Google redirige vers goméo

didipy -  
 g3n-h@ckm@n -
Bonjour,

J'ai un problème, à chaque fois que je me connecte à internet et que je fais une recherche sur google, quand je clique sur les liens de Google, je suis redirigé sur Goméo ou d'autre sites de recherche ou des sites de pub.
insupportable!
Merci d'avance pour celui (celle) qui m'aidera à virer ce problème

d'avance merci

11 réponses

  1. g3n-h@ckm@n
     
    salut


    /!\ ATTENTION SUIVRE A LA LETTRE CES INDICATIONS/!\

    __________________________________________________________
    >Ce logiciel n'est à utiliser que prescrit par un helper qualifié et formé à l'outil.<
    >>>>>>>Ne pas utiliser en dehors de ce cas de figure : dangereux!<<<<<<<<
    =====================================================


    ▶ Surtout , pense à l'enregistrement à renommer Combofix en "ton prenom.exe" avant qu'il soit enregistré sur ton disque dur

    Telecharge ici : Combofix

    Avant d'utiliser ComboFix :

    Si tu utilises AVG, IL FAUT IMPERATIVEMENT LE DESINSTALLER avant d'utiliser Combofix car il peut causer des dégâts en interaction avec l'outil pouvant mener à la réinstallation totale du système.
    La simple désactivation du résident n'est pas suffisante.
    Télécharge le désinstalleur d'AVG sur ce lien : https://www.avg.com/fr-fr/avg-remover
    Choisis la version adéquate (32 ou 64 bits)/!\

    Les logiciels d'émulation de CD comme Daemon Tools peuvent gêner les outils de désinfection. Utilise Defogger pour les désactiver temporairement :

    ▶ Télécharge Defogger (de jpshortstuff) sur ton Bureau

    ▶ Lance le

    Une fenêtre apparait : clique sur "Disable"

    ▶ Fais redémarrer l'ordinateur si l'outil te le demande

    Note : Quand nous aurons terminé la désinfection, tu pourras réactiver ces logiciels en relançant Defogger et en cliquant sur "Re-enable"

    _________________________________________________________
    >> referme les fenêtres de tous les programmes en cours.
    >> Désactive provisoirement et seulement le temps de l'utilisation de ComboFix,
    >>la protection en temps réel de ton Antivirus et de tes Antispywares,
    >>qui peuvent gêner fortement la procédure de recherche et de nettoyage de l'outil.

    °°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°


    si tu as XP => double clique
    si tu as Vista ou windows 7 => clic droit "executer en tant que...."


    sur combofix renommé

    ¤¤¤¤¤¤¤¤¤¤ LAISSE-LE INSTALLER LA CONSOLE DE RECUPERATION S'IL TE LE DEMANDE ¤¤¤¤¤¤¤¤¤¤

    ▶ !!!!!NE TOUCHE A RIEN PENDANT LE TRAVAIL DE COMBOFIX (SOURIS/CLAVIER.....)!!!!!

    ▶ n'oublie pas de reactiver la garde de ton Antivirus et de tes Antispywares, avant de te reconnecter à internet.

    ▶▶ Reviens sur le forum, et copie et colle la totalité du contenu de C:\Combofix.txt dans ton prochain message.

    0
  2. didipy
     
    Bonjour

    et merci à toi g3n-h@ckm@n pour ta réponse rapide voici le rapport

    ComboFix 11-06-27.04 - Administrator 28/06/2011 15:52:31.1.1 - x86
    Microsoft Windows XP Professionnel 5.1.2600.2.1252.33.1033.18.2038.1418 [GMT 2:00]
    Lancé depuis: c:\documents and settings\Administrator\Desktop\didipy.exe
    AV: McAfee VirusScan Enterprise+AntiSpyware Enterprise *Disabled/Outdated* {918A2B0B-2C60-4016-A4AB-E868DEABF7F0}
    * Un nouveau point de restauration a été créé
    .
    .
    (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    c:\documents and settings\Administrator\WINDOWS
    c:\windows\daemon.dll
    c:\windows\Imaqia.exe
    c:\windows\Ivyvia.exe
    c:\windows\regsvr32.exe
    c:\windows\system\VEN2232.OLB
    c:\windows\system32\sshnas21.dll
    c:\windows\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
    c:\windows\unin0407.exe
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    -------\Legacy_IWIN_SERVICE
    -------\Legacy_SSHNAS
    -------\Legacy_USNJSVC
    -------\Service_sshnas
    -------\Service_usnjsvc
    .
    .
    ((((((((((((((((((((((((((((( Fichiers créés du 2011-05-28 au 2011-06-28 ))))))))))))))))))))))))))))))))))))
    .
    .
    2011-06-24 21:17 . 2011-06-24 21:17 -------- d-----w- c:\documents and settings\Administrator\Application Data\GlarySoft
    2011-06-24 21:12 . 2011-06-24 21:12 -------- d-----w- c:\program files\Glary Utilities
    2011-06-24 21:12 . 2011-06-24 21:12 -------- d-----w- c:\documents and settings\Administrator\Application Data\McAfee
    2011-06-24 21:11 . 2011-06-24 21:08 74848 ----a-w- c:\windows\system32\MfeOtlkAddin.dll
    2011-06-24 21:11 . 2011-06-24 21:08 22816 ----a-w- c:\windows\system32\MFEOtlk.dll
    2011-06-24 21:11 . 2011-06-24 21:08 9344 ----a-w- c:\windows\system32\drivers\mfeclnk.sys
    2011-06-24 21:11 . 2011-06-24 21:08 88544 ----a-w- c:\windows\system32\drivers\mfetdi2k.sys
    2011-06-24 21:11 . 2011-06-24 21:08 85152 ----a-w- c:\windows\system32\drivers\mferkdet.sys
    2011-06-24 21:11 . 2011-06-24 21:08 145936 ----a-w- c:\windows\system32\mfevtps.exe
    .
    .
    .
    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2011-06-25 07:32 . 2008-01-12 05:53 49152 ---ha-w- c:\documents and settings\Administrator\Application Data\Microsoft\Virtual PC\VPCKeyboard.dll
    2011-06-24 21:08 . 2008-01-09 01:50 58456 ----a-w- c:\windows\system32\drivers\mfebopk.sys
    2011-06-24 21:08 . 2008-01-09 01:50 171296 ----a-w- c:\windows\system32\drivers\mfeavfk.sys
    2011-06-24 21:08 . 2008-01-09 01:50 116104 ----a-w- c:\windows\system32\drivers\mfeapfk.sys
    2011-06-24 21:08 . 2008-01-09 01:50 436728 ----a-w- c:\windows\system32\drivers\mfehidk.sys
    .
    .
    ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
    REGEDIT4
    .
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\lib\NMBgMonitor.exe" [2005-09-16 94208]
    "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-01-16 68856]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2003-12-05 98304]
    "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2003-12-05 499712]
    "High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2004-10-27 61952]
    "SMSERIAL"="sm56hlpr.exe" [2005-11-10 557056]
    "igfxtray"="c:\windows\system32\igfxtray.exe" [2005-11-03 98304]
    "igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-11-03 77824]
    "igfxpers"="c:\windows\system32\igfxpers.exe" [2005-11-03 118784]
    "IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2006-07-03 802816]
    "IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2006-07-02 700416]
    "S7UB Start"="c:\program files\Common Files\Siemens\S7ubtoox\s7ubtstx.exe" [2006-03-13 102453]
    "McAfeeUpdaterUI"="c:\program files\McAfee\Common Framework\udaterui.exe" [2011-01-12 161088]
    "DAEMON Tools-1033"="c:\program files\D-Tools\daemon.exe" [2004-08-22 81920]
    "NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
    "BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 110592]
    "WinCC flexible Smart Start"="c:\program files\Siemens\SIMATIC WinCC flexible\WinCC flexible 2005\HmiSmartStart.exe" [2006-04-11 164816]
    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
    "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
    "ShStatEXE"="c:\program files\McAfee\VirusScan Enterprise\SHSTAT.EXE" [2011-01-12 215360]
    "Norton Ghost 9.0"="c:\program files\Symantec\Norton Ghost\Agent\GhostTray.exe" [2004-11-10 1126400]
    .
    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
    .
    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    Service Manager.lnk - c:\program files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe [2002-12-17 74308]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Nokia.PCSync]
    2008-06-17 14:00 1249280 ----a-w- c:\program files\Nokia\Nokia PC Suite 7\PcSync2.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite Tray]
    2008-08-11 06:31 1124352 ----a-w- c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
    "RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe"
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "AntiVirusOverride"=dword:00000001
    .
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "c:\\Program Files\\Common Files\\Siemens\\SQLANY\\dbsrv7.exe"=
    "c:\\Program Files\\McAfee\\Common Framework\\FrameworkService.exe"=
    "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
    "c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
    "c:\\Program Files\\Zattoo\\Zattoo2.exe"=
    "c:\\WINDOWS\\system32\\sessmgr.exe"=
    "c:\\Program Files\\MSSOAP\\Binaries\\MsSoapT.exe"=
    "c:\\Program Files\\Siemens\\Step7\\S7INF\\S7usiapx.exe"=
    "c:\\Program Files\\Siemens\\Step7\\S7BIN\\S7tgtopx.exe"=
    "c:\\Program Files\\Zattoo\\zattood.exe"=
    "c:\\WINDOWS\\system32\\CNAC6RPK.EXE"=
    "c:\\Program Files\\Siemens\\SIMATIC WinCC flexible\\WinCC flexible 2005\\HmiES.exe"=
    "c:\\Program Files\\Siemens\\SIMATIC WinCC flexible\\WinCC flexible 2005\\TraceServer.exe"=
    "c:\\Program Files\\Siemens\\SIMATIC WinCC flexible\\WinCC flexible 2005 Runtime\\HmiLoad.exe"=
    "c:\\Program Files\\Siemens\\SIMATIC WinCC flexible\\WinCC flexible 2005 Runtime\\Miniweb.exe"=
    "c:\\Program Files\\Siemens\\SIMATIC WinCC flexible\\WinCC flexible 2005 Runtime\\SmartServer.exe"=
    "c:\\WINDOWS\\system32\\Gateway.exe"=
    "c:\\WINDOWS\\system32\\GatewayDDE.exe"=
    "c:\\Program Files\\SEW\\MotionStudio\\SEWManager.exe"=
    "c:\\Program Files\\SEW\\MotionStudio\\Ofdas.exe"=
    "c:\\Program Files\\SEW\\SEW-Communication-Server\\Secos.exe"=
    .
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
    .
    R0 d347bus;d347bus;c:\windows\system32\drivers\d347bus.sys [08/01/2008 22:42 155136]
    R0 d347prt;d347prt;c:\windows\system32\drivers\d347prt.sys [08/01/2008 22:42 5248]
    R0 PQV2i;PQV2i;c:\windows\system32\drivers\PQV2i.sys [10/11/2004 10:30 138801]
    R1 mfetdi2k;McAfee Inc. mfetdi2k;c:\windows\system32\drivers\mfetdi2k.sys [24/06/2011 23:11 88544]
    R1 PQIMount;PQIMount;c:\windows\system32\drivers\PQIMount.sys [10/11/2004 10:49 46800]
    R2 almservice;Automation License Manager Service;c:\program files\Common Files\Siemens\SWS\almsrv\almsrvx.exe [30/11/2006 09:17 761918]
    R2 dpmconv;dpmconv;c:\windows\system32\drivers\dpmconv.sys [07/05/2007 12:19 269824]
    R2 Dpmtrcdd;Dpmtrcdd;c:\windows\system32\drivers\dpmtrcdd.sys [07/05/2007 12:29 28331]
    R2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [24/06/2011 23:11 145936]
    R2 MSSQL$WINCCFLEXIBLE;MSSQL$WINCCFLEXIBLE;c:\program files\Microsoft SQL Server\MSSQL$WINCCFLEXIBLE\Binn\sqlservr.exe -sWINCCFLEXIBLE --> c:\program files\Microsoft SQL Server\MSSQL$WINCCFLEXIBLE\Binn\sqlservr.exe -sWINCCFLEXIBLE [?]
    R2 NA_Service;NetAccess Service;c:\windows\system32\NA_Service.exe [09/01/2008 04:14 49152]
    R2 Peakcan;Peakcan;c:\windows\system32\drivers\PEAKCAN.SYS [31/01/2008 16:12 255872]
    R2 s7asysvx;S7 Global Services;c:\program files\Siemens\Step7\S7BIN\s7asysvx.exe [13/03/2006 17:00 69685]
    R2 s7odpx2x;s7odpx2x;c:\windows\system32\drivers\s7odpx2x.sys [18/04/2007 08:29 78408]
    R2 s7oiehsx;SIMATIC IEPG Help Service;c:\program files\Common Files\Siemens\S7IEPG\s7oiehsx.exe [18/04/2007 08:37 213064]
    R2 S7OTMCDX;Step7 Memory Card Driver;c:\windows\system32\drivers\s7otmcdx.sys [18/04/2007 08:34 274344]
    R2 s7snsrtx;PROFINET IO RT-Protocol;c:\windows\system32\drivers\s7snsrtx.sys [26/01/2006 13:29 70912]
    R2 S7TraceServiceX;S7TraceServiceX;c:\program files\Common Files\Siemens\Automation\TraceEngine\bin\S7TraceServiceX.exe [22/03/2007 12:29 163840]
    R2 Sim9Sync;SIMATIC NET Synchronization Service;c:\windows\system32\sim9sync.exe [19/07/2010 18:03 94208]
    R2 SQLAgent$WINCCFLEXIBLE;SQLAgent$WINCCFLEXIBLE;c:\program files\Microsoft SQL Server\MSSQL$WINCCFLEXIBLE\Binn\sqlagent.EXE -i WINCCFLEXIBLE --> c:\program files\Microsoft SQL Server\MSSQL$WINCCFLEXIBLE\Binn\sqlagent.EXE -i WINCCFLEXIBLE [?]
    R2 vnccom;vnccom;c:\windows\system32\drivers\vnccom.SYS [20/07/2010 15:20 6016]
    R2 vsnl2ada;SIMATIC MPI/PROFIBUS FDL Transport Driver;c:\windows\system32\drivers\vsnl2ada.sys [07/05/2007 12:19 105058]
    R3 Duntlw;UNTLW device;c:\windows\system32\drivers\DuntlwNT.sys [14/12/2009 13:40 53568]
    R3 fwkbdrtm;fwkbdrtm;c:\windows\system32\drivers\fwkbdrtm.sys [07/05/2007 14:23 2976]
    R3 S7opciax;SIMATIC CP 5611;c:\windows\system32\drivers\S7opciax.sys [09/03/2006 18:06 214600]
    S2 Ampro5611;CP5611 Amprolyzer;c:\windows\system32\drivers\Ampro5611.sys [15/08/2010 13:52 82496]
    S2 gupdate;Service Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [29/01/2010 17:08 135664]
    S3 CanPhoneService;CanPhoneService;c:\program files\Lenze\Systembus\Canphsrv.exe [23/08/2010 15:32 110592]
    S3 dpmcslv;dpmcslv;c:\windows\system32\drivers\dpmcslv.sys [07/05/2007 14:23 68280]
    S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [24/06/2011 23:11 85152]
    S3 Pcan_usb;PCAN-USB Device Driver;c:\windows\system32\drivers\Pcan_usb.sys [23/08/2010 16:45 343679]
    S3 S5AS511;S5AS511;c:\windows\system32\drivers\S5AS511.SYS [07/05/2007 13:34 15360]
    S3 S5MCD;S5MCD;c:\windows\system32\drivers\S5MCD.SYS [07/05/2007 13:34 188416]
    S3 s7oefs_x;SIMATIC MPI/EFS Driver;c:\windows\system32\drivers\s7oefs_x.sys [18/10/2002 02:34 30512]
    S3 usb2ser;usb2ser;c:\windows\system32\drivers\usb2ser.sys [11/06/2008 14:30 30336]
    .
    --- Autres Services/Pilotes en mémoire ---
    .
    *Deregistered* - mfeavfk01
    .
    Contenu du dossier 'Tâches planifiées'
    .
    2011-06-28 c:\windows\Tasks\GlaryInitialize.job
    - c:\program files\Glary Utilities\initialize.exe [2011-06-24 06:25]
    .
    2011-06-28 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2010-01-29 15:08]
    .
    2011-06-28 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2010-01-29 15:08]
    .
    .
    ------- Examen supplémentaire -------
    .
    uStart Page = hxxp://www.wuuta.com/
    mStart Page = hxxp://www.wuuta.com/
    uInternet Connection Wizard,ShellNext = hxxp://www.siemens.com/
    uSearchAssistant = hxxp://www.google.com/ie
    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
    IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
    IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
    LSP: c:\windows\system32\asdns.dll
    .
    - - - - ORPHELINS SUPPRIMES - - - -
    .
    AddRemove-PL7 ProV44 - c:\windows\PL7SYS\UNINSTAL\SETUP PL7PRO
    AddRemove-PL7 ProV45 - c:\windows\PL7SYS\UNINSTAL\SETUP PL7PRO
    AddRemove-TRWinProg - c:\windows\unin0407.exe
    AddRemove-{10B15004-CD2A-49BD-ACB7-DFA124F39273} - c:\program files\InstallShield Installation Information\{10B15004-CD2A-49BD-ACB7-DFA124F39273}\setup.exe -runfromtemp -l0x0009 -removeonly\ -REMV
    .
    .
    .
    **************************************************************************
    .
    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2011-06-28 15:58
    Windows 5.1.2600 Service Pack 2 NTFS
    .
    Recherche de processus cachés ...
    .
    Recherche d'éléments en démarrage automatique cachés ...
    .
    Recherche de fichiers cachés ...
    .
    Scan terminé avec succès
    Fichiers cachés: 0
    .
    **************************************************************************
    .
    --------------------- DLLs chargées dans les processus actifs ---------------------
    .
    - - - - - - - > 'explorer.exe'(4904)
    c:\windows\system32\ccofgnt.dll
    c:\program files\McAfee\Common Framework\McTrayLegacySupportPlugin.dll
    c:\program files\McAfee\Common Framework\McTrayInterfaceLib.dll
    c:\program files\McAfee\Common Framework\McAfeeWin32GUISupportDLL.dll
    c:\windows\system32\WPDShServiceObj.dll
    c:\program files\Nokia\Nokia PC Suite 7\phonebrowser.dll
    c:\program files\Nokia\Nokia PC Suite 7\NGSCM.DLL
    c:\program files\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_fre.nlr
    c:\program files\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
    c:\program files\Microsoft Virtual PC\VPCShExH.DLL
    c:\windows\system32\PortableDeviceTypes.dll
    c:\windows\system32\PortableDeviceApi.dll
    .
    ------------------------ Autres processus actifs ------------------------
    .
    c:\program files\Intel\Wireless\Bin\EvtEng.exe
    c:\program files\Intel\Wireless\Bin\S24EvMon.exe
    c:\windows\sm56hlpr.exe
    c:\windows\System32\GEARSec.exe
    c:\windows\system32\rundll32.exe
    c:\program files\McAfee\Common Framework\FrameworkService.exe
    c:\program files\McAfee\VirusScan Enterprise\VsTskMgr.exe
    c:\program files\McAfee\VirusScan Enterprise\mfeann.exe
    c:\program files\Common Files\Siemens\Sqlany\dbsrv7.exe
    c:\program files\Microsoft SQL Server\MSSQL$WINCCFLEXIBLE\Binn\sqlservr.exe
    c:\program files\Symantec\Norton Ghost\Agent\PQV2iSvc.exe
    c:\windows\system32\NA_XWAY.exe
    c:\program files\McAfee\Common Framework\naPrdMgr.exe
    c:\program files\Intel\Wireless\Bin\RegSrvc.exe
    c:\program files\McAfee\Common Framework\McTray.exe
    c:\program files\Microsoft SQL Server\MSSQL$WINCCFLEXIBLE\Binn\sqlagent.EXE
    c:\program files\Common Files\McAfee\SystemCore\mcshield.exe
    c:\program files\Common Files\Siemens\ALMPanelPlugin\ALMPanelPlugin.exe
    c:\windows\system32\CNAC6RPK.EXE
    c:\program files\Siemens\SIMATIC WinCC flexible\WinCC flexible 2005\HmiES.exe
    c:\windows\system32\wscntfy.exe
    c:\windows\system32\S7OTBXSX.EXE
    c:\windows\system32\wbem\wmiapsrv.exe
    c:\program files\siemens\simatic wincc flexible\wincc flexible 2005\TraceServer.exe
    .
    **************************************************************************
    .
    Heure de fin: 2011-06-28 15:59:53 - La machine a redémarré
    ComboFix-quarantined-files.txt 2011-06-28 13:59
    .
    Avant-CF: 20 925 026 304 bytes free
    Après-CF: 20 845 256 704 bytes free
    .
    - - End Of File - - EEC89C163F73D91E8E88CE72EF0DE268
    0
  3. g3n-h@ckm@n
     

    __________________________________________________
    =>/!\Le script qui suit a été écrit spécialement cet ordinateur/!\ <=
    =>il est fort déconseillé de le transposer sur un autre ordinateur !<=
    ----------------------------------------------------------------------------


    Toujours avec toutes les protections désactivées, fais ceci :

    ▶ Ouvre le bloc-notes (Menu démarrer --> programmes --> accessoires --> bloc-notes)
    ▶ Copie/colle dans le bloc-notes ce qui entre les lignes ci dessous (sans les lignes) :

    ----------------------------------------------------------
    KillAll::

    Registry::
    [HKEY_LOCAL_MACHINE\System\CurrentControlSet\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "3389:TCP"=-
    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "AntiVirusOverride"=dword:00000000
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "DAEMON Tools-1033"=-
    "NeroFilterCheck"=-
    "Adobe Reader Speed Launcher"=-

    DDS::
    LSP: c:\windows\system32\asdns.dll
    uStart Page = hxxp://www.wuuta.com/
    mStart Page = hxxp://www.wuuta.com/


    ------------------------------------------------------------------

    ▶ Enregistre ce fichier sur ton Bureau (et pas ailleurs !) sous le nom CFScript.txt
    ▶ Quitte le Bloc Notes

    ▶ Fais un glisser/déposer de ce fichier CFScript sur le fichier combofix

    ▶ Patiente le temps du scan. Le Bureau va disparaître à plusieurs reprises : c'est normal ! Ne touche à rien tant que le scan n'est pas terminé.
    ▶ Une fois le scan achevé, un rapport va s'afficher: poste son contenu.
    ▶ Si le fichier ne s'ouvre pas, il se trouve ici => C:\ComboFix.txt

    0
  4. didipy
     
    Voici le nouveau rapport merci d'avance

    ComboFix 11-06-27.04 - Administrator 29/06/2011 9:36.2.1 - x86
    Microsoft Windows XP Professionnel 5.1.2600.2.1252.33.1033.18.2038.1428 [GMT 2:00]
    Lancé depuis: c:\documents and settings\Administrator\Desktop\didipy.exe
    Commutateurs utilisés :: c:\documents and settings\Administrator\Desktop\CFScript.txt
    AV: McAfee VirusScan Enterprise+AntiSpyware Enterprise *Disabled/Outdated* {918A2B0B-2C60-4016-A4AB-E868DEABF7F0}
    .
    .
    (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    c:\windows\system32\asdns.dll
    .
    .
    ((((((((((((((((((((((((((((( Fichiers créés du 2011-05-28 au 2011-06-29 ))))))))))))))))))))))))))))))))))))
    .
    .
    2011-06-29 07:33 . 2011-06-29 07:33 -------- d-----w- C:\didipy
    2011-06-24 21:17 . 2011-06-24 21:17 -------- d-----w- c:\documents and settings\Administrator\Application Data\GlarySoft
    2011-06-24 21:12 . 2011-06-24 21:12 -------- d-----w- c:\program files\Glary Utilities
    2011-06-24 21:12 . 2011-06-24 21:12 -------- d-----w- c:\documents and settings\Administrator\Application Data\McAfee
    2011-06-24 21:11 . 2011-06-24 21:08 74848 ----a-w- c:\windows\system32\MfeOtlkAddin.dll
    2011-06-24 21:11 . 2011-06-24 21:08 22816 ----a-w- c:\windows\system32\MFEOtlk.dll
    2011-06-24 21:11 . 2011-06-24 21:08 9344 ----a-w- c:\windows\system32\drivers\mfeclnk.sys
    2011-06-24 21:11 . 2011-06-24 21:08 88544 ----a-w- c:\windows\system32\drivers\mfetdi2k.sys
    2011-06-24 21:11 . 2011-06-24 21:08 85152 ----a-w- c:\windows\system32\drivers\mferkdet.sys
    2011-06-24 21:11 . 2011-06-24 21:08 145936 ----a-w- c:\windows\system32\mfevtps.exe
    .
    .
    .
    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2011-06-25 07:32 . 2008-01-12 05:53 49152 ---ha-w- c:\documents and settings\Administrator\Application Data\Microsoft\Virtual PC\VPCKeyboard.dll
    2011-06-24 21:08 . 2008-01-09 01:50 58456 ----a-w- c:\windows\system32\drivers\mfebopk.sys
    2011-06-24 21:08 . 2008-01-09 01:50 171296 ----a-w- c:\windows\system32\drivers\mfeavfk.sys
    2011-06-24 21:08 . 2008-01-09 01:50 116104 ----a-w- c:\windows\system32\drivers\mfeapfk.sys
    2011-06-24 21:08 . 2008-01-09 01:50 436728 ----a-w- c:\windows\system32\drivers\mfehidk.sys
    .
    .
    ((((((((((((((((((((((((((((( SnapShot@2011-06-28_13.57.42 )))))))))))))))))))))))))))))))))))))))))
    .
    + 2011-06-29 07:40 . 2011-06-29 07:40 16384 c:\windows\temp\Perflib_Perfdata_ccc.dat
    .
    ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
    REGEDIT4
    .
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\lib\NMBgMonitor.exe" [2005-09-16 94208]
    "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-01-16 68856]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2003-12-05 98304]
    "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2003-12-05 499712]
    "High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2004-10-27 61952]
    "SMSERIAL"="sm56hlpr.exe" [2005-11-10 557056]
    "igfxtray"="c:\windows\system32\igfxtray.exe" [2005-11-03 98304]
    "igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-11-03 77824]
    "igfxpers"="c:\windows\system32\igfxpers.exe" [2005-11-03 118784]
    "IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2006-07-03 802816]
    "IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2006-07-02 700416]
    "S7UB Start"="c:\program files\Common Files\Siemens\S7ubtoox\s7ubtstx.exe" [2006-03-13 102453]
    "McAfeeUpdaterUI"="c:\program files\McAfee\Common Framework\udaterui.exe" [2011-01-12 161088]
    "BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 110592]
    "WinCC flexible Smart Start"="c:\program files\Siemens\SIMATIC WinCC flexible\WinCC flexible 2005\HmiSmartStart.exe" [2006-04-11 164816]
    "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
    "Norton Ghost 9.0"="c:\program files\Symantec\Norton Ghost\Agent\GhostTray.exe" [2004-11-10 1126400]
    .
    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
    .
    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    Service Manager.lnk - c:\program files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe [2002-12-17 74308]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Nokia.PCSync]
    2008-06-17 14:00 1249280 ----a-w- c:\program files\Nokia\Nokia PC Suite 7\PcSync2.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite Tray]
    2008-08-11 06:31 1124352 ----a-w- c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
    "RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe"
    .
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "c:\\Program Files\\Common Files\\Siemens\\SQLANY\\dbsrv7.exe"=
    "c:\\Program Files\\McAfee\\Common Framework\\FrameworkService.exe"=
    "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
    "c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
    "c:\\Program Files\\Zattoo\\Zattoo2.exe"=
    "c:\\WINDOWS\\system32\\sessmgr.exe"=
    "c:\\Program Files\\MSSOAP\\Binaries\\MsSoapT.exe"=
    "c:\\Program Files\\Siemens\\Step7\\S7INF\\S7usiapx.exe"=
    "c:\\Program Files\\Siemens\\Step7\\S7BIN\\S7tgtopx.exe"=
    "c:\\Program Files\\Zattoo\\zattood.exe"=
    "c:\\WINDOWS\\system32\\CNAC6RPK.EXE"=
    "c:\\Program Files\\Siemens\\SIMATIC WinCC flexible\\WinCC flexible 2005\\HmiES.exe"=
    "c:\\Program Files\\Siemens\\SIMATIC WinCC flexible\\WinCC flexible 2005\\TraceServer.exe"=
    "c:\\Program Files\\Siemens\\SIMATIC WinCC flexible\\WinCC flexible 2005 Runtime\\HmiLoad.exe"=
    "c:\\Program Files\\Siemens\\SIMATIC WinCC flexible\\WinCC flexible 2005 Runtime\\Miniweb.exe"=
    "c:\\Program Files\\Siemens\\SIMATIC WinCC flexible\\WinCC flexible 2005 Runtime\\SmartServer.exe"=
    "c:\\WINDOWS\\system32\\Gateway.exe"=
    "c:\\WINDOWS\\system32\\GatewayDDE.exe"=
    "c:\\Program Files\\SEW\\MotionStudio\\SEWManager.exe"=
    "c:\\Program Files\\SEW\\MotionStudio\\Ofdas.exe"=
    "c:\\Program Files\\SEW\\SEW-Communication-Server\\Secos.exe"=
    .
    R0 PQV2i;PQV2i;c:\windows\system32\drivers\PQV2i.sys [10/11/2004 10:30 138801]
    R1 mfetdi2k;McAfee Inc. mfetdi2k;c:\windows\system32\drivers\mfetdi2k.sys [24/06/2011 23:11 88544]
    R1 PQIMount;PQIMount;c:\windows\system32\drivers\PQIMount.sys [10/11/2004 10:49 46800]
    R2 almservice;Automation License Manager Service;c:\program files\Common Files\Siemens\SWS\almsrv\almsrvx.exe [30/11/2006 09:17 761918]
    R2 dpmconv;dpmconv;c:\windows\system32\drivers\dpmconv.sys [07/05/2007 12:19 269824]
    R2 Dpmtrcdd;Dpmtrcdd;c:\windows\system32\drivers\dpmtrcdd.sys [07/05/2007 12:29 28331]
    R2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [24/06/2011 23:11 145936]
    R2 MSSQL$WINCCFLEXIBLE;MSSQL$WINCCFLEXIBLE;c:\program files\Microsoft SQL Server\MSSQL$WINCCFLEXIBLE\Binn\sqlservr.exe -sWINCCFLEXIBLE --> c:\program files\Microsoft SQL Server\MSSQL$WINCCFLEXIBLE\Binn\sqlservr.exe -sWINCCFLEXIBLE [?]
    R2 NA_Service;NetAccess Service;c:\windows\system32\NA_Service.exe [09/01/2008 04:14 49152]
    R2 Peakcan;Peakcan;c:\windows\system32\drivers\PEAKCAN.SYS [31/01/2008 16:12 255872]
    R2 s7asysvx;S7 Global Services;c:\program files\Siemens\Step7\S7BIN\s7asysvx.exe [13/03/2006 17:00 69685]
    R2 s7odpx2x;s7odpx2x;c:\windows\system32\drivers\s7odpx2x.sys [18/04/2007 08:29 78408]
    R2 s7oiehsx;SIMATIC IEPG Help Service;c:\program files\Common Files\Siemens\S7IEPG\s7oiehsx.exe [18/04/2007 08:37 213064]
    R2 S7OTMCDX;Step7 Memory Card Driver;c:\windows\system32\drivers\s7otmcdx.sys [18/04/2007 08:34 274344]
    R2 s7snsrtx;PROFINET IO RT-Protocol;c:\windows\system32\drivers\s7snsrtx.sys [26/01/2006 13:29 70912]
    R2 S7TraceServiceX;S7TraceServiceX;c:\program files\Common Files\Siemens\Automation\TraceEngine\bin\S7TraceServiceX.exe [22/03/2007 12:29 163840]
    R2 Sim9Sync;SIMATIC NET Synchronization Service;c:\windows\system32\sim9sync.exe [19/07/2010 18:03 94208]
    R2 SQLAgent$WINCCFLEXIBLE;SQLAgent$WINCCFLEXIBLE;c:\program files\Microsoft SQL Server\MSSQL$WINCCFLEXIBLE\Binn\sqlagent.EXE -i WINCCFLEXIBLE --> c:\program files\Microsoft SQL Server\MSSQL$WINCCFLEXIBLE\Binn\sqlagent.EXE -i WINCCFLEXIBLE [?]
    R2 vnccom;vnccom;c:\windows\system32\drivers\vnccom.SYS [20/07/2010 15:20 6016]
    R2 vsnl2ada;SIMATIC MPI/PROFIBUS FDL Transport Driver;c:\windows\system32\drivers\vsnl2ada.sys [07/05/2007 12:19 105058]
    R3 Duntlw;UNTLW device;c:\windows\system32\drivers\DuntlwNT.sys [14/12/2009 13:40 53568]
    R3 fwkbdrtm;fwkbdrtm;c:\windows\system32\drivers\fwkbdrtm.sys [07/05/2007 14:23 2976]
    R3 S7opciax;SIMATIC CP 5611;c:\windows\system32\drivers\S7opciax.sys [09/03/2006 18:06 214600]
    S2 Ampro5611;CP5611 Amprolyzer;c:\windows\system32\drivers\Ampro5611.sys [15/08/2010 13:52 82496]
    S2 gupdate;Service Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [29/01/2010 17:08 135664]
    S3 CanPhoneService;CanPhoneService;c:\program files\Lenze\Systembus\Canphsrv.exe [23/08/2010 15:32 110592]
    S3 dpmcslv;dpmcslv;c:\windows\system32\drivers\dpmcslv.sys [07/05/2007 14:23 68280]
    S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [24/06/2011 23:11 85152]
    S3 Pcan_usb;PCAN-USB Device Driver;c:\windows\system32\drivers\Pcan_usb.sys [23/08/2010 16:45 343679]
    S3 S5AS511;S5AS511;c:\windows\system32\drivers\S5AS511.SYS [07/05/2007 13:34 15360]
    S3 S5MCD;S5MCD;c:\windows\system32\drivers\S5MCD.SYS [07/05/2007 13:34 188416]
    S3 s7oefs_x;SIMATIC MPI/EFS Driver;c:\windows\system32\drivers\s7oefs_x.sys [18/10/2002 02:34 30512]
    S3 usb2ser;usb2ser;c:\windows\system32\drivers\usb2ser.sys [11/06/2008 14:30 30336]
    .
    --- Autres Services/Pilotes en mémoire ---
    .
    *Deregistered* - mfeavfk01
    .
    Contenu du dossier 'Tâches planifiées'
    .
    2011-06-29 c:\windows\Tasks\GlaryInitialize.job
    - c:\program files\Glary Utilities\initialize.exe [2011-06-24 06:25]
    .
    2011-06-29 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2010-01-29 15:08]
    .
    2011-06-28 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2010-01-29 15:08]
    .
    .
    ------- Examen supplémentaire -------
    .
    uInternet Connection Wizard,ShellNext = hxxp://www.siemens.com/
    uSearchAssistant = hxxp://www.google.com/ie
    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
    IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
    IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
    LSP: c:\windows\system32\asdns.dll
    .
    - - - - ORPHELINS SUPPRIMES - - - -
    .
    HKLM-Run-ShStatEXE - c:\program files\McAfee\VirusScan Enterprise\SHSTAT.EXE
    .
    .
    .
    **************************************************************************
    .
    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2011-06-29 09:40
    Windows 5.1.2600 Service Pack 2 NTFS
    .
    Recherche de processus cachés ...
    .
    Recherche d'éléments en démarrage automatique cachés ...
    .
    Recherche de fichiers cachés ...
    .
    Scan terminé avec succès
    Fichiers cachés: 0
    .
    **************************************************************************
    .
    --------------------- DLLs chargées dans les processus actifs ---------------------
    .
    - - - - - - - > 'explorer.exe'(1852)
    c:\windows\system32\ccofgnt.dll
    c:\program files\McAfee\Common Framework\McTrayLegacySupportPlugin.dll
    c:\program files\McAfee\Common Framework\McTrayInterfaceLib.dll
    c:\program files\McAfee\Common Framework\McAfeeWin32GUISupportDLL.dll
    c:\windows\system32\WPDShServiceObj.dll
    c:\program files\Nokia\Nokia PC Suite 7\phonebrowser.dll
    c:\program files\Nokia\Nokia PC Suite 7\NGSCM.DLL
    c:\program files\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_fre.nlr
    c:\program files\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
    c:\program files\Microsoft Virtual PC\VPCShExH.DLL
    c:\windows\system32\PortableDeviceTypes.dll
    c:\windows\system32\PortableDeviceApi.dll
    .
    ------------------------ Autres processus actifs ------------------------
    .
    c:\program files\Intel\Wireless\Bin\EvtEng.exe
    c:\program files\Intel\Wireless\Bin\S24EvMon.exe
    c:\windows\sm56hlpr.exe
    c:\windows\system32\rundll32.exe
    c:\windows\System32\GEARSec.exe
    c:\program files\McAfee\Common Framework\FrameworkService.exe
    c:\program files\McAfee\VirusScan Enterprise\VsTskMgr.exe
    c:\program files\Common Files\Siemens\Sqlany\dbsrv7.exe
    c:\program files\McAfee\VirusScan Enterprise\mfeann.exe
    c:\program files\Microsoft SQL Server\MSSQL$WINCCFLEXIBLE\Binn\sqlservr.exe
    c:\program files\McAfee\Common Framework\naPrdMgr.exe
    c:\program files\Symantec\Norton Ghost\Agent\PQV2iSvc.exe
    c:\program files\Intel\Wireless\Bin\RegSrvc.exe
    c:\program files\McAfee\Common Framework\McTray.exe
    c:\program files\Microsoft SQL Server\MSSQL$WINCCFLEXIBLE\Binn\sqlagent.EXE
    c:\program files\Common Files\McAfee\SystemCore\mcshield.exe
    c:\program files\Common Files\Siemens\ALMPanelPlugin\ALMPanelPlugin.exe
    c:\windows\system32\CNAC6RPK.EXE
    c:\windows\system32\wscntfy.exe
    c:\program files\siemens\simatic wincc flexible\wincc flexible 2005\TraceServer.exe
    .
    **************************************************************************
    .
    Heure de fin: 2011-06-29 09:42:13 - La machine a redémarré
    ComboFix-quarantined-files.txt 2011-06-29 07:42
    ComboFix2.txt 2011-06-28 13:59
    .
    Avant-CF: 20 791 947 264 bytes free
    Après-CF: 20 810 448 896 octets libres
    .
    - - End Of File - - 0C2A3DE13792F23B425F689F79CE2EFE
    0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. g3n-h@ckm@n
     
    hello

    desactive ton antivirus
    desactive Windows defender si présent
    desactive ton pare-feu

    Ferme toutes tes appilications en cours

    telecharge et enregistre ceci sur ton bureau :

    Pre_Scan

    mirroir :

    http://www.archive-host.com

    s'il n'est pas sur ton bureau coupe-le de ton dossier telechargements et colle-le sur ton bureau

    Avertissement: Il y aura une extinction courte du bureau --> pas de panique.

    une fois telechargé lance-le , laisse faire le scan jusqu'à l'apparition de "Pre_scan.txt" sur le bureau.

    si 'outil est bloqué par l'infection utilise cette version : Version .pif

    si l'outil detecte un proxy et que tu n'en as pas installé clique sur "supprimer le proxy"

    si l'outil semble ne pas avoir fonctionné renomme-le winlogon , ou change son extension en .com ou .scr

    Il se peut qu'une multitude de fenêtres noires clignotent , laisse-le travailler

    Poste Pre_Scan.txt qui apparaitra sur le bureau en fin de scan

    ▶▶▶ NE LE POSTE PAS SUR LE FORUM (il est trop long)

    clique sur ce lien : http://www.cijoint.fr/

    ▶ Clique sur Parcourir et cherche le fichier ci-dessus.

    ▶ Clique sur Ouvrir.

    ▶ Clique sur "Cliquez ici pour déposer le fichier".

    Un lien de cette forme :

    http://www.cijoint.fr/cjlink.php?file=cjge368/cijSKAP5fU.txt

    est ajouté dans la page.

    ▶ Copie ce lien dans ta réponse.
    0
  7. didipy
     
    aussitot dit aussitot fait

    http://www.cijoint.fr/cjlink.php?file=cj201106/cijOyD2cN7.txt
    0
  8. g3n-h@ckm@n
     
    tu es sur d'avoir desactivé la protection de MacAfee ?
    0
  9. didipy
     
    j'ai refais la démarche avec MacAfee en moins

    http://www.cijoint.fr/cjlink.php?file=cj201106/cijnvO7J4i.txt
    0
  10. g3n-h@ckm@n
     
    fais glisser une icone n'importe quel fichier sur Pre_scan , pre_script va apparaitre

    ouvre Pre_script et colle ce qui suit en gras, à l'interieur du texte qui s'ouvre ,
    sans les lignes , en une seule fois en le mettant en surbrillance :
    ___________________________________________________
    Registry::
    [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar]
    "{2318C2B1-4965-11d4-9B18-009027A5CD4F}"=-
    [-HKCU\Software\20W6RLKX65]
    [-HKCU\Software\Grand Virtual]
    [-HKCU\Software\OTGV1DNWQQ]
    [HKEY_LOCAL_MACHINE\System\CurrentControlSet\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "1900:UDP"=-
    "2869:TCP"=-
    "139:TCP"=-
    "445:TCP"=-
    "137:UDP"=-
    "138:UDP"=-

    folder::
    C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
    C:\Program Files\Spybot - Search & Destroy

    attrib::

    ___________________________________________________

    copie-le (ctrl+c ou clique droit sur la selection puis => copier)

    puis onglet fichier => enregistrer (pas enregistrer sous...) , puis ferme le texte

    des fenetres noires risquent de clignoter , c'est normal , c'est le programme qui travaille

    poste Pre_Script.txt qui apparaitra sur le bureau en fin de travail
    ¤¤¤¤¤¤¤¤¤¤_g3n-h@ckm@n_developpement_¤¤¤¤¤¤¤¤¤¤
    ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤_Pre_scan_¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
    0
  11. didipy
     
    le voici

    http://www.cijoint.fr/cjlink.php?file=cj201106/cijb7XYmxs.txt
    0
  12. g3n-h@ckm@n
     
    Télécharge ici :OTL

    enregistre le sur ton Bureau.

    si tu as XP => double clique
    si tu as Vista ou windows 7 => clic droit "executer en tant que...."


    sur OTL.exe pour le lancer.

    => Clique ici pour voir la Configuration

    ▶Clic sur Analyse.

    A la fin du scan, le Bloc-Notes va s'ouvrir avec le rapport (OTL.txt).

    Ce fichier est sur ton Bureau (en général C:\Documents and settings\le_nom_de_ta_session\OTL.txt)

    ▶▶▶ NE LE POSTE PAS SUR LE FORUM (il est trop long)

    Pour me le transmettre clique sur ce lien : http://www.cijoint.fr/

    ▶ Clique sur Parcourir et cherche le fichier ci-dessus.

    ▶ Clique sur Ouvrir.

    ▶ Clique sur "Cliquez ici pour déposer le fichier".

    juste au niveau du bouton , en fin de chargement du fichier , Un lien de cette forme apparaitra :

    http://www.cijoint.fr/cjlink.php?file=cjge368/cijSKAP5fU.txt

    ▶ Copie ce lien dans ta réponse.

    ▶▶ Tu feras la meme chose avec le "Extra.txt" qui logiquement sera aussi sur ton bureau.
    0