PUP.optional.sweetIM

Résolu
moon -  
2011N2 Messages postés 13379 Date d'inscription   Statut Contributeur sécurité Dernière intervention   -
Bonjour,

Je poste le rapport MBAM

Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org

Version de la base de données: v2013.08.18.01

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 10.0.9200.16635
Moon :: MOON-VAIO [administrateur]

18/08/2013 12:50:08
MBAM-log-2013-08-18 (14-41-51).txt

Type d'examen: Examen complet (C:\|D:\|E:\|F:\|)
Options d'examen activées: Mémoire | Démarrage | Registre | Système de fichiers | Heuristique/Extra | Heuristique/Shuriken | PUP | PUM
Options d'examen désactivées: P2P
Elément(s) analysé(s): 401112
Temps écoulé: 1 heure(s), 32 minute(s), 51 seconde(s)

Processus mémoire détecté(s): 0
(Aucun élément nuisible détecté)

Module(s) mémoire détecté(s): 0
(Aucun élément nuisible détecté)

Clé(s) du Registre détectée(s): 0
(Aucun élément nuisible détecté)

Valeur(s) du Registre détectée(s): 0
(Aucun élément nuisible détecté)

Elément(s) de données du Registre détecté(s): 0
(Aucun élément nuisible détecté)

Dossier(s) détecté(s): 0
(Aucun élément nuisible détecté)

Fichier(s) détecté(s): 2
C:\Windows\Installer\14bb30d5.msi (PUP.Optional.SweetIM) -> Aucune action effectuée.
C:\Windows\Installer\14bb30da.msi (PUP.Optional.SweetIM) -> Aucune action effectuée.

(fin)

23 réponses

  • 1
  • 2
  1. Moon3003 Messages postés 19 Statut Membre
     
    # AdwCleaner v2.306 - Rapport créé le 18/08/2013 à 15:26:18
    # Mis à jour le 19/07/2013 par Xplode
    # Système d'exploitation : Windows 7 Home Premium Service Pack 1 (64 bits)
    # Nom d'utilisateur : Moon - MOON-VAIO
    # Mode de démarrage : Normal
    # Exécuté depuis : C:\Users\Moon\Downloads\adwcleaner.exe
    # Option [Suppression]

    ***** [Services] *****

    ***** [Fichiers / Dossiers] *****

    ***** [Registre] *****

    Clé Supprimée : HKCU\Software\YahooPartnerToolbar
    Clé Supprimée : HKLM\Software\DeviceVM
    Clé Supprimée : HKLM\SOFTWARE\Microsoft\Tracing\boxore_RASAPI32
    Clé Supprimée : HKLM\SOFTWARE\Microsoft\Tracing\boxore_RASMANCS
    Clé Supprimée : HKLM\SOFTWARE\Microsoft\Tracing\offerbox_RASAPI32
    Clé Supprimée : HKLM\SOFTWARE\Microsoft\Tracing\offerbox_RASMANCS
    Clé Supprimée : HKLM\SOFTWARE\Microsoft\Tracing\SweetPacksUpdateManager_RASAPI32
    Clé Supprimée : HKLM\SOFTWARE\Microsoft\Tracing\SweetPacksUpdateManager_RASMANCS

    ***** [Navigateurs] *****

    -\\ Internet Explorer v10.0.9200.16635

    [OK] Le registre ne contient aucune entrée illégitime.

    -\\ Mozilla Firefox v22.0 (fr)

    Fichier : C:\Users\Moon\AppData\Roaming\Mozilla\Firefox\Profiles\9w3512j0.default\prefs.js

    [OK] Le fichier ne contient aucune entrée illégitime.

    -\\ Google Chrome v [Impossible d'obtenir la version]

    Fichier : C:\Users\Moon\AppData\Local\Google\Chrome\User Data\Default\Preferences

    [OK] Le fichier ne contient aucune entrée illégitime.

    *************************

    AdwCleaner[S1].txt - [359 octets] - [18/08/2013 15:25:50]
    AdwCleaner[S2].txt - [1548 octets] - [18/08/2013 15:26:18]

    ########## EOF - C:\AdwCleaner[S2].txt - [1608 octets] ##########
    0
  2. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  3. 2011N2 Messages postés 13379 Date d'inscription   Statut Contributeur sécurité Dernière intervention   920
     
    Re,

    Ok, fais moi un nouveau rapport ZHPDiag. :)

    Gabriel.
    0
  4. 2011N2 Messages postés 13379 Date d'inscription   Statut Contributeur sécurité Dernière intervention   920
     
    Re,

    Ok fais ZHPfix comme ceci avec ces lignes.

    Gabriel.
    0
  5. 2011N2 Messages postés 13379 Date d'inscription   Statut Contributeur sécurité Dernière intervention   920
     
    Re,

    Parfait, fais moi un nouveau ZHPDiag pour voir si tout est ok.

    Gabriel.
    0
  6. Moon3003 Messages postés 19 Statut Membre
     
    ok c'est en route ! Du coup, c'était quoi ? Je fais super attention je ne sais pas comment j'ai choppé ça !
    0
  7. 2011N2 Messages postés 13379 Date d'inscription   Statut Contributeur sécurité Dernière intervention   920
     
    Quelques LPIs comme expliqué dans les liens que je t'ai donné, mais rien de méchant. :)

    Ok, je m'absente jusqu'à ce soir.

    @+ :)

    Gabriel.
    0
  8. Moon3003 Messages postés 19 Statut Membre
     
    Désolée, du coup j'étais partie. Je suis en train de tout faire, ca va aller vite j'ai déjà la moitié des logiciels. Je te donne les liens quand c'est terminé.
    0
  9. Moon3003 Messages postés 19 Statut Membre
     
    j'ai fait une recherche pour USB fix, est-ce qu'il y a quelque chose ?

    ############################## | UsbFix V 7.129 | [Recherche]

    Utilisateur: Moon (Administrateur) # MOON-VAIO
    Mis à jour le 24/06/2013 par El Desaparecido
    Lancé à 11:19:30 | 19/08/2013

    Site Web: https://www.sosvirus.net/
    Upload Malware: http://www.sosvirus.net/upload-malware-pour-analyse-t489.html
    Contact: contact@sosvirus.net

    PC: Sony Corporation (VPCEA1S1E) (x64-based PC)
    CPU: Intel(R) Core(TM) i3 CPU M 330 @ 2.13GHz (2133)
    RAM -> [Total : 3950 | Free : 2240]
    BIOS: BIOS Date: 09/23/09 11:58:43 Ver: 08.00.10
    BOOT: Normal boot

    OS: Microsoft Windows 7 Édition Familiale Premium (6.1.7601 64-Bit) # Service Pack 1
    WB: Windows Internet Explorer 10.0.9200.16635

    SC: Security Center Service [Enabled]
    WU: Windows Update Service [Enabled]
    AV: Avira Desktop [(!) Disabled | Updated]
    FW: Windows FireWall Service [Enabled]

    C:\ (%systemdrive%) -> Disque fixe # 455 Go (253 Go libre(s) - 56%) [] # NTFS
    F:\ -> CD-ROM
    G:\ -> Disque amovible # 4 Go (499 Mo libre(s) - 13%) [PACO USB] # FAT32
    H:\ -> Disque amovible # 2 Go (531 Mo libre(s) - 27%) [] # FAT

    ################## | Processus Actif |

    C:\Windows\system32\csrss.exe (492)
    C:\Windows\system32\wininit.exe (560)
    C:\Windows\system32\csrss.exe (584)
    C:\Windows\system32\services.exe (624)
    C:\Windows\system32\winlogon.exe (656)
    C:\Windows\system32\lsass.exe (668)
    C:\Windows\system32\lsm.exe (676)
    C:\Windows\system32\svchost.exe (804)
    C:\Windows\system32\svchost.exe (892)
    C:\Windows\system32\atiesrxx.exe (956)
    C:\Windows\System32\svchost.exe (1016)
    C:\Windows\System32\svchost.exe (332)
    C:\Windows\system32\svchost.exe (484)
    C:\Windows\system32\svchost.exe (616)
    C:\Windows\system32\svchost.exe (1056)
    C:\Windows\system32\atieclxx.exe (1184)
    C:\Program Files (x86)\Online Armor\OAcat.exe (1260)
    C:\Windows\System32\spoolsv.exe (1380)
    C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (1420)
    C:\Windows\system32\svchost.exe (1440)
    C:\Windows\System32\svchost.exe (1520)
    C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (1600)
    C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (1652)
    C:\Windows\system32\taskhost.exe (1688)
    C:\Windows\system32\Dwm.exe (1864)
    C:\Windows\system32\taskeng.exe (1912)
    C:\Program Files\Sony\VAIO Power Management\SPMgr.exe (1992)
    C:\Windows\Explorer.EXE (1272)
    C:\Program Files\Sony\VAIO Gate\VAIO Gate.exe (2076)
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (2104)
    C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (2192)
    C:\Program Files (x86)\SONY\Marketing Tools\MarketingTools.exe (2212)
    C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (2236)
    C:\Program Files\Sony\VAIO Update\VAIOUpdt.exe (2260)
    C:\Program Files\Sony\VAIO Care\VCSystemTray.exe (2268)
    C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (2632)
    C:\Program Files (x86)\SONY\ISB Utility\ISBMgr.exe (2652)
    C:\Program Files (x86)\SONY\PMB\PMBVolumeWatcher.exe (2696)
    C:\Program Files (x86)\SONY\Marketing Tools\MarketingTools.exe (2704)
    C:\Program Files (x86)\iTunes\iTunesHelper.exe (2896)
    C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (2908)
    C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (2916)
    C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (3060)
    C:\Program Files\Bonjour\mDNSResponder.exe (1616)
    C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (876)
    C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (2152)
    C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (1716)
    C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (2628)
    C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (2320)
    C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (504)
    C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe (1768)
    C:\Windows\system32\svchost.exe (3080)
    C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe (3128)
    C:\Program Files (x86)\SONY\VAIO Event Service\VESMgr.exe (3156)
    C:\Program Files\Sony\VAIO Smart Network\VSNService.exe (3184)
    C:\Program Files\Sony\VAIO Smart Network\VSNClient.exe (3240)
    C:\Windows\SysWOW64\DllHost.exe (3300)
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (3340)
    C:\Program Files (x86)\SONY\VAIO Event Service\VESMgrSub.exe (3404)
    C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (3532)
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (3676)
    C:\Windows\system32\wbem\wmiprvse.exe (3716)
    C:\Windows\SysWOW64\DllHost.exe (3784)
    C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (4092)
    C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE (1964)
    C:\Program Files\iPod\bin\iPodService.exe (1124)
    C:\Program Files\Sony\VAIO Update\VUAgent.exe (3912)
    C:\Windows\system32\svchost.exe (4164)
    C:\Program Files\Sony\VAIO Power Management\SPMService.exe (4212)
    C:\Windows\system32\svchost.exe (4324)
    C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe (4384)
    C:\Windows\system32\svchost.exe (4444)
    C:\Program Files (x86)\Mozilla Firefox\firefox.exe (4912)
    C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe (4932)
    C:\Program Files\Windows Media Player\wmpnetwk.exe (4968)
    C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe (4580)
    C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe (2648)
    C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe (3976)
    C:\Program Files (x86)\Windows Live\Mail\wlmail.exe (1548)
    C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe (3956)
    C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (4120)
    C:\Program Files\Sony\VAIO Care\VCPerfService.exe (5312)
    C:\Program Files\Sony\VAIO Care\listener.exe (5420)
    C:\Windows\servicing\TrustedInstaller.exe (5488)
    C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (5604)
    C:\Windows\system32\wbem\wmiprvse.exe (5712)
    C:\UsbFix\Go.exe (2828)

    ################## | El Desaparecido Section |

    HKLM\SOFTWARE | Run : [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
    HKLM\SOFTWARE | Run : [ISBMgr.exe] - "C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe"
    HKLM\SOFTWARE | Run : [PMBVolumeWatcher] - C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe
    HKLM\SOFTWARE | Run : [MarketingTools] - C:\Program Files (x86)\Sony\Marketing Tools\MarketingTools.exe
    HKLM\SOFTWARE | Run : [AppleSyncNotifier] - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
    HKLM\SOFTWARE | Run : [APSDaemon] - "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
    HKLM\SOFTWARE | Run : [StartCCC] - "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
    HKLM\SOFTWARE | Run : [Adobe ARM] - "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    HKLM\SOFTWARE | Run : [CanonSolutionMenuEx] - C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE /logon
    HKLM\SOFTWARE | Run : [iTunesHelper] - "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
    HKLM\SOFTWARE | Run : [SunJavaUpdateSched] - "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
    HKLM\SOFTWARE | Run : [avgnt] - "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
    HKLM\SOFTWARE\wow6432Node | Run : [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
    HKLM\SOFTWARE\wow6432Node | Run : [ISBMgr.exe] - "C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe"
    HKLM\SOFTWARE\wow6432Node | Run : [PMBVolumeWatcher] - C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe
    HKLM\SOFTWARE\wow6432Node | Run : [MarketingTools] - C:\Program Files (x86)\Sony\Marketing Tools\MarketingTools.exe
    HKLM\SOFTWARE\wow6432Node | Run : [AppleSyncNotifier] - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
    HKLM\SOFTWARE\wow6432Node | Run : [APSDaemon] - "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
    HKLM\SOFTWARE\wow6432Node | Run : [StartCCC] - "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
    HKLM\SOFTWARE\wow6432Node | Run : [Adobe ARM] - "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    HKLM\SOFTWARE\wow6432Node | Run : [CanonSolutionMenuEx] - C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE /logon
    HKLM\SOFTWARE\wow6432Node | Run : [iTunesHelper] - "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
    HKLM\SOFTWARE\wow6432Node | Run : [SunJavaUpdateSched] - "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
    HKLM\SOFTWARE\wow6432Node | Run : [avgnt] - "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
    HKLM\SOFTWARE | RunOnce : [] -
    HKLM\SOFTWARE\wow6432Node | RunOnce : [] -
    HKU\S-1-5-19\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
    HKU\S-1-5-20\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
    HKU\S-1-5-21-914421951-3980233579-2647426404-1000\SOFTWARE | Run : [MobileDocuments] - C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe
    HKU\S-1-5-19\SOFTWARE | RunOnce : [mctadmin] - C:\Windows\System32\mctadmin.exe
    HKU\S-1-5-20\SOFTWARE | RunOnce : [mctadmin] - C:\Windows\System32\mctadmin.exe

    ################## | Éléments infectieux |

    ################## | Registre |

    Présent! HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System|DisableTaskMgr

    ################## | Mountpoints2 |

    ################## | Vaccin |

    C:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)

    ################## | E.O.F | https://www.sosvirus.net/ |
    0
  10. Moon3003 Messages postés 19 Statut Membre
     
    DELFIX

    # DelFix v10.4 - Rapport créé le 19/08/2013 à 11:30:23
    # Mis à jour le 19/07/2013 par Xplode
    # Nom d'utilisateur : Moon - MOON-VAIO
    # Système d'exploitation : Windows 7 Home Premium Service Pack 1 (64 bits)

    ~ Activation de l'UAC ... OK

    ~ Suppression des outils de désinfection ...

    Supprimé : C:\USBFix
    Supprimé : C:\ZHP
    Supprimé : C:\Program Files (x86)\ZHPDiag
    Supprimé : C:\PhysicalDisk0_MBR.bin
    Supprimé : C:\UsbFix [Scan 1] MOON-VAIO.txt
    Supprimé : C:\UsbFix [Scan 2] MOON-VAIO.txt
    Supprimé : C:\Users\Moon\Desktop\JRT.txt
    Supprimé : C:\Users\Moon\Desktop\ZHPDiag.txt
    Supprimé : C:\Users\Moon\Desktop\ZHPFixReport.txt
    Supprimé : C:\Users\Public\Desktop\MBRCheck.lnk
    Supprimé : C:\Users\Public\Desktop\ZHPDiag.lnk
    Supprimé : C:\Users\Public\Desktop\ZHPFix.lnk
    Supprimé : C:\Users\Moon\Downloads\adwcleaner.exe
    Supprimé : C:\Users\Moon\Downloads\JRT.exe
    Supprimé : C:\Users\Moon\Downloads\UsbFix.exe
    Supprimé : C:\Users\Moon\Downloads\ZHPDiag2.exe
    Supprimée : HKCU\Software\USBFix
    Supprimée : HKLM\SOFTWARE\AdwCleaner
    Supprimée : HKLM\SOFTWARE\g3n-h@ckm@n
    Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\USBFix
    Supprimée : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ZHPDiag_is1

    ########## - EOF - ##########
    0
  11. 2011N2 Messages postés 13379 Date d'inscription   Statut Contributeur sécurité Dernière intervention   920
     
    Re,

    Non rien de spécial avec USBfix, et c'est bon pour Delfix. ;)

    Gabriel.
    0
  12. moon3003
     
    J'ai presque fini, la vérif a été longue. J'ai une question à laquelle tu peux peut etre répondre : j'ai un problème avec ma web cam intégrée, elle n'est plus reconnue par le pc est-ce que tu sais ce que je peux faire, je l'ai désintallée, j'ai essayer plein de trucs mais impossible de la faire fonctionner.

    Voila Security CHeck

    Results of screen317's Security Check version 0.99.72
    Windows 7 Service Pack 1 x64 (UAC is enabled)
    Internet Explorer 10
    [b][u]''''''''''''''Antivirus/Firewall Check:''''''''''''''[/b][/u]
    Avira Desktop
    Antivirus up to date!
    [b][u]'''''''''Anti-malware/Other Utilities Check:'''''''''[/b][/u]
    Malwarebytes Anti-Malware version 1.75.0.1300
    Java(TM) 6 Update 33
    Java 7 Update 25
    Adobe Flash Player 11.8.800.94
    Adobe Reader XI
    Mozilla Firefox (23.0.1)
    [b][u]''''''''Process Check: objlist.exe by Laurent''''''''[/b][/u]
    Malwarebytes Anti-Malware mbamservice.exe
    Malwarebytes Anti-Malware mbamgui.exe
    Avira Antivir avgnt.exe
    Avira Antivir avguard.exe
    Tall Emu Online Armor OAcat.exe
    Malwarebytes' Anti-Malware mbamscheduler.exe
    [b][u]'''''''''''''''''System Health check'''''''''''''''''[/b][/u]
    Total Fragmentation on Drive C: =
    [b][u]''''''''''''''''''''End of Log''''''''''''''''''''''[/b][/u]
    0
  • 1
  • 2