Pb TR/Rookit.Gen

Résolu
Kanetheundertaker -  
 archet9 -
Bonjour,

J'ai apparemment un virus qu'Avira ne peut supprimer (cf le message trouvé dans le rapport de scan ci-dessous :
Le fichier 'C:\Windows\System32\drivers\zghiwjxu.sys'
contenait un virus ou un programme indésirable 'TR/Rootkit.Gen' [trojan].
Action(s) exécutée(s) :
Erreur lors de la création d'une copie de sécurité du fichier. Le fichier n'a pas été supprimé. Code d'erreur : 26004.
Impossible de trouver le fichier source.
Tentative en cours d'exécuter l'action à l'aide de la bibliothèque ARK.
Erreur dans la bibliothèque ARK.
Impossible de repérer le fichier pour sa suppression après le redémarrage. Cause possible : Un périphérique attaché au système ne fonctionne pas correctement.
.

Savez-vous comment je puis m'en débarasser?
Par avance, merci

21 réponses

  • 1
  • 2
  1. archet9
     
    Salut car à cette heure bonjour ou bonsoir!!!????

    'C:\Windows\System32\drivers\zghiwjxu.sys'

    C'est effectivement un "Rootkit"

    On va le virer.

    Pour cela:

    Télécharge The Avenger par Swandog46 sur ton Bureau:

    http://www.geekstogo.com/forum/files/file/393-the-avenger-by-swandog46/

    Click sur Avenger.zip pour ouvrir le fichier
    Extraire avenger.exe sur votre bureau

    . Maintenant, lance The Avenger en cliquant sur son icône du bureau.
    . Copie tout le texte en gras ci-dessous : mettre en surbrillance et appuyer sur les touches(Ctrl+C):

    Drivers to disable:
    zghiwjxu
    Drivers to delete:
    zghiwjxu
    Files to delete:
    C:\Windows\System32\drivers\zghiwjxu.sys


    . Colle ce texte (Ctrl+V) dans le cadre :

    Input script here

    . Appuie sur Execute

    . Le pc va redémarrer

    . Colle le rapport qui aparaitra.

    a+

    ........
    0
  2. dédétraqué Messages postés 4522 Statut Contributeur sécurité 286
     
    Salut Kanetheundertaker

    Bonne désinfection avec archet9

    @++ :)
    0
  3. dédétraqué Messages postés 4522 Statut Contributeur sécurité 286
     
    Salut archet9

    Rapide sur la gâchette :)))
    0
  4. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  5. archet9
     
    Bah ...Tous les éléments sont la....!!!!!

    contenait un virus ou un programme indésirable 'TR/Rootkit.Gen' [trojan].

    a+

    ........
    0
  6. kanetheundertaker
     
    Bonjour,

    J'ai appliqué la procédure d'Archet9.
    Voici la log :
    Logfile of The Avenger Version 2.0, (c) by Swandog46
    http://swandog46.geekstogo.com

    Platform: Windows Vista

    *******************

    Script file opened successfully.
    Script file read successfully.

    Backups directory opened successfully at C:\Avenger

    *******************

    Beginning to process script file:

    Rootkit scan active.
    No rootkits found!

    Driver "zghiwjxu" disabled successfully.
    Driver "zghiwjxu" deleted successfully.
    File "C:\Windows\System32\drivers\zghiwjxu.sys" deleted successfully.

    Completed script processing.

    *******************

    Finished! Terminate.

    Apparemment, cela a l'air d'avoir fonctionné.
    Je vais rescanner l'ordi avec Avira et vous tiens au courant.

    Déjà un grand merci pour votre aide.
    0
  7. archet9
     
    Désactives le contrôle des comptes utilisateurs (tu le réactiveras après ta désinfection):

    https://www.zebulon.fr/astuces/pratique/220-desactiver-l-uac-dans-vista.html

    ensuite fais ceci:

    ---> Télécharges ComboFix.exe de sUBs sur ton Bureau :

    http://download.bleepingcomputer.com/sUBs/ComboFix.exe

    /!\ Déconnecte-toi du net et ferme toutes les applications, antivirus et antispyware y compris /!\

    ---> "Clique droit" sur Combofix.exe et choisis: "Exécuter en tant qu'administrateur"
    Un "pop-up" va apparaître qui dit que "ComboFix est utilisé à vos risques et avec aucune garantie...".
    Acceptes en cliquant sur "Oui"

    ---> Mets-le en langue française F
    Tape sur la touche 1 (Yes) pour démarrer le scan.

    /!\ Ne touche à rien tant que le scan n'est pas terminé. /!\

    En fin de scan, il est possible que ComboFix ait besoin de redémarrer le PC pour finaliser la désinfection, laisse-le faire.

    Une fois le scan achevé, un rapport va s'afficher : Poste son contenu

    /!\ Réactive la protection en temps réel de ton antivirus et de ton antispyware avant de te reconnecter à Internet. /!\

    Note : Le rapport se trouve également là : C:\ComboFix.txt

    a+
    0
  8. Kanetheundertakerr Messages postés 7 Statut Membre
     
    Bonsoir,
    Ci-joint, le rapport de ComboFix. Pour info, l'antivirus a tourné dans la journée est n'a rien détecté.
    Pour ma culture générale, j'ai une question concernant TR/Rootkit.Gen : quels sont ses effets?
    0
  9. Kanetheundertakerr Messages postés 7 Statut Membre
     
    ComboFix 10-05-26.01 - Zeus 26/05/2010 20:05:31.2.2 - x86
    Microsoft® Windows Vista(TM) Édition Familiale Premium 6.0.6000.0.1252.33.1036.18.2046.1247 [GMT 2:00]
    Lancé depuis: c:\users\Zeus\Desktop\ComboFix.exe
    AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
    SP: AntiVir Desktop *disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
    SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
    .

    (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\users\Zeus\AppData\Local\Windows Server
    c:\users\Zeus\AppData\Local\Windows Server\flags.ini
    c:\users\Zeus\AppData\Local\Windows Server\uses32.dat
    c:\windows\jestertb.dll
    c:\windows\system32\hlp.dat

    .
    ((((((((((((((((((((((((((((( Fichiers créés du 2010-04-26 au 2010-05-26 ))))))))))))))))))))))))))))))))))))
    .

    2010-05-26 18:15 . 2010-05-26 18:16 -------- d-----w- c:\users\Zeus\AppData\Local\temp
    2010-05-26 18:15 . 2010-05-26 18:15 -------- d-----w- c:\users\Default\AppData\Local\temp
    2010-05-26 17:53 . 2010-05-26 17:53 320000 ----a-w- c:\windows\system32\CF2524.exe
    2010-05-25 19:11 . 2010-05-25 19:11 -------- d-----w- c:\programdata\McAfee
    2010-05-25 19:11 . 2010-05-25 19:11 -------- d-----w- c:\program files\McAfee Security Scan
    2010-05-16 21:17 . 2010-05-16 21:17 -------- d-----w- C:\PyGrenouille
    2010-05-09 17:55 . 2010-05-09 17:55 -------- d-----w- c:\program files\iPod
    2010-05-09 17:55 . 2010-05-09 17:57 -------- d-----w- c:\program files\iTunes
    2010-05-09 17:50 . 2010-05-09 17:50 -------- d-----w- c:\program files\Bonjour
    2010-05-08 23:09 . 2010-05-08 23:10 -------- d-----w- c:\program files\The KMPlayer FR
    2010-05-08 23:02 . 2010-05-08 23:02 -------- d-----w- c:\program files\CoreCodec
    2010-05-08 22:17 . 2010-05-08 22:17 0 ----a-w- c:\windows\ativpsrm.bin
    2010-05-08 22:15 . 2010-05-08 22:22 -------- d-----w- c:\program files\ATI TechnologiesBis
    2010-05-08 22:14 . 2008-01-09 19:58 237568 ----a-w- c:\windows\system32\Oemdspif.dll
    2010-05-08 22:14 . 2008-01-09 19:44 9773056 ----a-w- c:\windows\system32\atioglxx.dll
    2010-05-08 22:14 . 2008-01-09 22:43 3483648 ----a-w- c:\windows\system32\drivers\atikmdag.sys
    2010-05-08 22:14 . 2008-01-09 19:59 368640 ----a-w- c:\windows\system32\ATIDEMGX.dll
    2010-05-08 22:14 . 2008-01-09 19:58 43520 ----a-w- c:\windows\system32\ati2edxx.dll
    2010-05-08 22:14 . 2008-01-09 19:58 245760 ----a-w- c:\windows\system32\Ati2evxx.dll
    2010-05-08 22:14 . 2008-01-09 19:57 643072 ----a-w- c:\windows\system32\Ati2evxx.exe
    2010-05-08 22:14 . 2008-01-09 19:50 1519616 ----a-w- c:\windows\system32\atidxx32.dll
    2010-05-08 22:14 . 2008-01-09 19:22 47104 ----a-w- c:\windows\system32\amdpcom32.dll
    2010-05-08 22:14 . 2008-01-09 19:11 49152 ----a-w- c:\windows\system32\drivers\ati2erec.dll
    2010-05-08 22:14 . 2007-11-08 15:54 159146 ----a-w- c:\windows\system32\atiicdxx.dat
    2010-05-08 22:08 . 2010-05-08 22:08 -------- d-----w- C:\AMD2
    2010-05-08 12:59 . 2010-05-08 12:59 -------- d-----w- c:\users\Zeus\AppData\Local\Adobe
    2010-05-08 12:57 . 2010-05-08 12:58 -------- d-----w- c:\program files\Common Files\Adobe
    2010-05-08 11:41 . 2010-05-08 11:41 -------- d-----w- c:\program files\JRE
    2010-05-08 06:58 . 2010-05-08 07:15 411368 ----a-w- c:\windows\system32\deployJava1.dll
    2010-05-06 21:13 . 2010-05-06 21:13 -------- d-----w- c:\users\Zeus\AppData\Roaming\com.adobe.example.widget-programmes.40247E01796E652D304FB5752B197AB47987A585.1
    2010-05-06 21:13 . 2010-05-06 21:13 -------- d-----w- c:\program files\widget_programmes
    2010-04-30 00:31 . 2010-04-30 00:31 -------- d-----w- c:\windows\system32\oodag
    2010-04-29 22:54 . 2010-04-29 22:54 -------- d-----w- c:\users\Zeus\AppData\Local\O&O
    2010-04-29 22:52 . 2010-04-29 22:52 -------- d-----w- c:\program files\OO Software
    2010-04-28 13:45 . 2010-04-28 13:45 73000 ----a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 9.1.1.12\SetupAdmin.exe
    0
  10. Kanetheundertakerr Messages postés 7 Statut Membre
     
    .
    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2010-05-26 05:22 . 2007-11-02 20:16 -------- d-----w- c:\users\Zeus\AppData\Roaming\dvdcss
    2010-05-26 05:22 . 2007-09-15 21:00 -------- d-----w- c:\users\Zeus\AppData\Roaming\GHISLER
    2010-05-26 05:09 . 2009-07-18 07:05 -------- d-----w- c:\users\Zeus\AppData\Roaming\vlc
    2010-05-25 22:23 . 2009-05-04 22:46 -------- d-----w- c:\users\Zeus\AppData\Roaming\FileZilla
    2010-05-25 21:57 . 2007-12-09 13:05 -------- d-----w- c:\program files\Mozilla Thunderbird
    2010-05-25 21:50 . 2010-01-21 22:40 -------- d-----w- c:\users\Zeus\AppData\Roaming\QuickScan
    2010-05-25 19:14 . 2008-10-04 17:21 -------- d-----w- c:\programdata\NOS
    2010-05-22 06:32 . 2006-11-02 15:48 693516 ----a-w- c:\windows\system32\perfh00C.dat
    2010-05-22 06:32 . 2006-11-02 15:48 118782 ----a-w- c:\windows\system32\perfc00C.dat
    2010-05-20 00:01 . 2008-11-26 21:40 -------- d-----w- c:\program files\a-squared Free
    2010-05-19 19:13 . 2009-06-05 05:15 -------- d-----w- c:\users\Zeus\AppData\Roaming\XBMC
    2010-05-18 20:29 . 2009-05-01 16:27 1 ----a-w- c:\users\Zeus\AppData\Roaming\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
    2010-05-12 09:21 . 2009-10-04 19:48 221568 ------w- c:\windows\system32\MpSigStub.exe
    2010-05-09 17:55 . 2007-09-23 20:40 -------- d-----w- c:\program files\Common Files\Apple
    2010-05-09 17:52 . 2010-04-07 05:32 -------- d-----w- c:\program files\QuickTime
    2010-05-08 22:21 . 2007-09-15 19:03 -------- d-----w- c:\program files\ATI Technologies
    2010-05-08 12:17 . 2007-09-15 20:18 71856 ----a-w- c:\users\Zeus\AppData\Local\GDIPFONTCACHEV1.DAT
    2010-05-08 11:40 . 2009-05-01 16:25 -------- d-----w- c:\program files\OpenOffice.org 3
    2010-05-08 11:35 . 2007-04-18 05:44 -------- d-----w- c:\program files\Java
    2010-05-08 10:57 . 2008-02-18 20:40 -------- d-----w- c:\program files\CCleaner
    2010-05-08 07:14 . 2010-05-08 07:14 0 ----a-w- c:\windows\system32\REN2953.tmp
    2010-05-08 07:14 . 2010-05-08 07:14 0 ----a-w- c:\windows\system32\REN2952.tmp
    2010-05-08 07:14 . 2010-05-08 07:14 0 ----a-w- c:\windows\system32\REN2941.tmp
    2010-05-08 06:58 . 2008-06-22 12:30 -------- d-----w- c:\program files\Common Files\Java
    2010-05-08 06:58 . 2010-05-08 06:58 0 ----a-w- c:\windows\system32\REN8B7E.tmp
    2010-05-08 06:58 . 2010-05-08 06:58 0 ----a-w- c:\windows\system32\REN8B7D.tmp
    2010-05-08 06:58 . 2010-05-08 06:58 0 ----a-w- c:\windows\system32\REN8B7C.tmp
    2010-05-06 21:12 . 2009-01-04 08:23 -------- d-----w- c:\program files\Common Files\Adobe AIR
    2010-05-06 21:12 . 2008-06-03 20:29 38784 ----a-w- c:\users\Zeus\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
    2010-05-02 21:02 . 2007-10-20 08:20 -------- d-----w- c:\program files\QuickPar
    2010-04-29 21:33 . 2009-09-05 17:58 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
    2010-04-29 20:55 . 2008-07-07 18:18 -------- d-----w- c:\program files\Nero
    2010-04-29 20:55 . 2007-04-18 07:08 -------- d-----w- c:\program files\myphotobook
    2010-04-29 20:55 . 2008-09-16 22:20 -------- d-----w- c:\program files\Miranda IM
    2010-04-29 20:55 . 2007-09-15 19:05 -------- d-----w- c:\program files\Camera Assistant Software for Toshiba
    2010-04-29 20:55 . 2009-11-29 18:30 -------- d-----w- c:\program files\Alt WAV MP3 WMA OGG Converter
    2010-04-29 20:55 . 2008-08-19 20:38 -------- d-----w- c:\program files\Apple Software Update
    2010-04-29 20:55 . 2008-03-09 18:19 -------- d-----w- c:\program files\Audacity
    2010-04-29 20:55 . 2008-05-02 23:37 -------- d-----w- c:\program files\7-Zip
    2010-04-29 20:52 . 2008-05-02 23:01 -------- d-----w- c:\program files\Project64 1.6
    2010-04-29 20:52 . 2008-05-02 22:03 -------- d-----w- c:\program files\OpenAL
    2010-04-29 20:52 . 2007-04-18 06:05 -------- d-----w- c:\program files\ltmoh
    2010-04-29 20:51 . 2008-09-15 20:28 -------- d-----w- c:\program files\GSPOT
    2010-04-29 20:51 . 2009-05-04 22:46 -------- d-----w- c:\program files\FileZilla FTP Client
    2010-04-29 13:39 . 2009-09-05 17:58 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2010-04-29 13:39 . 2009-09-05 17:58 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
    2010-04-18 20:35 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
    2010-04-14 19:45 . 2010-04-14 19:45 -------- d-----w- c:\program files\SystemRequirementsLab
    2010-04-14 19:45 . 2010-04-14 19:45 84480 ----a-w- c:\users\Zeus\AppData\Roaming\SystemRequirementsLab\srlproxy_intel_4.1.66.0A.dll
    2010-04-14 19:45 . 2010-04-14 19:45 -------- d-----w- c:\users\Zeus\AppData\Roaming\SystemRequirementsLab
    2010-04-08 11:20 . 2010-04-08 11:20 91424 ----a-w- c:\windows\system32\dnssd.dll
    2010-04-08 11:20 . 2010-04-08 11:20 107808 ----a-w- c:\windows\system32\dns-sd.exe
    2010-04-07 05:42 . 2010-04-07 05:39 -------- d-----w- c:\programdata\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
    2010-04-07 05:17 . 2008-06-22 08:25 -------- d-----w- c:\program files\Safari
    2010-04-07 05:12 . 2010-04-07 05:12 79144 ----a-w- c:\programdata\Apple Computer\Installer Cache\Safari 5.31.22.7\SetupAdmin.exe
    2010-04-07 04:40 . 2007-09-22 20:01 -------- d-----w- c:\programdata\Yahoo! Companion
    2010-03-09 16:54 . 2010-04-11 15:44 832512 ----a-w- c:\windows\system32\wininet.dll
    2010-03-09 16:50 . 2010-04-11 15:44 56320 ----a-w- c:\windows\system32\iesetup.dll
    2010-03-09 16:50 . 2010-04-11 15:44 78336 ----a-w- c:\windows\system32\ieencode.dll
    2010-03-09 16:50 . 2010-04-11 15:44 52736 ----a-w- c:\windows\AppPatch\iebrshim.dll
    2010-03-09 16:48 . 2010-04-11 15:44 72704 ----a-w- c:\windows\system32\admparse.dll
    2010-03-09 14:17 . 2010-04-11 15:44 26624 ----a-w- c:\windows\system32\ieUnatt.exe
    2010-03-09 12:43 . 2010-04-11 15:44 48128 ----a-w- c:\windows\system32\mshtmler.dll
    2010-03-04 19:24 . 2010-04-16 19:03 434176 ----a-w- c:\windows\system32\vbscript.dll
    2007-12-03 19:51 . 2007-11-08 21:16 72 --sh--w- c:\windows\S2CCB746C.tmp
    .
    0
  11. Kanetheundertakerr Messages postés 7 Statut Membre
     
    ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2006-11-02 125440]
    "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 201728]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2007-07-10 1006264]
    "RtHDVCpl"="RtHDVCpl.exe" [2007-06-13 4489216]
    "NDSTray.exe"="NDSTray.exe" [BU]
    "SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-07-27 204800]
    "avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
    "OODefragTray"="c:\program files\OO Software\Defrag\oodtray.exe" [2009-09-25 2524416]
    "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-04-04 36272]
    "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768]
    "StartCCC"="c:\program files\ATI TechnologiesBis\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
    "AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-04-13 47392]
    "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-17 421888]
    "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-04-28 142120]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "TOSHIBA Online Product Information"="c:\program files\TOSHIBA\Toshiba Online Product Information\topi.exe" [2009-03-16 6158240]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "EnableLUA"= 0 (0x0)

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
    "aux1"=wdmaud.drv

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
    BootExecute REG_MULTI_SZ autocheck autochk *\0OODBS

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
    @="Service"

    [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Microsoft Office.lnk]
    path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Office.lnk
    backup=c:\windows\pss\Microsoft Office.lnk.CommonStartup
    backupExtension=.CommonStartup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\00TCrdMain]
    2007-05-22 14:32 538744 ----a-w- c:\program files\TOSHIBA\FlashCards\TCrdMain.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
    2010-03-24 18:17 952768 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
    2010-04-04 05:42 36272 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AppleSyncNotifier]
    2010-04-13 00:29 47392 ----a-w- c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HSON]
    2006-12-07 14:49 55416 ----a-w- c:\program files\TOSHIBA\TBS\HSON.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
    2010-04-28 13:06 142120 ----a-w- c:\program files\iTunes\iTunesHelper.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
    2010-03-17 19:53 421888 ----a-w- c:\program files\QuickTime\QTTask.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SmoothView]
    2007-05-23 13:57 509496 ----a-w- c:\program files\TOSHIBA\SmoothView\SmoothView.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Toshiba Registration]
    2007-02-19 14:00 571024 ----a-w- c:\program files\TOSHIBA\Registration\ToshibaRegistration.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TPwrMain]
    2007-03-29 08:39 411192 ----a-w- c:\program files\TOSHIBA\Power Saver\TPwrMain.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-3513664532-1852345973-900257888-1000]
    "EnableNotificationsRef"=dword:00000001

    R0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2008-11-13 716272]
    R2 a2freeAeLookupSvc;a-squared Free Service a2freeAeLookupSvc;c:\windows\TEMP\acrounlebk.exe service [x]
    R2 vmserverdWin32;VMware Registration Service;c:\program files\VMware\VMware Server\vmserverdWin32.exe [x]
    R3 ASPI;Advanced SCSI Programming Interface Driver;c:\windows\System32\DRIVERS\ASPI32.sys [2002-07-17 84832]
    R3 cpudrv;cpudrv;c:\program files\SystemRequirementsLab\cpudrv.sys [2009-12-18 11336]
    R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [x]
    R3 TpChoice;Touch Pad Detection Filter driver;c:\windows\system32\DRIVERS\TpChoice.sys [x]
    S0 CplIR;Embedded IR Driver;c:\windows\system32\DRIVERS\CplIR.SYS [2007-03-06 14848]
    S0 iaNvStor;Intel(R) Turbo Memory Technology NAND Controller;c:\windows\system32\DRIVERS\iaNvStor.sys [2007-03-10 210432]
    S2 a2free;a-squared Free Service;c:\program files\a-squared Free\a2service.exe [2010-04-15 1872320]
    S2 AntiVirSchedulerService;Avira AntiVir Planificateur;c:\program files\Avira\AntiVir Desktop\sched.exe [2009-07-17 108289]
    S2 TempoMonitoringService;Notebook Performance Tuning Service ;c:\program files\Toshiba TEMPRO\TempoSVC.exe [2008-11-05 99720]
    S3 NETw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\DRIVERS\NETw5v32.sys [2009-10-26 4247552]

    .
    .
    0
  12. Kanetheundertakerr Messages postés 7 Statut Membre
     
    ------- Examen supplémentaire -------
    .
    uStart Page = hxxp://www.yahoo.com/
    mStart Page = hxxp://www.yahoo.com/
    mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
    uInternet Settings,ProxyOverride = *.local
    uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*https://fr.yahoo.com/?p=us
    IE: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
    IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
    IE: {{C08CAF1D-C0A3-40D5-9970-06D067EAC017} - http://www.webtip.ch/cgi-bin/toshiba/tracker_url.pl?FR
    Trusted Zone: clinnav.com\www
    Trusted Zone: gouv.fr\cfspart.impots
    Trusted Zone: gouv.fr\www.impot
    .
    - - - - ORPHELINS SUPPRIMES - - - -

    HKCU-Run-gotnewupdate000.exe - c:\users\Zeus\AppData\Roaming\A0961AA9D656B93FFCD74955981ABAD0\gotnewupdate000.exe
    HKLM-Run-IaNvSrv - c:\program files\Intel\Intel Matrix Storage Manager\OROM\IaNvSrv\IaNvSrv.exe
    AddRemove-7-Zip - c:\program files\7-Zip\Uninstall.exe
    AddRemove-InstallShield_{51B4E156-14A5-4904-9AE4-B1AA2A0E46BE} - c:\progra~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe
    AddRemove-InstallShield_{5279374D-87FE-4879-9385-F17278EBB9D3} - c:\progra~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe
    AddRemove-InstallShield_{617C36FD-0CBE-4600-84B2-441CEB12FADF} - c:\program files\InstallShield Installation Information\{617C36FD-0CBE-4600-84B2-441CEB12FADF}\setup.exe
    AddRemove-InstallShield_{620BBA5E-F848-4D56-8BDA-584E44584C5E} - c:\progra~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe
    AddRemove-InstallShield_{A6D4234C-CB02-4048-AC3E-AD09404FA35A} - c:\progra~1\COMMON~1\INSTAL~1\Driver\1050\INTEL3~1\IDriver.exe
    AddRemove-InstallShield_{DB780B85-B4B5-4864-A49C-9B706B169C93} - c:\program files\InstallShield Installation Information\{DB780B85-B4B5-4864-A49C-9B706B169C93}\setup.exe
    AddRemove-InstallShield_{FEDD27A0-B306-45EF-BF58-B527406B42C8} - c:\program files\InstallShield Installation Information\{FEDD27A0-B306-45EF-BF58-B527406B42C8}\setup.exe
    AddRemove-Miranda IM - c:\program files\Miranda IM\Uninstall.exe
    AddRemove-mIRC - c:\program files\mIRC\uninstall.exe
    AddRemove-Mozilla Firefox (3.6.3) - c:\program files\Mozilla Firefox\uninstall\helper.exe
    AddRemove-MP3 Player Recovery Tool_is1 - c:\program files\Creative\MP3 Player Recovery Tool\unins000.exe
    AddRemove-myphotobook - c:\program files\myphotobook\uninst.exe
    AddRemove-OpenAL - c:\program files\OpenAL\oalinst.exe
    AddRemove-{2290A680-4083-410A-ADCC-7092C67FC052} - c:\program files\InstallShield Installation Information\{2290A680-4083-410A-ADCC-7092C67FC052}\setup.exe
    AddRemove-{37C866E4-AA67-4725-9E95-A39968DD7960} - c:\program files\InstallShield Installation Information\{37C866E4-AA67-4725-9E95-A39968DD7960}\setup.exe
    AddRemove-{6C5F3BDC-0A1B-4436-A696-5939629D5C31} - c:\program files\InstallShield Installation Information\{6C5F3BDC-0A1B-4436-A696-5939629D5C31}\setup.exe
    AddRemove-{78C6A78A-8B03-48C8-A47C-78BA1FCA2307} - c:\program files\InstallShield Installation Information\{78C6A78A-8B03-48C8-A47C-78BA1FCA2307}\setup.exe
    AddRemove-{8833FFB6-5B0C-4764-81AA-06DFEED9A476} - c:\program files\InstallShield Installation Information\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}\setup.exe
    AddRemove-{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E} - c:\program files\Intel\Intel Matrix Storage Manager\Uninstall\imsmudlg.exe
    AddRemove-{C4A4722E-79F9-417C-BD72-8D359A090C97} - c:\program files\InstallShield Installation Information\{C4A4722E-79F9-417C-BD72-8D359A090C97}\setup.exe
    AddRemove-{EBA29752-DDD2-4B62-B2E3-9841F92A3E3A} - c:\program files\InstallShield Installation Information\{EBA29752-DDD2-4B62-B2E3-9841F92A3E3A}\setup.exe

    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2010-05-26 20:16
    Windows 6.0.6000 NTFS

    Recherche de processus cachés ...

    Recherche d'éléments en démarrage automatique cachés ...

    Recherche de fichiers cachés ...

    Scan terminé avec succès
    Fichiers cachés: 0

    **************************************************************************
    .
    0
  13. Kanetheundertakerr Messages postés 7 Statut Membre
     
    --------------------- CLES DE REGISTRE BLOQUEES ---------------------

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.032\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.032"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.abr\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.abr"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.amr\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.amr"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ani\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.ani"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.arw\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.arw"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bay\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.bay"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bmp\UserChoice]
    @Denied: (2) (LocalSystem)
    @Denied: (2) (S-1-5-21-3513664532-1852345973-900257888-1000)
    "Progid"="ACDSee 10.0.bmp"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bw\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.bw"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bwf\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.bwf"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cel\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.cel"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cr2\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.cr2"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.crw\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.crw"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cs1\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.cs1"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cur\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.cur"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dcr\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.dcr"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dcx\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.dcx"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dib\UserChoice]
    @Denied: (2) (LocalSystem)
    @Denied: (2) (S-1-5-21-3513664532-1852345973-900257888-1000)
    "Progid"="ACDSee 10.0.dib"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.djv\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.djv"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.djvu\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.djvu"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dng\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.dng"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.emf\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.emf"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eps\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.eps"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.erf\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.erf"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.fff\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.fff"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.fpx\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.fpx"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.gif\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.gif"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.hdr\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.hdr"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.icl\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.icl"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.icn\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.icn"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.iff\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.iff"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ilbm\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.ilbm"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.int\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.int"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.inta\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.inta"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.iw4\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.iw4"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.j2c\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.j2c"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.j2k\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.j2k"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jbr\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.jbr"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jfif\UserChoice]
    @Denied: (2) (LocalSystem)
    @Denied: (2) (S-1-5-21-3513664532-1852345973-900257888-1000)
    "Progid"="ACDSee 10.0.jfif"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jif\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.jif"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jp2\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.jp2"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpc\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.jpc"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpe\UserChoice]
    @Denied: (2) (LocalSystem)
    @Denied: (2) (S-1-5-21-3513664532-1852345973-900257888-1000)
    "Progid"="ACDSee 10.0.jpe"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpeg\UserChoice]
    @Denied: (2) (LocalSystem)
    @Denied: (2) (S-1-5-21-3513664532-1852345973-900257888-1000)
    "Progid"="ACDSee 10.0.jpeg"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpg\UserChoice]
    @Denied: (2) (LocalSystem)
    @Denied: (2) (S-1-5-21-3513664532-1852345973-900257888-1000)
    "Progid"="ACDSee 10.0.jpg"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpk\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.jpk"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpx\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.jpx"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.kar\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.kar"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.kdc\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.kdc"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.lbm\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.lbm"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m15\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.m15"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m1a\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.m1a"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m2a\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.m2a"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m75\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.m75"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mef\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.mef"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mos\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.mos"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpv\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.mpv"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mrw\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.mrw"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.nef\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.nef"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.orf\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.orf"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pbm\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.pbm"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pbr\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.pbr"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pcd\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.pcd"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pct\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.pct"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pcx\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.pcx"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pef\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.pef"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pgm\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.pgm"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pic\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.pic"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pics\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.pics"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pict\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.pict"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pix\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.pix"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.png\UserChoice]
    @Denied: (2) (LocalSystem)
    @Denied: (2) (S-1-5-21-3513664532-1852345973-900257888-1000)
    "Progid"="ACDSee 10.0.png"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ppm\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.ppm"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.psd\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.psd"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.psp\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.psp"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pspbrush\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.pspbrush"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pspimage\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.pspimage"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.qcp\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.qcp"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.qtpf\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.qtpf"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.raf\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.raf"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ras\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.ras"
    0
  14. Kanetheundertakerr Messages postés 7 Statut Membre
     
    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.raw\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.raw"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rgb\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.rgb"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rgba\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.rgba"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rle\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.rle"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rsb\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.rsb"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sdv\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.sdv"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sfil\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.sfil"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sgi\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.sgi"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.smf\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.smf"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sml\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.sml"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sr2\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.sr2"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.srf\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.srf"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.swa\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.swa"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tga\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.tga"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.thm\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.thm"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tif\UserChoice]
    @Denied: (2) (LocalSystem)
    @Denied: (2) (S-1-5-21-3513664532-1852345973-900257888-1000)
    "Progid"="ACDSee 10.0.tif"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tiff\UserChoice]
    @Denied: (2) (LocalSystem)
    @Denied: (2) (S-1-5-21-3513664532-1852345973-900257888-1000)
    "Progid"="ACDSee 10.0.tiff"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ttc\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.ttc"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ttf\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.ttf"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ulw\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.ulw"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.v10o\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.v10o"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.v10p\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.v10p"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.v10pf\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.v10pf"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vfw\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.vfw"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wbm\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.wbm"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wbmp\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.wbmp"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmf\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.wmf"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xbm\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.xbm"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xif\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.xif"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xmp\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.xmp"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xpm\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="ACDSee 10.0.xpm"

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{614400F9-E0F5-B408-FF72-3C85DFB0F66D}*]
    "maajiecpbjaegfbjggmfnmlpem"=hex:61,61,00,76

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
    "??"=hex:34,28,65,c9,70,52,ba,b7,ae,79,93,17,55,c3,8a,66,04,18,8b,f0,44,e0,13,
    94,6e,bf,0d,05,fb,4e,27,1d,2e,fa,70,5e,17,61,85,a7,90,03,ca,33,d7,15,b3,5d,\
    "??"=hex:94,be,59,6e,ef,e0,a4,bd,b0,d1,73,b0,00,ab,c5,55

    [HKEY_USERS\S-1-5-21-3513664532-1852345973-900257888-1000\Software\SecuROM\License information*]
    @Allowed: (Read) (RestrictedCode)
    "datasecu"=hex:2a,3c,94,d3,de,bf,4a,b6,4c,d7,45,6a,69,9f,55,1c,9b,72,fd,64,ce,
    e8,60,29,11,5c,16,94,bc,8a,01,00,19,42,b6,10,d9,61,8e,cd,d1,b3,bc,4e,c4,94,\
    "rkeysecu"=hex:90,b3,86,8b,6f,99,8a,9c,2b,de,94,35,76,fa,86,c4

    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    "MSCurrentCountry"=dword:0000003d

    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    "MSCurrentCountry"=dword:00000000

    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    "MSCurrentCountry"=dword:00000000

    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    .
    Heure de fin: 2010-05-26 20:20:52
    ComboFix-quarantined-files.txt 2010-05-26 18:20
    ComboFix2.txt 2009-07-16 22:02

    Avant-CF: 9 533 648 896 octets libres
    Après-CF: 9 773 252 608 octets libres

    - - End Of File - - 75F17C91710CDD5DBB85F9EBB105917E
    0
  15. archet9
     
    Pour cotrole:

    Fais un scan avec cet antispyware :
    Malwarebytes + tutoriel

    Tu l'installes; mets le a jour...(onglet mise a jour)
    Click maintenant sur l'onglet recherche et coche la case :
    "Executer un examen rapide".
    Puis click sur "rechercher".
    Laisses le scanner le pc...
    A la fin du scan, clique sur Afficher les résultats
    Si des elements on ete trouvés :
    > click sur supprimer la selection.
    si il t'es demandé de redemarrer > click sur "oui".
    A la fin un rapport va s'ouvrir;
    sauvegarde le de maniere a le retrouver en vue de le poster sur le forum.
    Copies et colles le rapport stp.

    a+
    0
  16. kanetheundertaakerr
     
    Bonsoir,

    Ci-joint, le rapport.
    Ca a l'air pas mal du tout.
    Sais-tu quels sont les effets du TR/Rookit.Gen?

    Malwarebytes' Anti-Malware 1.46
    www.malwarebytes.org

    Version de la base de données: 4149

    Windows 6.0.6000
    Internet Explorer 7.0.6000.17037

    27/05/2010 19:49:30
    mbam-log-2010-05-27 (19-49-30).txt

    Type d'examen: Examen rapide
    Elément(s) analysé(s): 124516
    Temps écoulé: 10 minute(s), 54 seconde(s)

    Processus mémoire infecté(s): 0
    Module(s) mémoire infecté(s): 0
    Clé(s) du Registre infectée(s): 0
    Valeur(s) du Registre infectée(s): 0
    Elément(s) de données du Registre infecté(s): 0
    Dossier(s) infecté(s): 0
    Fichier(s) infecté(s): 0

    Processus mémoire infecté(s):
    (Aucun élément nuisible détecté)

    Module(s) mémoire infecté(s):
    (Aucun élément nuisible détecté)

    Clé(s) du Registre infectée(s):
    (Aucun élément nuisible détecté)

    Valeur(s) du Registre infectée(s):
    (Aucun élément nuisible détecté)

    Elément(s) de données du Registre infecté(s):
    (Aucun élément nuisible détecté)

    Dossier(s) infecté(s):
    (Aucun élément nuisible détecté)

    Fichier(s) infecté(s):
    (Aucun élément nuisible détecté)
    0
  17. archet9
     
    Un peu de lecture surl es rootkits:
    https://fr.wikipedia.org/wiki/Rootkit
    https://www.malekal.com/supprimer-rootkit-windows/#mozTocId447003
    http://ordidoc.canalblog.com/archives/2010/02/17/16785622.html

    >Télécharge HiJackThis : https://www.commentcamarche.net/telecharger/securite/11747-hijackthis/
    - Lance le programme, puis sélectionne < do a system scan and save a logfile >
    - Enregistre le rapport sur ton bureau.
    Et envoie, par copier/coller, ton rapport Hijackthis sur le forum,

    a+
    0
  18. Kanetheundertaker
     
    Voici le rapport Hijackthis. Y a t-il des éléments gênants ou pouvant ralentir le PC?

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 21:59:22, on 27/05/2010
    Platform: Windows Vista (WinNT 6.00.1904)
    MSIE: Internet Explorer v7.00 (7.00.6000.17037)
    Boot mode: Normal

    Running processes:
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Windows\system32\taskeng.exe
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\Windows\RtHDVCpl.exe
    C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
    C:\Program Files\OO Software\Defrag\oodtray.exe
    C:\Program Files\Common Files\Java\Java Update\jusched.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Windows\ehome\ehtray.exe
    C:\Program Files\Windows Media Player\wmpnscfg.exe
    C:\Program Files\ATI TechnologiesBis\ATI.ACE\Core-Static\MOM.EXE
    C:\Windows\ehome\ehmsas.exe
    C:\Program Files\ATI TechnologiesBis\ATI.ACE\Core-Static\CCC.exe
    C:\Windows\system32\wuauclt.exe
    C:\Windows\system32\wbem\unsecapp.exe
    C:\Windows\System32\mobsync.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\FileZilla FTP Client\filezilla.exe
    C:\Windows\system32\SearchFilterHost.exe
    C:\totalcmd\TOTALCMD.EXE
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/?p=us
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/?p=us
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*https://fr.yahoo.com/?p=us
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
    O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
    O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\YTSingleInstance.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
    O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
    O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
    O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
    O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
    O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
    O4 - HKLM\..\Run: [OODefragTray] C:\Program Files\OO Software\Defrag\oodtray.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI TechnologiesBis\ATI.ACE\Core-Static\CLIStart.exe"
    O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
    O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
    O4 - HKUS\S-1-5-18\..\Run: [TOSHIBA Online Product Information] C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [TOSHIBA Online Product Information] C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe (User 'Default user')
    O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
    O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
    O9 - Extra button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\Program Files\Paltalk Messenger\Paltalk.exe (file missing)
    O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: eBay - {C08CAF1D-C0A3-40D5-9970-06D067EAC017} - http://www.webtip.ch/cgi-bin/toshiba/tracker_url.pl?FR (file missing)
    O15 - Trusted Zone: http://www.impot.gouv.fr
    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab
    O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} - http://www.adobe.com/products/acrobat/nos/gp.cab
    O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
    O23 - Service: a-squared Free Service a2freeAeLookupSvc (a2freeAeLookupSvc) - Unknown owner - C:\Windows\TEMP\acrounlebk.exe (file missing)
    O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
    O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
    O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
    O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
    O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Unknown owner - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe (file missing)
    O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Nero BackItUp Scheduler 4.0 - Unknown owner - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe (file missing)
    O23 - Service: O&O Defrag - O&O Software GmbH - C:\Program Files\OO Software\Defrag\oodag.exe
    O23 - Service: Office Source Engine (ose) - Unknown owner - C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (file missing)
    O23 - Service: Planificateur LiveUpdate automatique - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
    O23 - Service: SeaPort - Unknown owner - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (file missing)
    O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
    O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe (file missing)
    O23 - Service: Notebook Performance Tuning Service (TempoMonitoringService) - Toshiba Europe GmbH - C:\Program Files\Toshiba TEMPRO\TempoSVC.exe
    O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
    O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
    O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
    O23 - Service: TOSHIBA Bluetooth Service - Unknown owner - c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe (file missing)
    O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Unknown owner - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (file missing)
    O23 - Service: VMware Authorization Service (VMAuthdService) - Unknown owner - C:\Program Files\VMware\VMware Server\vmware-authd.exe (file missing)
    O23 - Service: VMware Registration Service (vmserverdWin32) - Unknown owner - C:\Program Files\VMware\VMware Server\vmserverdWin32.exe (file missing)
    O23 - Service: Windows Live ID Sign-in Assistant (wlidsvc) - Unknown owner - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (file missing)
    O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
    0
  19. archet9
     
    Re

    Supprime Yahoo! Toolbar ...
    Met à jour IE7 pour IE8

    Relance Hijackthis et cette fois choisis "Do a system scan only"
    et coche les lignes suivantes si tu les trouves:

    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O8 - Extra context menu item: Add to Windows &Live Favorites - <[hxxp://favorites.live.com/quickadd.aspx>]
    O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
    O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
    O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Office Source Engine (ose) - Unknown owner - C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (file missing)

    ==> Appuis sur "Fix checked" et redémarre le pc.

    Pour desinstaller les outils utilisés

    Télécharge OTCleanIt sur ton Bureau: http://www.geekstogo.com/forum/files/file/403-otc-oldtimers-clean-it/

    Lance OTCleanIt avec un double-clic (sous Vista, lance-le en cliquant droit sur OTCleanIt.exe et en sélectionnant "exécuter en tant qu'administrateur")

    Appuie sur le bouton "CleanUp!"

    A la question "begin cleanup process?", réponds "YES"

    A la fin de l'opération, si OTCleanIt demande de redémarrer ("Do you want to reboot now?"), ferme ce que tu es en train de faire (internet, documents divers...) et clique sur "YES":

    Au redémarrage, OTCleanIt aura supprimé les outils de désinfection, et se sera même autodétruit!

    puis

    ---> Télécharge et installe CCleaner (N'installe pas la Yahoo Toolbar) :
    https://www.01net.com/telecharger/windows/Utilitaire/nettoyeurs_et_installeurs/fiches/32599.html

    * Lance-le. Va dans Options puis Avancé et décoche la case Effacer uniquement les fichiers etc....
    * Va dans Nettoyeur, choisis Analyse. Une fois terminé, lance le nettoyage.
    * Ensuite, choisis Registre, puis Chercher des erreurs. Une fois terminé, répare toutes les erreurs tant de fois qu il en trouve a l analyse(Sauvegarde la base de registre).
    * Décoche la case plus vieux que 24 h

    TRES IMPORTANT:

    ---> Il est nécessaire de désactiver,redémarrer puis réactiver la restauration système pour la purger :
    XP:
    http://service1.symantec.com/support/inter/tsgeninfointl.Nsf/fr_docid/20020830101856924
    VISTA:
    https://www.commentcamarche.net/faq/13214-vista-desactiver-reactiver-la-restauration-systeme-de-vista

    ---> Je te conseille de créer un point de restauration que tu pourras utiliser plus tard si tu as un problème :
    https://www.vulgarisation-informatique.com/creer-point-restauration.php

    ---> Changes le statut de ce topic :
    et mets le en "résolu"
    https://www.commentcamarche.net/infos/25917-forum-ccm-mode-d-emploi-marquer-mon-sujet-comme-resolu/

    Bonne continuation....
    ........
    0
  20. kanetheundertakerr
     
    Bonjour,
    Malheureusement, je ne pourrai faire le test que dans deux semaines.
    Je te tiendrai au courant et te remercie pour toute l'aide que tu m'as apportée.
    bonne journée
    0
  • 1
  • 2