HEEEEEELP!!! Trojan et spyware...
Résolu/Fermé
nanou.o
Messages postés
64
Date d'inscription
mercredi 21 juillet 2010
Statut
Membre
Dernière intervention
13 novembre 2010
-
21 juil. 2010 à 18:02
Utilisateur anonyme - 2 août 2010 à 17:10
Utilisateur anonyme - 2 août 2010 à 17:10
A voir également:
- HEEEEEELP!!! Trojan et spyware...
- Trojan remover - Télécharger - Antivirus & Antimalwares
- Temu spyware - Accueil - Applications & Logiciels
- Trojan spyware windows defender ✓ - Forum Virus
- Trojan al11 - Forum Virus
- Spyware gratuit - Télécharger - Antivirus & Antimalwares
58 réponses
nanou.o
Messages postés
64
Date d'inscription
mercredi 21 juillet 2010
Statut
Membre
Dernière intervention
13 novembre 2010
23 juil. 2010 à 21:09
23 juil. 2010 à 21:09
Coucou
Voilà les 2 derniers bilans:
http://www.cijoint.fr/cjlink.php?file=cj201007/cijEQa2PMT.txt
http://www.cijoint.fr/cjlink.php?file=cj201007/cijoloUHzf.txt
Par contre, j'ai cette fenêtre qui s'ouvre toutes les 10 secondes maintenant:
"cette page contient un risque de sécurité non spécifié, voulez vous continuer?", schant que antivir et pare feu sont désactivés...
Voilà les 2 derniers bilans:
http://www.cijoint.fr/cjlink.php?file=cj201007/cijEQa2PMT.txt
http://www.cijoint.fr/cjlink.php?file=cj201007/cijoloUHzf.txt
Par contre, j'ai cette fenêtre qui s'ouvre toutes les 10 secondes maintenant:
"cette page contient un risque de sécurité non spécifié, voulez vous continuer?", schant que antivir et pare feu sont désactivés...
Utilisateur anonyme
23 juil. 2010 à 22:07
23 juil. 2010 à 22:07
* Télécharge ici : USBFIX sur ton bureau
/!\ Désactive provisoirement et seulement le temps de l'utilisation d'USBFIX, la protection en temps réel de ton Antivirus et de tes Antispywares, qui peuvent gêner fortement la procédure de recherche et de nettoyage de l'outil.
si tu as XP => double clique
si tu as Vista ou windows 7 => clic droit "executer en tant que...."
sur l'icône Usbfix située sur ton Bureau.
Sur la page, clique sur le bouton :
« Recherche »
/!\ Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d'avoir été infectées sans les ouvrir
- puis clique sur OK
- Laisse travailler l'outil.
- Poste le rapport qui apparaît à la fin.
le rapport se trouve sur C:\ UsbFix.txt
Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.
/!\ Désactive provisoirement et seulement le temps de l'utilisation d'USBFIX, la protection en temps réel de ton Antivirus et de tes Antispywares, qui peuvent gêner fortement la procédure de recherche et de nettoyage de l'outil.
si tu as XP => double clique
si tu as Vista ou windows 7 => clic droit "executer en tant que...."
sur l'icône Usbfix située sur ton Bureau.
Sur la page, clique sur le bouton :
« Recherche »
/!\ Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d'avoir été infectées sans les ouvrir
- puis clique sur OK
- Laisse travailler l'outil.
- Poste le rapport qui apparaît à la fin.
le rapport se trouve sur C:\ UsbFix.txt
Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.
nanou.o
Messages postés
64
Date d'inscription
mercredi 21 juillet 2010
Statut
Membre
Dernière intervention
13 novembre 2010
24 juil. 2010 à 08:55
24 juil. 2010 à 08:55
Bonjour bonjour,
Voilà le rapport, nous branchons juste l'appareil photo et l'imprimante:
############################## | UsbFix 7.017 | [Recherche]
Utilisateur: MORNAS (Administrateur) # PC-DE-MORNAS [ASUSTeK Computer Inc. F5R]
Mis à jour le 22/07/10 par El Desaparecido / C_XX
Lancé à 08:49:08 | 24/07/2010
Site Web: http://pagesperso-orange.fr/NosTools/index.html
Contact: FindyKill.Contact@gmail.com
CPU: Intel(R) Core(TM) Duo CPU T2250 @ 1.73GHz
CPU 2: Intel(R) Core(TM) Duo CPU T2250 @ 1.73GHz
Microsoft® Windows Vista(TM) Édition Familiale Premium (6.0.6002 32-Bit) # Service Pack 2
Internet Explorer 8.0.6001.18928
Pare-feu Windows: Désactivé /!\
RAM -> 1919 Mo
C:\ (%systemdrive%) -> Disque fixe # 75 Go (18 Go libre(s) - 24%) [VistaOS] # NTFS
D:\ -> Disque fixe # 67 Go (64 Go libre(s) - 96%) [DATA] # NTFS
E:\ -> Disque amovible # 488 Mo (283 Mo libre(s) - 58%) [] # FAT
F:\ -> CD-ROM
G:\ -> Disque amovible # 2 Go (2 Go libre(s) - 100%) [] # FAT
################## | Éléments infectieux |
Présent! C:\Users\MORNAS\AppData\Roaming\mdbu.bin
################## | Registre |
################## | Mountpoints2 |
HKCU\.\.\.\.\Explorer\MountPoints2\{13b8da04-8c83-11dd-a984-001e8c61438b}
Shell\AutoRun\Command = I:\LaunchU3.exe -a
HKCU\.\.\.\.\Explorer\MountPoints2\{4d4e8c8c-a86f-11dd-8d0c-001e8c61438b}
Shell\AutoRun\Command = .\run\autorun.exe
Shell\open\Command = .\run\autorun.exe
HKCU\.\.\.\.\Explorer\MountPoints2\{6d49dfd7-0505-11df-b74c-001e8c61438b}
Shell\AutoRun\Command = G:\InstallTomTomHOME.exe
################## | Vaccin |
(!) Cet ordinateur n'est pas vacciné!
################## | E.O.F |
Voilà le rapport, nous branchons juste l'appareil photo et l'imprimante:
############################## | UsbFix 7.017 | [Recherche]
Utilisateur: MORNAS (Administrateur) # PC-DE-MORNAS [ASUSTeK Computer Inc. F5R]
Mis à jour le 22/07/10 par El Desaparecido / C_XX
Lancé à 08:49:08 | 24/07/2010
Site Web: http://pagesperso-orange.fr/NosTools/index.html
Contact: FindyKill.Contact@gmail.com
CPU: Intel(R) Core(TM) Duo CPU T2250 @ 1.73GHz
CPU 2: Intel(R) Core(TM) Duo CPU T2250 @ 1.73GHz
Microsoft® Windows Vista(TM) Édition Familiale Premium (6.0.6002 32-Bit) # Service Pack 2
Internet Explorer 8.0.6001.18928
Pare-feu Windows: Désactivé /!\
RAM -> 1919 Mo
C:\ (%systemdrive%) -> Disque fixe # 75 Go (18 Go libre(s) - 24%) [VistaOS] # NTFS
D:\ -> Disque fixe # 67 Go (64 Go libre(s) - 96%) [DATA] # NTFS
E:\ -> Disque amovible # 488 Mo (283 Mo libre(s) - 58%) [] # FAT
F:\ -> CD-ROM
G:\ -> Disque amovible # 2 Go (2 Go libre(s) - 100%) [] # FAT
################## | Éléments infectieux |
Présent! C:\Users\MORNAS\AppData\Roaming\mdbu.bin
################## | Registre |
################## | Mountpoints2 |
HKCU\.\.\.\.\Explorer\MountPoints2\{13b8da04-8c83-11dd-a984-001e8c61438b}
Shell\AutoRun\Command = I:\LaunchU3.exe -a
HKCU\.\.\.\.\Explorer\MountPoints2\{4d4e8c8c-a86f-11dd-8d0c-001e8c61438b}
Shell\AutoRun\Command = .\run\autorun.exe
Shell\open\Command = .\run\autorun.exe
HKCU\.\.\.\.\Explorer\MountPoints2\{6d49dfd7-0505-11df-b74c-001e8c61438b}
Shell\AutoRun\Command = G:\InstallTomTomHOME.exe
################## | Vaccin |
(!) Cet ordinateur n'est pas vacciné!
################## | E.O.F |
Shad || x ||
Messages postés
323
Date d'inscription
dimanche 11 juillet 2010
Statut
Membre
Dernière intervention
29 juillet 2010
32
Modifié par Shad || x || le 24/07/2010 à 12:04
Modifié par Shad || x || le 24/07/2010 à 12:04
Salut,
désolé de l'incruste ^^
juste pour faire avancer gen-hackman, enfin..surtout toi nanou ^^
Relance USBFix.exe par clic-droit "exécuter en tant qu'administrateur"
* Clique sur Suppression.
* Une fenêtre te demandera de bancher tous les périphériques externes (clés USB, lecteurs MP3, disques durs externes, etc ...). Branche le matériel puis clique sur OK pour poursuivre.
* Le bureau va disparaitre et ne sera plus accessible tout le temps du scan, c'est normal. Patiente le temps du nettoyage sans l'interrompre.
* A la fin, un rapport va être généré (C:\USBFix.txt).
* Envoie l'intégralité de son contenu dans ta prochaine réponse.
désolé de l'incruste ^^
juste pour faire avancer gen-hackman, enfin..surtout toi nanou ^^
Relance USBFix.exe par clic-droit "exécuter en tant qu'administrateur"
* Clique sur Suppression.
* Une fenêtre te demandera de bancher tous les périphériques externes (clés USB, lecteurs MP3, disques durs externes, etc ...). Branche le matériel puis clique sur OK pour poursuivre.
* Le bureau va disparaitre et ne sera plus accessible tout le temps du scan, c'est normal. Patiente le temps du nettoyage sans l'interrompre.
* A la fin, un rapport va être généré (C:\USBFix.txt).
* Envoie l'intégralité de son contenu dans ta prochaine réponse.
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
nanou.o
Messages postés
64
Date d'inscription
mercredi 21 juillet 2010
Statut
Membre
Dernière intervention
13 novembre 2010
24 juil. 2010 à 13:14
24 juil. 2010 à 13:14
Kikou
Y'a pas de souci, merci de t'intéresser à mon pauvre cas!
Voilà le bilan demandé:
############################## | UsbFix 7.017 | [Suppression]
Utilisateur: MORNAS (Administrateur) # PC-DE-MORNAS [ASUSTeK Computer Inc. F5R]
Mis à jour le 22/07/10 par El Desaparecido / C_XX
Lancé à 13:04:28 | 24/07/2010
Site Web: http://pagesperso-orange.fr/NosTools/index.html
Contact: FindyKill.Contact@gmail.com
CPU: Intel(R) Core(TM) Duo CPU T2250 @ 1.73GHz
CPU 2: Intel(R) Core(TM) Duo CPU T2250 @ 1.73GHz
Microsoft® Windows Vista(TM) Édition Familiale Premium (6.0.6002 32-Bit) # Service Pack 2
Internet Explorer 8.0.6001.18928
Pare-feu Windows: Désactivé /!\
RAM -> 1919 Mo
C:\ (%systemdrive%) -> Disque fixe # 75 Go (17 Go libre(s) - 23%) [VistaOS] # NTFS
D:\ -> Disque fixe # 67 Go (64 Go libre(s) - 96%) [DATA] # NTFS
E:\ -> Disque amovible # 488 Mo (283 Mo libre(s) - 58%) [] # FAT
F:\ -> CD-ROM
G:\ -> Disque amovible # 2 Go (2 Go libre(s) - 100%) [] # FAT
################## | Éléments infectieux |
Supprimé! C:\Users\MORNAS\AppData\Roaming\mdbu.bin
################## | Registre |
################## | Mountpoints2 |
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{13b8da04-8c83-11dd-a984-001e8c61438b}
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{4d4e8c8c-a86f-11dd-8d0c-001e8c61438b}
################## | Listing |
[24/07/2010 - 13:09:44 | SHD ] C:\$RECYCLE.BIN
[21/07/2010 - 06:31:42 | A | 112761] C:\aaw7boot.log
[21/07/2010 - 18:24:57 | A | 10903] C:\Ad-Report-CLEAN[1].txt
[14/12/2007 - 01:58:39 | D ] C:\ADOBE
[22/07/2010 - 19:43:47 | A | 4] C:\autoexec.bat
[24/10/2009 - 11:40:21 | SHD ] C:\Boot
[11/04/2009 - 08:36:36 | RASH | 333257] C:\bootmgr
[18/04/2007 - 11:26:27 | RAS | 8192] C:\BOOTSECT.BAK
[04/04/2007 - 06:01:54 | A | 19] C:\CA13.txt
[18/09/2006 - 23:43:37 | A | 10] C:\config.sys
[14/12/2007 - 03:37:03 | A | 18891] C:\devlist.txt
[02/11/2006 - 15:02:03 | SHD ] C:\Documents and Settings
[21/12/2007 - 20:02:46 | RH | 524288] C:\F5R.BIN
[04/06/2007 - 11:49:55 | RAH | 524288] C:\F5R.ROM
[18/10/2007 - 04:46:33 | A | 16] C:\F5R_Vista.40
[14/12/2007 - 03:33:42 | A | 9] C:\Finish.log
[23/06/2008 - 09:09:40 | SHD ] C:\found.000
[24/07/2010 - 12:50:12 | ASH | 2012471296] C:\hiberfil.sys
[04/01/2010 - 12:26:46 | RASH | 0] C:\IO.SYS
[22/07/2010 - 19:17:57 | D ] C:\Kill'em
[22/07/2010 - 16:55:28 | A | 24803] C:\List'em.txt
[06/08/2008 - 15:47:15 | D ] C:\MC_TMP
[04/01/2010 - 12:26:46 | RASH | 0] C:\MSDOS.SYS
[14/12/2007 - 01:12:55 | RHD ] C:\MSOCache
[07/08/2007 - 23:43:02 | A | 15] C:\NERO.LOG
[14/12/2007 - 01:54:23 | D ] C:\NIS
[17/05/2007 - 05:35:24 | A | 15] C:\NIS2007_A.TXT
[16/03/2007 - 01:18:45 | A | 25] C:\OFFICE2007_A.TXT
[24/07/2010 - 12:50:08 | ASH | 2326269952] C:\pagefile.sys
[13/12/2007 - 12:22:35 | A | 105] C:\Pass.txt
[28/09/2007 - 01:56:05 | A | 947] C:\Patch.LOG
[21/06/2008 - 23:18:25 | D ] C:\PerfLogs
[13/12/2007 - 11:40:06 | D ] C:\Preload
[22/07/2010 - 15:11:09 | RD ] C:\Program Files
[21/07/2010 - 18:24:42 | HD ] C:\ProgramData
[24/05/2007 - 00:43:40 | A | 17] C:\READER_A.TXT
[14/12/2007 - 03:07:11 | A | 420] C:\RHDSetup.log
[01/02/2008 - 16:03:23 | A | 159] C:\Setup.log
[27/04/2008 - 11:09:08 | D ] C:\SPDISK
[16/05/2006 - 02:22:24 | A | 5] C:\Store.LOG
[24/07/2010 - 09:56:19 | SHD ] C:\System Volume Information
[24/07/2010 - 13:09:44 | D ] C:\UsbFix
[24/07/2010 - 13:04:29 | A | 3353] C:\UsbFix.txt
[04/01/2009 - 17:53:38 | RD ] C:\Users
[14/09/2007 - 01:06:04 | A | 23] C:\V53.TXT
[21/07/2010 - 07:37:44 | D ] C:\Windows
[24/07/2010 - 13:05:25 | SHD ] D:\$RECYCLE.BIN
[13/04/2008 - 13:07:26 | D ] D:\FILM
[14/12/2007 - 01:04:46 | SHD ] D:\System Volume Information
[11/05/2006 - 20:30:46 | D ] E:\DCIM
[11/05/2006 - 20:31:16 | D ] E:\MISC
[20/04/2008 - 16:50:42 | AH | 512] E:\NIKON001.DSC
################## | Vaccin |
C:\Autorun.inf -> Dossier créé par UsbFix (El Desaparecido & C_XX)
D:\Autorun.inf -> Dossier créé par UsbFix (El Desaparecido & C_XX)
E:\Autorun.inf -> Dossier créé par UsbFix (El Desaparecido & C_XX)
################## | Upload |
Veuillez envoyer le fichier: C:\UsbFix_Upload_Me_PC-DE-MORNAS.zip
https://www.ionos.fr/?affiliate_id=77097
Merci de votre contribution.
################## | E.O.F |
Y'a pas de souci, merci de t'intéresser à mon pauvre cas!
Voilà le bilan demandé:
############################## | UsbFix 7.017 | [Suppression]
Utilisateur: MORNAS (Administrateur) # PC-DE-MORNAS [ASUSTeK Computer Inc. F5R]
Mis à jour le 22/07/10 par El Desaparecido / C_XX
Lancé à 13:04:28 | 24/07/2010
Site Web: http://pagesperso-orange.fr/NosTools/index.html
Contact: FindyKill.Contact@gmail.com
CPU: Intel(R) Core(TM) Duo CPU T2250 @ 1.73GHz
CPU 2: Intel(R) Core(TM) Duo CPU T2250 @ 1.73GHz
Microsoft® Windows Vista(TM) Édition Familiale Premium (6.0.6002 32-Bit) # Service Pack 2
Internet Explorer 8.0.6001.18928
Pare-feu Windows: Désactivé /!\
RAM -> 1919 Mo
C:\ (%systemdrive%) -> Disque fixe # 75 Go (17 Go libre(s) - 23%) [VistaOS] # NTFS
D:\ -> Disque fixe # 67 Go (64 Go libre(s) - 96%) [DATA] # NTFS
E:\ -> Disque amovible # 488 Mo (283 Mo libre(s) - 58%) [] # FAT
F:\ -> CD-ROM
G:\ -> Disque amovible # 2 Go (2 Go libre(s) - 100%) [] # FAT
################## | Éléments infectieux |
Supprimé! C:\Users\MORNAS\AppData\Roaming\mdbu.bin
################## | Registre |
################## | Mountpoints2 |
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{13b8da04-8c83-11dd-a984-001e8c61438b}
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{4d4e8c8c-a86f-11dd-8d0c-001e8c61438b}
################## | Listing |
[24/07/2010 - 13:09:44 | SHD ] C:\$RECYCLE.BIN
[21/07/2010 - 06:31:42 | A | 112761] C:\aaw7boot.log
[21/07/2010 - 18:24:57 | A | 10903] C:\Ad-Report-CLEAN[1].txt
[14/12/2007 - 01:58:39 | D ] C:\ADOBE
[22/07/2010 - 19:43:47 | A | 4] C:\autoexec.bat
[24/10/2009 - 11:40:21 | SHD ] C:\Boot
[11/04/2009 - 08:36:36 | RASH | 333257] C:\bootmgr
[18/04/2007 - 11:26:27 | RAS | 8192] C:\BOOTSECT.BAK
[04/04/2007 - 06:01:54 | A | 19] C:\CA13.txt
[18/09/2006 - 23:43:37 | A | 10] C:\config.sys
[14/12/2007 - 03:37:03 | A | 18891] C:\devlist.txt
[02/11/2006 - 15:02:03 | SHD ] C:\Documents and Settings
[21/12/2007 - 20:02:46 | RH | 524288] C:\F5R.BIN
[04/06/2007 - 11:49:55 | RAH | 524288] C:\F5R.ROM
[18/10/2007 - 04:46:33 | A | 16] C:\F5R_Vista.40
[14/12/2007 - 03:33:42 | A | 9] C:\Finish.log
[23/06/2008 - 09:09:40 | SHD ] C:\found.000
[24/07/2010 - 12:50:12 | ASH | 2012471296] C:\hiberfil.sys
[04/01/2010 - 12:26:46 | RASH | 0] C:\IO.SYS
[22/07/2010 - 19:17:57 | D ] C:\Kill'em
[22/07/2010 - 16:55:28 | A | 24803] C:\List'em.txt
[06/08/2008 - 15:47:15 | D ] C:\MC_TMP
[04/01/2010 - 12:26:46 | RASH | 0] C:\MSDOS.SYS
[14/12/2007 - 01:12:55 | RHD ] C:\MSOCache
[07/08/2007 - 23:43:02 | A | 15] C:\NERO.LOG
[14/12/2007 - 01:54:23 | D ] C:\NIS
[17/05/2007 - 05:35:24 | A | 15] C:\NIS2007_A.TXT
[16/03/2007 - 01:18:45 | A | 25] C:\OFFICE2007_A.TXT
[24/07/2010 - 12:50:08 | ASH | 2326269952] C:\pagefile.sys
[13/12/2007 - 12:22:35 | A | 105] C:\Pass.txt
[28/09/2007 - 01:56:05 | A | 947] C:\Patch.LOG
[21/06/2008 - 23:18:25 | D ] C:\PerfLogs
[13/12/2007 - 11:40:06 | D ] C:\Preload
[22/07/2010 - 15:11:09 | RD ] C:\Program Files
[21/07/2010 - 18:24:42 | HD ] C:\ProgramData
[24/05/2007 - 00:43:40 | A | 17] C:\READER_A.TXT
[14/12/2007 - 03:07:11 | A | 420] C:\RHDSetup.log
[01/02/2008 - 16:03:23 | A | 159] C:\Setup.log
[27/04/2008 - 11:09:08 | D ] C:\SPDISK
[16/05/2006 - 02:22:24 | A | 5] C:\Store.LOG
[24/07/2010 - 09:56:19 | SHD ] C:\System Volume Information
[24/07/2010 - 13:09:44 | D ] C:\UsbFix
[24/07/2010 - 13:04:29 | A | 3353] C:\UsbFix.txt
[04/01/2009 - 17:53:38 | RD ] C:\Users
[14/09/2007 - 01:06:04 | A | 23] C:\V53.TXT
[21/07/2010 - 07:37:44 | D ] C:\Windows
[24/07/2010 - 13:05:25 | SHD ] D:\$RECYCLE.BIN
[13/04/2008 - 13:07:26 | D ] D:\FILM
[14/12/2007 - 01:04:46 | SHD ] D:\System Volume Information
[11/05/2006 - 20:30:46 | D ] E:\DCIM
[11/05/2006 - 20:31:16 | D ] E:\MISC
[20/04/2008 - 16:50:42 | AH | 512] E:\NIKON001.DSC
################## | Vaccin |
C:\Autorun.inf -> Dossier créé par UsbFix (El Desaparecido & C_XX)
D:\Autorun.inf -> Dossier créé par UsbFix (El Desaparecido & C_XX)
E:\Autorun.inf -> Dossier créé par UsbFix (El Desaparecido & C_XX)
################## | Upload |
Veuillez envoyer le fichier: C:\UsbFix_Upload_Me_PC-DE-MORNAS.zip
https://www.ionos.fr/?affiliate_id=77097
Merci de votre contribution.
################## | E.O.F |
Shad || x ||
Messages postés
323
Date d'inscription
dimanche 11 juillet 2010
Statut
Membre
Dernière intervention
29 juillet 2010
32
24 juil. 2010 à 13:35
24 juil. 2010 à 13:35
Ok ;)
Il devrait revenir...je n'en doute pas ^^
Juste un truc avant qu'il continue:
Sur un PC: UN SEUL ANTIVIRUS !
Garde Antivir et vire le reste.
Il devrait revenir...je n'en doute pas ^^
Juste un truc avant qu'il continue:
Sur un PC: UN SEUL ANTIVIRUS !
Garde Antivir et vire le reste.
nanou.o
Messages postés
64
Date d'inscription
mercredi 21 juillet 2010
Statut
Membre
Dernière intervention
13 novembre 2010
24 juil. 2010 à 13:45
24 juil. 2010 à 13:45
euh... j'en aurais donc plusieurs en route en mm temps? C'est vrai que j'en ai essayé quelques uns mais je pensais n'avoir gardé actif que antivir.
Tant qu'on en cause, que conseillerais tu en protection mis à part antivir du coup?
Promis, je fais du ménage dans les antivirus...
Tant qu'on en cause, que conseillerais tu en protection mis à part antivir du coup?
Promis, je fais du ménage dans les antivirus...
nanou.o
Messages postés
64
Date d'inscription
mercredi 21 juillet 2010
Statut
Membre
Dernière intervention
13 novembre 2010
24 juil. 2010 à 13:54
24 juil. 2010 à 13:54
Alors du coup, j'ai, si je vois bien:
- norton
-hijack this
-malwarebytes
-adaware
-otl
-usbfix
- c cleaner
- avira
-kill them
Koi je garde, koi je vire? Et ceux qu'on garde, comment les utilise -t -on?
Idem, pour tous les rapports d'analyse, est ce que dois les garder? J'en ai dans des dossiers et sur le bureau...
- norton
-hijack this
-malwarebytes
-adaware
-otl
-usbfix
- c cleaner
- avira
-kill them
Koi je garde, koi je vire? Et ceux qu'on garde, comment les utilise -t -on?
Idem, pour tous les rapports d'analyse, est ce que dois les garder? J'en ai dans des dossiers et sur le bureau...
Shad || x ||
Messages postés
323
Date d'inscription
dimanche 11 juillet 2010
Statut
Membre
Dernière intervention
29 juillet 2010
32
24 juil. 2010 à 14:01
24 juil. 2010 à 14:01
Pour ce qui est de malwarebytes, hijackthis, ad-remover, usbfix, otl...tout ça ce sont des outils d'analyse et de suppression. Tu n'a pas à y toucher pour le moment ils seront tous supprimés une fois la désinfection terminée.
Garde ccleaner
Vire norton: http://service1.symantec.com/support/inter/tsgeninfointl.nsf/fr_docid/20050414110429924?OpenDocument&seg=hm&lg=fr&ct=fr
Et il y a encore un bout d'avast, vire le également: https://www.avast.com/fr-fr/uninstall-utility
Garde ccleaner
Vire norton: http://service1.symantec.com/support/inter/tsgeninfointl.nsf/fr_docid/20050414110429924?OpenDocument&seg=hm&lg=fr&ct=fr
Et il y a encore un bout d'avast, vire le également: https://www.avast.com/fr-fr/uninstall-utility
Utilisateur anonyme
Modifié par gen-hackman le 24/07/2010 à 14:12
Modifié par gen-hackman le 24/07/2010 à 14:12
petite entracte lol ^^
▶ Relance List&Kill'em(soit en clic droit "executer en tant que......" pour vista/7),avec le raccourci sur ton bureau.
mais cette fois-ci :
▶ choisis l'option ADD KEY
un document texte va s'ouvrir à l'apparition de : Text Please
▶copie/colle le texte en gras ci-dessous :
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center" /v "UacDisableNotify" /t REG_DWORD /d "0"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center" /v "InternetSettingsDisableNotify" /t REG_DWORD /d "0"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center" /v "AutoUpdateDisableNotify" /t REG_DWORD /d "0"
ensuite onglet "Fichier" clic sur enregistrer , puis ferme ce bloc notes
Laisse travailler l'outil
à la fin un rapport s'ouvre ,
▶ poste le resultat
?G3?-?@¢??@?(TM)©®?
▶ Relance List&Kill'em(soit en clic droit "executer en tant que......" pour vista/7),avec le raccourci sur ton bureau.
mais cette fois-ci :
▶ choisis l'option ADD KEY
un document texte va s'ouvrir à l'apparition de : Text Please
▶copie/colle le texte en gras ci-dessous :
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center" /v "UacDisableNotify" /t REG_DWORD /d "0"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center" /v "InternetSettingsDisableNotify" /t REG_DWORD /d "0"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center" /v "AutoUpdateDisableNotify" /t REG_DWORD /d "0"
ensuite onglet "Fichier" clic sur enregistrer , puis ferme ce bloc notes
Laisse travailler l'outil
à la fin un rapport s'ouvre ,
▶ poste le resultat
?G3?-?@¢??@?(TM)©®?
nanou.o
Messages postés
64
Date d'inscription
mercredi 21 juillet 2010
Statut
Membre
Dernière intervention
13 novembre 2010
24 juil. 2010 à 14:15
24 juil. 2010 à 14:15
Hey salut salut!
Pas de souci t'as ben raison de te reposer et de faire autre chose!
Ok je fais tout ca...
Pas de souci t'as ben raison de te reposer et de faire autre chose!
Ok je fais tout ca...
nanou.o
Messages postés
64
Date d'inscription
mercredi 21 juillet 2010
Statut
Membre
Dernière intervention
13 novembre 2010
24 juil. 2010 à 14:18
24 juil. 2010 à 14:18
et voilou, l'était rapide cuici:
¤¤¤¤¤¤¤¤¤¤ Keys :
Added : HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center" /v "UacDisableNotify" /t REG_DWORD /d "0"
Added : HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center" /v "InternetSettingsDisableNotify" /t REG_DWORD /d "0"
Added : HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center" /v "AutoUpdateDisableNotify" /t REG_DWORD /d "0"
¤¤¤¤¤¤¤¤¤¤ Keys :
Added : HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center" /v "UacDisableNotify" /t REG_DWORD /d "0"
Added : HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center" /v "InternetSettingsDisableNotify" /t REG_DWORD /d "0"
Added : HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center" /v "AutoUpdateDisableNotify" /t REG_DWORD /d "0"
nanou.o
Messages postés
64
Date d'inscription
mercredi 21 juillet 2010
Statut
Membre
Dernière intervention
13 novembre 2010
24 juil. 2010 à 14:48
24 juil. 2010 à 14:48
Re coucou
http://www.cijoint.fr/cjlink.php?file=cj201007/cijHJR1wkF.txt
http://www.cijoint.fr/cjlink.php?file=cj201007/cijzwmN1z2.txt
Voiloù
http://www.cijoint.fr/cjlink.php?file=cj201007/cijHJR1wkF.txt
http://www.cijoint.fr/cjlink.php?file=cj201007/cijzwmN1z2.txt
Voiloù
Utilisateur anonyme
Modifié par gen-hackman le 24/07/2010 à 15:17
Modifié par gen-hackman le 24/07/2010 à 15:17
si tu as XP => double clique
si tu as Vista ou windows 7 => clic droit "executer en tant que...."
sur OTL.exe pour le lancer.
▶Copie la liste qui se trouve en gras ci-dessous,
▶ colle-la dans la zone sous "Personnalisation" :
:processes
explorer.exe
iexplore.exe
firefox.exe
msnmsgr.exe
Teatimer.exe
:OTL
PRC - [2007/01/09 23:59:32 | 000,108,648 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
PRC - [2007/01/05 02:19:28 | 000,047,712 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
SRV - [2008/10/09 14:47:42 | 001,079,176 | ---- | M] (PC Tools) [On_Demand | Stopped] -- C:\Program Files\Spyware Doctor\pctsSvc.exe -- (sdCoreService)
SRV - [2008/06/13 17:29:14 | 000,356,920 | ---- | M] (PC Tools) [On_Demand | Stopped] -- C:\Program Files\Spyware Doctor\pctsAuxs.exe -- (sdAuxService)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Show Norton Toolbar) - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll (Symantec Corporation)
O3 - HKU\S-1-5-21-1273562678-3384725392-186920749-1000\..\Toolbar\WebBrowser: (no name) - {00000000-0000-0000-0000-000000000000} - No CLSID value found.
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab (Reg Error: Key error.)
@Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:DFC5A2B2
:Reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\run]
"iTunesHelper"=-
"QuickTime Task"=-
"Symantec PIF AlertEng"=-
"TkBellExe"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145
:commands
[emptytemp]
[start explorer]
[reboot]
▶ Clique sur "Correction" pour lancer la suppression.
▶ Poste le rapport qui logiquement s'ouvrira tout seul en fin de travail appres le redemarrage.
?G3?-?@¢??@?(TM)©®?
si tu as Vista ou windows 7 => clic droit "executer en tant que...."
sur OTL.exe pour le lancer.
▶Copie la liste qui se trouve en gras ci-dessous,
▶ colle-la dans la zone sous "Personnalisation" :
:processes
explorer.exe
iexplore.exe
firefox.exe
msnmsgr.exe
Teatimer.exe
:OTL
PRC - [2007/01/09 23:59:32 | 000,108,648 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
PRC - [2007/01/05 02:19:28 | 000,047,712 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
SRV - [2008/10/09 14:47:42 | 001,079,176 | ---- | M] (PC Tools) [On_Demand | Stopped] -- C:\Program Files\Spyware Doctor\pctsSvc.exe -- (sdCoreService)
SRV - [2008/06/13 17:29:14 | 000,356,920 | ---- | M] (PC Tools) [On_Demand | Stopped] -- C:\Program Files\Spyware Doctor\pctsAuxs.exe -- (sdAuxService)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Show Norton Toolbar) - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll (Symantec Corporation)
O3 - HKU\S-1-5-21-1273562678-3384725392-186920749-1000\..\Toolbar\WebBrowser: (no name) - {00000000-0000-0000-0000-000000000000} - No CLSID value found.
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab (Reg Error: Key error.)
@Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:DFC5A2B2
:Reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\run]
"iTunesHelper"=-
"QuickTime Task"=-
"Symantec PIF AlertEng"=-
"TkBellExe"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145
:commands
[emptytemp]
[start explorer]
[reboot]
▶ Clique sur "Correction" pour lancer la suppression.
▶ Poste le rapport qui logiquement s'ouvrira tout seul en fin de travail appres le redemarrage.
?G3?-?@¢??@?(TM)©®?
nanou.o
Messages postés
64
Date d'inscription
mercredi 21 juillet 2010
Statut
Membre
Dernière intervention
13 novembre 2010
24 juil. 2010 à 15:28
24 juil. 2010 à 15:28
Voilà
All processes killed
========== PROCESSES ==========
No active process named explorer.exe was found!
No active process named iexplore.exe was found!
No active process named firefox.exe was found!
Process msnmsgr.exe killed successfully!
No active process named Teatimer.exe was found!
========== OTL ==========
No active process named ccSvcHst.exe was found!
No active process named AppSvc32.exe was found!
Service sdCoreService stopped successfully!
Service sdCoreService deleted successfully!
C:\Program Files\Spyware Doctor\pctsSvc.exe moved successfully.
Service sdAuxService stopped successfully!
Service sdAuxService deleted successfully!
C:\Program Files\Spyware Doctor\pctsAuxs.exe moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1E8A6170-7264-4D0F-BEAE-D42A53123C75}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1E8A6170-7264-4D0F-BEAE-D42A53123C75}\ not found.
File C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{90222687-F593-4738-B738-FBEE9C7B26DF} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{90222687-F593-4738-B738-FBEE9C7B26DF}\ deleted successfully.
File C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll not found.
Registry value HKEY_USERS\S-1-5-21-1273562678-3384725392-186920749-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{00000000-0000-0000-0000-000000000000} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00000000-0000-0000-0000-000000000000}\ not found.
Starting removal of ActiveX control {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
C:\Windows\Downloaded Program Files\erma.inf moved successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
ADS C:\ProgramData\TEMP:DFC5A2B2 deleted successfully.
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\run\\iTunesHelper deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\run\\QuickTime Task deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\run\\Symantec PIF AlertEng not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\run\\TkBellExe deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\"NoDriveTypeAutoRun"|145 /E : value set successfully!
========== COMMANDS ==========
[EMPTYTEMP]
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: Default User
User: MORNAS
->Temp folder emptied: 48263258 bytes
->Temporary Internet Files folder emptied: 53993923 bytes
->Java cache emptied: 4002903 bytes
->FireFox cache emptied: 12474 bytes
->Flash cache emptied: 1967625 bytes
User: Public
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 103,00 mb
OTL by OldTimer - Version 3.2.9.1 log created on 07242010_152324
Files\Folders moved on Reboot...
Registry entries deleted on Reboot...
All processes killed
========== PROCESSES ==========
No active process named explorer.exe was found!
No active process named iexplore.exe was found!
No active process named firefox.exe was found!
Process msnmsgr.exe killed successfully!
No active process named Teatimer.exe was found!
========== OTL ==========
No active process named ccSvcHst.exe was found!
No active process named AppSvc32.exe was found!
Service sdCoreService stopped successfully!
Service sdCoreService deleted successfully!
C:\Program Files\Spyware Doctor\pctsSvc.exe moved successfully.
Service sdAuxService stopped successfully!
Service sdAuxService deleted successfully!
C:\Program Files\Spyware Doctor\pctsAuxs.exe moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1E8A6170-7264-4D0F-BEAE-D42A53123C75}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1E8A6170-7264-4D0F-BEAE-D42A53123C75}\ not found.
File C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{90222687-F593-4738-B738-FBEE9C7B26DF} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{90222687-F593-4738-B738-FBEE9C7B26DF}\ deleted successfully.
File C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll not found.
Registry value HKEY_USERS\S-1-5-21-1273562678-3384725392-186920749-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{00000000-0000-0000-0000-000000000000} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00000000-0000-0000-0000-000000000000}\ not found.
Starting removal of ActiveX control {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
C:\Windows\Downloaded Program Files\erma.inf moved successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
ADS C:\ProgramData\TEMP:DFC5A2B2 deleted successfully.
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\run\\iTunesHelper deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\run\\QuickTime Task deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\run\\Symantec PIF AlertEng not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\run\\TkBellExe deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\"NoDriveTypeAutoRun"|145 /E : value set successfully!
========== COMMANDS ==========
[EMPTYTEMP]
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: Default User
User: MORNAS
->Temp folder emptied: 48263258 bytes
->Temporary Internet Files folder emptied: 53993923 bytes
->Java cache emptied: 4002903 bytes
->FireFox cache emptied: 12474 bytes
->Flash cache emptied: 1967625 bytes
User: Public
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 103,00 mb
OTL by OldTimer - Version 3.2.9.1 log created on 07242010_152324
Files\Folders moved on Reboot...
Registry entries deleted on Reboot...
Utilisateur anonyme
24 juil. 2010 à 15:51
24 juil. 2010 à 15:51
vire les restes de norton avec cet outil :
Télécharge et exécute le Norton Removal Tool.
ensuite :
fais un scan avec antivir et poste le rapport
Télécharge et exécute le Norton Removal Tool.
ensuite :
fais un scan avec antivir et poste le rapport
nanou.o
Messages postés
64
Date d'inscription
mercredi 21 juillet 2010
Statut
Membre
Dernière intervention
13 novembre 2010
24 juil. 2010 à 16:37
24 juil. 2010 à 16:37
Coucou
Je l'ai fait à l'instant suite au mess de Shad, il m'avait posté un lien pour désinstaller. Je te poste le rapport antivir ce soir, corvée courses, tu me dis si je dois le refaire et que tout n'est pas parti?
Je l'ai fait à l'instant suite au mess de Shad, il m'avait posté un lien pour désinstaller. Je te poste le rapport antivir ce soir, corvée courses, tu me dis si je dois le refaire et que tout n'est pas parti?
nanou.o
Messages postés
64
Date d'inscription
mercredi 21 juillet 2010
Statut
Membre
Dernière intervention
13 novembre 2010
24 juil. 2010 à 19:29
24 juil. 2010 à 19:29
De retour, antivir me sort un message: "scan has detected viruses or unwante prog.
Il me demande si je repair ou cancel all.
On retrouve là dedans mes "adspy gen2" ainsi que "TR/BHO zwangi " avec différents chiffres. Une ptite quinzaine en tout dans la liste.
Koi je fais?
Il me demande si je repair ou cancel all.
On retrouve là dedans mes "adspy gen2" ainsi que "TR/BHO zwangi " avec différents chiffres. Une ptite quinzaine en tout dans la liste.
Koi je fais?
nanou.o
Messages postés
64
Date d'inscription
mercredi 21 juillet 2010
Statut
Membre
Dernière intervention
13 novembre 2010
25 juil. 2010 à 08:27
25 juil. 2010 à 08:27
Salut salut,
Voilà le bilan antivir
Avira AntiVir Personal
Report file date: samedi 24 juillet 2010 15:57
Scanning for 2566895 virus strains and unwanted programs.
Licensee : Avira AntiVir Personal - FREE Antivirus
Serial number : 0000149996-ADJIE-0000001
Platform : Windows Vista
Windows version : (Service Pack 2) [6.0.6002]
Boot mode : Normally booted
Username : SYSTEM
Computer name : PC-DE-MORNAS
Version information:
BUILD.DAT : 9.0.0.422 21701 Bytes 09/03/2010 10:29:00
AVSCAN.EXE : 9.0.3.10 466689 Bytes 13/10/2009 10:26:33
AVSCAN.DLL : 9.0.3.0 40705 Bytes 27/02/2009 09:58:24
LUKE.DLL : 9.0.3.2 209665 Bytes 20/02/2009 10:35:49
LUKERES.DLL : 9.0.2.0 12033 Bytes 27/02/2009 09:58:52
VBASE000.VDF : 7.10.0.0 19875328 Bytes 06/11/2009 06:35:52
VBASE001.VDF : 7.10.1.0 1372672 Bytes 19/11/2009 17:52:28
VBASE002.VDF : 7.10.3.1 3143680 Bytes 20/01/2010 20:10:12
VBASE003.VDF : 7.10.3.75 996864 Bytes 26/01/2010 18:45:48
VBASE004.VDF : 7.10.4.203 1579008 Bytes 05/03/2010 15:08:46
VBASE005.VDF : 7.10.6.82 2494464 Bytes 15/04/2010 18:20:25
VBASE006.VDF : 7.10.7.218 2294784 Bytes 02/06/2010 20:02:39
VBASE007.VDF : 7.10.9.165 4840960 Bytes 23/07/2010 18:41:30
VBASE008.VDF : 7.10.9.166 2048 Bytes 23/07/2010 18:41:30
VBASE009.VDF : 7.10.9.167 2048 Bytes 23/07/2010 18:41:31
VBASE010.VDF : 7.10.9.168 2048 Bytes 23/07/2010 18:41:32
VBASE011.VDF : 7.10.9.169 2048 Bytes 23/07/2010 18:41:33
VBASE012.VDF : 7.10.9.170 2048 Bytes 23/07/2010 18:41:33
VBASE013.VDF : 7.10.9.171 2048 Bytes 23/07/2010 18:41:35
VBASE014.VDF : 7.10.9.172 2048 Bytes 23/07/2010 18:41:35
VBASE015.VDF : 7.10.9.173 2048 Bytes 23/07/2010 18:41:35
VBASE016.VDF : 7.10.9.174 2048 Bytes 23/07/2010 18:41:35
VBASE017.VDF : 7.10.9.175 2048 Bytes 23/07/2010 18:41:35
VBASE018.VDF : 7.10.9.176 2048 Bytes 23/07/2010 18:41:35
VBASE019.VDF : 7.10.9.177 2048 Bytes 23/07/2010 18:41:36
VBASE020.VDF : 7.10.9.178 2048 Bytes 23/07/2010 18:41:36
VBASE021.VDF : 7.10.9.179 2048 Bytes 23/07/2010 18:41:39
VBASE022.VDF : 7.10.9.180 2048 Bytes 23/07/2010 18:41:39
VBASE023.VDF : 7.10.9.181 2048 Bytes 23/07/2010 18:41:39
VBASE024.VDF : 7.10.9.182 2048 Bytes 23/07/2010 18:41:39
VBASE025.VDF : 7.10.9.183 2048 Bytes 23/07/2010 18:41:39
VBASE026.VDF : 7.10.9.184 2048 Bytes 23/07/2010 18:41:39
VBASE027.VDF : 7.10.9.185 2048 Bytes 23/07/2010 18:41:39
VBASE028.VDF : 7.10.9.186 2048 Bytes 23/07/2010 18:41:39
VBASE029.VDF : 7.10.9.187 2048 Bytes 23/07/2010 18:41:39
VBASE030.VDF : 7.10.9.188 2048 Bytes 23/07/2010 18:41:40
VBASE031.VDF : 7.10.9.193 68608 Bytes 23/07/2010 18:41:42
Engineversion : 8.2.4.26
AEVDF.DLL : 8.1.2.0 106868 Bytes 23/04/2010 19:20:12
AESCRIPT.DLL : 8.1.3.41 1364346 Bytes 20/07/2010 18:18:03
AESCN.DLL : 8.1.6.1 127347 Bytes 12/05/2010 17:05:45
AESBX.DLL : 8.1.3.1 254324 Bytes 23/04/2010 19:20:12
AERDL.DLL : 8.1.8.2 614772 Bytes 20/07/2010 18:17:44
AEPACK.DLL : 8.2.3.2 471414 Bytes 20/07/2010 18:17:29
AEOFFICE.DLL : 8.1.1.8 201081 Bytes 21/07/2010 18:15:56
AEHEUR.DLL : 8.1.2.6 2793846 Bytes 20/07/2010 18:17:18
AEHELP.DLL : 8.1.13.2 242039 Bytes 20/07/2010 18:16:30
AEGEN.DLL : 8.1.3.17 385396 Bytes 21/07/2010 18:15:55
AEEMU.DLL : 8.1.2.0 393588 Bytes 23/04/2010 19:20:11
AECORE.DLL : 8.1.16.2 192887 Bytes 20/07/2010 18:16:19
AEBB.DLL : 8.1.1.0 53618 Bytes 23/04/2010 19:20:11
AVWINLL.DLL : 9.0.0.3 18177 Bytes 12/12/2008 07:47:59
AVPREF.DLL : 9.0.3.0 44289 Bytes 26/08/2009 14:14:02
AVREP.DLL : 8.0.0.7 159784 Bytes 18/02/2010 17:46:55
AVREG.DLL : 9.0.0.0 36609 Bytes 05/12/2008 09:32:09
AVARKT.DLL : 9.0.0.3 292609 Bytes 24/03/2009 14:05:41
AVEVTLOG.DLL : 9.0.0.7 167169 Bytes 30/01/2009 09:37:08
SQLITE3.DLL : 3.6.1.0 326401 Bytes 28/01/2009 14:03:49
SMTPLIB.DLL : 9.2.0.25 28417 Bytes 02/02/2009 07:21:33
NETNT.DLL : 9.0.0.0 11521 Bytes 05/12/2008 09:32:10
RCIMAGE.DLL : 9.0.0.25 2438913 Bytes 15/05/2009 14:39:58
RCTEXT.DLL : 9.0.73.0 86785 Bytes 13/10/2009 11:25:47
Configuration settings for the scan:
Jobname.............................: Complete system scan
Configuration file..................: c:\program files\avira\antivir desktop\sysscan.avp
Logging.............................: low
Primary action......................: interactive
Secondary action....................: ignore
Scan master boot sector.............: on
Scan boot sector....................: on
Boot sectors........................: C:, D:,
Process scan........................: on
Scan registry.......................: on
Search for rootkits.................: on
Integrity checking of system files..: off
Scan all files......................: All files
Scan archives.......................: on
Recursion depth.....................: 20
Smart extensions....................: on
Macro heuristic.....................: on
File heuristic......................: medium
Deviating risk categories...........: +APPL,+GAME,+JOKE,+PCK,+PFS,+SPR,
Start of the scan: samedi 24 juillet 2010 15:57
Starting search for hidden objects.
'115406' objects were checked, '0' hidden objects were found.
The scan of running processes will be started
Scan process 'SearchFilterHost.exe' - '1' Module(s) have been scanned
Scan process 'SearchProtocolHost.exe' - '1' Module(s) have been scanned
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'Browser.exe' - '1' Module(s) have been scanned
Scan process 'WmiPrvSE.exe' - '1' Module(s) have been scanned
Scan process 'FTCOMModule.exe' - '1' Module(s) have been scanned
Scan process 'OraConfigRecover.exe' - '1' Module(s) have been scanned
Scan process 'CoreCom.exe' - '1' Module(s) have been scanned
Scan process 'Deskboard.exe' - '1' Module(s) have been scanned
Scan process 'SystrayApp.exe' - '1' Module(s) have been scanned
Scan process 'ConnectivityManager.exe' - '1' Module(s) have been scanned
Scan process 'AlertModule.exe' - '1' Module(s) have been scanned
Scan process 'Launcher.exe' - '1' Module(s) have been scanned
Scan process 'CCC.exe' - '1' Module(s) have been scanned
Scan process 'VideoCamSuiteAutoStart.exe' - '1' Module(s) have been scanned
Scan process 'MOM.exe' - '1' Module(s) have been scanned
Scan process 'msnmsgr.exe' - '1' Module(s) have been scanned
Scan process 'LightScribeControlPanel.exe' - '1' Module(s) have been scanned
Scan process 'sidebar.exe' - '1' Module(s) have been scanned
Scan process 'avgnt.exe' - '1' Module(s) have been scanned
Scan process 'RtHDVCpl.exe' - '1' Module(s) have been scanned
Scan process 'SynTPEnh.exe' - '1' Module(s) have been scanned
Scan process 'WLIDSVCM.EXE' - '1' Module(s) have been scanned
Scan process 'notepad.exe' - '1' Module(s) have been scanned
Scan process 'SearchIndexer.exe' - '1' Module(s) have been scanned
Scan process 'WLIDSVC.EXE' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'StkCSrv.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'SeaPort.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'LSSrvc.exe' - '1' Module(s) have been scanned
Scan process 'FTRTSVC.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'mDNSResponder.exe' - '1' Module(s) have been scanned
Scan process 'bgsvcgen.exe' - '1' Module(s) have been scanned
Scan process 'ATKOSD.exe' - '1' Module(s) have been scanned
Scan process 'ACEngSvr.exe' - '1' Module(s) have been scanned
Scan process 'ACMON.exe' - '1' Module(s) have been scanned
Scan process 'BatteryLife.exe' - '1' Module(s) have been scanned
Scan process 'wcourier.exe' - '1' Module(s) have been scanned
Scan process 'HControl.exe' - '1' Module(s) have been scanned
Scan process 'taskeng.exe' - '1' Module(s) have been scanned
Scan process 'ALU.exe' - '1' Module(s) have been scanned
Scan process 'taskeng.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'taskeng.exe' - '1' Module(s) have been scanned
Scan process 'dwm.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'avguard.exe' - '1' Module(s) have been scanned
Scan process 'sched.exe' - '1' Module(s) have been scanned
Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
Scan process 'ASLDRSrv.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'Ati2evxx.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'SLsvc.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'audiodg.exe' - '0' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'Ati2evxx.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'lsm.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'wininit.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
74 processes with 74 modules were scanned
Voilà le bilan antivir
Avira AntiVir Personal
Report file date: samedi 24 juillet 2010 15:57
Scanning for 2566895 virus strains and unwanted programs.
Licensee : Avira AntiVir Personal - FREE Antivirus
Serial number : 0000149996-ADJIE-0000001
Platform : Windows Vista
Windows version : (Service Pack 2) [6.0.6002]
Boot mode : Normally booted
Username : SYSTEM
Computer name : PC-DE-MORNAS
Version information:
BUILD.DAT : 9.0.0.422 21701 Bytes 09/03/2010 10:29:00
AVSCAN.EXE : 9.0.3.10 466689 Bytes 13/10/2009 10:26:33
AVSCAN.DLL : 9.0.3.0 40705 Bytes 27/02/2009 09:58:24
LUKE.DLL : 9.0.3.2 209665 Bytes 20/02/2009 10:35:49
LUKERES.DLL : 9.0.2.0 12033 Bytes 27/02/2009 09:58:52
VBASE000.VDF : 7.10.0.0 19875328 Bytes 06/11/2009 06:35:52
VBASE001.VDF : 7.10.1.0 1372672 Bytes 19/11/2009 17:52:28
VBASE002.VDF : 7.10.3.1 3143680 Bytes 20/01/2010 20:10:12
VBASE003.VDF : 7.10.3.75 996864 Bytes 26/01/2010 18:45:48
VBASE004.VDF : 7.10.4.203 1579008 Bytes 05/03/2010 15:08:46
VBASE005.VDF : 7.10.6.82 2494464 Bytes 15/04/2010 18:20:25
VBASE006.VDF : 7.10.7.218 2294784 Bytes 02/06/2010 20:02:39
VBASE007.VDF : 7.10.9.165 4840960 Bytes 23/07/2010 18:41:30
VBASE008.VDF : 7.10.9.166 2048 Bytes 23/07/2010 18:41:30
VBASE009.VDF : 7.10.9.167 2048 Bytes 23/07/2010 18:41:31
VBASE010.VDF : 7.10.9.168 2048 Bytes 23/07/2010 18:41:32
VBASE011.VDF : 7.10.9.169 2048 Bytes 23/07/2010 18:41:33
VBASE012.VDF : 7.10.9.170 2048 Bytes 23/07/2010 18:41:33
VBASE013.VDF : 7.10.9.171 2048 Bytes 23/07/2010 18:41:35
VBASE014.VDF : 7.10.9.172 2048 Bytes 23/07/2010 18:41:35
VBASE015.VDF : 7.10.9.173 2048 Bytes 23/07/2010 18:41:35
VBASE016.VDF : 7.10.9.174 2048 Bytes 23/07/2010 18:41:35
VBASE017.VDF : 7.10.9.175 2048 Bytes 23/07/2010 18:41:35
VBASE018.VDF : 7.10.9.176 2048 Bytes 23/07/2010 18:41:35
VBASE019.VDF : 7.10.9.177 2048 Bytes 23/07/2010 18:41:36
VBASE020.VDF : 7.10.9.178 2048 Bytes 23/07/2010 18:41:36
VBASE021.VDF : 7.10.9.179 2048 Bytes 23/07/2010 18:41:39
VBASE022.VDF : 7.10.9.180 2048 Bytes 23/07/2010 18:41:39
VBASE023.VDF : 7.10.9.181 2048 Bytes 23/07/2010 18:41:39
VBASE024.VDF : 7.10.9.182 2048 Bytes 23/07/2010 18:41:39
VBASE025.VDF : 7.10.9.183 2048 Bytes 23/07/2010 18:41:39
VBASE026.VDF : 7.10.9.184 2048 Bytes 23/07/2010 18:41:39
VBASE027.VDF : 7.10.9.185 2048 Bytes 23/07/2010 18:41:39
VBASE028.VDF : 7.10.9.186 2048 Bytes 23/07/2010 18:41:39
VBASE029.VDF : 7.10.9.187 2048 Bytes 23/07/2010 18:41:39
VBASE030.VDF : 7.10.9.188 2048 Bytes 23/07/2010 18:41:40
VBASE031.VDF : 7.10.9.193 68608 Bytes 23/07/2010 18:41:42
Engineversion : 8.2.4.26
AEVDF.DLL : 8.1.2.0 106868 Bytes 23/04/2010 19:20:12
AESCRIPT.DLL : 8.1.3.41 1364346 Bytes 20/07/2010 18:18:03
AESCN.DLL : 8.1.6.1 127347 Bytes 12/05/2010 17:05:45
AESBX.DLL : 8.1.3.1 254324 Bytes 23/04/2010 19:20:12
AERDL.DLL : 8.1.8.2 614772 Bytes 20/07/2010 18:17:44
AEPACK.DLL : 8.2.3.2 471414 Bytes 20/07/2010 18:17:29
AEOFFICE.DLL : 8.1.1.8 201081 Bytes 21/07/2010 18:15:56
AEHEUR.DLL : 8.1.2.6 2793846 Bytes 20/07/2010 18:17:18
AEHELP.DLL : 8.1.13.2 242039 Bytes 20/07/2010 18:16:30
AEGEN.DLL : 8.1.3.17 385396 Bytes 21/07/2010 18:15:55
AEEMU.DLL : 8.1.2.0 393588 Bytes 23/04/2010 19:20:11
AECORE.DLL : 8.1.16.2 192887 Bytes 20/07/2010 18:16:19
AEBB.DLL : 8.1.1.0 53618 Bytes 23/04/2010 19:20:11
AVWINLL.DLL : 9.0.0.3 18177 Bytes 12/12/2008 07:47:59
AVPREF.DLL : 9.0.3.0 44289 Bytes 26/08/2009 14:14:02
AVREP.DLL : 8.0.0.7 159784 Bytes 18/02/2010 17:46:55
AVREG.DLL : 9.0.0.0 36609 Bytes 05/12/2008 09:32:09
AVARKT.DLL : 9.0.0.3 292609 Bytes 24/03/2009 14:05:41
AVEVTLOG.DLL : 9.0.0.7 167169 Bytes 30/01/2009 09:37:08
SQLITE3.DLL : 3.6.1.0 326401 Bytes 28/01/2009 14:03:49
SMTPLIB.DLL : 9.2.0.25 28417 Bytes 02/02/2009 07:21:33
NETNT.DLL : 9.0.0.0 11521 Bytes 05/12/2008 09:32:10
RCIMAGE.DLL : 9.0.0.25 2438913 Bytes 15/05/2009 14:39:58
RCTEXT.DLL : 9.0.73.0 86785 Bytes 13/10/2009 11:25:47
Configuration settings for the scan:
Jobname.............................: Complete system scan
Configuration file..................: c:\program files\avira\antivir desktop\sysscan.avp
Logging.............................: low
Primary action......................: interactive
Secondary action....................: ignore
Scan master boot sector.............: on
Scan boot sector....................: on
Boot sectors........................: C:, D:,
Process scan........................: on
Scan registry.......................: on
Search for rootkits.................: on
Integrity checking of system files..: off
Scan all files......................: All files
Scan archives.......................: on
Recursion depth.....................: 20
Smart extensions....................: on
Macro heuristic.....................: on
File heuristic......................: medium
Deviating risk categories...........: +APPL,+GAME,+JOKE,+PCK,+PFS,+SPR,
Start of the scan: samedi 24 juillet 2010 15:57
Starting search for hidden objects.
'115406' objects were checked, '0' hidden objects were found.
The scan of running processes will be started
Scan process 'SearchFilterHost.exe' - '1' Module(s) have been scanned
Scan process 'SearchProtocolHost.exe' - '1' Module(s) have been scanned
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'Browser.exe' - '1' Module(s) have been scanned
Scan process 'WmiPrvSE.exe' - '1' Module(s) have been scanned
Scan process 'FTCOMModule.exe' - '1' Module(s) have been scanned
Scan process 'OraConfigRecover.exe' - '1' Module(s) have been scanned
Scan process 'CoreCom.exe' - '1' Module(s) have been scanned
Scan process 'Deskboard.exe' - '1' Module(s) have been scanned
Scan process 'SystrayApp.exe' - '1' Module(s) have been scanned
Scan process 'ConnectivityManager.exe' - '1' Module(s) have been scanned
Scan process 'AlertModule.exe' - '1' Module(s) have been scanned
Scan process 'Launcher.exe' - '1' Module(s) have been scanned
Scan process 'CCC.exe' - '1' Module(s) have been scanned
Scan process 'VideoCamSuiteAutoStart.exe' - '1' Module(s) have been scanned
Scan process 'MOM.exe' - '1' Module(s) have been scanned
Scan process 'msnmsgr.exe' - '1' Module(s) have been scanned
Scan process 'LightScribeControlPanel.exe' - '1' Module(s) have been scanned
Scan process 'sidebar.exe' - '1' Module(s) have been scanned
Scan process 'avgnt.exe' - '1' Module(s) have been scanned
Scan process 'RtHDVCpl.exe' - '1' Module(s) have been scanned
Scan process 'SynTPEnh.exe' - '1' Module(s) have been scanned
Scan process 'WLIDSVCM.EXE' - '1' Module(s) have been scanned
Scan process 'notepad.exe' - '1' Module(s) have been scanned
Scan process 'SearchIndexer.exe' - '1' Module(s) have been scanned
Scan process 'WLIDSVC.EXE' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'StkCSrv.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'SeaPort.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'LSSrvc.exe' - '1' Module(s) have been scanned
Scan process 'FTRTSVC.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'mDNSResponder.exe' - '1' Module(s) have been scanned
Scan process 'bgsvcgen.exe' - '1' Module(s) have been scanned
Scan process 'ATKOSD.exe' - '1' Module(s) have been scanned
Scan process 'ACEngSvr.exe' - '1' Module(s) have been scanned
Scan process 'ACMON.exe' - '1' Module(s) have been scanned
Scan process 'BatteryLife.exe' - '1' Module(s) have been scanned
Scan process 'wcourier.exe' - '1' Module(s) have been scanned
Scan process 'HControl.exe' - '1' Module(s) have been scanned
Scan process 'taskeng.exe' - '1' Module(s) have been scanned
Scan process 'ALU.exe' - '1' Module(s) have been scanned
Scan process 'taskeng.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'taskeng.exe' - '1' Module(s) have been scanned
Scan process 'dwm.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'avguard.exe' - '1' Module(s) have been scanned
Scan process 'sched.exe' - '1' Module(s) have been scanned
Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
Scan process 'ASLDRSrv.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'Ati2evxx.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'SLsvc.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'audiodg.exe' - '0' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'Ati2evxx.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'lsm.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'wininit.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
74 processes with 74 modules were scanned
nanou.o
Messages postés
64
Date d'inscription
mercredi 21 juillet 2010
Statut
Membre
Dernière intervention
13 novembre 2010
25 juil. 2010 à 08:28
25 juil. 2010 à 08:28
Starting master boot sector scan:
Master boot sector HD0
[INFO] No virus was found!
Master boot sector HD1
[INFO] No virus was found!
Start scanning boot sectors:
Boot sector 'C:\'
[INFO] No virus was found!
Boot sector 'D:\'
[INFO] No virus was found!
Starting to scan executable files (registry).
The registry was scanned ( '49' files ).
Starting the file scan:
Begin scan in 'C:\' <VistaOS>
C:\hiberfil.sys
[WARNING] The file could not be opened!
[NOTE] This file is a Windows system file.
[NOTE] This file cannot be opened for scanning.
C:\pagefile.sys
[WARNING] The file could not be opened!
[NOTE] This file is a Windows system file.
[NOTE] This file cannot be opened for scanning.
C:\Program Files\Ad-Remover\Quarantine\C\Program Files\bardiscover\bardiscover.dll.vir
[DETECTION] Is the TR/BHO.Zwangi.642 Trojan
C:\Program Files\Ad-Remover\Quarantine\C\Program Files\bardiscover\bardiscover.exe.vir
[DETECTION] Is the TR/BHO.Zwangi.517 Trojan
C:\Program Files\Ad-Remover\Quarantine\C\Program Files\Hotbar\bin\11.0.175.0\HotbarSADF.exe.vir
[DETECTION] Contains recognition pattern of the ADSPY/AdSpy.Gen2 adware or spyware
C:\Program Files\Ad-Remover\Quarantine\C\Program Files\Hotbar\bin\11.0.175.0\Srv.exe.vir
[DETECTION] Contains recognition pattern of the ADSPY/AdSpy.Gen2 adware or spyware
C:\Program Files\Ad-Remover\Quarantine\C\Program Files\Hotbar\bin\11.0.175.0\Weather.exe.vir
[DETECTION] Contains recognition pattern of the ADSPY/AdSpy.Gen2 adware or spyware
C:\Program Files\Ad-Remover\Quarantine\C\Program Files\Hotbar\bin\11.0.175.0\WeSkin.VIR.vir
[DETECTION] Contains recognition pattern of the ADSPY/AdSpy.Gen2 adware or spyware
C:\Program Files\Ad-Remover\Quarantine\C\Program Files\Hotbar\bin\11.0.175.0\firefox\extensions\plugins\npclntax_HotbarSA.dll.vir
[DETECTION] Contains recognition pattern of the ADSPY/AdSpy.Gen2 adware or spyware
C:\Users\MORNAS\AppData\Local\qcufaj.VIR
[DETECTION] Contains virus patterns of Adware ADWARE/Adware.Gen2
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7UDZT58W\upgrade[1].cab
[0] Archive type: CAB (Microsoft)
--> upgrade.exe
[DETECTION] Is the TR/BHO.Zwangi.626 Trojan
--> [UnknownDir]/bardiscover.dll
[DETECTION] Is the TR/GerVar.598016.DP Trojan
--> [UnknownDir]/bardiscover.exe
[DETECTION] Is the TR/BHO.Zwangi.618 Trojan
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DHW1NJQC\upgrade[1].cab
[0] Archive type: CAB (Microsoft)
--> upgrade.exe
[DETECTION] Is the TR/BHO.Zwangi.621 Trojan
--> [UnknownDir]/bardiscover.dll
[DETECTION] Is the TR/BHO.Zwangi.627 Trojan
--> [UnknownDir]/bardiscover.exe
[DETECTION] Is the TR/BHO.Zwangi.640 Trojan
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DHW1NJQC\upgrade[2].cab
[0] Archive type: CAB (Microsoft)
--> upgrade.exe
[DETECTION] Is the TR/GerVar.669904 Trojan
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G1HNZ4X7\upgrade[2].cab
[0] Archive type: CAB (Microsoft)
--> upgrade.exe
[DETECTION] Is the TR/BHO.Zwangi.578 Trojan
--> [UnknownDir]/bardiscover.dll
[DETECTION] Is the TR/BHO.Zwangi.642 Trojan
--> [UnknownDir]/bardiscover.exe
[DETECTION] Is the TR/BHO.Zwangi.517 Trojan
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LOOHBLFU\upgrade[1].cab
[0] Archive type: CAB (Microsoft)
--> upgrade.exe
[DETECTION] Contains recognition pattern of the DR/Zwangi.aal dropper
--> [UnknownDir]/bardiscover.dll
[DETECTION] Contains virus patterns of Adware ADWARE/Zwangi.aal
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LOOHBLFU\upgrade[2].cab
[0] Archive type: CAB (Microsoft)
--> upgrade.exe
[DETECTION] Is the TR/Drop.TMR Trojan
--> [UnknownDir]/bardiscover.dll
[DETECTION] Contains virus patterns of Adware ADWARE/Agent.NEE
--> [UnknownDir]/bardiscover.exe
[DETECTION] Is the TR/BHO.Zwangi.619 Trojan
Begin scan in 'D:\' <DATA>
Beginning disinfection:
C:\Program Files\Ad-Remover\Quarantine\C\Program Files\bardiscover\bardiscover.dll.vir
[DETECTION] Is the TR/BHO.Zwangi.642 Trojan
[WARNING] The file was ignored!
C:\Program Files\Ad-Remover\Quarantine\C\Program Files\bardiscover\bardiscover.exe.vir
[DETECTION] Is the TR/BHO.Zwangi.517 Trojan
[WARNING] The file was ignored!
C:\Program Files\Ad-Remover\Quarantine\C\Program Files\Hotbar\bin\11.0.175.0\HotbarSADF.exe.vir
[DETECTION] Contains recognition pattern of the ADSPY/AdSpy.Gen2 adware or spyware
[WARNING] The file was ignored!
C:\Program Files\Ad-Remover\Quarantine\C\Program Files\Hotbar\bin\11.0.175.0\Srv.exe.vir
[DETECTION] Contains recognition pattern of the ADSPY/AdSpy.Gen2 adware or spyware
[WARNING] The file was ignored!
C:\Program Files\Ad-Remover\Quarantine\C\Program Files\Hotbar\bin\11.0.175.0\Weather.exe.vir
[DETECTION] Contains recognition pattern of the ADSPY/AdSpy.Gen2 adware or spyware
[WARNING] The file was ignored!
C:\Program Files\Ad-Remover\Quarantine\C\Program Files\Hotbar\bin\11.0.175.0\WeSkin.VIR.vir
[DETECTION] Contains recognition pattern of the ADSPY/AdSpy.Gen2 adware or spyware
[WARNING] The file was ignored!
C:\Program Files\Ad-Remover\Quarantine\C\Program Files\Hotbar\bin\11.0.175.0\firefox\extensions\plugins\npclntax_HotbarSA.dll.vir
[DETECTION] Contains recognition pattern of the ADSPY/AdSpy.Gen2 adware or spyware
[WARNING] The file was ignored!
C:\Users\MORNAS\AppData\Local\qcufaj.VIR
[DETECTION] Contains virus patterns of Adware ADWARE/Adware.Gen2
[WARNING] The file was ignored!
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7UDZT58W\upgrade[1].cab
[WARNING] The file was ignored!
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DHW1NJQC\upgrade[1].cab
[WARNING] The file was ignored!
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DHW1NJQC\upgrade[2].cab
[WARNING] The file was ignored!
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G1HNZ4X7\upgrade[2].cab
[WARNING] The file was ignored!
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LOOHBLFU\upgrade[1].cab
[WARNING] The file was ignored!
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LOOHBLFU\upgrade[2].cab
[WARNING] The file was ignored!
End of the scan: samedi 24 juillet 2010 23:18
Used time: 1:53:23 Hour(s)
The scan has been done completely.
27563 Scanned directories
446720 Files were scanned
23 Viruses and/or unwanted programs were found
0 Files were classified as suspicious
0 files were deleted
0 Viruses and unwanted programs were repaired
0 Files were moved to quarantine
0 Files were renamed
2 Files cannot be scanned
446695 Files not concerned
4776 Archives were scanned
16 Warnings
2 Notes
115406 Objects were scanned with rootkit scan
0 Hidden objects were found
Master boot sector HD0
[INFO] No virus was found!
Master boot sector HD1
[INFO] No virus was found!
Start scanning boot sectors:
Boot sector 'C:\'
[INFO] No virus was found!
Boot sector 'D:\'
[INFO] No virus was found!
Starting to scan executable files (registry).
The registry was scanned ( '49' files ).
Starting the file scan:
Begin scan in 'C:\' <VistaOS>
C:\hiberfil.sys
[WARNING] The file could not be opened!
[NOTE] This file is a Windows system file.
[NOTE] This file cannot be opened for scanning.
C:\pagefile.sys
[WARNING] The file could not be opened!
[NOTE] This file is a Windows system file.
[NOTE] This file cannot be opened for scanning.
C:\Program Files\Ad-Remover\Quarantine\C\Program Files\bardiscover\bardiscover.dll.vir
[DETECTION] Is the TR/BHO.Zwangi.642 Trojan
C:\Program Files\Ad-Remover\Quarantine\C\Program Files\bardiscover\bardiscover.exe.vir
[DETECTION] Is the TR/BHO.Zwangi.517 Trojan
C:\Program Files\Ad-Remover\Quarantine\C\Program Files\Hotbar\bin\11.0.175.0\HotbarSADF.exe.vir
[DETECTION] Contains recognition pattern of the ADSPY/AdSpy.Gen2 adware or spyware
C:\Program Files\Ad-Remover\Quarantine\C\Program Files\Hotbar\bin\11.0.175.0\Srv.exe.vir
[DETECTION] Contains recognition pattern of the ADSPY/AdSpy.Gen2 adware or spyware
C:\Program Files\Ad-Remover\Quarantine\C\Program Files\Hotbar\bin\11.0.175.0\Weather.exe.vir
[DETECTION] Contains recognition pattern of the ADSPY/AdSpy.Gen2 adware or spyware
C:\Program Files\Ad-Remover\Quarantine\C\Program Files\Hotbar\bin\11.0.175.0\WeSkin.VIR.vir
[DETECTION] Contains recognition pattern of the ADSPY/AdSpy.Gen2 adware or spyware
C:\Program Files\Ad-Remover\Quarantine\C\Program Files\Hotbar\bin\11.0.175.0\firefox\extensions\plugins\npclntax_HotbarSA.dll.vir
[DETECTION] Contains recognition pattern of the ADSPY/AdSpy.Gen2 adware or spyware
C:\Users\MORNAS\AppData\Local\qcufaj.VIR
[DETECTION] Contains virus patterns of Adware ADWARE/Adware.Gen2
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7UDZT58W\upgrade[1].cab
[0] Archive type: CAB (Microsoft)
--> upgrade.exe
[DETECTION] Is the TR/BHO.Zwangi.626 Trojan
--> [UnknownDir]/bardiscover.dll
[DETECTION] Is the TR/GerVar.598016.DP Trojan
--> [UnknownDir]/bardiscover.exe
[DETECTION] Is the TR/BHO.Zwangi.618 Trojan
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DHW1NJQC\upgrade[1].cab
[0] Archive type: CAB (Microsoft)
--> upgrade.exe
[DETECTION] Is the TR/BHO.Zwangi.621 Trojan
--> [UnknownDir]/bardiscover.dll
[DETECTION] Is the TR/BHO.Zwangi.627 Trojan
--> [UnknownDir]/bardiscover.exe
[DETECTION] Is the TR/BHO.Zwangi.640 Trojan
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DHW1NJQC\upgrade[2].cab
[0] Archive type: CAB (Microsoft)
--> upgrade.exe
[DETECTION] Is the TR/GerVar.669904 Trojan
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G1HNZ4X7\upgrade[2].cab
[0] Archive type: CAB (Microsoft)
--> upgrade.exe
[DETECTION] Is the TR/BHO.Zwangi.578 Trojan
--> [UnknownDir]/bardiscover.dll
[DETECTION] Is the TR/BHO.Zwangi.642 Trojan
--> [UnknownDir]/bardiscover.exe
[DETECTION] Is the TR/BHO.Zwangi.517 Trojan
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LOOHBLFU\upgrade[1].cab
[0] Archive type: CAB (Microsoft)
--> upgrade.exe
[DETECTION] Contains recognition pattern of the DR/Zwangi.aal dropper
--> [UnknownDir]/bardiscover.dll
[DETECTION] Contains virus patterns of Adware ADWARE/Zwangi.aal
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LOOHBLFU\upgrade[2].cab
[0] Archive type: CAB (Microsoft)
--> upgrade.exe
[DETECTION] Is the TR/Drop.TMR Trojan
--> [UnknownDir]/bardiscover.dll
[DETECTION] Contains virus patterns of Adware ADWARE/Agent.NEE
--> [UnknownDir]/bardiscover.exe
[DETECTION] Is the TR/BHO.Zwangi.619 Trojan
Begin scan in 'D:\' <DATA>
Beginning disinfection:
C:\Program Files\Ad-Remover\Quarantine\C\Program Files\bardiscover\bardiscover.dll.vir
[DETECTION] Is the TR/BHO.Zwangi.642 Trojan
[WARNING] The file was ignored!
C:\Program Files\Ad-Remover\Quarantine\C\Program Files\bardiscover\bardiscover.exe.vir
[DETECTION] Is the TR/BHO.Zwangi.517 Trojan
[WARNING] The file was ignored!
C:\Program Files\Ad-Remover\Quarantine\C\Program Files\Hotbar\bin\11.0.175.0\HotbarSADF.exe.vir
[DETECTION] Contains recognition pattern of the ADSPY/AdSpy.Gen2 adware or spyware
[WARNING] The file was ignored!
C:\Program Files\Ad-Remover\Quarantine\C\Program Files\Hotbar\bin\11.0.175.0\Srv.exe.vir
[DETECTION] Contains recognition pattern of the ADSPY/AdSpy.Gen2 adware or spyware
[WARNING] The file was ignored!
C:\Program Files\Ad-Remover\Quarantine\C\Program Files\Hotbar\bin\11.0.175.0\Weather.exe.vir
[DETECTION] Contains recognition pattern of the ADSPY/AdSpy.Gen2 adware or spyware
[WARNING] The file was ignored!
C:\Program Files\Ad-Remover\Quarantine\C\Program Files\Hotbar\bin\11.0.175.0\WeSkin.VIR.vir
[DETECTION] Contains recognition pattern of the ADSPY/AdSpy.Gen2 adware or spyware
[WARNING] The file was ignored!
C:\Program Files\Ad-Remover\Quarantine\C\Program Files\Hotbar\bin\11.0.175.0\firefox\extensions\plugins\npclntax_HotbarSA.dll.vir
[DETECTION] Contains recognition pattern of the ADSPY/AdSpy.Gen2 adware or spyware
[WARNING] The file was ignored!
C:\Users\MORNAS\AppData\Local\qcufaj.VIR
[DETECTION] Contains virus patterns of Adware ADWARE/Adware.Gen2
[WARNING] The file was ignored!
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7UDZT58W\upgrade[1].cab
[WARNING] The file was ignored!
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DHW1NJQC\upgrade[1].cab
[WARNING] The file was ignored!
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DHW1NJQC\upgrade[2].cab
[WARNING] The file was ignored!
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G1HNZ4X7\upgrade[2].cab
[WARNING] The file was ignored!
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LOOHBLFU\upgrade[1].cab
[WARNING] The file was ignored!
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LOOHBLFU\upgrade[2].cab
[WARNING] The file was ignored!
End of the scan: samedi 24 juillet 2010 23:18
Used time: 1:53:23 Hour(s)
The scan has been done completely.
27563 Scanned directories
446720 Files were scanned
23 Viruses and/or unwanted programs were found
0 Files were classified as suspicious
0 files were deleted
0 Viruses and unwanted programs were repaired
0 Files were moved to quarantine
0 Files were renamed
2 Files cannot be scanned
446695 Files not concerned
4776 Archives were scanned
16 Warnings
2 Notes
115406 Objects were scanned with rootkit scan
0 Hidden objects were found