Aide combofix svp

Résolu
freddyzack Messages postés 30 Statut Membre -  
juju666 Messages postés 35446 Date d'inscription   Statut Contributeur sécurité Dernière intervention   -
Bonjour,


j' ai un rapport combofix a vous montrez mais je ne sais comment faire merci

31 réponses

  • 1
  • 2
Résumé de la discussion

Problème initial: sur Windows Vista, la demande porte sur la manière de réaliser et présenter un rapport lié à ComboFix, afin d'obtenir des instructions claires pour obtenir le document attendu.
Des solutions proposées, notamment exécuter AdwCleaner en mode Recherche pour générer un rapport, puis copier son contenu dans la réponse suivante et vérifier les emplacements de sauvegarde; ensuite ZHPFix est utilisé.
Par ailleurs, Malwarebytes' Anti-Malware est recommandé comme examen complet, avec un rapport sur les éléments détectés; le processus se termine par des rapports de nettoyage et des résultats visibles.
Des extraits de rapports supplémentaires indiquent la présence d'adware et de modules Conduit dans le registre et les navigateurs, soulignant l'importance d'examiner aussi les extensions et les paramètres de recherche.

Généré automatiquement par IA
sur la base des meilleures réponses
  1. juju666 Messages postés 35446 Date d'inscription   Statut Contributeur sécurité Dernière intervention   4 796
     
    bonjour

    pourquoi avoir lancé combofix ?

    bah tu le colle ici ...
    0
    1. freddyzack Messages postés 30 Statut Membre
       
      sur un conseil d' un ami voici mon rapport merci encore

      ComboFix 11-09-09.01 - Elisabeth 09/09/2011 10:31:03.3.1 - x86
      Microsoft® Windows Vista(TM) Édition Familiale Basique 6.0.6002.2.1252.33.1036.18.1983.1174 [GMT 2:00]
      Lancé depuis: c:\users\Elisabeth\Desktop\ComboFix.exe
      AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
      SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
      SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
      .
      .
      (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
      .
      .
      c:\windows\system32\nvdispco3220150.dll
      .
      .
      ((((((((((((((((((((((((((((( Fichiers créés du 2011-08-09 au 2011-09-09 ))))))))))))))))))))))))))))))))))))
      .
      .
      2011-09-09 08:40 . 2011-09-09 08:40 -------- d-----w- c:\users\Elisabeth\AppData\Local\temp
      2011-09-09 08:40 . 2011-09-09 08:40 -------- d-----w- c:\users\Public\AppData\Local\temp
      2011-09-09 08:40 . 2011-09-09 08:40 -------- d-----w- c:\users\Default\AppData\Local\temp
      2011-09-06 15:48 . 2011-08-12 02:44 7152464 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{6CD76643-6473-484C-8046-A637EEAC0CD5}\mpengine.dll
      2011-09-02 14:35 . 2011-09-02 14:35 -------- d-----w- C:\AeriaGames
      2011-09-02 14:15 . 2011-09-09 08:15 -------- d-----w- c:\program files\Common Files\Akamai
      2011-08-30 10:15 . 2011-08-30 10:15 -------- d-----w- c:\users\UpdatusUser
      2011-08-30 10:14 . 2011-05-21 04:01 2560616 ----a-w- c:\windows\system32\nvsvcr.dll
      2011-08-30 10:14 . 2011-05-21 04:01 543336 ----a-w- c:\windows\system32\easyupdatusapiu.dll
      2011-08-30 10:12 . 2011-08-30 10:12 -------- d-----w- c:\programdata\NVIDIA Corporation
      2011-08-29 08:21 . 2011-08-30 12:48 -------- d-----w- c:\program files\Accelerer PC
      2011-08-29 08:20 . 2011-08-29 16:11 -------- d-----w- c:\users\Elisabeth\AppData\Local\OpenCandy
      2011-08-29 08:20 . 2011-08-29 08:20 -------- d-----w- c:\users\Elisabeth\AppData\Roaming\OpenCandy
      2011-08-29 08:20 . 2011-08-29 08:20 -------- d-----w- c:\program files\Cheat Engine 6.1
      2011-08-29 07:58 . 2011-08-29 08:10 -------- d-----w- c:\program files\Farming Simulator 2011
      2011-08-29 07:51 . 2011-08-29 07:51 -------- d-----w- c:\windows\Java
      2011-08-29 07:51 . 2009-11-12 15:19 27136 ----a-w- c:\windows\system32\PCWizard.cpl
      2011-08-29 07:51 . 2011-08-29 07:51 -------- d-----w- c:\program files\CPUID
      2011-08-24 12:34 . 2011-07-11 13:25 2048 ----a-w- c:\windows\system32\tzres.dll
      .
      .
      .
      (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
      .
      2011-08-09 09:09 . 2010-06-24 10:33 18328 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
      2011-07-04 11:43 . 2010-07-11 07:31 40112 ----a-w- c:\windows\avastSS.scr
      2011-07-04 11:43 . 2008-12-19 07:12 199304 ----a-w- c:\windows\system32\aswBoot.exe
      2011-07-04 11:36 . 2011-06-17 05:04 441176 ----a-w- c:\windows\system32\drivers\aswSnx.sys
      2011-07-04 11:36 . 2008-12-19 07:12 309848 ----a-w- c:\windows\system32\drivers\aswSP.sys
      2011-07-04 11:35 . 2008-12-19 07:12 43608 ----a-w- c:\windows\system32\drivers\aswTdi.sys
      2011-07-04 11:32 . 2008-12-19 07:12 25432 ----a-w- c:\windows\system32\drivers\aswRdr.sys
      2011-07-04 11:32 . 2008-12-19 07:12 54104 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
      2011-07-04 11:32 . 2008-12-19 07:12 19544 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
      2011-06-15 11:15 . 2011-05-16 05:53 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
      2008-11-19 08:36 . 2008-11-19 08:36 225 ----a-w- c:\program files\Iminentconfig.cmd
      2011-04-14 16:47 . 2011-05-08 17:39 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
      .
      .
      ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
      .
      .
      *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
      REGEDIT4
      .
      [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
      "{4daac69c-cba7-45e2-9bc8-1044483d3352}"= "c:\program files\Softonic_France\tbSoft.dll" [2010-11-13 3913000]
      .
      [HKEY_CLASSES_ROOT\clsid\{4daac69c-cba7-45e2-9bc8-1044483d3352}]
      .
      [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
      2010-11-13 20:58 3913000 ----a-w- c:\program files\ConduitEngine\ConduitEngine.dll
      .
      [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4daac69c-cba7-45e2-9bc8-1044483d3352}]
      2010-11-13 20:58 3913000 ----a-w- c:\program files\Softonic_France\tbSoft.dll
      .
      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
      "{4daac69c-cba7-45e2-9bc8-1044483d3352}"= "c:\program files\Softonic_France\tbSoft.dll" [2010-11-13 3913000]
      "{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files\ConduitEngine\ConduitEngine.dll" [2010-11-13 3913000]
      .
      [HKEY_CLASSES_ROOT\clsid\{4daac69c-cba7-45e2-9bc8-1044483d3352}]
      .
      [HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
      .
      [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
      "{4DAAC69C-CBA7-45E2-9BC8-1044483D3352}"= "c:\program files\Softonic_France\tbSoft.dll" [2010-11-13 3913000]
      .
      [HKEY_CLASSES_ROOT\clsid\{4daac69c-cba7-45e2-9bc8-1044483d3352}]
      .
      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
      @="{472083B0-C522-11CF-8763-00608CC02F24}"
      [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
      2011-07-04 11:43 122512 ----a-w- c:\program files\Alwil Software\Avast5\ashShell.dll
      .
      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "RocketDock"="c:\program files\RocketDock\RocketDock.exe" [2007-09-02 495616]
      "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
      .
      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "VX3000"="c:\windows\vVX3000.exe" [2009-06-26 757248]
      "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-06-08 37296]
      "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
      "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696]
      .
      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
      "ConsentPromptBehaviorAdmin"= 0 (0x0)
      "EnableUIADesktopToggle"= 0 (0x0)
      .
      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccleaner]
      2011-08-25 14:59 2622784 ----a-w- c:\program files\CCleaner\CCleaner.exe
      .
      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LifeCam]
      2009-07-24 14:05 118640 ----a-w- c:\program files\Microsoft LifeCam\LifeExp.exe
      .
      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Piratrax]
      2011-01-09 09:45 798464 ----a-w- c:\program files\Piratrax\piratrax_launch.exe
      .
      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VistaStartMenuSE]
      2009-11-25 16:23 2751320 ----a-w- c:\program files\Vista Start Menu\VistaStartMenu.exe
      .
      R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
      R3 maconfservice;Ma-Config Service;c:\program files\ma-config.com\maconfservice.exe [2009-09-23 238960]
      R3 ovt530;Webcam Deluxe;c:\windows\system32\Drivers\ov530vid.sys [x]
      R3 RTLWUSB;802.11g USB 2.0 WLAN Dongle;c:\windows\system32\DRIVERS\RTL8187.sys [2007-05-01 169472]
      R3 SetupNTGLM7X;SetupNTGLM7X;D:\NTGLM7X.sys [x]
      R3 WPFFontCache_v0400;Cache de police de Windows Presentation Foundation 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
      R3 WSDPrintDevice;Prise en charge de l'impression WSD via UMB;c:\windows\system32\DRIVERS\WSDPrint.sys [2008-01-19 16896]
      R4 sptd;sptd;c:\windows\system32\Drivers\sptd.sys [2009-08-07 722416]
      R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040]
      S1 aswSnx;aswSnx; [x]
      S1 aswSP;aswSP; [x]
      S2 acedrv11;acedrv11;c:\windows\system32\drivers\acedrv11.sys [2008-07-30 277736]
      S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2008-01-19 21504]
      S2 aswFsBlk;aswFsBlk; [x]
      S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2011-07-04 54104]
      S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-05-21 2214504]
      S3 athrusb;802.11g Wireless USB2.0 Adapter driver;c:\windows\system32\DRIVERS\athrusb.sys [2007-01-29 451072]
      .
      .
      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
      LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
      HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
      hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
      LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
      Akamai REG_MULTI_SZ Akamai
      .
      Contenu du dossier 'Tâches planifiées'
      .
      2011-09-08 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1019982253-855118549-3322040707-1000Core.job
      - c:\users\Elisabeth\AppData\Local\Google\Update\GoogleUpdate.exe [2011-01-09 09:53]
      .
      2011-09-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1019982253-855118549-3322040707-1000UA.job
      - c:\users\Elisabeth\AppData\Local\Google\Update\GoogleUpdate.exe [2011-01-09 09:53]
      .
      2011-09-08 c:\windows\Tasks\User_Feed_Synchronization-{76C4697A-F498-4E08-9D47-5AF7C92D23D3}.job
      - c:\windows\system32\msfeedssync.exe [2011-08-11 09:26]
      .
      .
      ------- Examen supplémentaire -------
      .
      uStart Page = hxxp://www.google.com/chrome/thankyou.html?hl=fr&oneclickinstalled=&installdataindex=defaultbrowser
      mStart Page = hxxp://www.duxet.com/
      IE: Envoyer au périphérique &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
      Trusted Zone: com.tw\www.msi
      TCP: DhcpNameServer = 212.27.40.241 212.27.40.240
      DPF: CabBuilder - hxxp://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
      FF - ProfilePath - c:\users\Elisabeth\AppData\Roaming\Mozilla\Firefox\Profiles\iewiop1t.default\
      FF - prefs.js: browser.search.selectedEngine -
      .
      - - - - ORPHELINS SUPPRIMES - - - -
      .
      WebBrowser-{977AE9CC-AF83-45E8-9E03-E2798216E2D5} - (no file)
      .
      .
      .
      **************************************************************************
      .
      catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
      Rootkit scan 2011-09-09 10:40
      Windows 6.0.6002 Service Pack 2 NTFS
      .
      Recherche de processus cachés ...
      .
      Recherche d'éléments en démarrage automatique cachés ...
      .
      Recherche de fichiers cachés ...
      .
      Scan terminé avec succès
      Fichiers cachés: 0
      .
      **************************************************************************
      .
      [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Akamai]
      "ServiceDll"="C:/Program Files/Common Files/Akamai/netsession_win_2da1ebd.dll"
      .
      [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Akamai]
      "ServiceDll"="C:/Program Files/Common Files/Akamai/netsession_win_2da1ebd.dll"
      .
      Heure de fin: 2011-09-09 10:45:57
      ComboFix-quarantined-files.txt 2011-09-09 08:45
      ComboFix2.txt 2011-02-15 09:29
      ComboFix3.txt 2010-08-26 15:08
      .
      Avant-CF: 166 635 712 512 octets libres
      Après-CF: 166 616 260 608 octets libres
      .
      Current=1 Default=1 Failed=0 LastKnownGood=11 Sets=1,2,3,4,5,6,7,8,9,11
      - - End Of File - - 611515EC2507950B89781FCB6FB30D72
      0
    2. freddyzack Messages postés 30 Statut Membre
       
      pouvez vous me dire ce que je doit faire a l' issu de cela merci
      0
    3. heraultais34600 Messages postés 776 Statut Membre 97
       
      Bonjour,

      ComboFix est un outil puissant qui ne doit pas être utilisé sans l'assistance d'une personne qualifiée.
      Il serait très intéressant de savoir pourquoi vous avez lancé directement ComboFix.
      Avez-vous des problèmes sur votre ordinateur (pc lent, ouverture intempestive de pages publicitaires, ....?

      A bientôt
      0
  2. juju666 Messages postés 35446 Date d'inscription   Statut Contributeur sécurité Dernière intervention   4 796
     
    eh ben ton ami est pas de bon conseil on utilise pas combofix pour un oui ou un non ...

    si ton pc ne serait jamais redémarré suit à combofix il t aurait encore aidé? ^^

    ▶ ▶ DÉSACTIVE TES PROTECTIONS DURANT LA PROCÉDURE

    ▶ ▶ SCRIPT PERSONNALISE A CET ORDINATEUR, NE PAS REPRODUIRE : DANGEREUX !!!!


    ▶ Créé un nouveau document texte : clic droit de souris sur le bureau > Nouveau > Document Texte, et copie dedans les lignes suivantes :

    KillAll::
    
    DirLook::
    c:\users\UpdatusUser      
    
    Folder::
    c:\users\Elisabeth\AppData\Local\OpenCandy    
    c:\users\Elisabeth\AppData\Roaming\OpenCandy    
    c:\program files\ConduitEngine
    c:\program files\Softonic_France
    
    File::
    c:\program files\Iminentconfig.cmd      
    
    Registry::
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]  
    "{4daac69c-cba7-45e2-9bc8-1044483d3352}"=-
    [-HKEY_CLASSES_ROOT\clsid\{4daac69c-cba7-45e2-9bc8-1044483d3352}]  
    [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
    [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4daac69c-cba7-45e2-9bc8-1044483d3352}] 
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] 
    "{4daac69c-cba7-45e2-9bc8-1044483d3352}"=-
    "{30F9B915-B755-4826-820B-08FBA6BD249D}"=-
    [-HKEY_CLASSES_ROOT\clsid\{4daac69c-cba7-45e2-9bc8-1044483d3352}] 
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]   
    "{4DAAC69C-CBA7-45E2-9BC8-1044483D3352}"=-
    [-HKEY_CLASSES_ROOT\clsid\{4daac69c-cba7-45e2-9bc8-1044483d3352}]  
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]  
    "Adobe Reader Speed Launcher"="-
    
    Firefox::
    FF - prefs.js: browser.search.selectedEngine -      
    
    
    


    ▶ Enregistre ce fichier sous le nom CFScript

    ▶ Fait un glisser/déposer de ce fichier CFScript sur le fichier ComboFix.exe comme sur la capture :http://i261.photobucket.com/albums/ii49/Malekal_morte/CFScript-2.gif

    ▶ Combofix se lance, laisse toi guider..

    ▶ Patiente le temps du scan. Le bureau va disparaître à plusieurs reprises: c'est normal!
    Ne touche à rien tant que le scan n'est pas terminé.
    ▶ Une fois le scan achevé, un rapport va s'afficher: poste son contenu, en précisant où en sont tes soucis

    ▶ Si le fichier ne s'ouvre pas, il se trouve ici > C:\ComboFix.txt
    0
  3. freddyzack Messages postés 30 Statut Membre
     
    merci beaucoup je fait ce que tu m' a dit et je te tiend au courrant
    0
    1. freddyzack Messages postés 30 Statut Membre
       
      ComboFix 11-09-09.03 - Elisabeth 09/09/2011 14:41:04.4.1 - x86
      Microsoft® Windows Vista(TM) Édition Familiale Basique 6.0.6002.2.1252.33.1036.18.1983.1164 [GMT 2:00]
      Lancé depuis: c:\users\Elisabeth\Desktop\ComboFix.exe
      Commutateurs utilisés :: c:\users\Elisabeth\Desktop\CFScript.txt
      AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
      SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
      SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
      .
      FILE ::
      "c:\program files\Iminentconfig.cmd"
      .
      .
      (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
      .
      .
      c:\program files\ConduitEngine
      c:\program files\ConduitEngine\appContextMenu.xml
      c:\program files\ConduitEngine\ConduitEngine.dll
      c:\program files\ConduitEngine\ConduitEngineHelper.exe
      c:\program files\ConduitEngine\ConduitEngineUninstall.exe
      c:\program files\ConduitEngine\engineContextMenu.xml
      c:\program files\ConduitEngine\EngineSettings.json
      c:\program files\ConduitEngine\INSTALL.LOG
      c:\program files\ConduitEngine\toolbar.cfg
      c:\program files\Iminentconfig.cmd
      c:\program files\Softonic_France
      c:\program files\Softonic_France\GottenAppsContextMenu.xml
      c:\program files\Softonic_France\INSTALL.LOG
      c:\program files\Softonic_France\OtherAppsContextMenu.xml
      c:\program files\Softonic_France\SharedAppsContextMenu.xml
      c:\program files\Softonic_France\Softonic_FranceToolbarHelper.exe
      c:\program files\Softonic_France\tbSoft.dll
      c:\program files\Softonic_France\toolbar.cfg
      c:\program files\Softonic_France\ToolbarContextMenu.xml
      c:\program files\Softonic_France\UNWISE.EXE
      c:\program files\Softonic_France\UNWISE.INI
      c:\users\Elisabeth\AppData\Local\OpenCandy
      c:\users\Elisabeth\AppData\Roaming\OpenCandy
      c:\users\Elisabeth\AppData\Roaming\OpenCandy\OpenCandy_B2C100FBCD7A478282FD4E6AA83E9BBF\1602.ico
      c:\users\Elisabeth\AppData\Roaming\OpenCandy\OpenCandy_B2C100FBCD7A478282FD4E6AA83E9BBF\LatestDLMgr.exe
      c:\users\Elisabeth\AppData\Roaming\OpenCandy\OpenCandy_B2C100FBCD7A478282FD4E6AA83E9BBF\pcspeedup.exe
      .
      .
      ((((((((((((((((((((((((((((( Fichiers créés du 2011-08-09 au 2011-09-09 ))))))))))))))))))))))))))))))))))))
      .
      .
      2011-09-09 12:50 . 2011-09-09 13:00 -------- d-----w- c:\users\Elisabeth\AppData\Local\temp
      2011-09-09 12:50 . 2011-09-09 12:50 -------- d-----w- c:\users\Public\AppData\Local\temp
      2011-09-09 12:50 . 2011-09-09 12:50 -------- d-----w- c:\users\Default\AppData\Local\temp
      2011-09-06 15:48 . 2011-08-12 02:44 7152464 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{6CD76643-6473-484C-8046-A637EEAC0CD5}\mpengine.dll
      2011-09-02 14:35 . 2011-09-09 08:56 -------- d-----w- C:\AeriaGames
      2011-09-02 14:15 . 2011-09-09 12:52 -------- d-----w- c:\program files\Common Files\Akamai
      2011-08-30 10:15 . 2011-08-30 10:15 -------- d-----w- c:\users\UpdatusUser
      2011-08-30 10:14 . 2011-05-21 04:01 2560616 ----a-w- c:\windows\system32\nvsvcr.dll
      2011-08-30 10:14 . 2011-05-21 04:01 543336 ----a-w- c:\windows\system32\easyupdatusapiu.dll
      2011-08-30 10:12 . 2011-08-30 10:12 -------- d-----w- c:\programdata\NVIDIA Corporation
      2011-08-29 08:21 . 2011-08-30 12:48 -------- d-----w- c:\program files\Accelerer PC
      2011-08-29 08:20 . 2011-08-29 08:20 -------- d-----w- c:\program files\Cheat Engine 6.1
      2011-08-29 07:58 . 2011-08-29 08:10 -------- d-----w- c:\program files\Farming Simulator 2011
      2011-08-29 07:51 . 2011-08-29 07:51 -------- d-----w- c:\windows\Java
      2011-08-29 07:51 . 2009-11-12 15:19 27136 ----a-w- c:\windows\system32\PCWizard.cpl
      2011-08-29 07:51 . 2011-08-29 07:51 -------- d-----w- c:\program files\CPUID
      2011-08-24 12:34 . 2011-07-11 13:25 2048 ----a-w- c:\windows\system32\tzres.dll
      .
      .
      .
      (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
      .
      2011-08-09 09:09 . 2010-06-24 10:33 18328 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
      2011-07-04 11:43 . 2010-07-11 07:31 40112 ----a-w- c:\windows\avastSS.scr
      2011-07-04 11:43 . 2008-12-19 07:12 199304 ----a-w- c:\windows\system32\aswBoot.exe
      2011-07-04 11:36 . 2011-06-17 05:04 441176 ----a-w- c:\windows\system32\drivers\aswSnx.sys
      2011-07-04 11:36 . 2008-12-19 07:12 309848 ----a-w- c:\windows\system32\drivers\aswSP.sys
      2011-07-04 11:35 . 2008-12-19 07:12 43608 ----a-w- c:\windows\system32\drivers\aswTdi.sys
      2011-07-04 11:32 . 2008-12-19 07:12 25432 ----a-w- c:\windows\system32\drivers\aswRdr.sys
      2011-07-04 11:32 . 2008-12-19 07:12 54104 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
      2011-07-04 11:32 . 2008-12-19 07:12 19544 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
      2011-06-15 11:15 . 2011-05-16 05:53 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
      2011-04-14 16:47 . 2011-05-08 17:39 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
      .
      .
      (((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
      .
      ---- Directory of c:\users\UpdatusUser ----
      .
      2011-08-30 10:15 . 2011-08-30 10:15 24 --sha-w- c:\users\UpdatusUser\AppData\Roaming\Microsoft\Protect\S-1-5-21-1019982253-855118549-3322040707-1001\Preferred
      2011-08-30 10:15 . 2011-08-30 10:15 388 --sha-w- c:\users\UpdatusUser\AppData\Roaming\Microsoft\Protect\S-1-5-21-1019982253-855118549-3322040707-1001\2bb49a3a-f40d-4f96-b4b5-81d4186ab77e
      2011-08-30 10:15 . 2011-08-30 10:15 24 --sha-w- c:\users\UpdatusUser\AppData\Roaming\Microsoft\Protect\CREDHIST
      2011-08-30 10:15 . 2011-08-30 10:15 524288 --sha-w- c:\users\UpdatusUser\AppData\Local\Microsoft\Windows\UsrClass.dat{9713187b-d259-11e0-8d88-0019db2723fb}.TMContainer00000000000000000002.regtrans-ms
      2011-08-30 10:15 . 2011-09-09 12:40 524288 --sha-w- c:\users\UpdatusUser\AppData\Local\Microsoft\Windows\UsrClass.dat{9713187b-d259-11e0-8d88-0019db2723fb}.TMContainer00000000000000000001.regtrans-ms
      2011-08-30 10:15 . 2011-09-09 12:40 65536 --sha-w- c:\users\UpdatusUser\AppData\Local\Microsoft\Windows\UsrClass.dat{9713187b-d259-11e0-8d88-0019db2723fb}.TM.blf
      2011-08-30 10:15 . 2011-08-30 10:15 0 ---ha-w- c:\users\UpdatusUser\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG2
      2011-08-30 10:15 . 2011-09-09 13:00 262144 ---ha-w- c:\users\UpdatusUser\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG1
      2011-08-30 10:15 . 2011-09-09 13:00 262144 ---ha-w- c:\users\UpdatusUser\AppData\Local\Microsoft\Windows\UsrClass.dat
      2011-08-30 10:15 . 2011-08-30 10:15 20 --sh--w- c:\users\UpdatusUser\ntuser.ini
      2011-08-30 10:15 . 2011-08-30 10:15 524288 --sha-w- c:\users\UpdatusUser\NTUSER.DAT{d8932e6d-6a6f-11db-b6ab-a038f15a5785}.TMContainer00000000000000000002.regtrans-ms
      2011-08-30 10:15 . 2011-09-09 12:40 524288 --sha-w- c:\users\UpdatusUser\NTUSER.DAT{d8932e6d-6a6f-11db-b6ab-a038f15a5785}.TMContainer00000000000000000001.regtrans-ms
      2011-08-30 10:15 . 2011-09-09 12:40 65536 --sha-w- c:\users\UpdatusUser\NTUSER.DAT{d8932e6d-6a6f-11db-b6ab-a038f15a5785}.TM.blf
      2011-08-30 10:15 . 2011-08-30 10:15 0 ---ha-w- c:\users\UpdatusUser\ntuser.dat.LOG2
      2011-08-30 10:15 . 2011-09-09 13:00 262144 ---ha-w- c:\users\UpdatusUser\ntuser.dat.LOG1
      2011-08-30 10:15 . 2006-09-18 21:35 3 ----a-w- c:\users\UpdatusUser\AppData\Roaming\Microsoft\Windows\SendTo\Compressed (zipped) Folder.ZFSendToTarget
      2011-08-30 10:15 . 2008-04-06 11:34 146 --sha-w- c:\users\UpdatusUser\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
      2011-08-30 10:15 . 2011-01-05 17:35 16384 --sha-w- c:\users\UpdatusUser\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
      2011-08-30 10:15 . 2011-01-05 17:35 16384 --sha-w- c:\users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
      2011-08-30 10:15 . 2009-03-17 17:01 145 --sha-w- c:\users\UpdatusUser\AppData\Local\Microsoft\Windows\History\desktop.ini
      2011-08-30 10:15 . 2009-03-17 17:01 145 --sha-w- c:\users\UpdatusUser\AppData\Local\Microsoft\Windows\History\History.IE5\desktop.ini
      2011-08-30 10:15 . 2006-11-02 12:50 1662 ----a-w- c:\users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Narrator.lnk
      2011-08-30 10:15 . 2009-03-17 17:01 67 --sha-w- c:\users\UpdatusUser\AppData\Local\Microsoft\Windows\Temporary Internet Files\desktop.ini
      2011-08-30 10:15 . 2006-11-02 12:51 1659 ----a-w- c:\users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Command Prompt.lnk
      2011-08-30 10:15 . 2008-04-06 11:34 1699 ----a-w- c:\users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Notepad.lnk
      2011-08-30 10:15 . 2006-09-18 21:33 7 ----a-w- c:\users\UpdatusUser\AppData\Roaming\Microsoft\Windows\SendTo\Desktop (create shortcut).DeskLink
      2011-08-30 10:15 . 2008-04-06 11:34 258 ----a-w- c:\users\UpdatusUser\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
      2011-08-30 10:15 . 2008-04-06 11:34 240 ----a-w- c:\users\UpdatusUser\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
      2011-08-30 10:15 . 2006-11-02 12:51 1629 ----a-w- c:\users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\On-Screen Keyboard.lnk
      2011-08-30 10:15 . 2008-04-06 11:34 1537 ----a-w- c:\users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Explorer.lnk
      2011-08-30 10:15 . 2008-04-06 11:34 678 --sha-w- c:\users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Desktop.ini
      2011-08-30 10:15 . 2006-09-18 21:28 438 --sha-w- c:\users\UpdatusUser\AppData\Roaming\Microsoft\Windows\SendTo\Desktop.ini
      2011-08-30 10:15 . 2006-09-18 21:33 4 ----a-w- c:\users\UpdatusUser\AppData\Roaming\Microsoft\Windows\SendTo\Mail Recipient.MAPIMail
      2011-08-30 10:15 . 2008-04-06 11:36 704 --sha-w- c:\users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Desktop.ini
      2011-08-30 10:15 . 2008-04-06 11:36 1753 ----a-w- c:\users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Ease of Access.lnk
      2011-08-30 10:15 . 2006-11-02 12:50 1653 ----a-w- c:\users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Magnify.lnk
      2011-08-30 10:15 . 2008-04-06 11:34 230 ----a-w- c:\users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Run.lnk
      2011-08-30 10:15 . 2008-04-06 11:34 230 ----a-w- c:\users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\computer.lnk
      2011-08-30 10:15 . 2008-04-06 11:34 230 ----a-w- c:\users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Control Panel.lnk
      2011-08-30 10:15 . 2008-04-06 11:34 448 --sha-w- c:\users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Desktop.ini
      2011-08-30 10:15 . 2008-04-06 11:34 318 --sha-w- c:\users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance\Desktop.ini
      2011-08-30 10:15 . 2008-04-06 11:34 230 ----a-w- c:\users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance\Help.lnk
      2011-08-30 10:15 . 2011-09-09 13:00 262144 --sha-w- c:\users\UpdatusUser\NTUSER.DAT
      .
      .
      ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
      .
      .
      *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
      REGEDIT4
      .
      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
      @="{472083B0-C522-11CF-8763-00608CC02F24}"
      [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
      2011-07-04 11:43 122512 ----a-w- c:\program files\Alwil Software\Avast5\ashShell.dll
      .
      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "RocketDock"="c:\program files\RocketDock\RocketDock.exe" [2007-09-02 495616]
      "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
      .
      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "VX3000"="c:\windows\vVX3000.exe" [2009-06-26 757248]
      "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-06-08 37296]
      "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
      "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696]
      .
      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
      "ConsentPromptBehaviorAdmin"= 0 (0x0)
      "EnableUIADesktopToggle"= 0 (0x0)
      .
      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccleaner]
      2011-08-25 14:59 2622784 ----a-w- c:\program files\CCleaner\CCleaner.exe
      .
      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LifeCam]
      2009-07-24 14:05 118640 ----a-w- c:\program files\Microsoft LifeCam\LifeExp.exe
      .
      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Piratrax]
      2011-01-09 09:45 798464 ----a-w- c:\program files\Piratrax\piratrax_launch.exe
      .
      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VistaStartMenuSE]
      2009-11-25 16:23 2751320 ----a-w- c:\program files\Vista Start Menu\VistaStartMenu.exe
      .
      R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
      R3 maconfservice;Ma-Config Service;c:\program files\ma-config.com\maconfservice.exe [2009-09-23 238960]
      R3 ovt530;Webcam Deluxe;c:\windows\system32\Drivers\ov530vid.sys [x]
      R3 RTLWUSB;802.11g USB 2.0 WLAN Dongle;c:\windows\system32\DRIVERS\RTL8187.sys [2007-05-01 169472]
      R3 SetupNTGLM7X;SetupNTGLM7X;D:\NTGLM7X.sys [x]
      R3 WPFFontCache_v0400;Cache de police de Windows Presentation Foundation 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
      R3 WSDPrintDevice;Prise en charge de l'impression WSD via UMB;c:\windows\system32\DRIVERS\WSDPrint.sys [2008-01-19 16896]
      R4 sptd;sptd;c:\windows\system32\Drivers\sptd.sys [2009-08-07 722416]
      R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040]
      S1 aswSnx;aswSnx; [x]
      S1 aswSP;aswSP; [x]
      S2 acedrv11;acedrv11;c:\windows\system32\drivers\acedrv11.sys [2008-07-30 277736]
      S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2008-01-19 21504]
      S2 aswFsBlk;aswFsBlk; [x]
      S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2011-07-04 54104]
      S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-05-21 2214504]
      S3 athrusb;802.11g Wireless USB2.0 Adapter driver;c:\windows\system32\DRIVERS\athrusb.sys [2007-01-29 451072]
      .
      .
      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
      LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
      HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
      hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
      LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
      Akamai REG_MULTI_SZ Akamai
      .
      Contenu du dossier 'Tâches planifiées'
      .
      2011-09-08 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1019982253-855118549-3322040707-1000Core.job
      - c:\users\Elisabeth\AppData\Local\Google\Update\GoogleUpdate.exe [2011-01-09 09:53]
      .
      2011-09-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1019982253-855118549-3322040707-1000UA.job
      - c:\users\Elisabeth\AppData\Local\Google\Update\GoogleUpdate.exe [2011-01-09 09:53]
      .
      2011-09-08 c:\windows\Tasks\User_Feed_Synchronization-{76C4697A-F498-4E08-9D47-5AF7C92D23D3}.job
      - c:\windows\system32\msfeedssync.exe [2011-08-11 09:26]
      .
      .
      ------- Examen supplémentaire -------
      .
      uStart Page = hxxp://www.google.com/chrome/thankyou.html?hl=fr&oneclickinstalled=&installdataindex=defaultbrowser
      mStart Page = hxxp://www.duxet.com/
      IE: Envoyer au périphérique &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
      Trusted Zone: com.tw\www.msi
      TCP: DhcpNameServer = 212.27.40.241 212.27.40.240
      DPF: CabBuilder - hxxp://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
      FF - ProfilePath - c:\users\Elisabeth\AppData\Roaming\Mozilla\Firefox\Profiles\iewiop1t.default\
      FF - prefs.js: browser.search.selectedEngine -
      .
      - - - - ORPHELINS SUPPRIMES - - - -
      .
      AddRemove-conduitEngine - c:\progra~1\CONDUI~1\ConduitEngineUninstall.exe
      AddRemove-Softonic_France Toolbar - c:\progra~1\SOFTON~1\UNWISE.EXE
      .
      .
      .
      **************************************************************************
      .
      catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
      Rootkit scan 2011-09-09 15:00
      Windows 6.0.6002 Service Pack 2 NTFS
      .
      Recherche de processus cachés ...
      .
      Recherche d'éléments en démarrage automatique cachés ...
      .
      Recherche de fichiers cachés ...
      .
      Scan terminé avec succès
      Fichiers cachés: 0
      .
      **************************************************************************
      .
      [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Akamai]
      "ServiceDll"="C:/Program Files/Common Files/Akamai/netsession_win_2da1ebd.dll"
      .
      [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Akamai]
      "ServiceDll"="C:/Program Files/Common Files/Akamai/netsession_win_2da1ebd.dll"
      .
      --------------------- DLLs chargées dans les processus actifs ---------------------
      .
      - - - - - - - > 'Explorer.exe'(3136)
      c:\progra~1\Stardock\OBJECT~1\DESKSC~1\DesktopControlPanel.dll
      c:\progra~1\Stardock\OBJECT~1\DESKSC~1\DreamControl.dll
      .
      ------------------------ Autres processus actifs ------------------------
      .
      c:\windows\system32\nvvsvc.exe
      c:\program files\NVIDIA Corporation\Display\nvxdsync.exe
      c:\windows\system32\nvvsvc.exe
      c:\program files\Alwil Software\Avast5\AvastSvc.exe
      c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
      c:\program files\Executive Software\Diskeeper\DkService.exe
      c:\program files\Microsoft LifeCam\MSCamS32.exe
      c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
      c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
      c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
      c:\program files\Windows Media Player\wmpnetwk.exe
      c:\windows\system32\conime.exe
      c:\windows\system32\wbem\unsecapp.exe
      .
      **************************************************************************
      .
      Heure de fin: 2011-09-09 15:06:23 - La machine a redémarré
      ComboFix-quarantined-files.txt 2011-09-09 13:06
      ComboFix2.txt 2011-09-09 08:45
      ComboFix3.txt 2011-02-15 09:29
      ComboFix4.txt 2010-08-26 15:08
      .
      Avant-CF: 170 327 048 192 octets libres
      Après-CF: 170 138 804 224 octets libres
      .
      Current=1 Default=1 Failed=0 LastKnownGood=11 Sets=1,2,3,4,5,6,7,8,9,11
      - - End Of File - - B7C8AF551DA9B8070C10F08CFC711050
      0
  4. juju666 Messages postés 35446 Date d'inscription   Statut Contributeur sécurité Dernière intervention   4 796
     
    Ok...

    Télécharge AdwCleaner ( d'Xplode ) sur ton bureau.
    Lance le, clique sur [Recherche] puis patiente le temps du scan.
    Une fois le scan fini, un rapport s'ouvrira. Poste moi son contenu dans ta prochaine réponse.

    Note : Le rapport est également sauvegardé sous C:\AdwCleaner[R1].txt
    0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. freddyzack Messages postés 30 Statut Membre
     
    # AdwCleaner v1.305 - Rapport créé le 09/09/2011 à 15:46:25
    # Mis à jour le 07/09/11 à 19h par Xplode
    # Système d'exploitation : Windows Vista (TM) Home Basic Service Pack 2 (32 bits)
    # Nom d'utilisateur : Elisabeth - PC-DE-ELISABETH (Administrateur)
    # Exécuté depuis : C:\Users\Elisabeth\Downloads\adwcleaner0.exe
    # Option [Recherche]

    ***** [Processus] *****

    ***** [Services] *****

    ***** [Fichiers / Dossiers] *****

    Dossier Présent : C:\Program Files\Conduit

    ***** [Registre] *****

    Clé Présente : HKCU\Software\AppDataLow\Toolbar
    Clé Présente : HKCU\Software\AppDataLow\Software\Conduit
    Clé Présente : HKCU\Software\AppDataLow\Software\conduitEngine
    Clé Présente : HKCU\Software\AppDataLow\Software\PriceGong
    Clé Présente : HKLM\SOFTWARE\Conduit
    Clé Présente : HKLM\SOFTWARE\conduitEngine
    Clé Présente : HKLM\SOFTWARE\InstallPedia
    Clé Présente : HKLM\SOFTWARE\SweetIM
    Clé Présente : HKLM\SOFTWARE\Classes\Conduit.Engine
    Clé Présente : HKLM\SOFTWARE\Classes\CLSID\{3c471948-f874-49f5-b338-4f214a2ee0b1}
    Clé Présente : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{18EAB056-9057-F224-FD4C-1F6569C4D8D2}
    Clé Présente : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}
    Clé Présente : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}
    Clé Présente : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}
    Clé Présente : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}
    Clé Présente : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}
    Clé Présente : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EDDBB5EE-BB64-4bfc-9DBE-E7C85941335B}
    Clé Présente : HKLM\SOFTWARE\Microsoft\Office\Word\Addins\HostOL.MailAnim

    ***** [Navigateurs] *****

    -\\ Internet Explorer v8.0.6001.19120

    [OK] Le registre ne contient aucune entrée illégitime.

    -\\ Mozilla Firefox v4.0.1 (fr)

    Profil : iewiop1t.default
    Fichier : C:\Users\Elisabeth\AppData\Roaming\Mozilla\Firefox\Profiles\iewiop1t.default\prefs.js

    [OK] Le fichier ne contient aucune entrée illégitime.

    -\\ Google Chrome v13.0.782.220

    Fichier : C:\Users\Elisabeth\AppData\Local\Google\Chrome\User Data\Default\Preferences

    [OK] Le fichier ne contient aucune entrée illégitime.

    *************************

    AdwCleaner[R1].txt - [2460 octets] - [09/09/2011 15:46:25]

    ########## EOF - C:\AdwCleaner[R1].txt - [2588 octets] ##########
    0
  7. juju666 Messages postés 35446 Date d'inscription   Statut Contributeur sécurité Dernière intervention   4 796
     
    Relance AdwCleaner, clique cette fois sur [Suppression] puis patiente le temps du scan.
    Une fois le scan fini, un rapport s'ouvrira. Poste moi son contenu dans ta prochaine réponse.

    Note : Le rapport est également sauvegardé sous C:\AdwCleaner[S1].txt

    ~~

    Télécharge AD-Remover sur ton Bureau : (TeamXScript)

    http://www.teamxscript.org/adremoverTelechargement.html ( Lien officiel )
    OU
    https://www.androidworld.fr/ ( Miroir )

    /!\ Ferme toutes applications en cours /!\

    ▶ Double-clique sur l'icône Ad-remover située sur ton Bureau.
    ▶ Sur la page, clique sur le bouton « Scanner »
    ▶ Confirme le lancement du scan
    ▶ Laisse travailler l'outil.
    ▶ Quand il a fini, un rapport s'ouvrira : ferme le.

    ♦ Pour me transmettre le rapport

    clique sur ce lien : http://www.cijoint.fr/

    ▶ Clique sur Parcourir et cherche le fichier C:\Ad-Report-SCAN[1].txt

    ▶ Clique sur Ouvrir.

    ▶ Clique sur "Cliquez ici pour déposer le fichier".

    Un lien de cette forme :

    http://www.cijoint.fr/cjlink.php?file=cjge368/cijSKAP5fU.txt

    est ajouté dans la page.

    ▶ Copie ce lien dans ta réponse.
    0
  8. freddyzack Messages postés 30 Statut Membre
     
    # AdwCleaner v1.305 - Rapport créé le 09/09/2011 à 15:51:42
    # Mis à jour le 07/09/11 à 19h par Xplode
    # Système d'exploitation : Windows Vista (TM) Home Basic Service Pack 2 (32 bits)
    # Nom d'utilisateur : Elisabeth - PC-DE-ELISABETH (Administrateur)
    # Exécuté depuis : C:\Users\Elisabeth\Downloads\adwcleaner0.exe
    # Option [Suppression]

    ***** [KillNav] *****

    # chrome.exe [PID:2652] -> Tué

    ***** [Processus] *****

    ***** [Services] *****

    ***** [Fichiers / Dossiers] *****

    Dossier Supprimé : C:\Program Files\Conduit

    ***** [Registre] *****

    Clé Supprimée : HKCU\Software\AppDataLow\Toolbar
    Clé Supprimée : HKCU\Software\AppDataLow\Software\Conduit
    Clé Supprimée : HKCU\Software\AppDataLow\Software\conduitEngine
    Clé Supprimée : HKCU\Software\AppDataLow\Software\PriceGong
    Clé Supprimée : HKLM\SOFTWARE\Conduit
    Clé Supprimée : HKLM\SOFTWARE\conduitEngine
    Clé Supprimée : HKLM\SOFTWARE\InstallPedia
    Clé Supprimée : HKLM\SOFTWARE\SweetIM
    Clé Supprimée : HKLM\SOFTWARE\Classes\Conduit.Engine
    Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{3c471948-f874-49f5-b338-4f214a2ee0b1}
    Clé Supprimée : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{18EAB056-9057-F224-FD4C-1F6569C4D8D2}
    Clé Supprimée : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}
    Clé Supprimée : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}
    Clé Supprimée : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}
    Clé Supprimée : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}
    Clé Supprimée : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EDDBB5EE-BB64-4bfc-9DBE-E7C85941335B}
    Clé Supprimée : HKLM\SOFTWARE\Microsoft\Office\Word\Addins\HostOL.MailAnim

    ***** [Navigateurs] *****

    -\\ Internet Explorer v8.0.6001.19120

    [OK] Le registre ne contient aucune entrée illégitime.

    -\\ Mozilla Firefox v4.0.1 (fr)

    Profil : iewiop1t.default
    Fichier : C:\Users\Elisabeth\AppData\Roaming\Mozilla\Firefox\Profiles\iewiop1t.default\prefs.js

    [OK] Le fichier ne contient aucune entrée illégitime.

    -\\ Google Chrome v13.0.782.220

    Fichier : C:\Users\Elisabeth\AppData\Local\Google\Chrome\User Data\Default\Preferences

    [OK] Le fichier ne contient aucune entrée illégitime.

    *************************

    AdwCleaner[R1].txt - [2589 octets] - [09/09/2011 15:46:25]
    AdwCleaner[S1].txt - [2489 octets] - [09/09/2011 15:51:42]

    ########## EOF - C:\AdwCleaner[S1].txt - [2617 octets] ##########
    0
  9. juju666 Messages postés 35446 Date d'inscription   Statut Contributeur sécurité Dernière intervention   4 796
     
    Télécharge AD-Remover sur ton Bureau : (TeamXScript)

    http://www.teamxscript.org/adremoverTelechargement.html ( Lien officiel )
    OU
    https://www.androidworld.fr/ ( Miroir )

    /!\ Ferme toutes applications en cours /!\

    ▶ Double-clique sur l'icône Ad-remover située sur ton Bureau.
    ▶ Sur la page, clique sur le bouton « Scanner »
    ▶ Confirme le lancement du scan
    ▶ Laisse travailler l'outil.
    ▶ Quand il a fini, un rapport s'ouvrira : ferme le.

    ♦ Pour me transmettre le rapport

    clique sur ce lien : http://www.cijoint.fr/

    ▶ Clique sur Parcourir et cherche le fichier C:\Ad-Report-SCAN[1].txt

    ▶ Clique sur Ouvrir.

    ▶ Clique sur "Cliquez ici pour déposer le fichier".

    Un lien de cette forme :

    http://www.cijoint.fr/cjlink.php?file=cjge368/cijSKAP5fU.txt

    est ajouté dans la page.

    ▶ Copie ce lien dans ta réponse.
    0
  10. freddyzack Messages postés 30 Statut Membre
     
    http://www.cijoint.fr/cjlink.php?file=cj201109/cijwP50zl6.txt
    0
  11. freddyzack Messages postés 30 Statut Membre
     
    ci dessus le lien du dernier rapport merci
    0
  12. juju666 Messages postés 35446 Date d'inscription   Statut Contributeur sécurité Dernière intervention   4 796
     
    ok :)

    ▶ Relance AD-Remover, clique sur [ Nettoyer ]
    ▶ Laisse le pc redémarrer.
    ▶ Une fois revenu sur le bureau, le rapport devrait s'ouvrir : ferme-le

    ♦ Pour me transmettre le rapport

    clique sur ce lien : http://www.cijoint.fr/

    ▶ Clique sur Parcourir et cherche le fichier C:\Ad-Report-CLEAN[1].txt

    ▶ Clique sur Ouvrir.

    ▶ Clique sur "Cliquez ici pour déposer le fichier".

    Un lien de cette forme :

    http://www.cijoint.fr/cjlink.php?file=cjge368/cijSKAP5fU.txt

    est ajouté dans la page.

    ▶ Copie ce lien dans ta réponse.
    0
  13. freddyzack Messages postés 30 Statut Membre
     
    http://www.cijoint.fr/cjlink.php?file=cj201109/cijq4GAXqR.txt
    voici le dernier lien merci
    0
  14. juju666 Messages postés 35446 Date d'inscription   Statut Contributeur sécurité Dernière intervention   4 796
     
    parfait :)

    ▶ Télécharge MBAM et installe le selon l'emplacement par défaut
    https://www.malwarebytes.com/mwb-download/
    ▶ Effectue la mise à jour et lance Malwarebytes' Anti-Malware

    ▶ ▶ Si tu n''arrive pas à le mettre à jour, télécharge ce fichier , ferme MBAM, et exécute le

    ▶ Clique dans l'onglet du haut "Recherche"
    ▶ Coche l'option "Exécuter un examen complet" puis sur le bouton "Rechercher"
    ▶ Choisis de scanner tous tes disques durs, puis clique sur 'Lancer l'examen"

    A la fin de l'analyse, si MBAM n'a rien trouvé :

    ▶ Clique sur OK, le rapport s'ouvre spontanément

    Si des menaces ont été détectées :

    ▶ Clique sur OK puis "Afficher les résultats"
    ▶ Choisis l'option "Supprimer la sélection"
    ▶ Si MBAM demande le redémarrage de Windows : Clique sur "Oui"
    ▶ Une fois le PC redémarré, le rapport se trouve dans l'onglet "Rapports/Logs"
    ▶ Sinon le rapport s'ouvre automatiquement après la suppression

    Quelque soit le résultat, copie/colle le rapport dans le prochain message
    0
  15. freddyzack Messages postés 30 Statut Membre
     
    j' utilise piratrax et ccleaner asser souvent es-ce recomander?
    0
  16. juju666 Messages postés 35446 Date d'inscription   Statut Contributeur sécurité Dernière intervention   4 796
     
    je connais pas piratrax ...
    0
  17. freddyzack Messages postés 30 Statut Membre
     
    Malwarebytes' Anti-Malware 1.51.1.1800
    www.malwarebytes.org

    Version de la base de données: 7684

    Windows 6.0.6002 Service Pack 2
    Internet Explorer 8.0.6001.19120

    09/09/2011 17:18:06
    mbam-log-2011-09-09 (17-18-06).txt

    Type d'examen: Examen complet (C:\|)
    Elément(s) analysé(s): 287960
    Temps écoulé: 54 minute(s), 22 seconde(s)

    Processus mémoire infecté(s): 0
    Module(s) mémoire infecté(s): 0
    Clé(s) du Registre infectée(s): 0
    Valeur(s) du Registre infectée(s): 0
    Elément(s) de données du Registre infecté(s): 0
    Dossier(s) infecté(s): 0
    Fichier(s) infecté(s): 0

    Processus mémoire infecté(s):
    (Aucun élément nuisible détecté)

    Module(s) mémoire infecté(s):
    (Aucun élément nuisible détecté)

    Clé(s) du Registre infectée(s):
    (Aucun élément nuisible détecté)

    Valeur(s) du Registre infectée(s):
    (Aucun élément nuisible détecté)

    Elément(s) de données du Registre infecté(s):
    (Aucun élément nuisible détecté)

    Dossier(s) infecté(s):
    (Aucun élément nuisible détecté)

    Fichier(s) infecté(s):
    (Aucun élément nuisible détecté)
    0
  18. freddyzack Messages postés 30 Statut Membre
     
    voila dernier rapport ci dessus merci
    0
  19. juju666 Messages postés 35446 Date d'inscription   Statut Contributeur sécurité Dernière intervention   4 796
     
    Nous allons effectuer un diagnostic de ton PC:
    Télécharge ZHPDiag

    ▶ Laisse toi guider lors de l''installation,coche "Ajouter une icône sur le bureau" et "Exécuter ZHPDiag"

    ▶ Clique sur l''icône représentant une loupe (« Lancer le diagnostic »)

    ▶ Une fois le scan aux 100%, ferme ZHPDiag. Héberge le rapport ZHPDiag.txt présent sur ton bureau :

    Voici comment procéder

    ▶ Rends toi sur pjjoint.malekal.com
    ▶ Clique sur le bouton Parcourir
    ▶ Sélectionne le fichier que tu veux heberger et clique sur Ouvrir
    ▶ Clique sur le bouton Envoyer
    ▶ Un message de confirmation s''affiche (L''upload a réussi ! - Le lien à transmettre à vos correspondant pour visualiser le fichier est : https://pjjoint.malekal.com/files.php?id=df5ea299241015 Copie le lien dans ta prochaine réponse.

    A bientôt.
    0
  20. freddyzack Messages postés 30 Statut Membre
     
    je suis desoler mais je n'y parvient pas a faire le diagnostic avec zhpdiag mon pc redemare a chaque fois que je fait le diagnostic il plante sur une page bleu de teste memoires et redemare, que faire s' il vous plais
    0
  21. juju666 Messages postés 35446 Date d'inscription   Statut Contributeur sécurité Dernière intervention   4 796
     
    à quel % cela se produit ?
    0
  • 1
  • 2