Reboot au lancement de internet explorer - Page 3

  1. Bonjour Gen-hackman,

    me revoila après quelques vacances. J'ai exécuté CLRAV et voici le rapport :

    CLRAV.COM utility scan started 21/4/2011 22:11.
    -----------------------------------------------

    Scanning memory:
    Nothing to clean.
    scan finished 21/4/2011 22:12.

    toujours rien trouvé
    0
    1. desactive tes protections puis enregistre ceci sur ton bureau

      Pre_Scan

      Avertissement: Il y aura une extinction courte du bureau --> pas de panique.

      une fois telechargé lance-le , laisse faire le scan puis colle le contenu de "Pre_scan.txt" qui apparaitra à son terme , sur le bureau.

      si l'outil detecte un proxy et que tu n'en as pas installé clique sur "supprimer le proxy"

      si l'outil semble ne pas avoir fonctionné clique plusieurs fois très rapidement dessus
      0
      1. voici, et encore merci :

        ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Pre_Scan 1.0.0.34 ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

        ¤ XP | Vista | Seven - 32/64 ¤

        Mis à jour le 21/04/2011 | 15.30 par g3n-h@ckm@n
        Utilisateur : HP_Administrateur (Administrateurs)
        Ordinateur : CAMILLE

        Système d'exploitation : Microsoft Windows XP (32 bits)
        Internet Explorer : 8.0.6001.18702
        Mozilla Firefox : 4.0 (fr)

        Scan : 22:45:15 | 21/04/2011

        ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

        [HKCU\..\..\Winlogon] | Shell -> Modification apportée : -> explorer.exe

        ¤

        [HKLM\..\..\Winlogon] | Shell -> Aucune modification : explorer.exe -> explorer.exe
        [HKLM\..\..\Winlogon] | AutoRestartShell -> Aucune modification : 1 -> 1
        [HKLM\..\..\Winlogon] | userinit -> Aucune modification : C:\WINDOWS\System32\userinit.exe, -> C:\WINDOWS\System32\userinit.exe,
        [HKLM\..\..\Winlogon] | PowerDownAfterShutdown -> Aucune modification : 1 -> 1

        ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Associations ¤¤¤¤¤¤¤¤¤¤¤¤¤¤

        [.exe] : exefile
        [exefile | command] : "%1" %*
        [.com] : comfile
        [comfile | command] : "%1" %*
        [.scr] : scrfile
        [scrfile | command] : "%1" /S
        [.bat] : batfile
        [batfile | command] : "%1" %*
        [.cmd] : cmdfile
        [cmdfile | command] : "%1" %*
        [.pif] : piffile
        [piffile | command] : "%1" %*

        ¤

        [Firefox | Command] | @ -> Modification apportée : C:\Program Files\Mozilla Firefox\firefox.exe -> "C:\Program Files\Mozilla Firefox\Firefox.exe"
        [Firefox - Safemode | Command] | @ -> Aucune modification : "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode -> "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode
        [IE | Command] | @ -> Modification apportée : C:\Program Files\Internet Explorer\iexplore.exe -> "C:\Program Files\Internet Explorer\iexplore.exe"
        [Applications | IE | Command] | @ -> Aucune modification : "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 -> "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1

        ¤

        [Assoc | Applications] | @ -> Aucune modification : http://shell.windows.com/fileassoc/%04x/xml/redir.asp?Ext=%s -> http://shell.windows.com/fileassoc/%04x/xml/redir.asp?Ext=%s

        ¤¤¤¤¤¤¤¤¤¤ Services ¤¤¤¤¤¤¤¤¤¤

        [Ndisuio] | Start -> Aucune modification : 3 -> 3
        [lmhosts] | Start -> Aucune modification : 2 -> 2 : Service Actif
        [LanmanWorkstation] | Start -> Aucune modification : 2 -> 2 : Service Actif
        [LanmanServer] | Start -> Aucune modification : 2 -> 2 : Service Actif
        [Audiosrv] | Start -> Aucune modification : 2 -> 2 : Service Actif
        [ERSvc] | Start -> Aucune modification : 2 -> 2 : Service Actif
        [Bits] | Start -> Aucune modification : 2 -> 2 : Service Actif
        [CryptSvc] | Start -> Aucune modification : 2 -> 2 : Service Actif
        [EapHost] | Start -> Aucune modification : 2 -> 2 : Service Actif
        [SharedAccess] | Start -> Aucune modification : 2 -> 2 : Service Actif
        [wuauserv] | Start -> Aucune modification : 2 -> 2 : Service Actif
        [wscsvc] | Start -> Aucune modification : 2 -> 2 : Service Actif
        [wzcsvc] | Start -> Aucune modification : 2 -> 2 : Service Actif

        ¤¤¤¤¤¤¤¤¤¤ Internet Explorer ¤¤¤¤¤¤¤¤¤¤

        [HKCU | Main] | Start Page -> Modification apportée : https://www.01net.com/ -> https://www.google.com/?gws_rd=ssl
        [HKCU | Main] | Local Page -> Aucune Modification : C:\WINDOWS\system32\blank.htm -> C:\WINDOWS\system32\blank.htm
        [HKCU | Main] | Search Page -> Aucune Modification : http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch

        [HKLM | Main] | Start Page -> Aucune Modification : https://www.msn.com/fr-fr/?ocid=iehp -> https://www.msn.com/fr-fr/?ocid=iehp
        [HKLM | Main] | Local Page -> Aucune Modification : C:\WINDOWS\system32\blank.htm -> C:\WINDOWS\system32\blank.htm
        [HKLM | Main] | Default_Search_URL -> Aucune Modification : https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF -> https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        [HKLM | Main] | Default_Page_URL -> Aucune Modification : https://www.msn.com/fr-fr/?ocid=iehp -> https://www.msn.com/fr-fr/?ocid=iehp
        [HKLM | Main] | Search Page -> Aucune Modification : https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF -> https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF

        ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processus ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

        C:\WINDOWS\explorer.exe -> Processus stoppé

        ¤¤¤¤¤¤¤¤¤¤ Clés supprimées et Fichier mis en quarantaine ¤¤¤¤¤¤¤¤¤¤

        ¤¤¤¤¤¤¤¤¤¤ IFEO ¤¤¤¤¤¤¤¤¤¤

        ¤¤¤¤¤¤¤¤¤¤ Mountpoints2 ¤¤¤¤¤¤¤¤¤¤

        Supprimé : [HKCU\..\..\Mountpoints2\{20b5f2a2-5314-11e0-9da3-0014a5e5bd82}] -> command : J:\start.exe

        ¤¤¤¤¤¤¤¤¤¤ MBR ¤¤¤¤¤¤¤¤¤¤

        MBRCheck, version 1.2.3

        (c) 2010, AD

        Command-line: -za C:\MBR\MBR.bin

        Windows Version: Windows XP Professional

        Windows Information: Service Pack 3 (build 2600)

        Logical Drives Mask: 0x000001fc

        Analysis of file "C:\MBR\MBR.bin":

        Unknown MBR code

        Done!
        ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

        Fin : 22:45:33

        ¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤
        0
        1. reexplique-moi comment ca se passe peut etre qu on aura un element en plus
          0
          Précédent
          • 1
          • 2
          • 3