Probleme ctzjeqttom.dll

Résolu/Fermé
Ccarino Messages postés 183 Date d'inscription jeudi 9 octobre 2008 Statut Membre Dernière intervention 22 août 2011 - 3 avril 2010 à 13:37
moment de grace Messages postés 29042 Date d'inscription samedi 6 décembre 2008 Statut Contributeur sécurité Dernière intervention 18 juillet 2013 - 4 avril 2010 à 15:31
Bonjour

J'ai un soucis concernant une erreur:

run au niveau du fichier ctzjeqttom.dll

Voici le rapport HIJACKTHIS.

De plus IE ne répond pas après le lancement de la fenetre.




Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 00:32:19, on 16/08/2006
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17023)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\WINDOWS\Explorer.EXE
C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Windows Live\Family Safety\fsssvc.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\RTHDCPL.EXE
c:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\SysMonitor.exe
C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\TomTom HOME\TomTomHOME.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Program Files\AGEIA Technologies\TrayIcon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\ZSSnp211.exe
C:\WINDOWS\Domino.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICEE.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Acer\Empowering Technology\Acer.Empowering.Framework.Launcher.exe
C:\Program Files\Acer WLAN 11g USB Dongle\ZDWlan.exe
C:\Documents and Settings\alex\Application Data\Microsoft\Live Search\Notification-LiveSearch.exe
C:\Documents and Settings\alex\Application Data\Microsoft\Live Search\Mise-a-jour-LiveSearch.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Windows Live\Toolbar\wltuser.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://fr.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*https://fr.search.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://fr.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://fr.rd.yahoo.com/customize/ie/defaults/su/msgr8/*https://fr.search.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://fr.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*https://fr.search.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.rd.yahoo.com/customize/ie/defaults/su/msgr8/*https://fr.search.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: ShoppingReport - {100EB1FD-D03E-47FD-81F3-EE91287F9465} - C:\Program Files\ShoppingReport\Bin\2.5.0\ShoppingReport.dll
O2 - BHO: Windows Live Family Safety Browser Helper - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\WINDOWS\system32\eDStoolbar.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [LaunchApp] Alaunch
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [ntiMUI] c:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [Acer Empowering Technology Monitor] C:\WINDOWS\system32\SysMonitor.exe
O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe 1
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME\TomTomHOME.exe" -s
O4 - HKLM\..\Run: [{e5ba8a98-c221-5bc8-fcb5-90af4038ab6f}] C:\WINDOWS\System32\Rundll32.exe "C:\WINDOWS\system32\ctzjeqttom.dll" DllStart
O4 - HKLM\..\Run: [AGEIA PhysX SysTray] C:\Program Files\AGEIA Technologies\TrayIcon.exe
O4 - HKLM\..\Run: [fssui] "C:\Program Files\Windows Live\Family Safety\fsui.exe" -autorun
O4 - HKLM\..\Run: [ZSSnp211] C:\WINDOWS\ZSSnp211.exe
O4 - HKLM\..\Run: [Domino] C:\WINDOWS\Domino.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [RegistryBooster 2 d'Uniblue ] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
O4 - HKCU\..\Run: [kava] C:\WINDOWS\system32\kavo.exe
O4 - HKCU\..\Run: [EPSON Stylus DX8400 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICEE.EXE /FU "C:\WINDOWS\TEMP\E_S7B.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [Move each] C:\DOCUME~1\alex\APPLIC~1\MEETMI~1\Batvccake.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [s9201] "C:\Documents and Settings\All Users\Application Data\Secure Solutions\Antispyware 2008 XP\as2008xp.exe" /autorun
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - S-1-5-18 Startup: Outil de notification Live Search.lnk = C:\Documents and Settings\alex\Application Data\Microsoft\Live Search\Notification-LiveSearch.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: Outil de notification Live Search.lnk = C:\Documents and Settings\alex\Application Data\Microsoft\Live Search\Notification-LiveSearch.exe (User 'Default user')
O4 - Startup: Outil de notification Live Search.lnk = C:\Documents and Settings\alex\Application Data\Microsoft\Live Search\Notification-LiveSearch.exe
O4 - Global Startup: Acer Empowering Technology.lnk = ?
O4 - Global Startup: Acer WLAN 11g USB Dongle.lnk = C:\Program Files\Acer WLAN 11g USB Dongle\ZDWlan.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O4 - Global Startup: Logiciel Kodak EasyShare.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Allocam Multi Vision - {2D6B57BF-71FA-41A3-BDC5-3B5A25813D2E} - C:\PROGRA~1\ALLOCA~1\allocam.exe (file missing)
O9 - Extra 'Tools' menuitem: Allocam Multi Vision - {2D6B57BF-71FA-41A3-BDC5-3B5A25813D2E} - C:\PROGRA~1\ALLOCA~1\allocam.exe (file missing)
O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll
O9 - Extra button: ShopperReports - Compare product prices - {C5428486-50A0-4a02-9D20-520B59A9F9B2} - C:\Program Files\ShoppingReport\Bin\2.5.0\ShoppingReport.dll
O9 - Extra button: ShopperReports - Compare travel rates - {C5428486-50A0-4a02-9D20-520B59A9F9B3} - C:\Program Files\ShoppingReport\Bin\2.5.0\ShoppingReport.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://3dlifeplayer.dl.3dvia.com/player/install/3DVIA_player_installer.exe
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL (file missing)
O23 - Service: Memory Check Service (AcerMemUsageCheckService) - Acer Inc. - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
O23 - Service: Service Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe

21 réponses

moment de grace Messages postés 29042 Date d'inscription samedi 6 décembre 2008 Statut Contributeur sécurité Dernière intervention 18 juillet 2013 2 274
3 avril 2010 à 13:46
bonjour

effectivement il y a du beau monde

Télécharge ZHPDiag ( de Nicolas coolman ).
https://www.zebulon.fr/telechargements/securite/systeme/zhpdiag.html

Double clique sur le fichier d'installation, puis installe le avec les paramètres par défaut ( N'oublie pas de cocher " Créer une icône sur le bureau " )

Lance ZHPDiag en double cliquant sur l'icône présente sur ton bureau (Clique droit -> Executer en tant qu'admin ( vista )

Clique sur la loupe en haut à gauche, puis laisse l'outil scanner.

Une fois le scan terminé, clique sur l'icône en forme de disquette et enregistre le fichier sur ton bureau.

Rend toi sur Cjoint : http://www.cijoint.fr/

Clique sur "Parcourir " dans la partie " Joindre un fichier[...] "

Sélectionne le rapport ZHPdiag.txt qui se trouve sur ton bureau

Clique ensuite sur "Cliquez ici pour déposer le fichier " et copie/colle le lien dans ton prochain message


0
Ccarino Messages postés 183 Date d'inscription jeudi 9 octobre 2008 Statut Membre Dernière intervention 22 août 2011 10
3 avril 2010 à 14:15
http://www.cijoint.fr/cjlink.php?file=cj201004/cijXCydD6m.txt

tiens voila
0
moment de grace Messages postés 29042 Date d'inscription samedi 6 décembre 2008 Statut Contributeur sécurité Dernière intervention 18 juillet 2013 2 274
3 avril 2010 à 16:23
il y a des lignes qui diffèrent d'un rapport à l'autre...as tu fais quelque chose ?

de plus tu as un problème avec la date


Téléchargez USBFIX de El Desaparecido, C_xx

http://pagesperso-orange.fr/NosTools/Chiquitine29/UsbFix.exe
ou
https://www.ionos.fr/?affiliate_id=77097

/!\ Utilisateur de vista et windows 7 :
ne pas oublier de désactiver Le contrôle des comptes utilisateurs
https://www.commentcamarche.net/faq/8343-vista-desactiver-l-uac

/!\ Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d'avoir été infectées sans les ouvrir

Double clic sur le raccourci UsbFix présent sur le bureau .

Choisir l'option2 suppression
(d'autres options disponibles, voir le tutoriel).
Laissez travailler l'outil.
Le menu démarrer et les icônes vont disparaître.. c'est normal.

Si un message te demande de redémarrer l'ordinateur fais le ...

Au redémarrage, le fix se relance... laisses l'opération s'effectuer.

Le bloc note s'ouvre avec un rapport, envoies le dans la prochaine réponse


* Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque. ( C:\UsbFix.txt )

( CTRL+A Pour tout sélectionner , CTRL+C pour copier et CTRL+V pour coller )

* Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.


* Tuto : http://pagesperso-orange.fr/NosTools/usbfix.html


UsbFix peut te demander d'uploader un dossier compressé à cette adresse : https://www.ionos.fr/?affiliate_id=77097

Il est enregistré sur ton bureau.

Merci de l'envoyer à l'adresse indiquée afin d'aider l'auteur de UsbFix dans ses recherches.



0
Ccarino Messages postés 183 Date d'inscription jeudi 9 octobre 2008 Statut Membre Dernière intervention 22 août 2011 10
3 avril 2010 à 21:16
############################## | UsbFix V6.100 |

User : alex (Administrateurs) # ACER-DC6C4D74B4
Update on 18/03/2010 by El Desaparecido , C_XX & Chimay8
Start at: 00:06:51 | 16/08/2006
Website : http://pagesperso-orange.fr/NosTools/index.html
Contact : FindyKill.Contact@gmail.com

Intel(R) Pentium(R) 4 CPU 3.06GHz
Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 3
Internet Explorer 7.0.5730.11
Windows Firewall Status : Enabled
AV : avast! antivirus 4.8.1368 [VPS 100331-2] 4.8.1368 [ Enabled | Updated ]

A:\ -> Lecteur de disquettes 3 ½ pouces
C:\ -> Disque fixe local # 113,27 Go (10,54 Go free) [ACER] # NTFS
D:\ -> Disque fixe local # 113,73 Go (89,56 Go free) [ACERDATA] # FAT32
E:\ -> Disque CD-ROM
F:\ -> Disque amovible
G:\ -> Disque amovible
H:\ -> Disque fixe local # 465,76 Go (170,66 Go free) [chris didine] # NTFS
I:\ -> Disque amovible
J:\ -> Disque amovible

################## | Elements infectieux |

C:\DOCUME~1\alex\LOCALS~1\Temp\aa.exe
C:\autorun.inf
D:\autorun.inf
H:\autorun.inf
H:\msvcr71.dll
H:\ravmone.exe

################## | Registre |

[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "kava"
[HKLM\SOFTWARE\Classes\CLSID\MADOWN]
[HKCR\CLSID\MADOWN]

################## | Mountpoints2 |

HKCU\..\..\Explorer\MountPoints2\F
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe m.vbs

HKCU\..\..\Explorer\MountPoints2\H
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe m.vbs

HKCU\..\..\Explorer\MountPoints2\K
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe m.vbs

HKCU\..\..\Explorer\MountPoints2\{02929ce5-183c-11dd-ba05-9aab89e78494}
Shell\AutoRun\command =F:\tmf3w3g0.com
Shell\explore\Command =F:\tmf3w3g0.com
Shell\open\Command =F:\tmf3w3g0.com

HKCU\..\..\Explorer\MountPoints2\{0ce57850-7a5b-11dc-b961-00192150818f}
Shell\AutoRun\command =J:\
Shell\explore\Command =RECYCLER\INFO.exe
Shell\open\Command =RECYCLER\INFO.exe

HKCU\..\..\Explorer\MountPoints2\{18a8220c-37e9-11dd-ba28-0007cb0000ff}
Shell\AutoRun\command =F:\LaunchU3.exe -a

HKCU\..\..\Explorer\MountPoints2\{2493adf0-5277-11de-bbec-00192150818f}
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL fueFue.exE

HKCU\..\..\Explorer\MountPoints2\{2c652b85-ca44-11de-bc57-0007cb0000ff}
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe m.vbs

HKCU\..\..\Explorer\MountPoints2\{34541db6-8b30-11de-bc20-00192150818f}
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe m.vbs

HKCU\..\..\Explorer\MountPoints2\{3bcfb8e0-5806-11dd-ba55-0007cb0000ff}
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe m.vbs

HKCU\..\..\Explorer\MountPoints2\{3f693306-cf88-11dd-bb04-0007cb0000ff}
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe m.vbs

HKCU\..\..\Explorer\MountPoints2\{5d70b850-c35f-11dc-b99e-00192150818f}
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe m.vbs

HKCU\..\..\Explorer\MountPoints2\{5e815878-4c5d-11dd-ba3f-0007cb0000ff}
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe m.vbs

HKCU\..\..\Explorer\MountPoints2\{6a26fd69-205e-11dd-ba08-0007cb0000ff}
Shell\AutoRun\command =F:\InstallTomTomHOME.exe

HKCU\..\..\Explorer\MountPoints2\{73e094e1-2fdd-11db-b9cc-00192150818f}
Shell\AutoRun\command =tmf3w3g0.com
Shell\explore\Command =tmf3w3g0.com
Shell\open\Command =tmf3w3g0.com

HKCU\..\..\Explorer\MountPoints2\{842d3d5b-07aa-11dd-ba01-0007cb0000ff}
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe m.vbs

HKCU\..\..\Explorer\MountPoints2\{9b531637-87d0-11dd-ba93-0007cb0000ff}
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe m.vbs

HKCU\..\..\Explorer\MountPoints2\{9bb174ff-f84e-11dd-bb33-0007cb0000ff}
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe m.vbs

HKCU\..\..\Explorer\MountPoints2\{b6fb9914-cb08-11de-bc59-000000000000}
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe m.vbs

HKCU\..\..\Explorer\MountPoints2\{b72f25a9-b3ff-11dc-b982-00192150818f}
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe m.vbs

HKCU\..\..\Explorer\MountPoints2\{b72f25aa-b3ff-11dc-b982-00192150818f}
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe m.vbs

HKCU\..\..\Explorer\MountPoints2\{c3984102-c737-11de-bc55-000000000000}
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe m.vbs

HKCU\..\..\Explorer\MountPoints2\{d2b76871-2e78-11db-b9ab-00192150818f}
Shell\AutoRun\command =RavMon.exe
Shell\explore\Command =RavMon.exe -e
Shell\open\Command =RavMon.exe

HKCU\..\..\Explorer\MountPoints2\{dd7b1ae2-3b8a-11df-bc83-0007cb0000ff}
Shell\AutoRun\command ="H:\WD SmartWare.exe" autoplay=true

HKCU\..\..\Explorer\MountPoints2\{eb97bc5e-398c-11dd-ba29-0007cb0000ff}
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe m.vbs

################## | Vaccin |


################## | ! Fin du rapport # UsbFix V6.100 ! |
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
Ccarino Messages postés 183 Date d'inscription jeudi 9 octobre 2008 Statut Membre Dernière intervention 22 août 2011 10
3 avril 2010 à 21:17
desolé pour le double post

mais effectivement j'ai aussi un soucis avec la date et l'heure
0
moment de grace Messages postés 29042 Date d'inscription samedi 6 décembre 2008 Statut Contributeur sécurité Dernière intervention 18 juillet 2013 2 274
3 avril 2010 à 21:25
vu

tu ne m'as pas répondu

il y a des lignes qui diffèrent d'un rapport à l'autre...as tu fais quelque chose ?
(entre hijackthis et ZHP)

0
Ccarino Messages postés 183 Date d'inscription jeudi 9 octobre 2008 Statut Membre Dernière intervention 22 août 2011 10
3 avril 2010 à 21:29
j'ai juste installé un pour avoir internet en usb

desolé
0
moment de grace Messages postés 29042 Date d'inscription samedi 6 décembre 2008 Statut Contributeur sécurité Dernière intervention 18 juillet 2013 2 274
3 avril 2010 à 21:35
ok

https://www.commentcamarche.net/faq/8343-vista-desactiver-l-uac
Téléchargez Lop S&D.exe sur le Bueau

https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/LopSD.exe?attachauth=ANoY7co3ntqUavpZ3q1BG-h4pc13vqDZmhcNeEPChtsyrgAykRbhE8bZzhk979EfQD4AgwtQUHCaQ7ZQwNYMo3_0kA8htAspckDJtu2K5t6J9z6dLW4fpZyH4FpFL1tVMBZ8H-KnN7afZ5vt-WxZRpnynk-a0XmV_Y0C0q6DxGEDKie1TnPT7gFoZnoCnspzBmbW6ZzxA4fNr3oEDlbelNZON-LjF8nOmQ%3D%3D&attredirects=2
Certaines infections bloquent les telechargements d' outils de desinfection utilisez ce lien alternatif:
http://ww38.toofiles.com/fr/oip/documents/exe/yop4.html

Lop S&D est détecté par certains antivirus : il ne s'agit pas d'un virus (faux positif), mais d'un utilitaire destiné à mettre fin à des processus. Dans le cas d'une alerte de la part de votre antivirus, veuillez désactiver votre antivirus pendant la procédure

* Double-cliquez dessus pour lancer l'installation
* Puis double-cliquez sur le raccourci Lop S&D présent sur le Bureau
* Séléctionnez la langue souhaitée, puis choisir l'option 1 (Recherche)
* Patientez jusqu'à la fin du scan
* Postez le rapport généré sur un forum(C:\lopR.txt)
0
moment de grace Messages postés 29042 Date d'inscription samedi 6 décembre 2008 Statut Contributeur sécurité Dernière intervention 18 juillet 2013 2 274
3 avril 2010 à 21:38
as tu fait l'option 2 de usbfix ?
0
Ccarino Messages postés 183 Date d'inscription jeudi 9 octobre 2008 Statut Membre Dernière intervention 22 août 2011 10
3 avril 2010 à 21:50
nan
0
moment de grace Messages postés 29042 Date d'inscription samedi 6 décembre 2008 Statut Contributeur sécurité Dernière intervention 18 juillet 2013 2 274
3 avril 2010 à 21:51
vu

fais alors usbfix en premier

lop en second..
0
Ccarino Messages postés 183 Date d'inscription jeudi 9 octobre 2008 Statut Membre Dernière intervention 22 août 2011 10
3 avril 2010 à 22:07
############################## | UsbFix V6.100 |

User : alex (Administrateurs) # ACER-DC6C4D74B4
Update on 18/03/2010 by El Desaparecido , C_XX & Chimay8
Start at: 00:02:08 | 16/08/2006
Website : http://pagesperso-orange.fr/NosTools/index.html
Contact : FindyKill.Contact@gmail.com

Intel(R) Pentium(R) 4 CPU 3.06GHz
Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 3
Internet Explorer 7.0.5730.11
Windows Firewall Status : Enabled
AV : avast! antivirus 4.8.1368 [VPS 100331-2] 4.8.1368 [ Enabled | Updated ]

A:\ -> Lecteur de disquettes 3 ½ pouces
C:\ -> Disque fixe local # 113,27 Go (10,48 Go free) [ACER] # NTFS
D:\ -> Disque fixe local # 113,73 Go (89,56 Go free) [ACERDATA] # FAT32
E:\ -> Disque CD-ROM
F:\ -> Disque amovible
G:\ -> Disque amovible
I:\ -> Disque amovible
J:\ -> Disque amovible

################## | Elements infectieux |

Supprimé ! C:\DOCUME~1\alex\LOCALS~1\Temp\aax137.tmp.exe
Supprimé ! C:\DOCUME~1\alex\LOCALS~1\Temp\aax4C.tmp.exe
Supprimé ! C:\DOCUME~1\alex\LOCALS~1\Temp\aa.exe
Supprimé ! C:\autorun.inf
Supprimé ! C:\Recycler\S-1-5-21-4271909855-1139460094-1236175214-1005
Supprimé ! D:\autorun.inf

################## | Registre |

Supprimé ! [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "kava"
Supprimé ! [HKLM\SOFTWARE\Classes\CLSID\MADOWN]

################## | Mountpoints2 |

Supprimé ! HKCU\...\Explorer\MountPoints2\F\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\H\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\K\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{02929ce5-183c-11dd-ba05-9aab89e78494}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{0ce57850-7a5b-11dc-b961-00192150818f}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{18a8220c-37e9-11dd-ba28-0007cb0000ff}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{2493adf0-5277-11de-bbec-00192150818f}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{2c652b85-ca44-11de-bc57-0007cb0000ff}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{34541db6-8b30-11de-bc20-00192150818f}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{3bcfb8e0-5806-11dd-ba55-0007cb0000ff}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{5d70b850-c35f-11dc-b99e-00192150818f}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{5e815878-4c5d-11dd-ba3f-0007cb0000ff}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{6a26fd69-205e-11dd-ba08-0007cb0000ff}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{73e094e1-2fdd-11db-b9cc-00192150818f}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{842d3d5b-07aa-11dd-ba01-0007cb0000ff}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{9b531637-87d0-11dd-ba93-0007cb0000ff}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{9bb174ff-f84e-11dd-bb33-0007cb0000ff}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{b6fb9914-cb08-11de-bc59-000000000000}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{b72f25a9-b3ff-11dc-b982-00192150818f}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{b72f25aa-b3ff-11dc-b982-00192150818f}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{c3984102-c737-11de-bc55-000000000000}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{d2b76871-2e78-11db-b9ab-00192150818f}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{dd7b1ae2-3b8a-11df-bc83-0007cb0000ff}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{eb97bc5e-398c-11dd-ba29-0007cb0000ff}\Shell\AutoRun\Command

################## | Listing des fichiers présent |

[16/08/2006 00:27|-rahs----|209] C:\boot.ini
[16/08/2006 00:05|---------|5658] C:\bootex.log
[10/08/2004 22:00|-rahs----|4952] C:\Bootfont.bin
[02/12/2006 00:55|--ahs----|515899904] C:\eDS_PSD_drive.vmdf
[?|?|?] C:\hiberfil.sys
[16/08/2006 01:03|-rahs----|0] C:\IO.SYS
[16/08/2006 01:03|-rahs----|0] C:\MSDOS.SYS
[10/08/2004 22:00|-rahs----|47564] C:\NTDETECT.COM
[18/09/2008 14:22|-rahs----|252240] C:\ntldr
[?|?|?] C:\pagefile.sys
[08/09/2006 22:35|-rahs----|80] C:\Preload.aaa
[16/08/2006 00:06|--a------|4393] C:\UsbFix.txt
[25/10/2009 16:52|--a------|5203072] D:\04 - Kalash - Pum pum.mp3
[29/08/2009 19:10|--a------|33193984] D:\chapelle.MPG
[29/08/2009 19:20|--a------|46891008] D:\parc.MPG
[29/08/2009 18:40|--a------|281772032] D:\chapelle6.MPG
[29/08/2009 23:52|--a------|684883968] D:\repas.MPG
[29/08/2009 22:06|--a------|105840640] D:\repas 1.MPG
[02/08/2008 20:14|--a------|70713344] D:\fifi.MPG
[02/08/2008 21:19|--a------|14057472] D:\chris.MPG
[02/08/2008 21:21|--a------|8552448] D:\philipe.MPG
[02/08/2008 21:27|--a------|21757952] D:\fifi 4.MPG
[02/08/2008 21:32|--a------|12910592] D:\fifi 6.MPG
[02/08/2008 21:41|--a------|8486912] D:\fifi 8.MPG
[02/08/2008 21:50|--a------|8028160] D:\M2U00023.MPG
[02/08/2008 22:14|--a------|15138816] D:\M2U00028.MPG
[02/08/2008 22:20|--a------|35291136] D:\M2U00029.MPG
[02/08/2008 22:23|--a------|10420224] D:\M2U00031.MPG
[02/08/2008 22:40|--a------|30900224] D:\M2U00034.MPG
[03/08/2008 19:00|--a------|18382848] D:\M2U00038.MPG
[03/08/2008 19:02|--a------|15826944] D:\M2U00039.MPG
[04/08/2008 18:09|--a------|37126144] D:\M2U00042.MPG
[04/08/2008 21:35|--a------|11993088] D:\M2U00055.MPG
[05/08/2008 21:00|--a------|21102592] D:\M2U00056.MPG
[05/08/2008 21:22|--a------|17891328] D:\M2U00057.MPG
[05/08/2008 21:57|--a------|73859072] D:\M2U00058.MPG
[05/08/2008 22:29|--a------|25624576] D:\M2U00059.MPG
[05/08/2008 22:30|--a------|4521984] D:\M2U00060.MPG
[07/08/2008 21:53|--a------|33652736] D:\M2U00067.MPG
[07/08/2008 21:53|--a------|16973824] D:\M2U00068.MPG
[07/08/2008 21:54|--a------|17203200] D:\M2U00069.MPG
[08/08/2008 00:27|--a------|38731776] D:\M2U00070.MPG
[08/08/2008 00:27|--a------|6127616] D:\M2U00071.MPG
[08/08/2008 03:53|--a------|27492352] D:\M2U00072.MPG
[08/08/2008 03:58|--a------|68190208] D:\M2U00073.MPG
[08/08/2008 04:08|--a------|181010432] D:\M2U00074.MPG
[08/08/2008 04:09|--a------|25329664] D:\fann27.MPG
[10/08/2008 05:33|--a------|11042816] D:\fann26.MPG
[11/08/2008 03:45|--a------|62259200] D:\fann25.MPG
[11/08/2008 03:46|--a------|9830400] D:\fann24.MPG
[11/08/2008 03:51|--a------|45285376] D:\M2U00079.MPG
[11/08/2008 04:37|--a------|68976640] D:\fann21.MPG
[11/08/2008 06:46|--a------|78217216] D:\fann22.MPG
[11/08/2008 06:47|--a------|33226752] D:\fann23.MPG
[12/08/2008 03:05|--a------|32735232] D:\M2U00083.MPG
[12/08/2008 03:05|--a------|458752] D:\M2U00084.MPG
[12/08/2008 03:15|--a------|19070976] D:\M2U00085.MPG
[12/08/2008 03:58|--a------|49446912] D:\M2U00086.MPG
[12/08/2008 03:59|--a------|15368192] D:\M2U00087.MPG
[12/08/2008 04:00|--a------|20086784] D:\M2U00089.MPG
[12/08/2008 04:07|--a------|9011200] D:\M2U00090.MPG
[12/08/2008 04:09|--a------|26279936] D:\M2U00091.MPG
[12/08/2008 04:12|--a------|37093376] D:\M2U00092.MPG
[14/08/2008 01:22|--a------|74135552] D:\M2U00096.MPG
[16/08/2008 00:09|--a------|124420096] D:\fann20.MPG
[16/08/2008 00:10|--a------|41189376] D:\M2U00099.MPG
[12/01/2009 06:33|--a------|37093376] D:\M2U00139.MPG
[09/09/2009 23:49|--a------|8355840] D:\M2U00140.MPG
[09/09/2009 23:50|--a------|84312064] D:\M2U00142.MPG
[02/08/2008 19:52|--a------|7634944] D:\fifi 1.MPG
[24/07/2009 23:14|--a------|17170432] D:\fann19.MPG
[29/08/2009 16:47|--a------|39616512] D:\mairie 5.MPG
[24/07/2009 23:16|--a------|34832384] D:\charles.MPG
[24/07/2009 23:16|--a------|21856256] D:\fann18.MPG
[24/07/2009 23:16|--a------|30638080] D:\fann17.MPG
[24/07/2009 23:18|--a------|94208000] D:\fann7.MPG
[24/07/2009 23:20|--a------|106430464] D:\fann9.MPG
[24/07/2009 23:20|--a------|16187392] D:\fann3.MPG
[24/07/2009 23:22|--a------|21430272] D:\fann4.MPG
[24/07/2009 23:23|--a------|68091904] D:\fann6.MPG
[24/07/2009 23:24|--a------|9469952] D:\fann5.MPG
[24/07/2009 23:25|--a------|63373312] D:\fann2.MPG
[24/07/2009 23:26|--a------|21987328] D:\fann1.MPG
[24/07/2009 23:29|--a------|137658368] D:\ann.MPG
[24/07/2009 23:31|--a------|78020608] D:\fann.MPG
[24/07/2009 23:32|--a------|57835520] D:\charlo.MPG
[24/07/2009 23:34|--a------|44433408] D:\tamtam.MPG
[25/07/2009 22:26|--a------|107347968] D:\fann16.MPG
[25/07/2009 22:27|--a------|26083328] D:\fann15.MPG
[25/07/2009 22:27|--a------|22183936] D:\fann14.MPG
[25/07/2009 22:38|--a------|20381696] D:\fann13.MPG
[26/07/2009 00:11|--a------|42041344] D:\fann10.MPG
[26/07/2009 00:20|--a------|64552960] D:\fann11.MPG
[26/07/2009 00:20|--a------|52953088] D:\fann12.MPG
[01/08/2009 23:00|--a------|38895616] D:\dydy.MPG
[01/08/2009 23:01|--a------|11141120] D:\dylan.MPG
[29/08/2009 16:45|--a------|49938432] D:\mairie.MPG
[29/08/2009 16:48|--a------|15073280] D:\mairie 7.MPG
[29/08/2009 16:48|--a------|84705280] D:\mairie4.MPG
[29/08/2009 16:49|--a------|11796480] D:\mairie3.MPG
[29/08/2009 16:49|--a------|5996544] D:\mairie2.MPG
[29/08/2009 16:57|--a------|599883776] D:\marie.MPG
[29/08/2009 16:34|--a------|2785280] D:\mairie 1.MPG
[29/08/2009 17:14|--a------|2719744] D:\M2U00287.MPG
[29/08/2009 16:48|--a------|2752512] D:\mairie 8.MPG
[25/10/2009 16:55|--a------|4880914] D:\07-rik_rok_-_hold_me-tl.mp3
[25/10/2009 16:59|--a------|5487493] D:\10 - Diamond - Fanm k fS.mp3
[25/10/2009 17:03|--a------|3828810] D:\bascom x - eyes on the prize(sweet sop riddim).mp3
[02/08/2008 21:24|--a------|67895296] D:\fifi 2.MPG
[23/02/2010 12:41|--a------|5515193] D:\Crocadile-Pussy Cyatt_Alley Cyatt Diss_(Badda D (1).mp3
[25/10/2009 19:10|--a------|5124322] D:\Kalash ft Speedy - Money time.mp3
[25/10/2009 17:13|--a------|5554453] D:\LUTAN FYAH - BLESSING.mp3
[06/10/2009 23:39|--a------|4113599] D:\Mc Cr'u - Dan#a do Creu.mp3
[25/10/2009 16:46|--a------|2486902] D:\Princess lover feat Krys - Ka fe fwet.mp3
[23/02/2010 12:41|--a------|2735169] D:\Speedy an bande ti blates.mp3
[17/08/2006 04:40|--a------|734126080] D:\Barnyard.FRENCH.DVDRiP.XviD-BARNYARD-UGM.avi
[24/11/2005 22:51|--a------|649319750] D:\Bankoul'l' 2005.AVI
[25/11/2005 20:22|--a------|729505582] D:\HUMOUR - Les poids lourds du rire.AVI
[29/12/2009 23:56|--a------|348] D:\moduleName.txt
[05/08/2008 22:32|--a------|2923614] D:\Photo 091.jpg
[05/08/2008 22:32|--a------|2644695] D:\Photo 092.jpg
[05/08/2008 22:32|--a------|2637965] D:\Photo 093.jpg
[14/11/2008 11:06|--a------|1023] D:\Photo 094.jpg
[14/11/2008 11:06|--a------|1023] D:\Photo 095.jpg
[14/11/2008 11:47|--a------|1023] D:\Photo 096.jpg
[14/11/2008 11:47|--a------|1023] D:\Photo 097.jpg
[14/11/2008 11:47|--a------|1023] D:\Photo 098.jpg
[14/11/2008 11:47|--a------|1023] D:\Photo 099.jpg
[16/08/2006 02:27|--ahs----|325120] D:\Thumbs.db
[29/08/2009 17:09|--a------|109379584] D:\sortie de mairie.MPG
[29/08/2009 17:13|--a------|26017792] D:\rire mairie.MPG
[29/08/2009 16:46|--a------|77168640] D:\nous rire mairie.MPG
[24/07/2009 23:13|--a------|34308096] D:\charles 1.MPG
[14/08/2008 01:22|--a------|45776896] D:\fann tambour.MPG
[02/08/2008 19:51|--a------|51478528] D:\soeur dydy.MPG
[02/08/2008 20:30|--a------|44204032] D:\didine kiki.MPG
[29/08/2009 18:43|--a------|73793536] D:\chapelle 1.MPG
[29/08/2009 18:42|--a------|142278656] D:\chapelle 2.MPG
[29/08/2009 17:13|--a------|4325376] D:\sortie mairie.MPG
[29/08/2009 17:25|--a------|10027008] D:\sortie mairie 1.MPG
[29/08/2009 19:15|--a------|4423680] D:\md cheveau.MPG
[02/08/2008 21:26|--a------|17104896] D:\fifi 3.MPG
[02/08/2008 21:28|--a------|8880128] D:\fifi 5.MPG
[02/08/2008 21:35|--a------|9207808] D:\fifi 7.MPG

################## | Vaccination |

# C:\autorun.inf -> Dossier créé par UsbFix (El Desaparecido).
# D:\autorun.inf -> Dossier créé par UsbFix (El Desaparecido).

################## | Upload |

Veuillez envoyer le fichier : C:\UsbFix_Upload_Me_ACER-DC6C4D74B4.zip : https://www.ionos.fr/?affiliate_id=77097
Merci pour votre contribution .

################## | ! Fin du rapport # UsbFix V6.100 ! |
0
Ccarino Messages postés 183 Date d'inscription jeudi 9 octobre 2008 Statut Membre Dernière intervention 22 août 2011 10
3 avril 2010 à 22:13
--------------------\\ Lop S&D 4.2.5-0 XP/Vista

Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 3
X86-based PC ( Multiprocessor Free : Intel(R) Pentium(R) 4 CPU 3.06GHz )
BIOS : Default System BIOS
USER : alex ( Administrator )
BOOT : Normal boot
Antivirus : avast! antivirus 4.8.1368 [VPS 100331-2] 4.8.1368 (Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total:113 Go (Free:10 Go)
D:\ (Local Disk) - FAT32 - Total:113 Go (Free:89 Go)
E:\ (CD or DVD)
F:\ (USB)
G:\ (USB)
I:\ (USB)
J:\ (USB)

"C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
Option : [1] ( 16/08/2006| 0:10 )

--------------------\\ Listing des dossiers dans APPLIC~1

[30/09/2006|17:57] C:\DOCUME~1\ADMINI~1\APPLIC~1\Identities
[30/09/2006|17:57] C:\DOCUME~1\ADMINI~1\APPLIC~1\Microsoft

[16/08/2006|01:20] C:\DOCUME~1\alex\APPLIC~1\Adobe
[18/05/2008|14:37] C:\DOCUME~1\alex\APPLIC~1\AdobeUM
[16/08/2006|00:27] C:\DOCUME~1\alex\APPLIC~1\Apple Computer
[05/04/2007|14:06] C:\DOCUME~1\alex\APPLIC~1\Azureus
[12/04/2007|23:00] C:\DOCUME~1\alex\APPLIC~1\CamfrogWEB
[04/08/2006|21:11] C:\DOCUME~1\alex\APPLIC~1\CyberLink
[31/12/2006|12:54] C:\DOCUME~1\alex\APPLIC~1\DivX
[16/08/2006|01:08] C:\DOCUME~1\alex\APPLIC~1\dvdcss
[16/08/2006|04:58] C:\DOCUME~1\alex\APPLIC~1\EoRezo
[26/12/2007|17:19] C:\DOCUME~1\alex\APPLIC~1\EPSON
[09/08/2009|20:22] C:\DOCUME~1\alex\APPLIC~1\Google
[04/03/2007|15:18] C:\DOCUME~1\alex\APPLIC~1\Help
[02/10/2007|14:31] C:\DOCUME~1\alex\APPLIC~1\HTML Executable
[30/09/2006|17:57] C:\DOCUME~1\alex\APPLIC~1\Identities
[15/05/2008|22:14] C:\DOCUME~1\alex\APPLIC~1\InstallShield
[03/09/2008|20:31] C:\DOCUME~1\alex\APPLIC~1\Lavasoft
[22/11/2006|20:12] C:\DOCUME~1\alex\APPLIC~1\Macromedia
[02/09/2008|17:02] C:\DOCUME~1\alex\APPLIC~1\meet mix eggs
[10/03/2009|17:07] C:\DOCUME~1\alex\APPLIC~1\Microsoft
[29/06/2007|23:19] C:\DOCUME~1\alex\APPLIC~1\MSNInstaller
[22/03/2007|13:07] C:\DOCUME~1\alex\APPLIC~1\PanoramaStudio
[06/08/2008|16:05] C:\DOCUME~1\alex\APPLIC~1\Real
[16/08/2006|02:07] C:\DOCUME~1\alex\APPLIC~1\Samsung
[16/08/2006|00:07] C:\DOCUME~1\alex\APPLIC~1\ShoppingReport
[16/08/2006|20:41] C:\DOCUME~1\alex\APPLIC~1\Skype
[24/11/2006|15:51] C:\DOCUME~1\alex\APPLIC~1\Sun
[12/06/2008|18:51] C:\DOCUME~1\alex\APPLIC~1\U3
[16/08/2006|01:03] C:\DOCUME~1\alex\APPLIC~1\Uniblue
[29/01/2009|23:04] C:\DOCUME~1\alex\APPLIC~1\vlc
[08/08/2008|18:59] C:\DOCUME~1\alex\APPLIC~1\Windows Live Writer
[15/08/2008|15:17] C:\DOCUME~1\alex\APPLIC~1\WinRAR
[16/08/2006|01:27] C:\DOCUME~1\alex\APPLIC~1\Yahoo!

[29/12/2009|23:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\3DVIA
[18/05/2008|14:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[16/08/2006|00:08] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[31/12/2006|11:46] C:\DOCUME~1\ALLUSE~1\APPLIC~1\CyberLink
[02/06/2008|21:40] C:\DOCUME~1\ALLUSE~1\APPLIC~1\EPSON
[29/07/2008|16:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ford does hold option
[17/04/2008|20:57] C:\DOCUME~1\ALLUSE~1\APPLIC~1\IM
[17/04/2008|20:56] C:\DOCUME~1\ALLUSE~1\APPLIC~1\IncrediMail
[18/08/2006|19:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\InstallShield
[26/12/2007|17:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kodak
[02/03/2009|19:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[16/08/2006|00:01] C:\DOCUME~1\ALLUSE~1\APPLIC~1\NOS
[04/03/2010|13:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Real
[03/09/2008|15:38] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Secure Solutions
[16/08/2006|00:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\services
[16/08/2006|04:59] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Skype
[06/08/2008|16:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SoftLand Ltd
[26/09/2007|16:55] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Sony Corporation
[03/12/2006|15:40] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec
[02/06/2008|21:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\UDL
[22/11/2006|21:51] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[10/02/2007|11:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Live Toolbar
[21/05/2008|18:51] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
[16/08/2006|01:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Yahoo!

[30/09/2006|17:57] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Identities
[30/09/2006|17:57] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft

[30/09/2006|17:58] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft

[30/09/2006|17:58] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft

--------------------\\ Tâches planifiées dans C:\WINDOWS\tasks

[02/04/2010 18:31][--a------] C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[16/08/2006 00:01][--a------] C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[16/08/2006 00:01][--ah-c---] C:\WINDOWS\tasks\SA.DAT
[10/08/2004 22:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini

--------------------\\ Listing des dossiers dans C:\Program Files

[13/06/2008|23:47] C:\Program Files\ABBYY FineReader 6.0 Sprint
[30/09/2006|17:58] C:\Program Files\Acer WLAN 11g USB Dongle
[30/09/2006|17:58] C:\Program Files\Adobe
[18/02/2009|00:54] C:\Program Files\AGEIA Technologies
[03/12/2006|15:35] C:\Program Files\Alwil Software
[26/12/2007|17:03] C:\Program Files\ATI Technologies
[26/12/2007|17:18] C:\Program Files\Bonjour
[12/04/2007|23:00] C:\Program Files\CFWebAdvancedU
[08/09/2006|12:53] C:\Program Files\ComPlus Applications
[22/11/2006|20:12] C:\Program Files\comsummer
[30/09/2006|17:58] C:\Program Files\CyberLink
[08/06/2008|21:01] C:\Program Files\DivX
[02/06/2008|21:47] C:\Program Files\EPSON
[07/02/2006|20:24] C:\Program Files\Fichiers communs
[16/08/2006|00:05] C:\Program Files\Free
[16/08/2006|03:09] C:\Program Files\FreeDial
[30/09/2006|17:58] C:\Program Files\GemMasterFrench
[16/08/2006|00:21] C:\Program Files\Google
[16/08/2006|00:18] C:\Program Files\InstallShield Installation Information
[01/04/2010|12:01] C:\Program Files\Internet Explorer
[16/08/2006|01:16] C:\Program Files\Java
[16/08/2006|01:44] C:\Program Files\Logitech
[26/06/2008|12:45] C:\Program Files\meet mix eggs
[19/09/2008|12:00] C:\Program Files\Messenger
[17/01/2008|01:00] C:\Program Files\Micro Application
[07/02/2006|21:36] C:\Program Files\Microsoft
[09/05/2007|23:26] C:\Program Files\Microsoft CAPICOM 2.1.0.2
[30/09/2006|17:59] C:\Program Files\microsoft frontpage
[27/11/2006|21:12] C:\Program Files\Microsoft Office
[16/08/2006|01:00] C:\Program Files\Microsoft Silverlight
[21/05/2008|18:54] C:\Program Files\Microsoft SQL Server Compact Edition
[07/02/2006|21:47] C:\Program Files\Microsoft Sync Framework
[11/03/2010|13:02] C:\Program Files\Movie Maker
[05/09/2009|02:45] C:\Program Files\MSBuild
[26/12/2007|17:15] C:\Program Files\MSN
[30/09/2006|17:59] C:\Program Files\MSN Gaming Zone
[16/08/2006|02:40] C:\Program Files\MSN Messenger
[16/08/2006|00:49] C:\Program Files\My Drivers
[18/09/2008|14:25] C:\Program Files\NetMeeting
[30/09/2006|17:59] C:\Program Files\NewTech Infosystems
[16/08/2006|00:01] C:\Program Files\NOS
[30/09/2006|17:59] C:\Program Files\Oca History Tool
[30/09/2006|17:59] C:\Program Files\Online Services
[12/08/2009|23:42] C:\Program Files\Outlook Express
[16/08/2006|04:27] C:\Program Files\QuickTime
[10/03/2007|22:59] C:\Program Files\Real
[30/09/2006|17:59] C:\Program Files\Realtek
[05/09/2009|02:45] C:\Program Files\Reference Assemblies
[16/08/2006|02:02] C:\Program Files\Samsung
[05/04/2007|14:06] C:\Program Files\Services en ligne
[12/08/2009|22:52] C:\Program Files\ShoppingReport
[16/08/2006|04:59] C:\Program Files\Sony
[28/11/2008|17:36] C:\Program Files\Sun
[16/05/2008|19:33] C:\Program Files\TomTom HOME
[16/08/2006|00:29] C:\Program Files\Trend Micro
[17/01/2008|01:01] C:\Program Files\Uninstall Information
[29/01/2009|23:01] C:\Program Files\VideoLAN
[06/12/2008|19:47] C:\Program Files\Vimicro
[29/12/2009|23:53] C:\Program Files\Virtools
[16/01/2009|19:00] C:\Program Files\VirtualDJ
[16/10/2009|23:05] C:\Program Files\Windows Live
[18/08/2006|03:01] C:\Program Files\Windows Live Favorites
[07/02/2006|21:35] C:\Program Files\Windows Live SkyDrive
[16/08/2006|01:00] C:\Program Files\Windows Live Toolbar
[13/01/2007|13:22] C:\Program Files\Windows Media Connect 2
[28/01/2010|15:42] C:\Program Files\Windows Media Player
[18/09/2008|14:25] C:\Program Files\Windows NT
[30/09/2006|17:59] C:\Program Files\Windows Plus
[08/09/2006|12:55] C:\Program Files\WindowsUpdate
[15/08/2008|17:48] C:\Program Files\WinRAR
[30/09/2006|17:59] C:\Program Files\xerox
[05/04/2008|21:15] C:\Program Files\XviD
[16/08/2006|00:22] C:\Program Files\Yahoo!
[16/08/2006|01:14] C:\Program Files\ZHPDiag

--------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs

[18/05/2008|14:39] C:\Program Files\Fichiers communs\Adobe
[27/11/2006|21:13] C:\Program Files\Fichiers communs\Designer
[26/12/2007|17:15] C:\Program Files\Fichiers communs\EPSON
[02/10/2007|14:31] C:\Program Files\Fichiers communs\HTML Executable Viewer
[18/08/2006|19:27] C:\Program Files\Fichiers communs\InstallShield
[22/11/2006|19:03] C:\Program Files\Fichiers communs\Java
[14/12/2008|23:54] C:\Program Files\Fichiers communs\Labtec
[30/09/2006|17:58] C:\Program Files\Fichiers communs\LightScribe
[21/02/2009|02:45] C:\Program Files\Fichiers communs\Microsoft Shared
[30/09/2006|17:58] C:\Program Files\Fichiers communs\MSSoap
[30/09/2006|17:58] C:\Program Files\Fichiers communs\muvee Technologies
[30/09/2006|17:58] C:\Program Files\Fichiers communs\NewTech Infosystems
[30/09/2006|17:58] C:\Program Files\Fichiers communs\ODBC
[26/12/2007|17:14] C:\Program Files\Fichiers communs\Real
[30/09/2006|17:58] C:\Program Files\Fichiers communs\Services
[26/09/2007|16:55] C:\Program Files\Fichiers communs\Sony Shared
[30/09/2006|17:58] C:\Program Files\Fichiers communs\SpeechEngines
[03/12/2006|15:40] C:\Program Files\Fichiers communs\Symantec Shared
[18/09/2008|14:25] C:\Program Files\Fichiers communs\System
[07/02/2006|20:24] C:\Program Files\Fichiers communs\Windows Live
[21/05/2008|18:52] C:\Program Files\Fichiers communs\WindowsLiveInstaller
[26/12/2007|17:15] C:\Program Files\Fichiers communs\xing shared

--------------------\\ Process

( 44 Processes )

... OK !

--------------------\\ Recherche avec S_Lop

Aucun fichier / dossier Lop trouvé !

--------------------\\ Recherche de Fichiers / Dossiers Lop

C:\DOCUME~1\ALLUSE~1\APPLIC~1\ford does hold option
C:\DOCUME~1\alex\LOCALS~1\Temp\nsh498.tmp
C:\DOCUME~1\alex\LOCALS~1\Temp\nshA.tmp
C:\DOCUME~1\alex\Cookies\alex@advertstream[2].txt
C:\DOCUME~1\alex\Cookies\alex@advertising[2].txt
C:\DOCUME~1\alex\Cookies\alex@bigpoint[2].txt
C:\DOCUME~1\alex\Cookies\alex@fr.deepolis.bigpoint[1].txt
C:\DOCUME~1\alex\Cookies\alex@fr.waroftitans.bigpoint[2].txt
C:\DOCUME~1\alex\Cookies\alex@seafight.bigpoint[1].txt
C:\DOCUME~1\alex\Cookies\alex@euroclick[2].txt
C:\DOCUME~1\alex\Cookies\alex@fr.partypoker[1].txt
C:\DOCUME~1\alex\Cookies\alex@partypoker[2].txt
C:\DOCUME~1\alex\Cookies\alex@seafight.bigpoint[1].txt

--------------------\\ Verification du Registre

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

..... OK !

--------------------\\ Verification du fichier Hosts

Fichier Hosts PROPRE


--------------------\\ Recherche de fichiers avec Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2006-08-16 00:12:04
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 848

--------------------\\ Recherche d'autres infections

--------------------\\ ROGUES ..

C:\DOCUME~1\ALLUSE~1\APPLIC~1\SoftLand Ltd

--------------------\\ Cracks & Keygens ..

C:\DOCUME~1\alex\Bureau\Virtual.DJ.v1.07b.Incl.Crack-AGAiN.rar


[F:7331][D:226]-> C:\DOCUME~1\alex\LOCALS~1\Temp
[F:1254][D:0]-> C:\DOCUME~1\alex\Cookies
[F:5594][D:48]-> C:\DOCUME~1\alex\LOCALS~1\TEMPOR~1\content.IE5

1 - "C:\Lop SD\LopR_1.txt" - 16/08/2006| 0:14 - Option : [1]

--------------------\\ Fin du rapport a 0:14:08
0
moment de grace Messages postés 29042 Date d'inscription samedi 6 décembre 2008 Statut Contributeur sécurité Dernière intervention 18 juillet 2013 2 274
3 avril 2010 à 22:13
vu

==> Lop S&D
0
Ccarino Messages postés 183 Date d'inscription jeudi 9 octobre 2008 Statut Membre Dernière intervention 22 août 2011 10
3 avril 2010 à 22:15
Je lance l'option 2 ou 3 après
0
moment de grace Messages postés 29042 Date d'inscription samedi 6 décembre 2008 Statut Contributeur sécurité Dernière intervention 18 juillet 2013 2 274
3 avril 2010 à 22:15
non

postes le rapport option 1 et je t'indiquerai la suite
0
Ccarino Messages postés 183 Date d'inscription jeudi 9 octobre 2008 Statut Membre Dernière intervention 22 août 2011 10
3 avril 2010 à 22:21
Le rapport option 1 de lops&d est posté à 22h13
0
moment de grace Messages postés 29042 Date d'inscription samedi 6 décembre 2008 Statut Contributeur sécurité Dernière intervention 18 juillet 2013 2 274
3 avril 2010 à 22:24
désolé

il m'avait échappé


1)

relances lops&d
option 2 suppression + hosts
poster le rapport

.................

2)

Téléchargez MalwareByte's Anti-Malware (que tu pourras garder ensuite)

http://www.malwarebytes.org/mbam/program/mbam-setup.exe

. Enregistres le sur le bureau
. Double cliques sur le fichier téléchargé pour lancer le processus d'installation.
. Dans l'onglet "mise à jour", cliques sur le bouton Recherche de mise à jour
. Si le pare-feu demande l'autorisation de se connecter pour malwarebytes, accepte
. Une fois la mise à jour terminé
. Rend-toi dans l'onglet, Recherche
. Sélectionnes Exécuter un examen complet (examen assez long)
. Cliques sur Rechercher
. Le scan démarre.
. A la fin de l'analyse, un message s'affiche : L'examen s'est terminé normalement. Cliquez sur 'Afficher les résultats' pour afficher tous les objets trouvés.
. Cliques sur Ok pour poursuivre.
. Si des malwares ont été détectés, clique sur Afficher les résultats
. Sélectionnes tout (ou laisses cochés) et cliques sur Supprimer la sélection Malwarebytes va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.
. Malwarebytes va ouvrir le bloc-notes et y copier le rapport d'analyse.
. Rends toi dans l'onglet rapport/log
. Tu cliques dessus pour l'afficher, une fois affiché
. Tu cliques sur edition en haut du boc notes, et puis sur sélectionner tous
. Tu recliques sur edition et puis sur copier et tu reviens sur le forum et dans ta réponse
. tu cliques droit dans le cadre de la reponse et coller


Si tu as besoin d'aide regarde ces tutoriels :
Aide: https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
http://www.infos-du-net.com/forum/278396-11-tuto-malwarebytes-anti-malware-mbam


0
Ccarino Messages postés 183 Date d'inscription jeudi 9 octobre 2008 Statut Membre Dernière intervention 22 août 2011 10
3 avril 2010 à 22:30
--------------------\\ Lop S&D 4.2.5-0 XP/Vista

Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 3
X86-based PC ( Multiprocessor Free : Intel(R) Pentium(R) 4 CPU 3.06GHz )
BIOS : Default System BIOS
USER : alex ( Administrator )
BOOT : Normal boot
Antivirus : avast! antivirus 4.8.1368 [VPS 100331-2] 4.8.1368 (Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total:113 Go (Free:10 Go)
D:\ (Local Disk) - FAT32 - Total:113 Go (Free:89 Go)
E:\ (CD or DVD)
F:\ (USB)
G:\ (USB)
I:\ (USB)
J:\ (USB)

"C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
Option : [2] ( 16/08/2006| 0:28 )


\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ SUPPRESSION

Supprime! - C:\DOCUME~1\alex\LOCALS~1\Temp\nsh498.tmp
Supprime! - C:\DOCUME~1\alex\LOCALS~1\Temp\nshA.tmp
Supprime! - C:\DOCUME~1\alex\Cookies\alex@advertstream[2].txt
Supprime! - C:\DOCUME~1\alex\Cookies\alex@advertising[2].txt
Supprime! - C:\DOCUME~1\alex\Cookies\alex@bigpoint[2].txt
Supprime! - C:\DOCUME~1\alex\Cookies\alex@fr.deepolis.bigpoint[1].txt
Supprime! - C:\DOCUME~1\alex\Cookies\alex@fr.waroftitans.bigpoint[2].txt
Supprime! - C:\DOCUME~1\alex\Cookies\alex@seafight.bigpoint[1].txt
Supprime! - C:\DOCUME~1\alex\Cookies\alex@euroclick[2].txt
Supprime! - C:\DOCUME~1\alex\Cookies\alex@fr.partypoker[1].txt
Supprime! - C:\DOCUME~1\alex\Cookies\alex@partypoker[2].txt
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\ford does hold option

\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\


--------------------\\ Listing des dossiers dans APPLIC~1

[30/09/2006|17:57] C:\DOCUME~1\ADMINI~1\APPLIC~1\Identities
[30/09/2006|17:57] C:\DOCUME~1\ADMINI~1\APPLIC~1\Microsoft

[16/08/2006|01:20] C:\DOCUME~1\alex\APPLIC~1\Adobe
[18/05/2008|14:37] C:\DOCUME~1\alex\APPLIC~1\AdobeUM
[16/08/2006|00:27] C:\DOCUME~1\alex\APPLIC~1\Apple Computer
[05/04/2007|14:06] C:\DOCUME~1\alex\APPLIC~1\Azureus
[12/04/2007|23:00] C:\DOCUME~1\alex\APPLIC~1\CamfrogWEB
[04/08/2006|21:11] C:\DOCUME~1\alex\APPLIC~1\CyberLink
[31/12/2006|12:54] C:\DOCUME~1\alex\APPLIC~1\DivX
[16/08/2006|01:08] C:\DOCUME~1\alex\APPLIC~1\dvdcss
[16/08/2006|04:58] C:\DOCUME~1\alex\APPLIC~1\EoRezo
[26/12/2007|17:19] C:\DOCUME~1\alex\APPLIC~1\EPSON
[09/08/2009|20:22] C:\DOCUME~1\alex\APPLIC~1\Google
[04/03/2007|15:18] C:\DOCUME~1\alex\APPLIC~1\Help
[02/10/2007|14:31] C:\DOCUME~1\alex\APPLIC~1\HTML Executable
[30/09/2006|17:57] C:\DOCUME~1\alex\APPLIC~1\Identities
[15/05/2008|22:14] C:\DOCUME~1\alex\APPLIC~1\InstallShield
[03/09/2008|20:31] C:\DOCUME~1\alex\APPLIC~1\Lavasoft
[22/11/2006|20:12] C:\DOCUME~1\alex\APPLIC~1\Macromedia
[02/09/2008|17:02] C:\DOCUME~1\alex\APPLIC~1\meet mix eggs
[10/03/2009|17:07] C:\DOCUME~1\alex\APPLIC~1\Microsoft
[29/06/2007|23:19] C:\DOCUME~1\alex\APPLIC~1\MSNInstaller
[22/03/2007|13:07] C:\DOCUME~1\alex\APPLIC~1\PanoramaStudio
[06/08/2008|16:05] C:\DOCUME~1\alex\APPLIC~1\Real
[16/08/2006|02:07] C:\DOCUME~1\alex\APPLIC~1\Samsung
[16/08/2006|00:07] C:\DOCUME~1\alex\APPLIC~1\ShoppingReport
[16/08/2006|20:41] C:\DOCUME~1\alex\APPLIC~1\Skype
[24/11/2006|15:51] C:\DOCUME~1\alex\APPLIC~1\Sun
[12/06/2008|18:51] C:\DOCUME~1\alex\APPLIC~1\U3
[16/08/2006|01:03] C:\DOCUME~1\alex\APPLIC~1\Uniblue
[29/01/2009|23:04] C:\DOCUME~1\alex\APPLIC~1\vlc
[08/08/2008|18:59] C:\DOCUME~1\alex\APPLIC~1\Windows Live Writer
[15/08/2008|15:17] C:\DOCUME~1\alex\APPLIC~1\WinRAR
[16/08/2006|01:27] C:\DOCUME~1\alex\APPLIC~1\Yahoo!

[29/12/2009|23:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\3DVIA
[18/05/2008|14:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[16/08/2006|00:08] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[31/12/2006|11:46] C:\DOCUME~1\ALLUSE~1\APPLIC~1\CyberLink
[02/06/2008|21:40] C:\DOCUME~1\ALLUSE~1\APPLIC~1\EPSON
[17/04/2008|20:57] C:\DOCUME~1\ALLUSE~1\APPLIC~1\IM
[17/04/2008|20:56] C:\DOCUME~1\ALLUSE~1\APPLIC~1\IncrediMail
[18/08/2006|19:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\InstallShield
[26/12/2007|17:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kodak
[02/03/2009|19:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[16/08/2006|00:01] C:\DOCUME~1\ALLUSE~1\APPLIC~1\NOS
[04/03/2010|13:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Real
[03/09/2008|15:38] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Secure Solutions
[16/08/2006|00:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\services
[16/08/2006|04:59] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Skype
[06/08/2008|16:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SoftLand Ltd
[26/09/2007|16:55] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Sony Corporation
[03/12/2006|15:40] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec
[02/06/2008|21:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\UDL
[22/11/2006|21:51] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[10/02/2007|11:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Live Toolbar
[21/05/2008|18:51] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
[16/08/2006|01:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Yahoo!

[30/09/2006|17:57] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Identities
[30/09/2006|17:57] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft

[30/09/2006|17:58] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft

[30/09/2006|17:58] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft

--------------------\\ Tâches planifiées dans C:\WINDOWS\tasks

[02/04/2010 18:31][--a------] C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[16/08/2006 00:01][--a------] C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[16/08/2006 00:01][--ah-c---] C:\WINDOWS\tasks\SA.DAT
[10/08/2004 22:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini

--------------------\\ Listing des dossiers dans C:\Program Files

[13/06/2008|23:47] C:\Program Files\ABBYY FineReader 6.0 Sprint
[30/09/2006|17:58] C:\Program Files\Acer WLAN 11g USB Dongle
[30/09/2006|17:58] C:\Program Files\Adobe
[18/02/2009|00:54] C:\Program Files\AGEIA Technologies
[03/12/2006|15:35] C:\Program Files\Alwil Software
[26/12/2007|17:03] C:\Program Files\ATI Technologies
[26/12/2007|17:18] C:\Program Files\Bonjour
[12/04/2007|23:00] C:\Program Files\CFWebAdvancedU
[08/09/2006|12:53] C:\Program Files\ComPlus Applications
[22/11/2006|20:12] C:\Program Files\comsummer
[30/09/2006|17:58] C:\Program Files\CyberLink
[08/06/2008|21:01] C:\Program Files\DivX
[02/06/2008|21:47] C:\Program Files\EPSON
[07/02/2006|20:24] C:\Program Files\Fichiers communs
[16/08/2006|00:05] C:\Program Files\Free
[16/08/2006|03:09] C:\Program Files\FreeDial
[30/09/2006|17:58] C:\Program Files\GemMasterFrench
[16/08/2006|00:21] C:\Program Files\Google
[16/08/2006|00:18] C:\Program Files\InstallShield Installation Information
[01/04/2010|12:01] C:\Program Files\Internet Explorer
[16/08/2006|01:16] C:\Program Files\Java
[16/08/2006|01:44] C:\Program Files\Logitech
[26/06/2008|12:45] C:\Program Files\meet mix eggs
[19/09/2008|12:00] C:\Program Files\Messenger
[17/01/2008|01:00] C:\Program Files\Micro Application
[07/02/2006|21:36] C:\Program Files\Microsoft
[09/05/2007|23:26] C:\Program Files\Microsoft CAPICOM 2.1.0.2
[30/09/2006|17:59] C:\Program Files\microsoft frontpage
[27/11/2006|21:12] C:\Program Files\Microsoft Office
[16/08/2006|01:00] C:\Program Files\Microsoft Silverlight
[21/05/2008|18:54] C:\Program Files\Microsoft SQL Server Compact Edition
[07/02/2006|21:47] C:\Program Files\Microsoft Sync Framework
[11/03/2010|13:02] C:\Program Files\Movie Maker
[05/09/2009|02:45] C:\Program Files\MSBuild
[26/12/2007|17:15] C:\Program Files\MSN
[30/09/2006|17:59] C:\Program Files\MSN Gaming Zone
[16/08/2006|02:40] C:\Program Files\MSN Messenger
[16/08/2006|00:49] C:\Program Files\My Drivers
[18/09/2008|14:25] C:\Program Files\NetMeeting
[30/09/2006|17:59] C:\Program Files\NewTech Infosystems
[16/08/2006|00:01] C:\Program Files\NOS
[30/09/2006|17:59] C:\Program Files\Oca History Tool
[30/09/2006|17:59] C:\Program Files\Online Services
[12/08/2009|23:42] C:\Program Files\Outlook Express
[16/08/2006|04:27] C:\Program Files\QuickTime
[10/03/2007|22:59] C:\Program Files\Real
[30/09/2006|17:59] C:\Program Files\Realtek
[05/09/2009|02:45] C:\Program Files\Reference Assemblies
[16/08/2006|02:02] C:\Program Files\Samsung
[05/04/2007|14:06] C:\Program Files\Services en ligne
[12/08/2009|22:52] C:\Program Files\ShoppingReport
[16/08/2006|04:59] C:\Program Files\Sony
[28/11/2008|17:36] C:\Program Files\Sun
[16/05/2008|19:33] C:\Program Files\TomTom HOME
[16/08/2006|00:29] C:\Program Files\Trend Micro
[17/01/2008|01:01] C:\Program Files\Uninstall Information
[29/01/2009|23:01] C:\Program Files\VideoLAN
[06/12/2008|19:47] C:\Program Files\Vimicro
[29/12/2009|23:53] C:\Program Files\Virtools
[16/01/2009|19:00] C:\Program Files\VirtualDJ
[16/10/2009|23:05] C:\Program Files\Windows Live
[18/08/2006|03:01] C:\Program Files\Windows Live Favorites
[07/02/2006|21:35] C:\Program Files\Windows Live SkyDrive
[16/08/2006|01:00] C:\Program Files\Windows Live Toolbar
[13/01/2007|13:22] C:\Program Files\Windows Media Connect 2
[28/01/2010|15:42] C:\Program Files\Windows Media Player
[18/09/2008|14:25] C:\Program Files\Windows NT
[30/09/2006|17:59] C:\Program Files\Windows Plus
[08/09/2006|12:55] C:\Program Files\WindowsUpdate
[15/08/2008|17:48] C:\Program Files\WinRAR
[30/09/2006|17:59] C:\Program Files\xerox
[05/04/2008|21:15] C:\Program Files\XviD
[16/08/2006|00:22] C:\Program Files\Yahoo!
[16/08/2006|01:14] C:\Program Files\ZHPDiag

--------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs

[18/05/2008|14:39] C:\Program Files\Fichiers communs\Adobe
[27/11/2006|21:13] C:\Program Files\Fichiers communs\Designer
[26/12/2007|17:15] C:\Program Files\Fichiers communs\EPSON
[02/10/2007|14:31] C:\Program Files\Fichiers communs\HTML Executable Viewer
[18/08/2006|19:27] C:\Program Files\Fichiers communs\InstallShield
[22/11/2006|19:03] C:\Program Files\Fichiers communs\Java
[14/12/2008|23:54] C:\Program Files\Fichiers communs\Labtec
[30/09/2006|17:58] C:\Program Files\Fichiers communs\LightScribe
[21/02/2009|02:45] C:\Program Files\Fichiers communs\Microsoft Shared
[30/09/2006|17:58] C:\Program Files\Fichiers communs\MSSoap
[30/09/2006|17:58] C:\Program Files\Fichiers communs\muvee Technologies
[30/09/2006|17:58] C:\Program Files\Fichiers communs\NewTech Infosystems
[30/09/2006|17:58] C:\Program Files\Fichiers communs\ODBC
[26/12/2007|17:14] C:\Program Files\Fichiers communs\Real
[30/09/2006|17:58] C:\Program Files\Fichiers communs\Services
[26/09/2007|16:55] C:\Program Files\Fichiers communs\Sony Shared
[30/09/2006|17:58] C:\Program Files\Fichiers communs\SpeechEngines
[03/12/2006|15:40] C:\Program Files\Fichiers communs\Symantec Shared
[18/09/2008|14:25] C:\Program Files\Fichiers communs\System
[07/02/2006|20:24] C:\Program Files\Fichiers communs\Windows Live
[21/05/2008|18:52] C:\Program Files\Fichiers communs\WindowsLiveInstaller
[26/12/2007|17:15] C:\Program Files\Fichiers communs\xing shared

--------------------\\ Process

( 42 Processes )

... OK !

--------------------\\ Recherche avec S_Lop

Aucun fichier / dossier Lop trouvé !

--------------------\\ Recherche de Fichiers / Dossiers Lop

Aucun fichier / dossier Lop trouvé !

--------------------\\ Verification du Registre

..... OK !

--------------------\\ Verification du fichier Hosts

Fichier Hosts PROPRE


--------------------\\ Recherche de fichiers avec Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2006-08-16 00:29:38
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 848

--------------------\\ Recherche d'autres infections

--------------------\\ ROGUES ..

C:\DOCUME~1\ALLUSE~1\APPLIC~1\SoftLand Ltd

--------------------\\ Cracks & Keygens ..

C:\DOCUME~1\alex\Bureau\Virtual.DJ.v1.07b.Incl.Crack-AGAiN.rar


[F:7329][D:225]-> C:\DOCUME~1\alex\LOCALS~1\Temp
[F:1245][D:0]-> C:\DOCUME~1\alex\Cookies
[F:5594][D:48]-> C:\DOCUME~1\alex\LOCALS~1\TEMPOR~1\content.IE5

1 - "C:\Lop SD\LopR_1.txt" - 16/08/2006| 0:14 - Option : [1]
2 - "C:\Lop SD\LopR_2.txt" - 16/08/2006| 0:31 - Option : [2]

--------------------\\ Fin du rapport a 0:31:43
0
Ccarino Messages postés 183 Date d'inscription jeudi 9 octobre 2008 Statut Membre Dernière intervention 22 août 2011 10
3 avril 2010 à 22:52
Malwarebytes' Anti-Malware 1.45
www.malwarebytes.org

Version de la base de données: 3950

Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.11

16/08/2006 00:49:58
mbam-log-2006-08-16 (00-49-58).txt

Type d'examen: Examen rapide
Elément(s) analysé(s): 123351
Temps écoulé: 10 minute(s), 48 seconde(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 31
Valeur(s) du Registre infectée(s): 3
Elément(s) de données du Registre infecté(s): 2
Dossier(s) infecté(s): 21
Fichier(s) infecté(s): 34

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):
HKEY_CLASSES_ROOT\CLSID\{100eb1fd-d03e-47fd-81f3-ee91287f9465} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{20ea9658-6bc3-4599-a87d-6371fe9295fc} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{a16ad1e9-f69a-45af-9462-b1c286708842} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{a7cddcdc-beeb-4685-a062-978f5e07ceee} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{c9ccbb35-d123-4a31-affc-9b2933132116} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{cdca70d8-c6a6-49ee-9bed-7429d6c477a2} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{d136987f-e1c4-4ccc-a220-893df03ec5df} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{e343edfc-1e6c-4cb5-aa29-e9c922641c80} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{a7cddcdc-beeb-4685-a062-978f5e07ceee} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{100eb1fd-d03e-47fd-81f3-ee91287f9465} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{c5428486-50a0-4a02-9d20-520b59a9f9b2} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{c5428486-50a0-4a02-9d20-520b59a9f9b3} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{c5428486-50a0-4a02-9d20-520b59a9f9b2} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{c5428486-50a0-4a02-9d20-520b59a9f9b3} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{100eb1fd-d03e-47fd-81f3-ee91287f9465} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\shoppingreport (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\shoppingreport.hbax (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\shoppingreport.hbax.1 (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\shoppingreport.hbinfoband (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\shoppingreport.hbinfoband.1 (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\shoppingreport.iebutton (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\shoppingreport.iebutton.1 (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\shoppingreport.iebuttona (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\shoppingreport.iebuttona.1 (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\shoppingreport.rprtctrl (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\shoppingreport.rprtctrl.1 (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Secure Solutions (Rogue.Multiple) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\ShoppingReport (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\SoftLand Ltd (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\mxlivemedia (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\ShoppingReport (Adware.ShopperReports) -> Quarantined and deleted successfully.

Valeur(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Extensions\CmdMapping\{c5428486-50a0-4a02-9d20-520b59a9f9b2} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Extensions\CmdMapping\{c5428486-50a0-4a02-9d20-520b59a9f9b3} (Adware.ShopperReports) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{90b8b761-df2b-48ac-bbe0-bcc03a819b3b} (Adware.Zango) -> Quarantined and deleted successfully.

Elément(s) de données du Registre infecté(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Dossier(s) infecté(s):
C:\Documents and Settings\All Users\Application Data\Secure Solutions (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Secure Solutions\Antispyware 2008 XP (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Secure Solutions\Antispyware 2008 XP\BASE (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Secure Solutions\Antispyware 2008 XP\DELETED (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Secure Solutions\Antispyware 2008 XP\LOG (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Secure Solutions\Antispyware 2008 XP\SAVED (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\alex\Application Data\ShoppingReport (Adware.ShopperReports) -> Quarantined and deleted successfully.
C:\Documents and Settings\alex\Application Data\ShoppingReport\cs (Adware.ShopperReports) -> Quarantined and deleted successfully.
C:\Documents and Settings\alex\Application Data\ShoppingReport\cs\db (Adware.ShopperReports) -> Quarantined and deleted successfully.
C:\Documents and Settings\alex\Application Data\ShoppingReport\cs\dwld (Adware.ShopperReports) -> Quarantined and deleted successfully.
C:\Documents and Settings\alex\Application Data\ShoppingReport\cs\report (Adware.ShopperReports) -> Quarantined and deleted successfully.
C:\Documents and Settings\alex\Application Data\ShoppingReport\cs\res1 (Adware.ShopperReports) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\SoftLand Ltd (Rogue.XPantiVirus) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\SoftLand Ltd\Antivirus 2008 XP (Rogue.XPantiVirus) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\SoftLand Ltd\Antivirus 2008 XP\BASE (Rogue.XPantiVirus) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\SoftLand Ltd\Antivirus 2008 XP\DELETED (Rogue.XPantiVirus) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\SoftLand Ltd\Antivirus 2008 XP\LOG (Rogue.XPantiVirus) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\SoftLand Ltd\Antivirus 2008 XP\SAVED (Rogue.XPantiVirus) -> Quarantined and deleted successfully.
C:\Program Files\ShoppingReport (Adware.ShopperReports) -> Quarantined and deleted successfully.
C:\Program Files\ShoppingReport\Bin (Adware.ShopperReports) -> Quarantined and deleted successfully.
C:\Program Files\ShoppingReport\Bin\2.5.0 (Adware.ShopperReports) -> Quarantined and deleted successfully.

Fichier(s) infecté(s):
C:\Program Files\ShoppingReport\Bin\2.5.0\ShoppingReport.dll (Adware.ShopperReports) -> Quarantined and deleted successfully.
C:\Documents and Settings\alex\Local Settings\Temp\ShprInstaller.exe (Adware.Shopper) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Secure Solutions\Antispyware 2008 XP\LOG\20080903153859906.log (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Secure Solutions\Antispyware 2008 XP\LOG\20080903212834500.log (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Secure Solutions\Antispyware 2008 XP\LOG\20080904162941015.log (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Secure Solutions\Antispyware 2008 XP\LOG\20080909104028265.log (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Secure Solutions\Antispyware 2008 XP\LOG\20080909171257734.log (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Secure Solutions\Antispyware 2008 XP\LOG\20080911070223656.log (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Secure Solutions\Antispyware 2008 XP\LOG\20080911114010906.log (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Secure Solutions\Antispyware 2008 XP\LOG\20080912135745421.log (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\alex\Application Data\ShoppingReport\cs\Config.xml (Adware.ShopperReports) -> Quarantined and deleted successfully.
C:\Documents and Settings\alex\Application Data\ShoppingReport\cs\db\Aliases.dbs (Adware.ShopperReports) -> Quarantined and deleted successfully.
C:\Documents and Settings\alex\Application Data\ShoppingReport\cs\db\Sites.dbs (Adware.ShopperReports) -> Quarantined and deleted successfully.
C:\Documents and Settings\alex\Application Data\ShoppingReport\cs\dwld\WhiteList.xip (Adware.ShopperReports) -> Quarantined and deleted successfully.
C:\Documents and Settings\alex\Application Data\ShoppingReport\cs\report\aggr_storage.xml (Adware.ShopperReports) -> Quarantined and deleted successfully.
C:\Documents and Settings\alex\Application Data\ShoppingReport\cs\report\send_storage.xml (Adware.ShopperReports) -> Quarantined and deleted successfully.
C:\Documents and Settings\alex\Application Data\ShoppingReport\cs\res1\WhiteList.dbs (Adware.ShopperReports) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\SoftLand Ltd\Antivirus 2008 XP\BASE\vbase.dat (Rogue.XPantiVirus) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\SoftLand Ltd\Antivirus 2008 XP\LOG\20080806164900250.log (Rogue.XPantiVirus) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\SoftLand Ltd\Antivirus 2008 XP\LOG\20080806195338734.log (Rogue.XPantiVirus) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\SoftLand Ltd\Antivirus 2008 XP\LOG\20080806201051484.log (Rogue.XPantiVirus) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\SoftLand Ltd\Antivirus 2008 XP\LOG\20080807171743831.log (Rogue.XPantiVirus) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\SoftLand Ltd\Antivirus 2008 XP\LOG\20080808182703671.log (Rogue.XPantiVirus) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\SoftLand Ltd\Antivirus 2008 XP\LOG\20080808183518312.log (Rogue.XPantiVirus) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\SoftLand Ltd\Antivirus 2008 XP\LOG\20080808191152593.log (Rogue.XPantiVirus) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\SoftLand Ltd\Antivirus 2008 XP\LOG\20080808192117500.log (Rogue.XPantiVirus) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\SoftLand Ltd\Antivirus 2008 XP\LOG\20080809222852921.log (Rogue.XPantiVirus) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\SoftLand Ltd\Antivirus 2008 XP\LOG\20080815130233250.log (Rogue.XPantiVirus) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\SoftLand Ltd\Antivirus 2008 XP\LOG\20080815134333625.log (Rogue.XPantiVirus) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\SoftLand Ltd\Antivirus 2008 XP\LOG\20080815143403625.log (Rogue.XPantiVirus) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\SoftLand Ltd\Antivirus 2008 XP\LOG\20080815144532515.log (Rogue.XPantiVirus) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\SoftLand Ltd\Antivirus 2008 XP\LOG\20080815161147984.log (Rogue.XPantiVirus) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\SoftLand Ltd\Antivirus 2008 XP\LOG\20080815170534906.log (Rogue.XPantiVirus) -> Quarantined and deleted successfully.
C:\Program Files\ShoppingReport\Uninst.exe (Adware.ShopperReports) -> Quarantined and deleted successfully.
0
moment de grace Messages postés 29042 Date d'inscription samedi 6 décembre 2008 Statut Contributeur sécurité Dernière intervention 18 juillet 2013 2 274
4 avril 2010 à 07:23
ok

tu peux vider la quarantaine

refais un nouveau rapport ZHP stp
0
Ccarino Messages postés 183 Date d'inscription jeudi 9 octobre 2008 Statut Membre Dernière intervention 22 août 2011 10
4 avril 2010 à 15:21
La quarantaine a été vidé




http://www.cijoint.fr/cjlink.php?file=cj201004/cijlCKDlH0.txt
0