EMzQuE5-lClSJM869uq3oc7-t7yg%3D%3D&attredirects=3

    * Lance l'installation du programme en exécutant le fichier téléchargé.
    * Double-clique maintenant sur le raccourci de Toolbar-S&D.
    * Sélectionne la langue souhaitée en tapant la lettre de ton choix puis en validant avec la touche Entrée.
    * Choisis maintenant l'option 1 (Recherche). Patiente jusqu'à la fin de la recherche.
    * Poste le rapport généré. (C:\TB.txt)
    0
    1. merci d avoir repondu mais je peus pas me servir Toolbar-S&D il disparait a chaque fois que je valide le 1
      0
      1. Contributeur sécurité
        Tu as bien désactivé l'UAC ?
        Essaie de le lancer par un clic droit "En tant qu'administrateur".
        0
        1. j ai desactivé mais ca marche toujours pas pourtant je m en suis deja servi
          0
          1. Contributeur sécurité
            On va faire autrement :

            ---> Télécharge OTM (OldTimer) sur ton Bureau :
            http://www.geekstogo.com/forum/files/file/402-otm-oldtimers-move-it/

            ---> Double-clique sur OTM.exe afin de le lancer.

            ---> Copie (Ctrl+C) le texte suivant ci-dessous :

            :processes
            explorer.exe

            :files
            c:\program files\search settings\kb128\searchsettings.dll
            c:\program files\search settings\searchsettings.exe

            :reg
            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks]
            "{E312764E-7706-43F1-8DAB-FCDD2B1E416D}"=-
            [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}]
            [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}]
            [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
            "SearchSettings"=-

            :commands
            [emptytemp]
            [start explorer]

            ---> Colle (Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.

            ---> Clique maintenant sur le bouton MoveIt! puis ferme OTM

            Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
            Accepte en cliquant sur YES.

            ---> Poste le rapport situé dans ce dossier : C:\_OTMoveIt\MovedFiles\
            Le nom du rapport correspond au moment de sa création : date_heure.log
            0
            1. je trouve pas le rapport il se bloque mais il a mis sur le bureau ca

              [.ShellClassInfo]
              LocalizedResourceName=@%SystemRoot%\system32\shell32.dll,-21799
              [LocalizedFileNames]
              Microsoft Office - 60 Day Trial.lnk=@C:\PROGRA~1\MICROS~2\mui\oaa.dll,-103

              et il etait ecrit sur la colone de droite
              error unable to interprete (process)
              error unable to interprete explorer.exe

              file folder c/ progamme search setting 128k..
              file folder c programme file search setting...
              0
              1. ouf j ai reussi otm voila le rapport

                All processes killed
                ========== PROCESSES ==========
                ========== FILES ==========
                File/Folder c:\program files\daemon tools toolbar\dttoolbar.dll not found.
                ========== SERVICES/DRIVERS ==========
                ========== REGISTRY ==========
                Registry key HKEY_CLASSES_ROOT\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17}\ not found.
                Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17}\ not found.
                Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17}\ not found.
                Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17}\ not found.
                Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar not found.
                ========== COMMANDS ==========

                [EMPTYTEMP]

                User: All Users

                User: Default
                ->Temp folder emptied: 0 bytes
                ->Temporary Internet Files folder emptied: 33170 bytes

                User: Default User
                ->Temp folder emptied: 0 bytes
                ->Temporary Internet Files folder emptied: 0 bytes

                User: Public

                User: regis
                ->Temp folder emptied: 2690387 bytes
                ->Temporary Internet Files folder emptied: 2815511 bytes
                ->Java cache emptied: 27197762 bytes
                ->FireFox cache emptied: 36324945 bytes

                %systemdrive% .tmp files removed: 0 bytes
                %systemroot% .tmp files removed: 0 bytes
                %systemroot%\System32 .tmp files removed: 0 bytes
                Windows Temp folder emptied: 0 bytes
                %systemroot%\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 3629166 bytes
                RecycleBin emptied: 0 bytes

                Total Files Cleaned = 69,32 mb

                OTM by OldTimer - Version 3.1.2.0 log created on 11192009_114309

                Files moved on Reboot...

                Registry entries deleted on Reboot...
                0
                1. Contributeur sécurité
                  Imprime ces instructions ou sauvegarde les sur ton Bureau car il faudra fermer toutes les fenêtres et applications lors de l'installation et de l'analyse.

                  Télécharge Malwarebytes' Anti-Malware (MBAM) et enregistre le sur ton bureau à partir de ce lien :

                  https://download.cnet.com/Malwarebytes/3000-8022_4-10804572.html

                  A la fin du téléchargement, ferme toutes les fenêtres et programmes, y compris celui-ci.

                  Double-clique sur l'icône Download_mbam-setup.exe sur ton bureau pour démarrer le programme d'installation.

                  Pendant l'installation, suis les indications (en particulier le choix de la langue et l'autorisation d'accession à Internet). N'apporte aucune modification aux réglages par défaut et, en fin d'installation, vérifie que les options Update Malwarebytes' Anti-Malware et Launch Malwarebytes' Anti-Malware sont cochées.

                  MBAM démarrera automatiquement et enverra un message demandant à mettre à jour le programme avant de lancer une analyse. Comme MBAM se met automatiquement à jour en fin d'installation, clique sur OK pour fermer la boîte de dialogue. La fenêtre principale de MBAM s'affiche :

                  Dans l'onglet analyse, vérifie que "Exécuter un examen rapide" est coché et clique sur le bouton Rechercher pour démarrer l'analyse.

                  MBAM analyse ton ordinateur. L'analyse peut prendre un certain temps. Il suffit de vérifier de temps en temps son avancement.

                  Lorsque le message indiquant la fin de l’analyse s’affiche, clique sur « Afficher le résultat » pour poursuivre..

                  Si des malwares ont été détectés, leur liste s'affiche.
                  Coche tous les éléments détectés par Malwarebytes' Anti-Malware puis clique sur « Supprimer la sélection » afin d'éradiquer les malwares détectés. MBAM va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.

                  MBAM va ouvrir le bloc-notes et y copier le rapport d'analyse. Ferme le bloc-note. (Le rapport peut être retrouvé sous l'onglet Rapports/logs)

                  Ferme MBAM en cliquant sur Quitter.

                  Poste le rapport sur le forum.

                  Tuto si besoin : https://forum.pcastuces.com/malwarebytes_antimalwares___tutoriel-f31s3.htm
                  0
                  1. merci je vais le faire cette apres midi vers 13h merci a toute
                    0
                    1. voila c est fait

                      Malwarebytes' Anti-Malware 1.41
                      Version de la base de données: 3195
                      Windows 6.0.6002 Service Pack 2

                      19/11/2009 12:42:12
                      mbam-log-2009-11-19 (12-42-12).txt

                      Type de recherche: Examen complet (C:\|D:\|E:\|)
                      Eléments examinés: 222516
                      Temps écoulé: 43 minute(s), 40 second(s)

                      Processus mémoire infecté(s): 0
                      Module(s) mémoire infecté(s): 0
                      Clé(s) du Registre infectée(s): 0
                      Valeur(s) du Registre infectée(s): 0
                      Elément(s) de données du Registre infecté(s): 0
                      Dossier(s) infecté(s): 0
                      Fichier(s) infecté(s): 0

                      Processus mémoire infecté(s):
                      (Aucun élément nuisible détecté)

                      Module(s) mémoire infecté(s):
                      (Aucun élément nuisible détecté)

                      Clé(s) du Registre infectée(s):
                      (Aucun élément nuisible détecté)

                      Valeur(s) du Registre infectée(s):
                      (Aucun élément nuisible détecté)

                      Elément(s) de données du Registre infecté(s):
                      (Aucun élément nuisible détecté)

                      Dossier(s) infecté(s):
                      (Aucun élément nuisible détecté)

                      Fichier(s) infecté(s):
                      (Aucun élément nuisible détecté)
                      0
                      1. .
                        et j ai fait ad remover pour gagné du temps ( enfin je l espere)

                        ======= RAPPORT D'AD-REMOVER 1.1.4.6_C | UNIQUEMENT XP/VISTA/7 =======
                        .
                        Mit à jour par C_XX le 16.11.2009 à 22:21
                        Contact: AdRemover.contact@gmail.com
                        Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html
                        .
                        Lancé à: 12:50:27, 19/11/2009 | Mode Normal | Option: CLEAN
                        Exécuté de: C:\Program Files\Ad-remover\
                        Système d'exploitation: Microsoft® Windows Vista™ Home Premium Service Pack 2 v6.0.6002
                        Nom du PC: PC-DE-REGIS | Utilisateur actuel: regis
                        .
                        ============== ÉLÉMENT(S) NEUTRALISÉ(S) ==============
                        .

                        HKCU\Software\Microsoft\Internet Explorer\LowRegistry\Search Settings
                        HKLM\software\Search Settings
                        HKCU\software\microsoft\internet explorer\searchscopes\{CF739809-1C6C-47C0-85B9-569DBB141420}
                        HKLM\software\microsoft\windows\currentversion\uninstall\{0B1AAC97-8563-41D9-AE47-58E6A222F0E1}
                        HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\SearchSettings
                        .
                        C:\Users\regis\AppData\LocalLow\Search Settings
                        C:\Program Files\Mozilla FireFox\Components\AskSearch.js
                        C:\Program Files\Mozilla Firefox\extensions\search@searchsettings.com
                        C:\Program Files\Search Settings
                        C:\Windows\Installer\2f749d.msi

                        (!) -- Fichiers temporaires supprimés.

                        .
                        ============== Scan additionnel ==============
                        .
                        .
                        * Mozilla FireFox Version 3.5.3 [fr] *
                        .
                        Nom du profil: q63jx4c7.default (regis)
                        .
                        (regis, prefs.js) Browser.startup.homepage, hxxp://google.fr
                        .
                        .
                        * Internet Explorer Version 8.0.6001.18828 *
                        .
                        [HKEY_CURRENT_USER\..\Internet Explorer\Main]
                        .
                        Start Page: hxxp://fr.msn.com/
                        Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
                        Search Page: hxxp://recherche.neuf.fr/
                        Search Bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
                        Default_search_url: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                        .
                        [HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]
                        .
                        Start Page: hxxp://fr.msn.com/
                        Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                        Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                        Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
                        Search bar: hxxp://search.msn.com/spbasic.htm
                        .
                        [HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]
                        .
                        Tabs: res://ieframe.dll/tabswelcome.htm
                        .
                        ===================================
                        .
                        2322 Octet(s) - C:\Ad-Report-CLEAN[1].log
                        2607 Octet(s) - C:\Ad-Report-SCAN[1].log
                        .
                        1 Fichier(s) - C:\Users\regis\AppData\Local\Temp
                        0 Fichier(s) - C:\Windows\Temp
                        .
                        21 Fichier(s) - C:\Program Files\Ad-remover\BACKUP
                        16 Fichier(s) - C:\Program Files\Ad-remover\QUARANTINE
                        .
                        Fin à: 12:53:27 | 19/11/2009 - CLEAN[1]
                        .
                        ============== E.O.F ==============
                        .
                        0
                        1. Contributeur sécurité
                          Oui, très bien.
                          Où en es-tu de tes problèmes ?
                          Comment se comporte ton PC ?
                          0
                          1. ca a lair d aller pas de changement qu aurais je du voir comme changement
                            0
                            1. tu vois un changement

                              Logfile of Trend Micro HijackThis v2.0.2
                              Scan saved at 13:10:26, on 19/11/2009
                              Platform: Windows Vista SP2 (WinNT 6.00.1906)
                              MSIE: Internet Explorer v8.00 (8.00.6001.18828)
                              Boot mode: Normal

                              Running processes:
                              C:\Windows\system32\taskeng.exe
                              C:\Windows\system32\Dwm.exe
                              C:\Program Files\Windows Defender\MSASCui.exe
                              C:\Windows\System32\igfxtray.exe
                              C:\Windows\System32\hkcmd.exe
                              C:\Windows\System32\igfxpers.exe
                              C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
                              C:\Program Files\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe
                              C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
                              C:\Program Files\Windows Media Player\wmpnscfg.exe
                              C:\Program Files\Acer\Acer PowerSmart Manager\ePowerTray.exe
                              C:\Windows\system32\igfxsrvc.exe
                              C:\Windows\system32\wbem\unsecapp.exe
                              C:\Users\regis\AppData\Local\Temp\RtkBtMnt.exe
                              C:\Windows\explorer.exe
                              C:\Program Files\Internet Explorer\iexplore.exe
                              C:\Program Files\Internet Explorer\iexplore.exe
                              C:\Windows\system32\SearchFilterHost.exe
                              C:\Windows\system32\SearchProtocolHost.exe
                              C:\Users\regis\Desktop\securité\HiJackThis.exe

                              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://actus.sfr.fr
                              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                              O1 - Hosts: ::1 localhost
                              O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                              O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                              O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                              O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                              O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
                              O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
                              O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
                              O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
                              O4 - HKLM\..\Run: [BackupManagerTray] "C:\Program Files\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe" -k
                              O4 - HKLM\..\Run: [Acer ePower Management] C:\Program Files\Acer\Acer PowerSmart Manager\ePowerTrayLauncher.exe
                              O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
                              O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
                              O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                              O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                              O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
                              O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
                              O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                              0
                              1. Contributeur sécurité
                                Avec les barres infectées tu aurais pu avoir un ralentissement.

                                Fais un nouvel Hijacjthis pour voir ce que ça donne.
                                0
                                1. je venais de le mettre mais je te le remet

                                  Logfile of Trend Micro HijackThis v2.0.2
                                  Scan saved at 13:14:11, on 19/11/2009
                                  Platform: Windows Vista SP2 (WinNT 6.00.1906)
                                  MSIE: Internet Explorer v8.00 (8.00.6001.18828)
                                  Boot mode: Normal

                                  Running processes:
                                  C:\Windows\system32\taskeng.exe
                                  C:\Windows\system32\Dwm.exe
                                  C:\Program Files\Windows Defender\MSASCui.exe
                                  C:\Windows\System32\igfxtray.exe
                                  C:\Windows\System32\hkcmd.exe
                                  C:\Windows\System32\igfxpers.exe
                                  C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
                                  C:\Program Files\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe
                                  C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
                                  C:\Program Files\Windows Media Player\wmpnscfg.exe
                                  C:\Program Files\Acer\Acer PowerSmart Manager\ePowerTray.exe
                                  C:\Windows\system32\igfxsrvc.exe
                                  C:\Windows\system32\wbem\unsecapp.exe
                                  C:\Users\regis\AppData\Local\Temp\RtkBtMnt.exe
                                  C:\Windows\explorer.exe
                                  C:\Program Files\Internet Explorer\iexplore.exe
                                  C:\Program Files\Internet Explorer\iexplore.exe
                                  C:\Users\regis\Desktop\securité\HiJackThis.exe

                                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://go.microsoft.com/fwlink/?linkid=54896
                                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://actus.sfr.fr
                                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
                                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
                                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                                  O1 - Hosts: ::1 localhost
                                  O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                                  O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                  O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                                  O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                                  O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
                                  O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
                                  O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
                                  O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
                                  O4 - HKLM\..\Run: [BackupManagerTray] "C:\Program Files\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe" -k
                                  O4 - HKLM\..\Run: [Acer ePower Management] C:\Program Files\Acer\Acer PowerSmart Manager\ePowerTrayLauncher.exe
                                  O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
                                  O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
                                  O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                                  O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                                  O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
                                  O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
                                  O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                                  0
                                  1. Contributeur sécurité
                                    Impeccable !
                                    0
                                    1. bien et tout les 04 c est rien
                                      0
                                      1. Contributeur sécurité
                                        Tu n'en a pas beaucoup, pas de soucis.
                                        0
                                        1. en tout cas merci beaucoup
                                          0
                                        2. si tu t y connais pour brancher un deuxieme portable en wifi correctement
                                          je suis preneur
                                          0
                                      2. en tout cas un grand merci
                                        une autre fois j aurais des questions pour brancher un deuxieme portable en wifi
                                        car j ai oublié comment on le fais correctement

                                        alors peut etre a plus tard merci
                                        0
                                        • 1
                                        • 2