Problème Avast et Spybot

Fermé
Ghis76 Messages postés 21 Date d'inscription mercredi 18 avril 2007 Statut Membre Dernière intervention 23 avril 2007 - 18 avril 2007 à 10:49
 Utilisateur anonyme - 24 avril 2007 à 19:16
Bonjour,
J'ai un gros problème et je ne sais comment le résoudre, Svp, si
vous pouviez m'aider.
J'ai voulu installé le logiciel Avast, au début il a fonctioné quelques
heures et comme il n'était pas sur toutes les sessions de l'ordi, nous avons essayé de le mettre en partager et depuis plus rien impossible de le faire fonctionner même en le réinstallant, j'ai constater que mon logiciel Spybot est également vide, alors qu'il fonctionnait correctement. Même si je le réinstalle il reste vide.
Actuellement mon ordi n'a plus d'anti virus.
J'ai windows Xp2, et j'ai utilisé le logiciel Hijackthis, je ne sais pas si cela vous sera utile, mais voici le rapport
You can reference this log by going to: http://hjt.networktechs.com/parse.php?log=323566
--------------------------------------------------------------------------------
Logfile of HijackThis v1.99.1Up To Date Version of HijackThis
You are using the latest version of HijackThis. Check www.merijn.org frequently for updates.
Scan saved at 09:42:19, on 18/04/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exeSmss.exe
What is it?
Session Manager SubSystem - smss.exe

What does it do?
smss.exe - This is the session manager subsystem, which is responsible for starting the user session. This process is initiated by the system thread and is responsible for various activities, including launching the Winlogon and Win32 (Csrss.exe) processes and setting system variables. After it has launched these processes, it waits for either Winlogon or Csrss to end. If this happens "normally," the system shuts down; if it happens unexpectedly, Smss.exe causes the system to stop responding (hang).

Additional Reading:
Smss.exe does not resolve forward references in environment

You will not be able to end this through task manager!

More info


--------------------------------------------------------------------------------

Virus Precaution:

The smss.exe which is from Microsoft is located at c:windowsSystem32smss.exe . We've been able to find several viruses that run as smss to trick you.

Adware.Advision - Symantec Corporation
Adware.DreamAd - Symantec Corporation
Backdoor.IRC.Aladinz.O - Symantec Corporation
Backdoor.IRC.Flood.F - Symantec Corporation
W32.Dalbug.Worm - Symantec Corporation
W32.Resdoc - Symantec Corporation
C:\WINDOWS\system32\winlogon.exeWinlogon.exe

What is it?
Windows Logon Process - Winlogon.exe

What does it do?
Direct Quote from here:
This is the process responsible for managing user logon and logoff. Moreover, Winlogon is active only when the user presses CTRL+ALT+DEL, at which point it shows the security dialog box.

Search MS for more info: Link

Virus Precaution:
The original Winlogon.exe from Microsoft gets placed in the C:WINDOWSSystem32 directory. if you find it anywhere else then you should be suspicious for sure.

You'll want to keep an eye on this google search for any known viruses. We've been able to find only 1 report of a virus so far.

Troj/Madr-B @ Sophos
Netsky.D @ Trend Micro
C:\WINDOWS\system32\services.exeservices.exe
services.exe is a part of Windows that manages the processes. Anytime a service starts or stops it is through services.exe. During system startup and shutdown is when this process sees most of its action. You should never end this process unless it is running outside of your windows system folder.

C:\WINDOWS\system32\lsass.exelsass.exe
What is it?
Local Security Authentication Server - lsass.exe

What does it do?
lsass.exe - It generates the process responsible for authenticating users for the Winlogon service. This process is performed by using authentication packages such as the default Msgina.dll. If authentication is successful, Lsass generates the user's access token, which is used to launch the initial shell. Other processes that the user initiates inherit this token.

You will not be able to end this through task manager!

From MS


--------------------------------------------------------------------------------

The lsass.exe which is from Microsoft is located at c:windowsSystem32lsass.exe . there's a few viruses that have been found to run as lsass.exe to hide from you.
C:\WINDOWS\system32\svchost.exeSvchost.exe

What is it?
Service Host Process - svchost.exe

What does it do?

Here's a direct quote from MS about this: (source)
Svchost.exe is a generic host process name for services that are run from dynamic-link libraries (DLLs). The Svchost.exe file is located in the %SystemRoot%System32 folder. At startup, Svchost.exe checks the services portion of the registry to construct a list of services that it needs to load. There can be multiple instances of Svchost.exe running at the same time. Each Svchost.exe session can contain a grouping of services, so that separate services can be run depending on how and where Svchost.exe is started. This allows for better control and debugging.

Svchost.exe groups are identified in the following registry key:

HKEY_LOCAL_MACHINESoftwareMicrosoftWindows NTCurrentVersionSvchost

Each value under this key represents a separate Svchost group and is displayed as a separate instance when you are viewing active processes. Each value is a REG_MULTI_SZ value and contains the services that run under that Svchost group. Each Svchost group can contain one or more service_names extracted from the following registry key, whose Parameters key contains a ServiceDLL value:

HKEY_LOCAL_MACHINESystemCurrentControlSetServicesService

If you're running Windows XP Home edition then you'll have to download this file HERE and put it in your windows/system32 directory. If you're running XP Pro then you won't need that file since you already have it.

1.) Start --> Run --> cmd
2.) Tasklist /svc >C:ianaginfo.txt

Here's an example of what I got when I issued this command if you'd like to take a look at an example.

A Description of Svchost.exe in Windows XP:
https://support.microsoft.com/en-us/windows?ui=en-US&rs=en-001&ad=US

More Info
More Info

Virus Precaution:
The original file from Microsoft gets placed in the Located in C:WINDOWSSystem32 directory. If you find it anywhere else then you should be suspicious for sure.

You'll want to keep an eye on this google search for any known viruses.

C:\WINDOWS\System32\svchost.exeSvchost.exe

What is it?
Service Host Process - svchost.exe

What does it do?

Here's a direct quote from MS about this: (source)
Svchost.exe is a generic host process name for services that are run from dynamic-link libraries (DLLs). The Svchost.exe file is located in the %SystemRoot%System32 folder. At startup, Svchost.exe checks the services portion of the registry to construct a list of services that it needs to load. There can be multiple instances of Svchost.exe running at the same time. Each Svchost.exe session can contain a grouping of services, so that separate services can be run depending on how and where Svchost.exe is started. This allows for better control and debugging.

Svchost.exe groups are identified in the following registry key:

HKEY_LOCAL_MACHINESoftwareMicrosoftWindows NTCurrentVersionSvchost

Each value under this key represents a separate Svchost group and is displayed as a separate instance when you are viewing active processes. Each value is a REG_MULTI_SZ value and contains the services that run under that Svchost group. Each Svchost group can contain one or more service_names extracted from the following registry key, whose Parameters key contains a ServiceDLL value:

HKEY_LOCAL_MACHINESystemCurrentControlSetServicesService

If you're running Windows XP Home edition then you'll have to download this file HERE and put it in your windows/system32 directory. If you're running XP Pro then you won't need that file since you already have it.

1.) Start --> Run --> cmd
2.) Tasklist /svc >C:ianaginfo.txt

Here's an example of what I got when I issued this command if you'd like to take a look at an example.

A Description of Svchost.exe in Windows XP:
https://support.microsoft.com/en-us/windows?ui=en-US&rs=en-001&ad=US

More Info
More Info

Virus Precaution:
The original file from Microsoft gets placed in the Located in C:WINDOWSSystem32 directory. If you find it anywhere else then you should be suspicious for sure.

You'll want to keep an eye on this google search for any known viruses.

C:\WINDOWS\system32\svchost.exeSvchost.exe

What is it?
Service Host Process - svchost.exe

What does it do?

Here's a direct quote from MS about this: (source)
Svchost.exe is a generic host process name for services that are run from dynamic-link libraries (DLLs). The Svchost.exe file is located in the %SystemRoot%System32 folder. At startup, Svchost.exe checks the services portion of the registry to construct a list of services that it needs to load. There can be multiple instances of Svchost.exe running at the same time. Each Svchost.exe session can contain a grouping of services, so that separate services can be run depending on how and where Svchost.exe is started. This allows for better control and debugging.

Svchost.exe groups are identified in the following registry key:

HKEY_LOCAL_MACHINESoftwareMicrosoftWindows NTCurrentVersionSvchost

Each value under this key represents a separate Svchost group and is displayed as a separate instance when you are viewing active processes. Each value is a REG_MULTI_SZ value and contains the services that run under that Svchost group. Each Svchost group can contain one or more service_names extracted from the following registry key, whose Parameters key contains a ServiceDLL value:

HKEY_LOCAL_MACHINESystemCurrentControlSetServicesService

If you're running Windows XP Home edition then you'll have to download this file HERE and put it in your windows/system32 directory. If you're running XP Pro then you won't need that file since you already have it.

1.) Start --> Run --> cmd
2.) Tasklist /svc >C:ianaginfo.txt

Here's an example of what I got when I issued this command if you'd like to take a look at an example.

A Description of Svchost.exe in Windows XP:
https://support.microsoft.com/en-us/windows?ui=en-US&rs=en-001&ad=US

More Info
More Info

Virus Precaution:
The original file from Microsoft gets placed in the Located in C:WINDOWSSystem32 directory. If you find it anywhere else then you should be suspicious for sure.

You'll want to keep an eye on this google search for any known viruses.

C:\WINDOWS\system32\spoolsv.exeSpoolsv.exe

What is it?
SPOOLer SerVice - spoolsv.exe

What does it do?
spoolsv.exe - The spooler service is responsible for managing spooled print/fax jobs

You will be able to end this through task manager!

More info


--------------------------------------------------------------------------------

Virus Precaution:
The spoolsv.exe which is from Microsoft is located at c:windowsSystem32spoolsv.exe . We've been able to find several viruses that run as spoolsv to trick you.

Backdoor.Ciadoor.B - Symantec Corporation
Hacktool.Privshell - Symantec Corporation
VBS.Masscal.Worm (vbs) - Symantec Corporation
Graybird-A @ Sophos

C:\Program Files\Executive Software\DiskeeperLite\DKService.exeDkService.exe
DkService.exe is Executive Software's diskeeper. It is the best hard drive disk defragmentation program I've found. In NT based OS's this file will be run as a service and is used for a users sheduled disk defragmentation. It is good to have your drive scheduled to defrag at least once a week at a time when you know you'll be in bed.
C:\WINDOWS\System32\FTRTSVC.exeFTRTSVC.exe
We Don't know! Please post a comment with information about this file
C:\WINDOWS\System32\svchost.exeSvchost.exe

What is it?
Service Host Process - svchost.exe

What does it do?

Here's a direct quote from MS about this: (source)
Svchost.exe is a generic host process name for services that are run from dynamic-link libraries (DLLs). The Svchost.exe file is located in the %SystemRoot%System32 folder. At startup, Svchost.exe checks the services portion of the registry to construct a list of services that it needs to load. There can be multiple instances of Svchost.exe running at the same time. Each Svchost.exe session can contain a grouping of services, so that separate services can be run depending on how and where Svchost.exe is started. This allows for better control and debugging.

Svchost.exe groups are identified in the following registry key:

HKEY_LOCAL_MACHINESoftwareMicrosoftWindows NTCurrentVersionSvchost

Each value under this key represents a separate Svchost group and is displayed as a separate instance when you are viewing active processes. Each value is a REG_MULTI_SZ value and contains the services that run under that Svchost group. Each Svchost group can contain one or more service_names extracted from the following registry key, whose Parameters key contains a ServiceDLL value:

HKEY_LOCAL_MACHINESystemCurrentControlSetServicesService

If you're running Windows XP Home edition then you'll have to download this file HERE and put it in your windows/system32 directory. If you're running XP Pro then you won't need that file since you already have it.

1.) Start --> Run --> cmd
2.) Tasklist /svc >C:ianaginfo.txt

Here's an example of what I got when I issued this command if you'd like to take a look at an example.

A Description of Svchost.exe in Windows XP:
https://support.microsoft.com/en-us/windows?ui=en-US&rs=en-001&ad=US

More Info
More Info

Virus Precaution:
The original file from Microsoft gets placed in the Located in C:WINDOWSSystem32 directory. If you find it anywhere else then you should be suspicious for sure.

You'll want to keep an eye on this google search for any known viruses.

C:\WINDOWS\system32\nvsvc32.exenvsvc32.exe
What is it?
NVIDIA Driver Helper Service - nvsvc32.exe

What does it do?
nvsvc32.exe - For all of you that have video cards that utilize one of the Nvidia chipsets running under Windows NT4/2k/XP/2k3 they install a driver help service. We have emailed Nvidia asking them about this but haven't been able to get a response. I was able to to end this task without any issues.

There have been a number of reports that say this service is the root of some nasty shutdown slowdowns! Even though I haven't experienced this personally, Black Viper is a source that I trust and he has stated this service has caused extreme slowdowns during shutdown.

There's been a number of rumors posted that state that this is some form of spyware. I have not found it to transmit any form of data while I've been using it. I also don't believe Nvidia is stupid enough to package spyware and send it to their massive installation base.

You'll want to visit nvidia.com for more information about them and their products. You may also want to download the latest drivers from them.

Virus Precaution:
nvsvc32.exe is located at c:windowsSystem32 vsvc32.exe . We've been unable to find any threats that run as nvsvc32.exe to trick you.

C:\WINDOWS\system32\svchost.exeSvchost.exe

What is it?
Service Host Process - svchost.exe

What does it do?

Here's a direct quote from MS about this: (source)
Svchost.exe is a generic host process name for services that are run from dynamic-link libraries (DLLs). The Svchost.exe file is located in the %SystemRoot%System32 folder. At startup, Svchost.exe checks the services portion of the registry to construct a list of services that it needs to load. There can be multiple instances of Svchost.exe running at the same time. Each Svchost.exe session can contain a grouping of services, so that separate services can be run depending on how and where Svchost.exe is started. This allows for better control and debugging.

Svchost.exe groups are identified in the following registry key:

HKEY_LOCAL_MACHINESoftwareMicrosoftWindows NTCurrentVersionSvchost

Each value under this key represents a separate Svchost group and is displayed as a separate instance when you are viewing active processes. Each value is a REG_MULTI_SZ value and contains the services that run under that Svchost group. Each Svchost group can contain one or more service_names extracted from the following registry key, whose Parameters key contains a ServiceDLL value:

HKEY_LOCAL_MACHINESystemCurrentControlSetServicesService

If you're running Windows XP Home edition then you'll have to download this file HERE and put it in your windows/system32 directory. If you're running XP Pro then you won't need that file since you already have it.

1.) Start --> Run --> cmd
2.) Tasklist /svc >C:ianaginfo.txt

Here's an example of what I got when I issued this command if you'd like to take a look at an example.

A Description of Svchost.exe in Windows XP:
https://support.microsoft.com/en-us/windows?ui=en-US&rs=en-001&ad=US

More Info
More Info

Virus Precaution:
The original file from Microsoft gets placed in the Located in C:WINDOWSSystem32 directory. If you find it anywhere else then you should be suspicious for sure.

You'll want to keep an eye on this google search for any known viruses.

C:\WINDOWS\Explorer.EXEexplorer.exe

What is it?
Windows Explorer - explorer.exe


What does it do?
explorer.exe - Below is a direct quote from Microsoft found on THIS page:

This is the user shell, which we see as the familiar taskbar, desktop, and so on. This process isn't as vital to the running of Windows as you might expect, and can be stopped (and restarted) from Task Manager, usually with no negative side effects on the system.

I have found that stopping this process is needed sometimes to stop some other processes.

More Info
More Info

Virus Precaution:
The original file from Microsoft gets placed at C:WINDOWSSystem32explorer.exe . if you find it anywhere else then you should be suspicious for sure.

You'll want to keep an eye on this google search for any known viruses. There's only one unique virus found through this search. All of the results are the various names of this single virus.

Deloder-A @ Sophos
MyDoom.B @ Symantec

C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exeWkUFind.exe
WkUFind.exe is related to Microsoft Works/PictureIt! and will check for software updates. It is safe to remove this from your system startup.
C:\WINDOWS\system32\rundll32.exerundll32.exe

What is it?
Run a DLL as an App - rundll32.exe


What does it do?
Direct Quote from MS: (Source)
Microsoft Windows 95, Windows 98, and Windows Millennium Edition (Me) contains two command-line utility programs named Rundll.exe and Rundll32.exe that allow you to invoke a function exported from a DLL, either 16-bit or 32-bit. However, Rundll and Rundll32 programs do not allow you to call any exported function from any DLL. For example, you can not use these utility programs to call the Win32 API (Application Programming Interface) calls exported from the system DLLs. The programs only allow you to call functions from a DLL that are explicitly written to be called by them. This article provides more details on the use of Rundll and Rundll32 programs under the Windows operating systems listed above.

More Info
More Info

Virus Precaution:
The original file from Microsoft gets placed in the Located at C:WINDOWSSystem32 undll32.exe . If you find it anywhere else then you should be suspicious for sure.

You'll want to keep an eye on this google search for any known viruses.

.


W32.Miroot.Worm @ Symantec
Backdoor.Lastdoor @ Symantec
Trojan.StartPage @ Symantec

C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exehpztsb10.exe

What is it?

hpztsb10.exe is?associated with HP printer products software and drivers.

What does it do?

HP spool service application for Windows 32 bit environments on X86 platforms "PC's"

More info:

www.hp.com

C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exePrintScreen.exe
"Gadwin PrintScreen - utility to capture
C:\Program Files\Copernic Desktop Search 2\DesktopSearchService.exeUnknown Item
Sorry. We are not sure what this item is. If you would like, you can click on it to request additional information about it.
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exeRoboTaskBarIcon.exe
Roboform - password manager and web form filler. Will work without this startup entry, as the "active" component is an integrated Internet Explorer browser plugin More information can be found here.

Quote:

Save and Remember Online Passwords
Every other site these days forces you to create a UserID and Password combination. RoboForm saves the day by saving the online passwords (AutoSave dialog) and then filling login forms from the saved data (AutoFill dialog).

C:\PROGRA~1\Wanadoo\EspaceWanadoo.exeEspaceWanadoo.exe

What is it?

EspaceWanadoo.exe is software associated with an internet provider called Wanadoo.

What does it do?

Wanadoo's software provides connection configuration and other "kit" for their Internet Services.

More info:

Check out this google search for more info about Wanadoo Internet services.

C:\WINDOWS\system32\ctfmon.exectfmon.exe

What is it?
Language bar AKA Alternative User Input Services - ctfmon.exe

What does it do?
ctfmon.exe - it's an ever annoying helper tool that comes rather unexpectedly at times and liked by nearly nobody.

Ctfmon.exe monitors the active windows and provides text input service support for speech recognition, handwriting recognition, keyboard, translation, and other alternative user input technologies.

Loads of information can be found on microsoft's site here.

Unless you're using anything in that list above you'll want to stop this file from loading!

How do I get rid of it?
There's been a number of threads in our forum as well as others about this. A typical thread can be found here.

control panel --> regional and language options --> languages tab --> details button --> language bar button

Virus Precaution:
Just like so many of the other files I've written about so far, ctfmon.exe is located in the c:windowsSystem32ctfmon.exe. At the time of this writing there isn't any spyware, viruses or anything like that masking itself as this file. If you find any info on one then please let me know!
C:\Program Files\Antipub\antipub.exeUnknown Item
Sorry. We are not sure what this item is. If you would like, you can click on it to request additional information about it.
C:\PROGRA~1\Wanadoo\ComComp.exeComComp.exe

Common Components? (ComComp.EXE) is a prerequisite for any VisualTax? program?

It MUST be downloaded and installed once by first time users of any VisualTax product (T1, T2, T3, T4, FP).?There is no need to download again for each product.


C:\PROGRA~1\Wanadoo\Toaster.exeToaster.exe
We Don't know! Please post a comment with information about this file
C:\PROGRA~1\Wanadoo\Inactivity.exeInactivity.exe
We Don't know! Please post a comment with information about this file
C:\PROGRA~1\Wanadoo\PollingModule.exePollingModule.exe
We Don't know! Please post a comment with information about this file
C:\PROGRA~1\Magentic\bin\MgApp.exeUnknown Item
Sorry. We are not sure what this item is. If you would like, you can click on it to request additional information about it.
C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXEALERTM~1.EXE
We Don't know! Please post a comment with information about this file
C:\PROGRA~1\Wanadoo\Watch.exeWatch.exe
Watch.exe - This is a process from Lavasoft for Ad ware this monitors your system and entries for spyware that tries to changeyour system, for Ad ware to work this should not be removed.

C:\HTJ\HijackThis.exeHijackThis.exe
This is our favorite application for fighting against malware and other trashy application that bog systems down. Our guide to using this software can be found here. We have also taken the time to write a system to process the log files created from this application here.
C:\Program Files\Executive Software\DiskeeperLite\DfrgNTFS.exedfrgntfs.exe
dfrgntfs.exe
--------------------------------------------------------------------------------

What is it?
Windows Defrag - dfrgntfs.exe

What does it do?
This is the process in Windows 2000 and XP that handles the file defragmentation process. This helps to speed up things like opening and reading files which will make it so that your applications run as fast as they can on your system. NEVER end this process, if you do it can cause corruption in whatever file it was processing when you ended it.


R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.orange.fr/portail Start Page
This is where you go when you first open IE. Should be something like google.com or iamnotageek.com if theres a site you don't know here clean this line!
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.microsoft.com/fr-fr/?ref=go Start Page
This is where you go when you first open IE. Should be something like google.com or iamnotageek.com if theres a site you don't know here clean this line!
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.exalead.fr/search/??definition=homepageInternet Start Page
This is where you go when you first open IE. Should be something like google.com or iamnotageek.com if theres a site you don't know here clean this line!
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.microsoft.com/fr-fr/?ref=go Start Page
This is where you go when you first open IE. Should be something like google.com or iamnotageek.com if theres a site you don't know here clean this line!
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.microsoft.com/fr-fr/?ref=go Start Page
This is where you go when you first open IE. Should be something like google.com or iamnotageek.com if theres a site you don't know here clean this line!
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.microsoft.com/fr-fr/?ref=go Start Page
This is where you go when you first open IE. Should be something like google.com or iamnotageek.com if theres a site you don't know here clean this line!
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.microsoft.com/fr-fr/?ref=go Start Page
This is where you go when you first open IE. Should be something like google.com or iamnotageek.com if theres a site you don't know here clean this line!
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =Internet Start Page
This is where you go when you first open IE. Should be something like google.com or iamnotageek.com if theres a site you don't know here clean this line!
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBRInternet&cc=fr&toHttps=1&redig=2F6538E9BD8A42E3A46A123231DB1B43 Start Page
This is where you go when you first open IE. Should be something like google.com or iamnotageek.com if theres a site you don't know here clean this line!
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = WanadooInternet Start Page
This is where you go when you first open IE. Should be something like google.com or iamnotageek.com if theres a site you don't know here clean this line!
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = LiensInternet Start Page
This is where you go when you first open IE. Should be something like google.com or iamnotageek.com if theres a site you don't know here clean this line!
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLLDefault Search Page
When using the search toolbar this is your default search. Should be either yahoo, msn or google cause all others suck
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)File Missing
When a file is missing, you should always have HijackThis fix the item.
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dllAcroIEhelper.ocx AcroIEhelper.dll - Adobe Acrobat reader http://www.adobe.com/products/acrobat/reads
AcroIEhelper.ocx AcroIEhelper.dll - Adobe Acrobat reader https://get2.adobe.com/reader/otherversions/
O2 - BHO: CJava Object - {43F7497C-7687-4DEA-A057-F21BD81BC896} - C:\WINDOWS\System32\msjava32.dllmsjava32.dll - Trojan connecting to/hailing from adult chat sites (camscenter.com sexecam.net) - WAR
msjava32.dll - Trojan connecting to/hailing from adult chat sites (camscenter.com sexecam.net) - WARNING despite all apprearances this is in NO way a Microsoft file!
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll (file missing)File Missing
When a file is missing, you should always have HijackThis fix the item.
O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - C:\Program Files\eoRezo\EoAdv\EoRezobho.dll (file missing)File Missing
When a file is missing, you should always have HijackThis fix the item.
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dllUnnamed BHO
RoboForm.dll - RoboForm https://www.roboform.com/
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dllUnnamed BHO
ssv.dll - Related to Sun_Java_software https://www.java.com/en/download/
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)File Missing
When a file is missing, you should always have HijackThis fix the item.
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dllUnnamed BHO
WindowsLiveLogin.dll - Microsoft Windows_Live https://support.microsoft.com/en-us/windows/windows-essentials-2707b879-5004-4349-c4a4-e5900945f2a9
O2 - BHO: (no name) - {A685D287-785F-9822-002D-7F4A37C2D302} - (no file)File Missing
When a file is missing, you should always have HijackThis fix the item.
O2 - BHO: Barre d'outils MSN Search Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1105\fr-fr\msntb.dllUnnamed BHO
msntb.dll - MSN Toolbar https://www.bing.com/?toHttps=1&redig=C5A5F4D5ECA345F689A948C005FF88A7
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)File Missing
When a file is missing, you should always have HijackThis fix the item.
O3 - Toolbar: Barre d'outils MSN Search - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1105\fr-fr\msntb.dllUnknown Item
Sorry. We are not sure what this item is. If you would like, you can click on it to request additional information about it.
O3 - Toolbar: Sonerie Toolbar - {157B91D9-D643-403b-92FE-FB48DA68D6C4} - (no file)File Missing
When a file is missing, you should always have HijackThis fix the item.
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)File Missing
When a file is missing, you should always have HijackThis fix the item.
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dllUnknown Item
Sorry. We are not sure what this item is. If you would like, you can click on it to request additional information about it.
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exeMicrosoft Works Update Detection
Checks for updates to MS Works
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgentUnknown Item
Sorry. We are not sure what this item is. If you would like, you can click on it to request additional information about it.
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exeHPDJ Taskbar Utility
"(1) Ghostscript device driver for printers understanding Hewlett-Packard's Printer Command Language - see here for more info or (2) Creates 1 or all 3 icons on taskbar. The 1st one has a yellow border around it warning that ink is low on the printer. The 2nd one is HP Device Detection Software and the 3rd one is about a card being inserted into the Hp printer"
O4 - HKLM\..\Run: [ekiofdjhne] c:\windows\system32\ekiofdjhne.exe ekiofdjhneUnknown Item
Sorry. We are not sure what this item is. If you would like, you can click on it to request additional information about it.
O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\GestMaj.exe EspaceWanadoo.exeUnknown Item
Sorry. We are not sure what this item is. If you would like, you can click on it to request additional information about it.
O4 - HKCU\..\Run: [Gadwin PrintScreen 2.6] C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe /nosplashUnknown Item
Sorry. We are not sure what this item is. If you would like, you can click on it to request additional information about it.
O4 - HKCU\..\Run: [Copernic Desktop Search 2] "C:\Program Files\Copernic Desktop Search 2\DesktopSearchService.exe" /trayUnknown Item
Sorry. We are not sure what this item is. If you would like, you can click on it to request additional information about it.
O4 - HKCU\..\Run: [Magentic] C:\PROGRA~1\Magentic\bin\Magentic.exe /cUnknown Item
Sorry. We are not sure what this item is. If you would like, you can click on it to request additional information about it.
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"RoboForm
"Roboform - password manager and web form filler. Will work without this startup entry
O4 - HKCU\..\Run: [Nero PhotoShow Media Manager] C:\PROGRA~1\Nero\NEROPH~1\data\Xtras\mssysmgr.exeUnknown Item
Sorry. We are not sure what this item is. If you would like, you can click on it to request additional information about it.
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exeCtfmon.exe
"CoolWebSearch Ctfmon32 parasite variant"
O4 - Startup: Anti-Pub.lnk = C:\Program Files\Antipub\antipub.exe

O8 - Extra context menu item: &MSN Search - res://C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1105\fr-fr\msntb.dll/search.htmInternet Right Click Menu
Most of the time this is garbage leave it only if you actually use this function. Otherwise for the sake of cleanliness get rid of this sucker. A wise man once said Cleanliness is next to godliness
O8 - Extra context menu item: &Recherche AOL Toolbar - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTMLInternet Right Click Menu
Most of the time this is garbage leave it only if you actually use this function. Otherwise for the sake of cleanliness get rid of this sucker. A wise man once said Cleanliness is next to godliness
O8 - Extra context menu item: Barre RoboForm - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.htmlInternet Right Click Menu
Most of the time this is garbage leave it only if you actually use this function. Otherwise for the sake of cleanliness get rid of this sucker. A wise man once said Cleanliness is next to godliness
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000Internet Right Click Menu
Most of the time this is garbage leave it only if you actually use this function. Otherwise for the sake of cleanliness get rid of this sucker. A wise man once said Cleanliness is next to godliness
O8 - Extra context menu item: Enregistrer le formulaire - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.htmlInternet Right Click Menu
Most of the time this is garbage leave it only if you actually use this function. Otherwise for the sake of cleanliness get rid of this sucker. A wise man once said Cleanliness is next to godliness
O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0000.1105\fr-fr\msntabres.dll/229?f2323b672d014723b8a2a74b390ef92Internet Right Click Menu
Most of the time this is garbage leave it only if you actually use this function. Otherwise for the sake of cleanliness get rid of this sucker. A wise man once said Cleanliness is next to godliness
O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0000.1105\fr-fr\msntabres.dll/230?f2323b672d014723b8a2a74b390ef92Internet Right Click Menu
Most of the time this is garbage leave it only if you actually use this function. Otherwise for the sake of cleanliness get rid of this sucker. A wise man once said Cleanliness is next to godliness
O8 - Extra context menu item: Personnaliser le menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.htmlInternet Right Click Menu
Most of the time this is garbage leave it only if you actually use this function. Otherwise for the sake of cleanliness get rid of this sucker. A wise man once said Cleanliness is next to godliness
O8 - Extra context menu item: Remplir le formulaire - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.htmlInternet Right Click Menu
Most of the time this is garbage leave it only if you actually use this function. Otherwise for the sake of cleanliness get rid of this sucker. A wise man once said Cleanliness is next to godliness
O8 - Extra context menu item: Voir les cookies - C:\WINDOWS\web\showcookies.htmInternet Right Click Menu
Most of the time this is garbage leave it only if you actually use this function. Otherwise for the sake of cleanliness get rid of this sucker. A wise man once said Cleanliness is next to godliness
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dllSun Java Console
Related to Sun Java
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dllSun Java Console
Related to Sun Java
O9 - Extra button: Remplir - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.htmlCompila
Related to Roboform Note: File is located under C:ProgrammiSiber SystemsAI RoboForm
O9 - Extra 'Tools' menuitem: Remplir le formulaire - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.htmlCompila
Related to Roboform Note: File is located under C:ProgrammiSiber SystemsAI RoboForm
O9 - Extra button: Enregistrer - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.htmlSave Forms
Related to Roboform Password Manager and Web Form Filler that completely automates password entering and form filling. Note: file is found under C:Program FilesSiber SystemsAI RoboForm folder.
O9 - Extra 'Tools' menuitem: Enregistrer le formulaire - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.htmlSave Forms
Related to Roboform Password Manager and Web Form Filler that completely automates password entering and form filling. Note: file is found under C:Program FilesSiber SystemsAI RoboForm folder.
O9 - Extra button: Barre RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.htmlRoboForm
Related to Roboform Password Manager and Web Form Filler that completely automates password entering and form filling. Note: file is found under C:Program FilesSiber SystemsAI RoboForm folder.
O9 - Extra 'Tools' menuitem: Barre RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.htmlRoboForm
Related to Roboform Password Manager and Web Form Filler that completely automates password entering and form filling. Note: file is found under C:Program FilesSiber SystemsAI RoboForm folder.
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)File Missing
When a file is missing, you should always have HijackThis fix the item.
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)File Missing
When a file is missing, you should always have HijackThis fix the item.
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\WINDOWS\system32\shdocvw.dllYahoo! Messenger
Yahoo Messenger
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\WINDOWS\system32\shdocvw.dllYahoo! Messenger
Yahoo Messenger
O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe (file missing)File Missing
When a file is missing, you should always have HijackThis fix the item.
O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe (file missing)File Missing
When a file is missing, you should always have HijackThis fix the item.
O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)File Missing
When a file is missing, you should always have HijackThis fix the item.
O11 - Options group: [INTERNATIONAL] International*IE Advanced Options
This is rarely modified by programs.
O16 - DPF: PackageHtmlCab - http://acces.blonde.com/package/PackageHtmlCab.CABUnknown Item
Sorry. We are not sure what this item is. If you would like, you can click on it to request additional information about it.
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - https://www.microsoft.com/fr-fr/?ref=go BHO
http://www.microsoft.com/genuine/downloads/WhyValidate.aspx?FamilyID=b446ae53-3759-40cf-80d5-cde4bbe07999&displaylang=en
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - https://onedrive.live.com/ BHO
MsnPUpld.cab - MSN photo upload tool
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/... BHO
http://v5.windowsupdate.microsoft.com/windowsupdate/v6/default.aspx
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
Microsoft Windows Update more here
O16 - DPF: {F4653484-F38C-455F-BB15-1175E527754E} (VideoProducer Class) - http://www.normal.video-party.com/class/webcam2.cabUnknown Item
Sorry. We are not sure what this item is. If you would like, you can click on it to request additional information about it.
O17 - HKLM\System\CCS\Services\Tcpip\..\{2A3AE27A-53CB-459C-A5DB-E0BB58355CEC}: NameServer = 85.255.113.130,85.255.112.113Internet Settings
These may not be bad if your internet connection is set manually
O17 - HKLM\System\CCS\Services\Tcpip\..\{655AB98D-28FB-4721-A02C-7E88AAE5AD4C}: NameServer = 85.255.113.130,85.255.112.113Internet Settings
These may not be bad if your internet connection is set manually
O17 - HKLM\System\CCS\Services\Tcpip\..\{7AC237AB-9C87-439A-B4BC-A28DB452638A}: NameServer = 85.255.113.130,85.255.112.113Internet Settings
These may not be bad if your internet connection is set manually
O17 - HKLM\System\CCS\Services\Tcpip\..\{C1097410-77C7-446D-B7F4-B80DA6E836B6}: NameServer = 85.255.113.130,85.255.112.113Internet Settings
These may not be bad if your internet connection is set manually
O17 - HKLM\System\CCS\Services\Tcpip\..\{C7CA6BE1-BAF3-4A5E-BBCA-7CB22B7C33A3}: NameServer = 85.255.113.130,85.255.112.113Internet Settings
These may not be bad if your internet connection is set manually
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.113.130 85.255.112.113Internet Settings
These may not be bad if your internet connection is set manually
O17 - HKLM\System\CS1\Services\Tcpip\..\{2A3AE27A-53CB-459C-A5DB-E0BB58355CEC}: NameServer = 85.255.113.130,85.255.112.113Internet Settings
These may not be bad if your internet connection is set manually
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.113.130 85.255.112.113Internet Settings
These may not be bad if your internet connection is set manually
O17 - HKLM\System\CS2\Services\Tcpip\..\{2A3AE27A-53CB-459C-A5DB-E0BB58355CEC}: NameServer = 85.255.113.130,85.255.112.113Internet Settings
These may not be bad if your internet connection is set manually
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.113.130 85.255.112.113Internet Settings
These may not be bad if your internet connection is set manually
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLLExtra Protocols
There's a few known hijackers that use this but I haven't found anything good come out of these
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLLExtra Protocols
There's a few known hijackers that use this but I haven't found anything good come out of these
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dllAppInit_DLLs Registry value autorun
Very few known *good* purposes of this. Norton Cleansweep being the headliner of good items
Loads a .dll into memory when a user logs in. Frequently used by VERY bad hijackers.
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dllShellServiceObjectDelayLoad Registry key autorun
HJT automatically weeds out the good ones here so we'll flag this as bad. Consult a HJT expert before cleaning anything.
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\DiskeeperLite\DKService.exeDiskeeper
Executive Software's Diskeeper (Defragmenter)
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exeUnknown Item
Sorry. We are not sure what this item is. If you would like, you can click on it to request additional information about it.
O23 - Service: InCD Helper (InCDsrv) - Unknown owner - C:\Documents and Settings\ghislaine\Mes documents\imagine\InCD\InCDsrv.exe (file missing)File Missing
When a file is missing, you should always have HijackThis fix the item.
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exeNVIDIA Driver Helper Service
Related to NVIDIA drivers.
O23 - Service: Planificateur LiveUpdate automatique - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)File Missing
When a file is missing, you should always have HijackThis fix the item.
Merci de me répondre
A voir également:

41 réponses

Utilisateur anonyme
21 avril 2007 à 17:59
on recommence:
------------------------
fais un scan seul avec Hijackthis
coches ces cases
Ensuites tu fais fixer objets

-------------------------------------------------------
O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - (no file)
O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - (no file)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {A685D287-785F-9822-002D-7F4A37C2D302} - (no file)
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O3 - Toolbar: Sonerie Toolbar - {157B91D9-D643-403b-92FE-FB48DA68D6C4} - (no file)
O3 - Toolbar: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe (file missing)
O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe (file missing)
O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
O16 - DPF: PackageHtmlCab - http://acces.blonde.com/package/PackageHtmlCab.CAB
Inconnu
O16 - DPF: {F4653484-F38C-455F-BB15-1175E527754E} (VideoProducer Class) - http://www.normal.video-party.com/class/webcam2.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{2A3AE27A-53CB-459C-A5DB-E0BB58355CEC}: NameServer = 85.255.113.130,85.255.112.113
O17 - HKLM\System\CCS\Services\Tcpip\..\{655AB98D-28FB-4721-A02C-7E88AAE5AD4C}: NameServer = 85.255.113.130,85.255.112.113
O17 - HKLM\System\CCS\Services\Tcpip\..\{7AC237AB-9C87-439A-B4BC-A28DB452638A}: NameServer = 85.255.113.130,85.255.112.113

O17 - HKLM\System\CCS\Services\Tcpip\..\{C1097410-77C7-446D-B7F4-B80DA6E836B6}: NameServer = 85.255.113.130,85.255.112.113
O17 - HKLM\System\CCS\Services\Tcpip\..\{C7CA6BE1-BAF3-4A5E-BBCA-7CB22B7C33A3}: NameServer = 85.255.113.130,85.255.112.113
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.113.130 85.255.112.113
O17 - HKLM\System\CS1\Services\Tcpip\..\{2A3AE27A-53CB-459C-A5DB-E0BB58355CEC}: NameServer = 85.255.113.130,85.255.112.113
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.113.130 85.255.112.113
O17 - HKLM\System\CS2\Services\Tcpip\..\{2A3AE27A-53CB-459C-A5DB-E0BB58355CEC}: NameServer = 85.255.113.130,85.255.112.113
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.113.130 85.255.112.113

0
Ghis76 Messages postés 21 Date d'inscription mercredi 18 avril 2007 Statut Membre Dernière intervention 23 avril 2007
21 avril 2007 à 18:18
j'avais oublié une croix
c'est fait
0
Ghis76 Messages postés 21 Date d'inscription mercredi 18 avril 2007 Statut Membre Dernière intervention 23 avril 2007
21 avril 2007 à 18:21
voici le log
Logfile of HijackThis v1.99.1
Scan saved at 18:15:57, on 21/04/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Executive Software\DiskeeperLite\DKService.exe
C:\WINDOWS\System32\FTRTSVC.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe
C:\Program Files\Copernic Desktop Search 2\DesktopSearchService.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Antipub\antipub.exe
C:\PROGRA~1\Magentic\bin\MgApp.exe
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\PROGRA~1\Wanadoo\EspaceWanadoo.exe
C:\PROGRA~1\Wanadoo\ComComp.exe
C:\PROGRA~1\Wanadoo\Toaster.exe
C:\PROGRA~1\Wanadoo\Inactivity.exe
C:\PROGRA~1\Wanadoo\PollingModule.exe
C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
C:\PROGRA~1\Wanadoo\Watch.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\linkprd.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Hijackthis Version Française\hijackthis vf.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.orange.fr/portail
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.exalead.fr/search/??definition=homepage
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Barre d'outils MSN Search Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1105\fr-fr\msntb.dll
O3 - Toolbar: Barre d'outils MSN Search - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1105\fr-fr\msntb.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\GestMaj.exe EspaceWanadoo.exe
O4 - HKCU\..\Run: [Gadwin PrintScreen 2.6] C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe /nosplash
O4 - HKCU\..\Run: [Copernic Desktop Search 2] "C:\Program Files\Copernic Desktop Search 2\DesktopSearchService.exe" /tray
O4 - HKCU\..\Run: [Magentic] C:\PROGRA~1\Magentic\bin\Magentic.exe /c
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKCU\..\Run: [Instant Access] C:\WINDOWS\system32\linkprd.exe /res
O4 - Startup: Anti-Pub.lnk = C:\Program Files\Antipub\antipub.exe
O8 - Extra context menu item: &MSN Search - res://C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1105\fr-fr\msntb.dll/search.htm
O8 - Extra context menu item: &Recherche AOL Toolbar - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: Barre RoboForm - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Enregistrer le formulaire - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0000.1105\fr-fr\msntabres.dll/229?f2323b672d014723b8a2a74b390ef92
O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0000.1105\fr-fr\msntabres.dll/230?f2323b672d014723b8a2a74b390ef92
O8 - Extra context menu item: Personnaliser le menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Remplir le formulaire - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: Voir les cookies - C:\WINDOWS\web\showcookies.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Remplir - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Remplir le formulaire - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Enregistrer - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Enregistrer le formulaire - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Barre RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: Barre RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\WINDOWS\system32\shdocvw.dll
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {201B9B37-848F-40BD-90EA-7B8F0AA89D6A} - http://scripts.dlv4.com/binaries/egaccess4/egaccess4_1071_em_XP.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - https://onedrive.live.com/
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
O17 - HKLM\System\CCS\Services\Tcpip\..\{BC808BE1-E16F-4815-A278-75E7169A4AAC}: NameServer = 80.10.246.130 80.10.246.3
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\DiskeeperLite\DKService.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
O23 - Service: InCD Helper (InCDsrv) - Unknown owner - C:\Documents and Settings\ghislaine\Mes documents\imagine\InCD\InCDsrv.exe (file missing)
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Planificateur LiveUpdate automatique - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
0
Utilisateur anonyme
21 avril 2007 à 18:21
ok
fais ceci
reboot ta machine en mode sans échec
https://leblogdeclaude.blogspot.com/2007/04/informatique-rebooter-xp-en-mode-sans.html
relances alors Navipromo
choisis alors l'option deux pas la 1 !

0
Ghis76 Messages postés 21 Date d'inscription mercredi 18 avril 2007 Statut Membre Dernière intervention 23 avril 2007
21 avril 2007 à 18:39
le mode sans echec ne fonctionne pas, et j'ai eu une fenêtre :
windows n'a pas demaré corrctement un nouveau logiciel pu matériel peut-être la cause...
0
Utilisateur anonyme
21 avril 2007 à 18:23
allons-y doucement !
-------------------------------------------------------------------------------
ok
fais ceci
reboot ta machine en mode sans échec
https://leblogdeclaude.blogspot.com/
relances alors Navipromo
choisis alors l'option deux pas la 1 !
0
Ghis76 Messages postés 21 Date d'inscription mercredi 18 avril 2007 Statut Membre Dernière intervention 23 avril 2007
21 avril 2007 à 18:47
je ne peux démarrer en mode sans échec ,est-ce que je fais tout de même Navipromo avec l'option 2
0
Utilisateur anonyme
21 avril 2007 à 18:47
enlèves tous tes trucs usb sauf ta souris
0
Ghis76 Messages postés 21 Date d'inscription mercredi 18 avril 2007 Statut Membre Dernière intervention 23 avril 2007
21 avril 2007 à 18:54
j'ai tout débranché je vais réessayer le mode sans echec
0
Ghis76 Messages postés 21 Date d'inscription mercredi 18 avril 2007 Statut Membre Dernière intervention 23 avril 2007
21 avril 2007 à 19:07
Je ne peux toujours pas démarer en mode sans échec, j'ai tout débranché sauf ma souris, mais depuis que j'ai mon problème avast j'ai téléchargé pas mal de logiciel
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
Utilisateur anonyme
21 avril 2007 à 20:54
Il existe une manip pour forcer le mode sans échec:
fais ceci:
http://service1.symantec.com/support/inter/tsgeninfointl.nsf/fr_docid/20020905112131924
0
AU SECOURS
Gros problème, j'ai fais le mode sans échec de suymantec comme
vous l'avez suggéré et plus rien ne fonctionne. Je reste bloqué sur le BIOS qui tourne en boucle plus rien ne réponds quel que soit le
c
0
sorry ca a coupé, plus rien ne répond quel que soit la facon de
vouloir redémarrer.
Que dois je faire ?
JE PANIQUE SVP répondez moi vite.
Je dial avec vous avec l'ordi portable professionnel de mon mari
mais je ne peux l utliser couramment.
A l'aide !!
0
Utilisateur anonyme
22 avril 2007 à 10:38
je n'avais pas mis cette manip d'office sur ma page, car il m'était arrivé aussi de rester coincé.
"Il existe une autre méthode, avec Msconfig, je ne là préconnise pas du tout, j'en connais qui sont resté "enfermé" en boucle !"

https://leblogdeclaude.blogspot.com/2007/04/informatique-rebooter-xp-en-mode-sans.html

Je ne la conseille que si vraimant le pc refuse le mode sans échec ( ce qui en soit n'est déjà pas normal)
Mais le problème est que tu dois aller en mode sans échec....pour effectuer certaines action de décontamination, et que seul ce mode permet !!!

pas de panique j'examine le soucis, et cherche la solution, tant soit peu qu'elle existe.
-------------------------------------------------------------------
je crois, que tu as été attaqué par un Rootkit:
------------------------------------------------------------------
Ce fichier archive en .ZIP contient un fichier .DLL ainsi qu'un fichier .EXE. Si ce dernier est exécuté, le virus se copie dans le dossier Application Data du profil de l'utilisateur sous les noms hidn.exe et hldrrr.exe, y copie également un rootkit m_hook.sys
-------------------------------------------------------------
ma source:
http://66.102.9.104/search?q=cache:0DRejNpUB7AJ:www.secuser.com/alertes/2006/baglegn.htm+m_hook.sys&hl=fr&ct=clnk&cd=3&gl=fr
-------------------------------------------------------------------
tu as écrit:
< 3 > Ghis76 (mercredi 18 avril 2007 à 11:52:48)

Merci Philo de votre réponse
J'ai téléchargé super antispyware, et pendant le scan
est apparu un écran bleu sur lequel etait écrit:
Sur votre ordinateur le problème semble être causé par le fichier suivant: m_hook.sys pag-fault-in nonpageg-area
puis, l'ordi c'est éteint et rallumé tout seul.

-------------------------------------------------------------------------
je voudrais savoir, si tu sais intercepter le menu de démarrage avec la touche F8 ?
Tapotte f8 au démarrage.
normalement, tu devrais avoir un menu

1.démarrage normal
2.mode sans échec
3.dernière bonne configuration connue
ect...



0
Ghis76 Messages postés 21 Date d'inscription mercredi 18 avril 2007 Statut Membre Dernière intervention 23 avril 2007
22 avril 2007 à 12:10
Bonjour,
J' ai suivi vos conseils en utilisant msconfig pour démarrer car
le mode standard sans échec était inefficace.
Hors maintenant on tourne en boucle, et à chaque fin de boucle
il y a écrit no signal.
Je ne comprends plus rien , voila ce que j'ai fait pour bloquer tout:
demarrer, exécuter, mscondif, ok, cochez SAFEBOOT, ok

Même si je tapote f8 au démarrage, effectivement j'ai un menu mais même si je mets en surbrillance tout revient à la même page.

Effectivement, j'ai surement un virus mais il faut que j'arrive à rallumer l'ordi pour me sortir de là.
au secours! je ne sais plus quoi faire,merci de votre aide
0
Utilisateur anonyme
22 avril 2007 à 12:57
il sagit en fait de reconstruire le fichier boot.ini
on va faire cette manip---->
première question....je dois dire quelle est cruciale pour la suite...
as-tu le cd d'install XP ?
(pour accéder au mode console)
0
Bonsoir,
j'ai un cd de restauration,mais je ne sais pas si dedans il ya xp, je ne l'ai personnellement jamais utilisé.
j'ai eu un problème une fois de carte mère et xp a été réinstallé par un technicien, mon ordinateur a 4 ans et a été acheté avec la version xp, maintenant nous avons xp2
je ne sais pas si sur un cd de restauration, il ya l'installation xp,
merci de votre réponse
0
afideg Messages postés 10517 Date d'inscription lundi 10 octobre 2005 Statut Contributeur sécurité Dernière intervention 12 avril 2022 602
22 avril 2007 à 21:49
EDIT Une erreur s'est glissée dans la rédaction de mon post précédent. En effet, au § 1°-, il y a lieu de lire :

Télécharge FixWareout d'un de ces deux sites sur le bureau:
http://downloads.subratam.org/Fixwareout.exe
http://swandog46.geekstogo.com/Fixwareout.exe

Alors que le lien indiqué se rapporte à Combofix
Excusez-moi.
Merci


Le post précédent devient donc :

Bonjour Ghis76,
Salut Philo,

Je voudrais tenter ceci, s'il vous plaît:

1°- Télécharge FixWareout d'un de ces deux sites sur le bureau:
http://downloads.subratam.org/Fixwareout.exe
http://swandog46.geekstogo.com/Fixwareout.exe


Lance le fix: clique sur "Next", puis "Install",
puis assure-toi que "Run fixit" est activé puis clique sur "Finish".
Le fix va commencer, suis les messages à l'écran.

Il te sera demandé de redémarrer ton ordinateur, fais-le.
Ton système mettra un peu plus de temps au démarrage, c'est normal.

Au final, poste le contenu de "C:\fixwareout\report.txt"


Si et seulement s’il y a des difficultés de connexion après cette manip.
Faire ceci : Démarrer---->Paramètres---->Panneau de configuration---->Connexions réseau
Faire un clic droit sur la connexion par défaut, nommée en général "Connexion au réseau local" ou "Accès à distance" si tu utilises un modem téléphonique, et choisir Propriétés.
Faire un double clic sur l'élément Protocole Internet (TCP/IP) et choisir le bouton-radio « Obtenir les adresses des serveurs DNS automatiquement ».
Clique deux fois sur OK, et redémarre l'ordinateur.




2°- Télécharge ELIBAGLA en bas de cette page (clique sur le bouton "Descargar Elibagla") sur ton bureau. < http://www.zonavirus.com/datos/descargas/95/elibagla.asp >
Lance-le, de préférence en mode sans échec si tu en as la possibilité, en mode normal dans le cas contraire.
Patiente le temps du scan.
Lorsqu'il a terminé, poste le contenu du fichier « infoSat.txt » qui se trouve dans Poste de travail > Disque C:\

( j'espère ainsi retrouver le MSE )



3°- Télécharge Combofix.exe (par sUBs) sur ton Bureau
< http://download.bleepingcomputer.com/sUBs/ComboFix.exe >

Double clique "combofix.exe" et suis les invites.
Lorsque le scan sera complété, un rapport apparaîtra.
Copie/colle ce rapport dans ta prochaine réponse



4°- Pour la suite, tu n’auras pas accès à Internet, ni donc à CCM ; copie [ Soit tu copies/colles le contenu de la procédure dans un fichier texte(-que tu mets sur le bureau-) pour pouvoir le consulter en mode sans échec ] ou imprime donc la procédure suivante pour ne rien oublier .

_ Redémarrer en mode sans échec
:< http://www.coupdepoucepc.com/modules/news/article.php?storyid=253 >

Double clique sur navilog1.bat
Laisse-toi guider. Au menu principal, choisis 2 et valide
Laisse toi guider et réponds aux questions éventuelles
Ton bureau va disparaître, c'est normal.
Patiente jusqu'au message :
*** Nettoyage Terminé le ..... ***
Appuie sur une touche comme demandé, le bloc-notes va s'ouvrir.
Sauvegarde le rapport de manière à le retrouver ( « fichier » > « enregistrer sous » > choisis « bureau » )
Referme le bloc-notes. Ton bureau va réapparaître
Redémarre normalement et copier/coller l'intégralité dans une réponse.
Le rapport est en outre sauvegardé à la racine du disque (cleannavi.txt)

•- Si ton bureau ne réapparaît pas, fais CTRL+ALT+SUPP pour ouvrir le gestionnaire de tâches.
Puis rends-toi à l'onglet "processus". Clique en haut à gauche sur fichiers et choisis "exécuter"
Tape explorer et valide. Cela te fera apparaître ton bureau

•- Puis, clic sur "Démarrer"/"panneau de configuration"/"options internet"
- onglet "Contenu" puis bouton [Certificats...] et si tu trouves ceci, en particulier dans [Éditeurs ... approuvés], (mais regarde ailleurs aussi) : electronic-group, egroup, Montorgueil
VIP, "Sunny Day Design Ltd" ... , tu les supprimes.



SVP
Merci
Al.

0
Utilisateur anonyme
23 avril 2007 à 10:51
salut Adifeg???je ne vois pas ton post précédent, le <42> ???
------------------------------------------------------------------------------
pour le moment nous en sommes à tenter de restaurer le boot.ini
---------------------------------------------------------------------------
tu as dit ( ghis76 )

"j'ai un cd de restauration,mais je ne sais pas si dedans il ya xp, je ne l'ai personnellement jamais utilisé. "

Je pense d'abord à une chose....
dans le menu que tu fais apparaître avec F8,
vois-tu la phrase:
"dernière bonne configuration connue" ?


*****Dans chaque église, il y a toujours quelque chose qui cloche******
Je n'ai pas la prétention de résoudre les problèmes, j'essaie simplement de rendre service ;-)
0
Ghis76 Messages postés 21 Date d'inscription mercredi 18 avril 2007 Statut Membre Dernière intervention 23 avril 2007
23 avril 2007 à 21:13
Bonjour,
Mode sans échec, mode sans échec en réseau, dernière bonne configuration connu, tout les choix possibles de cette page rien ne fonctionne. J'ai le CD d'installation XP FAMILIALE. Quand je le met en route après plusieurs inscriptions qui défilent en bas, un écran bleu apparait ou en encadré il y a d'inscrit:
Le disque 0 de 57240 Mo ayant l' ID 0 du bus 0 sur atapi [ MBR ]

C: Partition1 [ NTFS ] 55239 Mo ( 21686 Mo libres )
F: Partition2 ( Inactif ( Gestionnairee d 2000 Mo ( 574 Mo libres )

Quelle est la marche à suivre ? et si on appuie sur entrée avec Partition1 sélectionné cela correspond t il à un reformatage et allons nous perdre toutes nos données et le virus sera t il supprimé ?

A quoi correspond Partition2 ? es ce une sauvegarde et de quoi ? et si oui comment l' utiliser ?

Merci de toutes vos réponses
0
afideg Messages postés 10517 Date d'inscription lundi 10 octobre 2005 Statut Contributeur sécurité Dernière intervention 12 avril 2022 602
23 avril 2007 à 21:36
Bonsoir Ghis76 et Philo,

Ghis76, as-tu suivi cette méthode < https://forums.cnetfrance.fr > ?

Elle n'est qu'un exemple parmi d'autres.


PS Quand tu clic à répétition sur F8, obtiens-tu le même résultat avec F5 ?
As-tu quelquechose sur F: Partition2 ?

Merci
Al.
0
Utilisateur anonyme
24 avril 2007 à 11:05
Salut adifeg,
je crois que l'on peut effectivement tenter une réparation de xp.
sur :
C: Partition1 [ NTFS ] 55239 Mo ( 21686 Mo libres )

Je ne sais d'ailleurs pas, si cette manip remet à zero le boot.ini?
Sous réserve, évidemment que la restauration réusisse ?
La question que je me pose:
Il y a t'il un lecteur de disquette sur ce PC ?
je pense alors à éditer le boot.ini sous dos sachant qu'il se trouve à la racine du disque, ça ne devrait pas trop poser de soucis pour l'éditer
edit boot.ini
il faudra férifier les attributs du fichier.
attrib boot.ini , pour voir si le fichier est protégé en écriture ?


0
afideg Messages postés 10517 Date d'inscription lundi 10 octobre 2005 Statut Contributeur sécurité Dernière intervention 12 avril 2022 602
24 avril 2007 à 11:20
Bonjour Philo,

Il faudrait parvenir ( dans une première étape ) à remplacer le script du Boot.INI par celui-ci ( avec batch sur disquette - mais je n'ai jamais fait - ) :

Remplacer son contenu par celui-ci:

[boot loader]
timeout=30
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
multi(0)disk(0)partition(2)\WINDOWS="Microsoft Windows XP Professionnel" /fastdetect
multi(0)disk(0)partition(2)\WINDOWS="Mode sans echec" /fastdetect /safeboot:minimal /sos /bootlog

On ne sait même pas recevoir son script actuel, à défaut de pouvoir démarrer en mode normal.

Vérifier aussi s'il ne s'agit pas d'un mauvais contact à sa barrette mémoire RAM.

Al.
0
Utilisateur anonyme
24 avril 2007 à 11:30
ok,
attendons des nouvelles de Ghis76 , pour continuer dans ce sens.
en principe il suffit d'éliminer cette ligne avec la commande EDIT...
"multi(0)disk(0)partition(2)\WINDOWS="Mode sans echec" /fastdetect /safeboot:minimal /sos /bootlog "
0
afideg Messages postés 10517 Date d'inscription lundi 10 octobre 2005 Statut Contributeur sécurité Dernière intervention 12 avril 2022 602
24 avril 2007 à 11:37
Re,

NON, il ne faut pas éliminer la dernière ligne .
C'est la plus importante.

Il faut REMPLACER le contenu actuel du script en BOOT.INI contenu dans le PC, par celui-ci :

[boot loader]
timeout=30
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
multi(0)disk(0)partition(2)\WINDOWS="Microsoft Windows XP Professionnel" /fastdetect
multi(0)disk(0)partition(2)\WINDOWS="Mode sans echec" /fastdetect /safeboot:minimal /sos /bootlog


Dans lequel, la dernière ligne a été ajoutée volontairement.
Cette dernière ligne pouvant devenir :
multi(0)disk(0)partition(2)\WINDOWS="Mode sans echec" /fastdetect /safeboot:minimal /sos
en cas d'échec avec la précédente.

Lire également ceci :< http://www.d2i.ch/pn/az/u.html > UNMOUNTABLE_BOOT_VOLUME --> Partition non active ;
qui ressemble fort à ce que j'avais dit en MP :
« - Démarrage PC > F8 à répétition > choisir "dernière bonne configuration connue". +==> tenter avec F5 et F10 .
- Si échec, idem, mais choisir "démarrer en ligne de commande DOS", et taper CHKDSK /P /R dans la fenêtre DOS , puis [Enter]
( pas besoin du CD )

- Si échec, CD obligé.
»


Al.
0
Utilisateur anonyme
24 avril 2007 à 13:03
Pour moi son Boot.ini, doit être comme ceci (je me fie au mien)
aucune ligne de rajouter:
https://www.hiboox.com
------------------------------
copie de mon Boot.ini
------------------------------------------
[boot loader]
timeout=30
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professionnel" /fastdetect
-------------------------------------------------
tu suggères donc de rajouter une ligne :
multi(0)disk(0)partition(2)\WINDOWS="Mode sans echec" /fastdetect /safeboot:minimal /sos /bootlog
--------------------------------------------
ce qui aurait pour effet d'ajouter le choix au reboot ....?
Pour l'instant, le choix existe bien, mais l'ordi ne boote pas en mode sans échec.
C'est a essayer de toute façon...

0
afideg Messages postés 10517 Date d'inscription lundi 10 octobre 2005 Statut Contributeur sécurité Dernière intervention 12 avril 2022 602
24 avril 2007 à 13:42
Re,
Philo, j'ai proposé plusieurs choses:

1)- - « - Démarrage PC > F8 à répétition > choisir "dernière bonne configuration connue". +==> tenter avec F5 et F10 .
- Si échec, idem, mais choisir "démarrer en ligne de commande DOS", et taper CHKDSK /P /R dans la fenêtre DOS , puis [Enter] ( pas besoin du CD )
- Si échec, CD obligé. »

2)- Il faut REMPLACER le contenu actuel du script en BOOT.INI contenu dans le PC, par celui-ci :

[boot loader]
timeout=30
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
multi(0)disk(0)partition(2)\WINDOWS="Microsoft Windows XP Professionnel" /fastdetect
multi(0)disk(0)partition(2)\WINDOWS="Mode sans echec" /fastdetect /safeboot:minimal /sos /bootlog

Dans lequel, la dernière ligne a été ajoutée volontairement.

NB Philo, sur ton PC tu n'as qu'une partition, d'où : "partition(1)" ; l'internaute a deux partitions, d'où l'on devrait avoir : "partition(2)"

3)- Cette dernière ligne pouvant devenir :
multi(0)disk(0)partition(2)\WINDOWS="Mode sans echec" /fastdetect /safeboot:minimal /sos
en cas d'échec avec la précédente.

4)- Lire également ceci :< http://www.d2i.ch/pn/az/u.html > UNMOUNTABLE_BOOT_VOLUME --> Partition non active

5)- Vérifier aussi s'il ne s'agit pas d'un mauvais contact à sa barrette mémoire RAM.

6)- Elibagla.


Salwa va émettre aussi son avis.
Merci à Salwa.

Al.
0
salwa5 Messages postés 7452 Date d'inscription jeudi 30 novembre 2006 Statut Contributeur Dernière intervention 18 août 2012 1 642
24 avril 2007 à 15:39
bonjour si j'ai bien compris c impossible de demarrer le pc donc le moyen le plus simple c'est de faire une reparation windows avec le cd windows xp tout est expliqué ici

http://www.informatruc.com/reparer-windows-xp-2


si ca donne rien alors on peu essayer de recuperer les donneé important de l'ordi avec le cd linux par exemple et ensuite formater

a+++
0
Utilisateur anonyme
24 avril 2007 à 18:47
salut à tous,
Je suis tout à fait d'accord avec ce que tu propose Adifeg, j'en suis toujours à me demander si :
"La question que je me pose:"
Il y a t'il un lecteur de disquette sur ce PC ?
Pas eu de réponse à cette question?

A ce point nous sommes bloqué dans la tentative de rebooter la machine.
En attente de nouvelles de Ghis76 .
0
afideg Messages postés 10517 Date d'inscription lundi 10 octobre 2005 Statut Contributeur sécurité Dernière intervention 12 avril 2022 602
24 avril 2007 à 19:05
Salut et merci Salwa,

Comme tu le lis, "Les convoyeurs attendent !"

C'est une expression typique relative aux lâchers de pigeons voyageurs de concours : quand le temps est mauvais, les transporteurs de pigeons attendent que le ciel soit propice.

C'est ce que nous sommes contraints de faire en attendant les commentaires et réponses de l'internaute.

Quels pigeons, disais-tu Philo ?
Les voyageurs!

Bonne soirée
Al.
0