Virus "Hacked by Godzilla" - Page 2

  1. Contributeur sécurité
    ▶ Relance List&Kill'em (clic droit "exécuter en tant qu'administrateur" pour Vista/Seven) avec le raccourci sur ton bureau ,

    mais cette fois-ci :

    ▶ choisis l'option 2 = Mode Suppression

    laisse travailler l'outil.

    en fin de scan un rapport s'ouvre

    ▶ colle le contenu dans ta reponse

    Tu peux le désinstaller ensuite

    .....................

    lances MalwareByte's Anti-Malware que tu possèdes déjà

    mets le à jour

    examen complet

    supprimer ce qu'il trouve

    poster le rapport

    0
    1. Auras tu un peu de temps à me consacrer demain dans la journée pour terminer ces analyses ? Je dois y aller... Travail oblige !

      Un énorme merci pour ton aide qui sauve en quelques sorte mon entreprise (qui se résume à mon ordinateur)

      Bonne soirée
      0
      1. Contributeur sécurité
        pas de soucis, on vient quand on peut....et je serai là
        0
        1. Voici le rapport de Malware

          Malwarebytes' Anti-Malware 1.44
          Version de la base de données: 3510
          Windows 5.1.2600 Service Pack 3
          Internet Explorer 6.0.2900.5512

          16/02/2010 11:32:16
          mbam-log-2010-02-16 (11-32-16).txt

          Type de recherche: Examen complet (C:\|E:\|)
          Eléments examinés: 338891
          Temps écoulé: 2 hour(s), 25 minute(s), 48 second(s)

          Processus mémoire infecté(s): 0
          Module(s) mémoire infecté(s): 0
          Clé(s) du Registre infectée(s): 0
          Valeur(s) du Registre infectée(s): 1
          Elément(s) de données du Registre infecté(s): 0
          Dossier(s) infecté(s): 2
          Fichier(s) infecté(s): 20

          Processus mémoire infecté(s):
          (Aucun élément nuisible détecté)

          Module(s) mémoire infecté(s):
          (Aucun élément nuisible détecté)

          Clé(s) du Registre infectée(s):
          (Aucun élément nuisible détecté)

          Valeur(s) du Registre infectée(s):
          HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\captcha7 (Spyware.OnlineGames) -> Quarantined and deleted successfully.

          Elément(s) de données du Registre infecté(s):
          (Aucun élément nuisible détecté)

          Dossier(s) infecté(s):
          C:\Program Files\Spyware Process Detector (Rogue.SpywareProcessDetector) -> Quarantined and deleted successfully.
          C:\Documents and Settings\principal\Menu Démarrer\Programmes\PlayMP3z (Adware.PLayMP3z) -> Quarantined and deleted successfully.

          Fichier(s) infecté(s):
          C:\Documents and Settings\principal\Local Settings\Application Data\goohoow_navps.dat (Adware.Navipromo.H) -> Quarantined and deleted successfully.
          C:\Documents and Settings\principal\Local Settings\Application Data\goohoow_nav.dat (Adware.Navipromo.H) -> Quarantined and deleted successfully.
          C:\Documents and Settings\principal\Local Settings\Application Data\goohoow.dat (Adware.Navipromo.H) -> Quarantined and deleted successfully.
          C:\Documents and Settings\principal\Local Settings\Application Data\ogioi_navps.dat (Adware.Navipromo.H) -> Quarantined and deleted successfully.
          C:\Documents and Settings\principal\Local Settings\Application Data\ogioi_nav.dat (Adware.Navipromo.H) -> Quarantined and deleted successfully.
          C:\Documents and Settings\principal\Local Settings\Application Data\ogioi.dat (Adware.Navipromo.H) -> Quarantined and deleted successfully.
          C:\Documents and Settings\Florence\Local Settings\Temporary Internet Files\Content.IE5\ZVX97S48\win_protection_update[2].exe (Rogue.Installer) -> Quarantined and deleted successfully.
          C:\Kill'em\Quarantine\FBrowsingAdvisor.Kill'em\XPCOMEvents.dll (Adware.PLayMP3z) -> Quarantined and deleted successfully.
          C:\Program Files\Spyware Process Detector\safe.txt (Rogue.SpywareProcessDetector) -> Quarantined and deleted successfully.
          C:\Program Files\Spyware Process Detector\spydetector.cfg (Rogue.SpywareProcessDetector) -> Quarantined and deleted successfully.
          C:\Program Files\Spyware Process Detector\spydetector.dll (Rogue.SpywareProcessDetector) -> Quarantined and deleted successfully.
          C:\Documents and Settings\principal\Menu Démarrer\Programmes\PlayMP3z\Run PlayMP3z.lnk (Adware.PLayMP3z) -> Quarantined and deleted successfully.
          C:\WINDOWS\010112010146114101.xxe (KoobFace.Trace) -> Quarantined and deleted successfully.
          C:\WINDOWS\0101120101464849.xxe (KoobFace.Trace) -> Quarantined and deleted successfully.
          C:\WINDOWS\01011201014650115.xxe (KoobFace.Trace) -> Quarantined and deleted successfully.
          C:\WINDOWS\0101120101465448.xxe (KoobFace.Trace) -> Quarantined and deleted successfully.
          C:\WINDOWS\fdgg34353edfgdfdf (KoobFace.Trace) -> Quarantined and deleted successfully.
          C:\Program Files\captcha.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully.
          C:\WINDOWS\ld16.exe (Worm.KoobFace) -> Quarantined and deleted successfully.
          C:\WINDOWS\pp14.exe (Worm.KoobFace) -> Quarantined and deleted successfully.
          0
          1. Contributeur sécurité
            onglet rapport dans MalwareByte's Anti-Malware
            0
            1. Je l'ai posté juste au dessus de votre post
              0
              1. Contributeur sécurité
                il y avait du navipromo

                pour être sûr que c'est bien nettoyé

                Infection Navipromo….Pour info :

                Il s'installe via certains programmes, dont ceux-ci qu'il faut éviter à tout prix:
                * Funky Emoticons
                * go-astro
                * Games Attack
                * GoRecord
                * HotTVPlayer / HotTVPlayer & Paris Hilton
                * Live-Player
                * MailSkinner
                * Messenger Skinner
                * Instant Access
                * InternetGameBox
                * Officiale Emule (Version d'Emule modifiée)
                * Original Solitaire
                * SuperSexPlayer
                * Speed Downloading
                * Sudoplanet
                * Webmediaplayer

                il faudrait télécharge navilog1 sur le bureau :
                http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe

                Certaines infections bloquent les téléchargements d' outils de désinfection utilisez ce lien alternatif:
                http://ww38.toofiles.com/fr/oip/documents/exe/yop3.html

                1°Double-clique sur navilog1.exe présent sur ton bureau
                2°Sélectionnez la langue désirée dans le menu puis valide le choix par la touche « entrer »
                3°Petit message d’avertissement, appuyez sur une touche pour passe à la suite
                4°un nouveau avertissement, appuie sur une touche pour suivre
                5°Vérification de l’installation de Navilog1 : si tout est bon, appuyez sur une touche pour continuer
                6°Choisir option 1 : recherche/désinfection automatique
                7°La recherche va se lancer automatiquement et peut durée quelques minutes, patientez
                8°Une fois l’analyse terminé, fermez et enregistrez votre travail en cours, puis appuiez sur une touche pour que votre pc puisse démarrer
                9°Au redémarrage du pc, Navilog va supprimer ce qu’il a trouvé, patientez quelques instants.

                Un rapport est gèneré par l'outil. Il se trouve à cette emplacement :
                XP : demarrer/poste de travail/c:/cleannavi.txt
                0
                1. Il ne m'a pas proposé de redémarrer mon ordinateur

                  Le rapport du scan me met à la fin

                  Recherche executée en mode normal

                  Aucune Infection Navipromo/Egdaccess trouvée
                  0
                  1. Contributeur sécurité
                    ok

                    comment va le pc ?

                    1)

                    relances RSIT et postes le rapport log

                    2)

                    refaire MBAM qui n'était pas à jour
                    Version de la base de données: 3510

                    en scan complet
                    0
                    1. J'ai encore quelques pages internet qui s'ouvrent me disant "virus scan truc" je ferme la page et ca passe, mais c'est pas normal !

                      Je n'ai plus le captcha Windows en revanche.

                      RAPPORT RSTI :

                      Logfile of random's system information tool 1.06 (written by random/random)
                      Run by Florence at 2010-02-19 16:40:34
                      Microsoft Windows XP Édition familiale Service Pack 3
                      System drive C: has 21 GB (21%) free of 100 GB
                      Total RAM: 1023 MB (11% free)

                      Logfile of Trend Micro HijackThis v2.0.2
                      Scan saved at 16:40:54, on 19/02/2010
                      Platform: Windows XP SP3 (WinNT 5.01.2600)
                      MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
                      Boot mode: Normal

                      Running processes:
                      C:\WINDOWS\System32\smss.exe
                      C:\WINDOWS\system32\winlogon.exe
                      C:\WINDOWS\system32\services.exe
                      C:\WINDOWS\system32\lsass.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
                      C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\system32\brsvc01a.exe
                      C:\WINDOWS\system32\spoolsv.exe
                      C:\WINDOWS\system32\brss01a.exe
                      C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                      C:\Program Files\Bonjour\mDNSResponder.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\WINDOWS\System32\FTRTSVC.exe
                      C:\WINDOWS\system32\nvsvc32.exe
                      C:\WINDOWS\sYSteM32\SvchOst.eXE
                      C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\system32\SearchIndexer.exe
                      C:\WINDOWS\system32\wscntfy.exe
                      C:\WINDOWS\Explorer.EXE
                      C:\WINDOWS\RTHDCPL.EXE
                      C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe
                      C:\Program Files\Winamp\winampa.exe
                      C:\WINDOWS\system32\RUNDLL32.EXE
                      C:\WINDOWS\system32\LVCOMSX.EXE
                      C:\Program Files\Logitech\Video\LogiTray.exe
                      C:\Program Files\iTunes\iTunesHelper.exe
                      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                      C:\Program Files\Messenger\msmsgs.exe
                      C:\WINDOWS\system32\ctfmon.exe
                      C:\Program Files\TomTom HOME 2\HOMERunner.exe
                      C:\Program Files\DAEMON Tools Lite\daemon.exe
                      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                      C:\Documents and Settings\Florence\Local Settings\Application Data\Google\Update\1.2.183.13\GoogleCrashHandler.exe
                      C:\Program Files\Windows Desktop Search\WindowsSearch.exe
                      C:\Program Files\BitDefender\BitDefender 2009\seccenter.exe
                      C:\Program Files\Logitech\Video\FxSvr2.exe
                      C:\Program Files\iPod\bin\iPodService.exe
                      C:\Program Files\Windows Live\Contacts\wlcomm.exe
                      C:\Documents and Settings\Florence\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
                      C:\Documents and Settings\Florence\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
                      C:\Documents and Settings\Florence\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
                      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                      C:\Documents and Settings\Florence\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
                      C:\Documents and Settings\Florence\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
                      C:\Program Files\Call of Duty - Modern Warfare 2\iw4sp.exe
                      C:\WINDOWS\system32\NOTEPAD.EXE
                      C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
                      C:\Documents and Settings\Florence\Bureau\RSIT.exe
                      C:\Documents and Settings\Florence\Mes documents\Downloads\Florence.exe

                      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.ask.com/?o=15087&l=dis
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                      R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
                      O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                      O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                      O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                      O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
                      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
                      O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                      O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2009\IEToolbar.dll
                      O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                      O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
                      O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
                      O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
                      O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
                      O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
                      O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe"
                      O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2009\IEShow.exe"
                      O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
                      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                      O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
                      O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
                      O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
                      O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
                      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                      O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe"
                      O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|DEFAULT=cnx|PARAM=
                      O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                      O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                      O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\HOMERunner.exe" -s
                      O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
                      O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
                      O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Florence\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
                      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                      O4 - Global Startup: Desktop Manager.lnk = C:\Program Files\Research In Motion\BlackBerry\DesktopMgr.exe
                      O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
                      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                      O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                      O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
                      O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                      O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                      O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
                      O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
                      O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
                      O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...
                      O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - https://www.touslesdrivers.com/index.php?v_page=29
                      O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                      O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
                      O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                      O23 - Service: BitDefender Arrakis Server (Arrakis3) - BitDefender S.R.L. https://www.bitdefender.fr/ - C:\Program Files\Fichiers communs\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe
                      O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                      O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
                      O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
                      O23 - Service: Service Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
                      O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                      O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                      O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
                      O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
                      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                      O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S. R. L. - C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
                      0
                      1. Contributeur sécurité
                        ok

                        laisses tomber MBAM pour l'instant

                        Attention, avant de commencer, lit attentivement la procédure, et imprime la

                        Aide à l’utilisation
                        https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix

                        Télécharge ComboFix de sUBs sur ton Bureau :

                        http://download.bleepingcomputer.com/sUBs/ComboFix.exe

                        /!\ Déconnecte-toi du net et DESACTIVES TOUTES LES DEFENSES, antivirus et antispyware y compris /!\

                        ---> Double-clique sur ComboFix.exe
                        Un "pop-up" va apparaître qui dit que ComboFix est utilisé à vos risques et avec aucune garantie... Clique sur oui pour accepter

                        SURTOUT INSTALLES LA CONSOLE DE RECUPERATION
                        (si il te propose de l’installer remets provisoirement internet)

                        ---> Mets-le en langue française F
                        Tape sur la touche 1 (Yes) pour démarrer le scan.

                        Ne touche à rien(souris, clavier) tant que le scan n'est pas terminé, car tu risques de planter ton PC

                        En fin de scan, il est possible que ComboFix ait besoin de redémarrer le PC pour finaliser la désinfection, laisse-le faire.

                        Une fois le scan achevé, un rapport va s'afficher : Poste son contenu

                        /!\ Réactive la protection en temps réel de ton antivirus et de ton antispyware avant de te reconnecter à Internet. /!\

                        Note : Le rapport se trouve également là : C:\ComboFix.txt
                        0
                        1. Vu toutes les contraintes qu'il faut faire avant de lancer ComboFix, ya t'il un risque pour mon ordi ? Ou alors c'est tout bénef ?
                          0
                          1. Contributeur sécurité
                            tout benef car si on laisse une seule vérole, elle gardera la porte ouverte pour l'arrivée prochaine de copains

                            les virus travaillent aujourd'hui en équipe

                            important

                            installer la console s'il te le propose en remettant internet
                            0
                            Précédent
                            • 1
                            • 2