[VIRUS]contamination par Serwab

petpou Messages postés 14 Statut Membre -  
petpou Messages postés 14 Statut Membre -
Rebonjour à tous, après une première contamination, me revoila avec un nouveau virus SERWAB, internet explorer vient de le detecter, l'ordinateur est au ralenti, et l'explorateur se ferme de temps en temps. J'ai effectuer un petit nettoyage avec CCleaner, et donc je voudrais savoir si quelqu'un pourrai m'aider à nettoyer mon ordinateur de cette saleté virulante. J'ai une question: est ce qu'un virus contamine également des documents personnels comme des photos, films, fichiers photoshops...? merci d'avance pour votre aide
Configuration: Windows XP
Internet Explorer 6.0

6 réponses

  1. petpou Messages postés 14 Statut Membre
     
    Coucou, ya t-il des chasseurs de virus serwab?
    0
  2. Utilisateur anonyme
     
    Salut

    Oui, il se peut qu'un virus contamine tes fichiers persos.

    Télécharge SmitfraudFix (enregistre le sur le "bureau")
    http://siri.urz.free.fr/Fix/SmitfraudFix.zip

    décompresse SmitfraudFix
    Lance le fichier SmitfraudFix ou SmitfraudFix.cmd et choisit l option 1 copie le rapport ici

    ________________________________________________________

    Télécharge HijackThis :
    --->hijackthis
    Installe le dans son propre dossier :
    - clic droit sur le bureau, tu choisis "nouveau dossier" puis installe-le à l'intérieur.
    Double-clic sur HijackThis , clic sur "do a system scan and save logfile"
    Puis copie et colle le rapport ici stp
    0
    1. petpou Messages postés 14 Statut Membre
       
      Salut boule pat, comment ca va? le pere noel t'a ramené un nouveau clavier? C'est la deuxieme fois que tu me viens en aide, et je t'en remercie bien. Voici le rapport de Smitfraudfix:

      SmitFraudFix v2.134

      Rapport fait à 12:31:18,64, 24/01/2007
      Executé à partir de C:\Documents and Settings\SEB\Bureau\SmitfraudFix
      OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
      Le type du système de fichiers est NTFS
      Fix executé en mode normal

      »»»»»»»»»»»»»»»»»»»»»»»» C:\


      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS


      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system


      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web


      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32


      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles


      »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\SEB


      »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\SEB\Application Data


      »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer


      »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\SEB\Favoris


      »»»»»»»»»»»»»»»»»»»»»»»» Bureau


      »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files


      »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues


      »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

      [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
      "Source"="About:Home"
      "SubscribedURL"="About:Home"
      "FriendlyName"="Ma page d'accueil"


      »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      SrchSTS.exe by S!Ri
      Search SharedTaskScheduler's .dll


      »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
      "AppInit_DLLs"=""


      »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
      "System"=""


      »»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32


      »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll


      »»»»»»»»»»»»»»»»»»»»»»»» Fin



      Et voici maintenant le rapport Hijackthis:

      Logfile of HijackThis v1.99.1
      Scan saved at 12:38:16, on 24/01/2007
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
      C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
      C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
      C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
      C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
      C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
      C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
      C:\Program Files\Dell\Media Experience\DMXLauncher.exe
      C:\WINDOWS\system32\dla\tfswctrl.exe
      C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
      C:\Program Files\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe
      C:\Program Files\Broadcom\BACS\BacsTray.exe
      C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
      C:\Program Files\BroadJump\Client Foundation\CFD.exe
      C:\WINDOWS\system32\qttask.exe
      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      C:\WINDOWS\stsystra.exe
      C:\PROGRA~1\CLUB-I~1\LECOMP~1\SMARTB~1\MotiveSB.exe
      C:\Program Files\Club-Internet\Agent Wi-Fi V2.1\McciTrayApp.exe
      C:\WINDOWS\system32\rundll32.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Skype\Phone\Skype.exe
      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      C:\Program Files\Alwil Software\Avast4\ashServ.exe
      C:\Program Files\Adobe\Adobe Acrobat 6.0\Distillr\acrotray.exe
      C:\WINDOWS\system32\drivers\CDAC11BA.EXE
      C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
      C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
      C:\Program Files\Club-Internet\Le Compagnon Club\bin\lecompagnonclub.exe
      C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
      C:\Program Files\Club-Internet\Le Compagnon Club\bin\mpbtn.exe
      C:\PROGRA~1\Motive\ASSTCO~1\MOTIVE~1.EXE
      C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
      C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
      C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
      C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Autodesk Network License Manager\lmgrd.exe
      C:\WINDOWS\system32\MsPMSPSv.exe
      C:\Program Files\Autodesk Network License Manager\adskflex.exe
      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
      C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
      C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
      C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Documents and Settings\SEB\Bureau\Nouveau dossier\HijackThis.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer avec Club-Internet
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - (no file)
      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
      O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - c:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll
      O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - c:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll
      O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
      O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
      O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      O4 - HKLM\..\Run: [ShowLOMControl] 
      O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
      O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
      O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
      O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
      O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
      O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
      O4 - HKLM\..\Run: [AdobeVersionCue] C:\Program Files\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe
      O4 - HKLM\..\Run: [bacstray] C:\Program Files\Broadcom\BACS\BacsTray.exe
      O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
      O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
      O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\system32\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
      O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
      O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
      O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
      O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
      O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
      O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\CLUB-I~1\LECOMP~1\SMARTB~1\MotiveSB.exe
      O4 - HKLM\..\Run: [Club-Internet_McciTrayApp] C:\Program Files\Club-Internet\Agent Wi-Fi V2.1\McciTrayApp.exe
      O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
      O4 - Global Startup: Accélérateur de démarrage AutoCAD.lnk = C:\Program Files\Fichiers communs\Autodesk Shared\acstart16.exe
      O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
      O4 - Global Startup: Assistant d'Acrobat.lnk = C:\Program Files\Adobe\Adobe Acrobat 6.0\Distillr\acrotray.exe
      O4 - Global Startup: Bluetooth Manager.lnk = ?
      O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      O4 - Global Startup: LE COMPAGNON CLUB.lnk = C:\Program Files\Club-Internet\Le Compagnon Club\bin\matcli.exe
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
      O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
      O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
      O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
      O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
      O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
      O16 - DPF: {9D190AE6-C81E-4039-8061-978EBAD10073} (F-Secure Online Scanner 3.0) - https://www.f-secure.com/en/home/support
      O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
      O23 - Service: Autodesk Licensing Service - Autodesk, Inc. - C:\Program Files\Fichiers communs\Autodesk Shared\Service\AdskScSrv.exe
      O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
      O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
      O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
      O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
      O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
      O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
      O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
      O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
      O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
      O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
      O23 - Service: Viz 2005 - Macrovision Corporation - C:\Program Files\Autodesk Network License Manager\lmgrd.exe
      O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel(R) Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

      A toi de jouer boulepat, merci encore
      0
  3. Utilisateur anonyme
     
    Slaut Petpou

    Non, même pas juste une souris qu'il lui restait dans l'fond !
    Le clavier fait de la résistance !

    ¤ Tu peux jeter smitfraudfix

    ¤ Désinstalle ces deux programmes, car ils sont loin d'être à jour et comporte des failles, on les réinstallera à la fin de la manip

    - Adobe Acrobat
    - Java (tout ce que tu vois)

    ¤ Relance HijackThis, choisis "do a scan only" coche la case devant les lignes ci-dessous et clic en bas sur "fix checked"

    R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - (no file)
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - c:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll
    O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - c:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
    O4 - HKLM\..\Run: [ShowLOMControl]
    O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
    O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
    O4 - HKLM\..\Run: [AdobeVersionCue] C:\Program Files\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - Global Startup: Accélérateur de démarrage AutoCAD.lnk = C:\Program Files\Fichiers communs\Autodesk Shared\acstart16.exe
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: Assistant d'Acrobat.lnk = C:\Program Files\Adobe\Adobe Acrobat 6.0\Distillr\acrotray.exe
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)

    ¤ Je ne sais plus les logiciels anti-spywares que tu as donc en voici une liste si tu ne les as pas télécharge les et scanne complétement ton PC et supprime tout ce qu'ils pourraient te trouver :

    SpyBot-Search & Destroy: (gratuit en Français)
    --->Spybot
    Si tu as besoin d'aide avec Sybot regarde ce tutoriel:
    http://www.tutoriaux-excalibur.com/spybot.htm

    A² squared: (gratuit en Français)(fait un scan rusé et colle le rapport ici stp)
    --->A-squared
    Si tu as besoin d'aide avec A-squared regarde ce tutoriel:
    https://kerio.probb.fr/t223-tuto-pour-a-squared-free

    Ad-Aware SE Personal: (en Anglais disponible en Français, gratuit)
    --->Ad-aware
    Si tu as besoin d'aide pour ad-Aware regarde ce tutoriel:
    https://kerio.probb.fr/t207-tutoriel-pour-ad-aware-anti-spyware

    Télécharge, installe puis met à jour ce logiciel(Ewido), une fois que c'est fait, fais un scan complet de ton système, supprime (delete) tout ce qu'il te trouve puis colle le rapport ici stp
    Ewido: (en Anglais reste gratuit après la période d'essai)
    --->Ewido
    Si tu as besoin d'aide avec Ewido(devenu AVG-antispyware) regarde ce tutoriel:
    http://www.kachouri.com/tuto/tuto-161-avg-anti-spyware-75-pour-votre-securite.html

    ¤ Fait ce scan anti-virus en ligne avec Internet Explorer, accepte l'active X; la barre anti-popup du SP2(en haut) va se mettre à clignoter, clique dessus et choisit "accepter l'active X" pour faire fonctionner le scan anti-virus.
    Une fois qu'il a terminé colle le rapport ici stp

    _Online Scanner
    _Kaspersky Online Scanner
    _My Computer

    https://www.kaspersky.fr/downloads

    A+++

    0
  4. petpou Messages postés 14 Statut Membre
     
    Salut boulepat, ya du boulot a ce que je vois, alors je t'envoie tout d'abord les lignes de HijackThis que je n'ai pas trouver après la désinstallation de Acrobat et de Java:

    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - c:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll
    O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - c:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
    O4 - Global Startup: Assistant d'Acrobat.lnk = C:\Program Files\Adobe\Adobe Acrobat 6.0\Distillr\acrotray.exe
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll

    Et je te renvoie la suite un peu plus tard, merci
    0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. petpou Messages postés 14 Statut Membre
     
    Petit problème, quand j'ai voulu fixer les lignes que tu m'as signalé, ce message est apparu:

    unexpected error occured!
    Error #52 (nom ou numéro de fichiers incorrect) in Sub GetLongPath (.exe).
    Please send a report to merijn@spywareinfo.com, mentionning what you were doing, and what version of Windows you have;
    This message has been copied to your clipboard.

    J'ai surement du effectuer une connerie, car j'ai voulue désinstaller Kerio entre temps. J'avait installer auparavant Avast et Kerio
    0
  7. Utilisateur anonyme
     
    Salut

    Pas grave continue la suite ;-)
    0
    1. petpou Messages postés 14 Statut Membre
       
      Salut Boulepat, désolé je me suis absenté pendant en peyit bout de temps, mais me revoila penché sur la machine, en matière d'antispyware j'avais installer Kerio et Avast, j'ai eu quelques petit probleme avec Kerio, donc je l'ai désinstallé. pour Avast j'ai l'impression qu'il ne sert à rien, je vais peut être le remplacer avec une version gratuite de AVG, as tu des conseils à me donner sur ce sujet là?

      Sinon voila les rapports,

      A²squared:
      Version - a-squared Free 2.1

      Réglages Scan:

      Objets: Mémoire, Traces, Cookies, C:\
      Scan archives: Marche
      Heuristiques: Marche
      Scan ADS: Marche

      Début du scan: 07-02-02 20:01:11

      C:\Documents and Settings\SEB\Cookies\seb@247realmedia[2].txt Détecter: Trace.TrackingCookie
      C:\Documents and Settings\SEB\Cookies\seb@atdmt[2].txt Détecter: Trace.TrackingCookie
      C:\Documents and Settings\SEB\Cookies\seb@bs.serving-sys[1].txt Détecter: Trace.TrackingCookie
      C:\Documents and Settings\SEB\Cookies\seb@fastclick[2].txt Détecter: Trace.TrackingCookie
      C:\Documents and Settings\SEB\Cookies\seb@mediaplex[1].txt Détecter: Trace.TrackingCookie
      C:\Documents and Settings\SEB\Cookies\seb@serving-sys[1].txt Détecter: Trace.TrackingCookie
      C:\Documents and Settings\SEB\Cookies\seb@smartadserver[2].txt Détecter: Trace.TrackingCookie
      C:\Documents and Settings\SEB\Cookies\seb@stat.dealtime[2].txt Détecter: Trace.TrackingCookie
      C:\Documents and Settings\SEB\Cookies\seb@tradedoubler[2].txt Détecter: Trace.TrackingCookie
      C:\Documents and Settings\SEB\Cookies\seb@tribalfusion[2].txt Détecter: Trace.TrackingCookie
      C:\Documents and Settings\SEB\Cookies\seb@weborama[1].txt Détecter: Trace.TrackingCookie
      C:\Documents and Settings\SEB\Cookies\seb@zedo[1].txt Détecter: Trace.TrackingCookie
      C:\Documents and Settings\SEB\Mes documents\LOGICIEL\Sécurité\SmitfraudFix.zip/Process.exe Détecter: Riskware.RiskTool.Win32.Processor.20
      C:\Documents and Settings\SEB\Mes documents\LOGICIEL\Sécurité\SmitfraudFix.zip/Reboot.exe Détecter: Riskware.RiskTool.Win32.Reboot.f
      C:\WINDOWS\system32\Process.exe Détecter: Riskware.RiskTool.Win32.Processor.20

      Scanné

      Fichiers: 153556
      Traces: 96345
      Cookies: 80
      Processus: 57

      Trouver

      Fichiers: 3
      Traces: 0
      Cookies: 12
      Processus: 0
      Clés de Registre: 0

      Fin du Scan: 07-02-02 20:52:09
      Temps du Scan: 00:50:58

      Celui de Ewido:

      ---------------------------------------------------------
      AVG Anti-Spyware - Rapport d'analyse
      ---------------------------------------------------------

      + Créé à: 13:29 07-02-03

      + Résultat de l'analyse:



      C:\System Volume Information\_restore{340C3340-2EBB-4324-859A-C37E85627171}\RP7\A0002559.exe -> Not-A-Virus.Downloader.Win32.WinFixer.m : Aucune action entreprise.
      C:\Documents and Settings\SEB\Mes documents\LOGICIEL\Sécurité\WinAntiSpyware2007FreeInstall.exe -> Not-A-Virus.Downloader.Win32.WinFixer.o : Aucune action entreprise.
      C:\Documents and Settings\SEB\Cookies\seb@247realmedia[1].txt -> TrackingCookie.247realmedia : Aucune action entreprise.


      Fin du rapport

      Et enfin celui de Kaspersky:
      -------------------------------------------------------------------------------
      KASPERSKY ONLINE SCANNER REPORT
      07-02-03 16:48
      Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
      Kaspersky Online Scanner version: 5.0.83.0
      Kaspersky Anti-Virus database last update: 3/02/2007
      Kaspersky Anti-Virus database records: 249715
      -------------------------------------------------------------------------------

      Scan Settings:
      Scan using the following antivirus database: standard
      Scan Archives: true
      Scan Mail Bases: true

      Scan Target - My Computer:
      C:\
      D:\

      Scan Statistics:
      Total number of scanned objects: 94340
      Number of viruses found: 0
      Number of infected objects: 0 / 0
      Number of suspicious objects: 0
      Duration of the scan process: 01:01:45

      Infected Object Name / Virus Name / Last Action
      C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\791576950ebfab18ffae65fe78f04804_317f7cfe-190a-4e83-b1c9-595527d33e6e Object is locked skipped
      C:\Documents and Settings\All Users\Application Data\QSLLPSVCShare Object is locked skipped
      C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
      C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
      C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
      C:\Documents and Settings\LocalService\Local Settings\Historique\History.IE5\index.dat Object is locked skipped
      C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
      C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
      C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
      C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
      C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
      C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
      C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
      C:\Documents and Settings\SEB\Application Data\Skype\garopetpou\call256.dbb Object is locked skipped
      C:\Documents and Settings\SEB\Application Data\Skype\garopetpou\callmember256.dbb Object is locked skipped
      C:\Documents and Settings\SEB\Application Data\Skype\garopetpou\chat512.dbb Object is locked skipped
      C:\Documents and Settings\SEB\Application Data\Skype\garopetpou\chatmsg1024.dbb Object is locked skipped
      C:\Documents and Settings\SEB\Application Data\Skype\garopetpou\chatmsg2048.dbb Object is locked skipped
      C:\Documents and Settings\SEB\Application Data\Skype\garopetpou\chatmsg256.dbb Object is locked skipped
      C:\Documents and Settings\SEB\Application Data\Skype\garopetpou\chatmsg512.dbb Object is locked skipped
      C:\Documents and Settings\SEB\Application Data\Skype\garopetpou\contactgroup256.dbb Object is locked skipped
      C:\Documents and Settings\SEB\Application Data\Skype\garopetpou\index2.dat Object is locked skipped
      C:\Documents and Settings\SEB\Application Data\Skype\garopetpou\profile16384.dbb Object is locked skipped
      C:\Documents and Settings\SEB\Application Data\Skype\garopetpou\transfer256.dbb Object is locked skipped
      C:\Documents and Settings\SEB\Application Data\Skype\garopetpou\transfer512.dbb Object is locked skipped
      C:\Documents and Settings\SEB\Application Data\Skype\garopetpou\user1024.dbb Object is locked skipped
      C:\Documents and Settings\SEB\Cookies\index.dat Object is locked skipped
      C:\Documents and Settings\SEB\Local Settings\Application Data\ApplicationHistory\cli.exe.c88dbd71.ini.inuse Object is locked skipped
      C:\Documents and Settings\SEB\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
      C:\Documents and Settings\SEB\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
      C:\Documents and Settings\SEB\Local Settings\Historique\History.IE5\index.dat Object is locked skipped
      C:\Documents and Settings\SEB\Local Settings\Historique\History.IE5\MSHist012007020320070204\index.dat Object is locked skipped
      C:\Documents and Settings\SEB\Local Settings\Temp\bbassistant.log Object is locked skipped
      C:\Documents and Settings\SEB\Local Settings\Temp\hpodvd09.log Object is locked skipped
      C:\Documents and Settings\SEB\Local Settings\Temp\Perflib_Perfdata_1b8.dat Object is locked skipped
      C:\Documents and Settings\SEB\Local Settings\Temp\Perflib_Perfdata_3e8.dat Object is locked skipped
      C:\Documents and Settings\SEB\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
      C:\Documents and Settings\SEB\NTUSER.DAT Object is locked skipped
      C:\Documents and Settings\SEB\ntuser.dat.LOG Object is locked skipped
      C:\Program Files\Alwil Software\Avast4\DATA\aswResp.dat Object is locked skipped
      C:\Program Files\Alwil Software\Avast4\DATA\Avast4.db Object is locked skipped
      C:\Program Files\Alwil Software\Avast4\DATA\log\AshWebSv.ws Object is locked skipped
      C:\Program Files\Alwil Software\Avast4\DATA\log\aswMaiSv.log Object is locked skipped
      C:\Program Files\Alwil Software\Avast4\DATA\log\nshield.log Object is locked skipped
      C:\Program Files\Alwil Software\Avast4\DATA\report\Protection résidente.txt Object is locked skipped
      C:\Program Files\Autodesk Network License Manager\License\License.txt Object is locked skipped
      C:\Program Files\Club-Internet\Le Compagnon Club\log\mpbtn.log Object is locked skipped
      C:\Program Files\Club-Internet\Le Compagnon Club\SmartBridge\AlertFilter.log Object is locked skipped
      C:\Program Files\Club-Internet\Le Compagnon Club\SmartBridge\log\httpclient.log Object is locked skipped
      C:\Program Files\Club-Internet\Le Compagnon Club\SmartBridge\SmartBridge.log Object is locked skipped
      C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
      C:\System Volume Information\_restore{340C3340-2EBB-4324-859A-C37E85627171}\RP19\change.log Object is locked skipped
      C:\WINDOWS\CSC\00000001 Object is locked skipped
      C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
      C:\WINDOWS\SchedLgU.Txt Object is locked skipped
      C:\WINDOWS\SoftwareDistribution\EventCache\{10B16156-A973-4AF7-9C64-75C6791C3811}.bin Object is locked skipped
      C:\WINDOWS\SoftwareDistribution\EventCache\{31A943B0-8DC6-4881-8B11-30BA530C50A3}.bin Object is locked skipped
      C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
      C:\WINDOWS\Sti_Trace.log Object is locked skipped
      C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
      C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
      C:\WINDOWS\system32\config\ACEEvent.evt Object is locked skipped
      C:\WINDOWS\system32\config\Antivirus.Evt Object is locked skipped
      C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
      C:\WINDOWS\system32\config\DEFAULT Object is locked skipped
      C:\WINDOWS\system32\config\default.LOG Object is locked skipped
      C:\WINDOWS\system32\config\SAM Object is locked skipped
      C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
      C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
      C:\WINDOWS\system32\config\SECURITY Object is locked skipped
      C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
      C:\WINDOWS\system32\config\SOFTWARE Object is locked skipped
      C:\WINDOWS\system32\config\software.LOG Object is locked skipped
      C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
      C:\WINDOWS\system32\config\SYSTEM Object is locked skipped
      C:\WINDOWS\system32\config\system.LOG Object is locked skipped
      C:\WINDOWS\system32\h323log.txt Object is locked skipped
      C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
      C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
      C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
      C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
      C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
      C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
      C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
      C:\WINDOWS\Temp\Perflib_Perfdata_750.dat Object is locked skipped
      C:\WINDOWS\Temp\_avast4_\Webshlock.txt Object is locked skipped
      C:\WINDOWS\wiadebug.log Object is locked skipped
      C:\WINDOWS\wiaservc.log Object is locked skipped
      C:\WINDOWS\WindowsUpdate.log Object is locked skipped

      Scan process completed.

      Tout à l'air de bien se passer, j'espere que tu vas me dire la meme chose. qu'il n'y a pas une petite bête cacher quelque part?
      Qu'es ce que tu en pense si je me protège avec la version gratuite d'AVG, et Kerio?

      Merci encore a toi Boulepat, avec tou cet attirail d'anti spyware, j'espere pouvoir m'en sortir la prochaine fois tout seul, et de faire un peu de vacance. merci, merci
      0