Spyware secure .com

Résolu
kimmys Messages postés 18 Date d'inscription   Statut Membre Dernière intervention   -  
kimmys Messages postés 18 Date d'inscription   Statut Membre Dernière intervention   -
bonjour,voici plusieur jours que je suis envahis de spyware,je possedead-aware,a-sqared free et
spy bot et comme anti virus panda titanium, j ai deja passer toute la nuit a lire vos forum et a effectuer vos demarche mais sans succes ,c est pourquoi je demande votre aide merci voici le rapport hitjacktis
Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 09:41:25, on 05/07/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Panda Software\Panda Antivirus + Firewall 2007\TPSrv.exe
C:\Program Files\Panda Software\Panda Antivirus + Firewall 2007\pavsrv51.exe
C:\Program Files\Panda Software\Panda Antivirus + Firewall 2007\AVENGINE.EXE
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\Explorer.EXE
c:\program files\panda software\panda antivirus + firewall 2007\firewall\PNMSRV.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Panda Software\Panda Antivirus + Firewall 2007\APVXDWIN.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Panda Software\Panda Antivirus + Firewall 2007\PavFnSvr.exe
C:\Program Files\Fichiers communs\Panda Software\PavShld\pavprsrv.exe
C:\Program Files\Panda Software\Panda Antivirus + Firewall 2007\PsImSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
c:\program files\panda software\panda antivirus + firewall 2007\WebProxy.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\MSN\MSNCoreFiles\msn6.exe
C:\Documents and Settings\CARLOS\Bureau\HiJackThis_v2.exe
C:\Program Files\Panda Software\Panda Antivirus + Firewall 2007\psimreal.exe
C:\Program Files\Panda Software\Panda Antivirus + Firewall 2007\avciman.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Microsoft MSJava 32 - {43F7497C-7687-4DEA-A057-F21BD81BC896} - C:\WINDOWS\system32\msjava32.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Software\Panda Antivirus + Firewall 2007\APVXDWIN.EXE" /s
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game12.zylom.com/activex/zylomgamesplayer.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{5E10EC60-7736-4949-A749-B2A9BC5A8E93}: NameServer = 172.19.3.1
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O22 - SharedTaskScheduler: Pré-chargeur Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Démon de cache des catégories de composant - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - Unknown owner - C:\WINDOWS\System32\dmadmin.exe
O23 - Service: Journal des événements (Eventlog) - Unknown owner - C:\WINDOWS\system32\services.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Service COM de gravage de CD IMAPI (ImapiService) - Unknown owner - C:\WINDOWS\System32\imapi.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Partage de Bureau à distance NetMeeting (mnmsrvc) - Unknown owner - C:\WINDOWS\System32\mnmsrvc.exe
O23 - Service: Panda Function Service (PAVFNSVR) - Unknown owner - C:\Program Files\Panda Software\Panda Antivirus + Firewall 2007\PavFnSvr.exe
O23 - Service: Panda Process Protection Service (PavPrSrv) - Unknown owner - C:\Program Files\Fichiers communs\Panda Software\PavShld\pavprsrv.exe
O23 - Service: Panda anti-virus service (PAVSRV) - Panda Software International - C:\Program Files\Panda Software\Panda Antivirus + Firewall 2007\pavsrv51.exe
O23 - Service: Plug-and-Play (PlugPlay) - Unknown owner - C:\WINDOWS\system32\services.exe
O23 - Service: Panda Network Manager (PNMSRV) - Unknown owner - c:\program files\panda software\panda antivirus + firewall 2007\firewall\PNMSRV.EXE
O23 - Service: Panda IManager Service (PSIMSVC) - Panda Software - C:\Program Files\Panda Software\Panda Antivirus + Firewall 2007\PsImSvc.exe
O23 - Service: Gestionnaire de session d'aide sur le Bureau à distance (RDSessMgr) - Unknown owner - C:\WINDOWS\system32\sessmgr.exe
O23 - Service: Carte à puce (SCardSvr) - Unknown owner - C:\WINDOWS\System32\SCardSvr.exe
O23 - Service: Journaux et alertes de performance (SysmonLog) - Unknown owner - C:\WINDOWS\system32\smlogsvc.exe
O23 - Service: Panda TPSrv (TPSrv) - Unknown owner - C:\Program Files\Panda Software\Panda Antivirus + Firewall 2007\TPSrv.exe
O23 - Service: Cliché instantané de volume (VSS) - Unknown owner - C:\WINDOWS\System32\vssvc.exe
O23 - Service: Carte de performance WMI (WmiApSrv) - Unknown owner - C:\WINDOWS\System32\wbem\wmiapsrv.exe

--
End of file - 8607 bytes
Configuration: Windows XP
Internet Explorer 6.0

4 réponses

  1. jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 041
     
    O2 - BHO: Microsoft MSJava 32 - {43F7497C-7687-4DEA-A057-F21BD81BC896} - C:\WINDOWS\system32\msjava32.dll

    ca c'est nefaste pour info le lien suivant:

    http://www.castlecops.com/CLSID.html

    -----------------------

    télécharger sur le bureau
    Navilog.zip
    http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe

    = Double-Clic navilog1.zip
    = Extraire tout sur le bureau
    = Double-Clic navilog1 qui est sur le bureau
    = Appuyer sur une touche jusqu' arriver aux options
    = Choisir option 1

    un rapport : fixnavi.txt dans C : va se creer
    le copier/coller dans ton prochain message.

    = Lance navilog1
    = Cette fois-ci choisi l'option 2
    = Navilog va faire le nettoyage.. patient jusqu'à ce qui soit marqué *** Nettoyage Termine le ..... ***
    = Un rapport va être génrer sur ton C:\ qui sera en option 2
    Note: le bureau disparaît

    = colle le contenu du rapport de navilog (qui est en option2)
    ----------------------

    utilise aussi pour supprimer tes traces

    CCLEANER: (lance un netoyage et repare les clés) sans la barre yahoo
    https://www.01net.com/

    ---------------
    smit fraud fix

    http://telechargement.zebulon.fr/smitfraudfix.html

    2/ double clique sur smitfraudfix. puis selectionne 1 et appuyer sur entrée afin de créer le rapport des infection présentes. une fois le rapport effectué redemarre en mode sans echec (en appuyant sur F8 ou suppr, ou F5 au demarrage en général)

    3/ puis refaire comme en 2/ mais selectionne l'option 2 et appuyer sur entrée pour commencer la desinfection. lorsque le programme demande si tu veut nettoyer le registre metsoui en tapant 0 et entrée

    ----------------

    AVG antispyxare

    https://www.01net.com/telecharger/

    Tuto :
    http://www.kachouri.com/tuto/tuto-161-avg-anti-spyware-75-pour-votre-securite.html

    ->Relance AVG AS -> "Analyse" ->"Paramètres"

    Sous la question "Comment réagir ?" :

    -> clique sur "Actions recommandées" et choisis "Quarantaines"
    -> Re-clique sur l'onglet "Analyse" puis réalise une "Analyse complète du système"

    Si un fichier est infecté en fin d'analyse

    ->Clique sur "Appliquer toutes les actions "

    ->Clique sur "Enregistrer le rapport" puis sur "Enregistrer le rapport sous".

    ->Enregistre ce fichier texte sur ton bureau ensuite colle le rapport ici

    -----------------------

    colle le rapport d'un scan en ligne
    avec un des suivants:

    bitdefender en ligne :
    http://www.bitdefender.fr/scan_fr/scan8/ie.html

    Panda en ligne :
    http://pandasoftware.fr

    ----------------

    recolle hijackthis
    1
    1. jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 041
       
      voila la ligne indiquée est

      Microsoft MSJava 32, CJava Object

      Trojan connecting to/hailing from adult chat sites (camscenter.com, sexecam.net) - WARNING: despite all apprearances this is in NO way a Microsoft file!
      0
      1. kimmys Messages postés 18 Date d'inscription   Statut Membre Dernière intervention   > jlpjlp Messages postés 52399 Statut Contributeur sécurité
         
        remerci j en suis toujour au point 1j attend la fin du rapport
        0
      2. kimmys Messages postés 18 Date d'inscription   Statut Membre Dernière intervention   > jlpjlp Messages postés 52399 Statut Contributeur sécurité
         
        re,encore moi comment je peux faire pour copier le rapport et te l envoyer
        merci
        0
      3. kimmys Messages postés 18 Date d'inscription   Statut Membre Dernière intervention   > jlpjlp Messages postés 52399 Statut Contributeur sécurité
         
        j ai réussi voici le rapport
        a-squared Free 2.1
        Ad-Aware SE Personal
        Adobe Flash Player ActiveX
        Adobe Photoshop 6.0
        Adobe Reader 7.0.8 - Français
        Adobe Shockwave Player
        Adobe SVG Viewer
        adsl TV
        ADSL Utility
        Archiveur WinRAR
        Big Kahuna Reef
        CamfrogWEB Advanced ActiveX Plugin (remove only)
        Correctif Windows XP - KB873339
        Correctif Windows XP - KB885835
        Correctif Windows XP - KB885836
        Correctif Windows XP - KB886185
        Correctif Windows XP - KB887472
        Correctif Windows XP - KB888302
        Correctif Windows XP - KB890859
        Correctif Windows XP - KB891781
        Desktop Destroyer 3D Screensaver Free
        Dial-Messenger 1.0.41
        DVD Solution
        eMule
        Google Toolbar for Internet Explorer
        Google Toolbar for Internet Explorer
        HijackThis 2.0.0
        InCD
        Jasc Paint Shop Pro 8
        Liquid Desktop 3D Screensaver Free
        Logiciel QuickCam de Logitech
        Logitech Desktop Messenger
        Logitech Print Service
        Logitech SetPoint
        Microsoft Office Professional Edition 2003
        mIRC
        Mirc 6.17 Fr Belswing V4
        Mise à jour de sécurité pour Lecteur Windows Media (KB911564)
        Mise à jour de sécurité pour Lecteur Windows Media 6.4 (KB925398)
        Mise à jour de sécurité pour Lecteur Windows Media 9 (KB917734)
        Mise à jour de sécurité pour Windows XP (KB893756)
        Mise à jour de sécurité pour Windows XP (KB896358)
        Mise à jour de sécurité pour Windows XP (KB896423)
        Mise à jour de sécurité pour Windows XP (KB896424)
        Mise à jour de sécurité pour Windows XP (KB896428)
        Mise à jour de sécurité pour Windows XP (KB899587)
        Mise à jour de sécurité pour Windows XP (KB899591)
        Mise à jour de sécurité pour Windows XP (KB900725)
        Mise à jour de sécurité pour Windows XP (KB901017)
        Mise à jour de sécurité pour Windows XP (KB901214)
        Mise à jour de sécurité pour Windows XP (KB902400)
        Mise à jour de sécurité pour Windows XP (KB904706)
        Mise à jour de sécurité pour Windows XP (KB905414)
        Mise à jour de sécurité pour Windows XP (KB905749)
        Mise à jour de sécurité pour Windows XP (KB908519)
        Mise à jour de sécurité pour Windows XP (KB911562)
        Mise à jour de sécurité pour Windows XP (KB911567)
        Mise à jour de sécurité pour Windows XP (KB911927)
        Mise à jour de sécurité pour Windows XP (KB912919)
        Mise à jour de sécurité pour Windows XP (KB913580)
        Mise à jour de sécurité pour Windows XP (KB914388)
        Mise à jour de sécurité pour Windows XP (KB914389)
        Mise à jour de sécurité pour Windows XP (KB917344)
        Mise à jour de sécurité pour Windows XP (KB917422)
        Mise à jour de sécurité pour Windows XP (KB917953)
        Mise à jour de sécurité pour Windows XP (KB918118)
        Mise à jour de sécurité pour Windows XP (KB918439)
        Mise à jour de sécurité pour Windows XP (KB919007)
        Mise à jour de sécurité pour Windows XP (KB920213)
        Mise à jour de sécurité pour Windows XP (KB920214)
        Mise à jour de sécurité pour Windows XP (KB920670)
        Mise à jour de sécurité pour Windows XP (KB920683)
        Mise à jour de sécurité pour Windows XP (KB920685)
        Mise à jour de sécurité pour Windows XP (KB921398)
        Mise à jour de sécurité pour Windows XP (KB922616)
        Mise à jour de sécurité pour Windows XP (KB922760)
        Mise à jour de sécurité pour Windows XP (KB922819)
        Mise à jour de sécurité pour Windows XP (KB923191)
        Mise à jour de sécurité pour Windows XP (KB923414)
        Mise à jour de sécurité pour Windows XP (KB923689)
        Mise à jour de sécurité pour Windows XP (KB923694)
        Mise à jour de sécurité pour Windows XP (KB923789)
        Mise à jour de sécurité pour Windows XP (KB923980)
        Mise à jour de sécurité pour Windows XP (KB924191)
        Mise à jour de sécurité pour Windows XP (KB924270)
        Mise à jour de sécurité pour Windows XP (KB924496)
        Mise à jour de sécurité pour Windows XP (KB924667)
        Mise à jour de sécurité pour Windows XP (KB925454)
        Mise à jour de sécurité pour Windows XP (KB925486)
        Mise à jour de sécurité pour Windows XP (KB925902)
        Mise à jour de sécurité pour Windows XP (KB926255)
        Mise à jour de sécurité pour Windows XP (KB926436)
        Mise à jour de sécurité pour Windows XP (KB927779)
        Mise à jour de sécurité pour Windows XP (KB927802)
        Mise à jour de sécurité pour Windows XP (KB928090)
        Mise à jour de sécurité pour Windows XP (KB928255)
        Mise à jour de sécurité pour Windows XP (KB928843)
        Mise à jour de sécurité pour Windows XP (KB929123)
        Mise à jour de sécurité pour Windows XP (KB929969)
        Mise à jour de sécurité pour Windows XP (KB930178)
        Mise à jour de sécurité pour Windows XP (KB931261)
        Mise à jour de sécurité pour Windows XP (KB931768)
        Mise à jour de sécurité pour Windows XP (KB931784)
        Mise à jour de sécurité pour Windows XP (KB932168)
        Mise à jour de sécurité pour Windows XP (KB933566)
        Mise à jour de sécurité pour Windows XP (KB935839)
        Mise à jour de sécurité pour Windows XP (KB935840)
        Mise à jour pour Windows XP (KB894391)
        Mise à jour pour Windows XP (KB898461)
        Mise à jour pour Windows XP (KB900485)
        Mise à jour pour Windows XP (KB908531)
        Mise à jour pour Windows XP (KB910437)
        Mise à jour pour Windows XP (KB911280)
        Mise à jour pour Windows XP (KB916595)
        Mise à jour pour Windows XP (KB920872)
        Mise à jour pour Windows XP (KB922582)
        Mise à jour pour Windows XP (KB927891)
        Mise à jour pour Windows XP (KB929338)
        Mise à jour pour Windows XP (KB930916)
        Mise à jour pour Windows XP (KB931836)
        Multimedia Launcher
        Navilog1 Version 2.0.5
        Nero OEM
        Panda Antivirus + Firewall 2007
        Picture Cube 3D 3D Screensaver Free
        PowerDVD
        PowerProducer
        Programme de gestion Camera de Logitech®
        ProSavageDDR and Utilities
        S3Display
        S3Gamma2
        S3Info2
        S3Overlay
        SpeedTouch USB Software
        Spybot - Search & Destroy 1.4
        Virtual DJ - Atomix Productions
        VoipBuster
        WebFldrs XP
        WebMediaPlayer
        Windows Installer 3.1 (KB893803)
        Windows Live Messenger
        Windows Live Sign-in Assistant
        Windows Live Toolbar
        Windows Live Toolbar
        Windows Media Format Runtime
        Windows XP Service Pack 2
        WinZip
        0
  2. kimmys Messages postés 18 Date d'inscription   Statut Membre Dernière intervention  
     
    tout d abbord merci
    je m en vais essayer tout cela et te recontacte
    0
  3. jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 041
     
    ce n'est pas le rapport navilog ca......
    0
    1. kimmys Messages postés 18 Date d'inscription   Statut Membre Dernière intervention  
       
      desole me suis plante je recommence
      encore merci pour ta patience
      0
    2. kimmys Messages postés 18 Date d'inscription   Statut Membre Dernière intervention  
       
      re merci j espere que c est celui la
      Search Navipromo version 2.0.5 commencé le 05/07/2007 à 14:26:41,02

      !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
      !!! Poster ce rapport sur le forum pour le faire analyser !!!
      !!! Ne pas lancer la partie désinfection sans l'avis d'un spécialiste !!!

      Fix lancé depuis C:\Program Files\navilog1
      Mise a jour le 01.07.2007 a 12h00 by IL-MAFIOSO

      Executé en mode normal

      *** Recherche Programmes installes ***


      WebMediaPlayer


      *** Recherche dossiers dans C:\WINDOWS ***




      *** Recherche dossiers dans C:\Program Files ***


      C:\Program Files\WebMediaPlayer trouvé !


      *** Recherche dossiers dans C:\Documents and Settings\All Users\Application Data ***




      *** Recherche dossiers dans C:\Documents and Settings\CARLOS\Application Data ***



      *** Recherche avec BlackLight Engine/F-secure ***
      BlackLight Engine est un produit de F-secure, pour + d'infos :
      https://www.f-secure.com/en

      Fichier(s) caché(s) dans C:\WINDOWS\system32 :

      c:\WINDOWS\system32\atnaaghsni.dat
      C:\windows\system32\atnaaghsni.exe
      c:\WINDOWS\system32\atnaaghsni_nav.dat
      c:\WINDOWS\system32\atnaaghsni_navps.dat

      Processus caché(s) dans C:\WINDOWS\system32 :

      C:\windows\system32\atnaaghsni.exe


      *** Recherche fichiers ***


      C:\WINDOWS\pack.epk trouvé !
      C:\WINDOWS\system32\nvs2.inf trouvé !


      *** Recherche cles registre ***


      Recherche dans [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs]



      Recherche dans [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage]



      Recherche Clé Magic Control

      HKEY_CURRENT_USER\Software\Lanconfig trouvé !
      HKEY_USERS\S-1-5-21-57989841-484763869-1202660629-1004\Software\Lanconfig trouvé !


      *** Module de Recherche complémentaire ***
      (Recherche fichiers spécifiques)

      1)Recherche fichiers connus:


      2)Recherche Heuristique :
      *
      C:\WINDOWS\system32\atnaaghsni.dat trouvé !
      **
      C:\WINDOWS\system32\atnaaghsni.dat trouvé !
      ***
      ****
      C:\WINDOWS\system32\atnaaghsni_navps.dat trouvé !
      *****
      ******
      *******
      ********

      3)Recherche Certificats :

      Certificat Egroup trouvé !


      *** Analyse Terminé le 05/07/2007 à 14:39:38,68 ***
      0
  4. jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 041
     
    fait la deuxieme partie qui va supprimer de nombreuses choses!

    = Lance navilog1
    = Cette fois-ci choisi l'option 2
    = Navilog va faire le nettoyage.. patient jusqu'à ce qui soit marqué *** Nettoyage Termine le ..... ***
    = Un rapport va être génrer sur ton C:\ qui sera en option 2
    Note: le bureau disparaît

    = colle le contenu du rapport de navilog (qui est en option2)

    et le reste!

    courage
    0
    1. kimmys Messages postés 18 Date d'inscription   Statut Membre Dernière intervention  
       
      voila qui est fait je te l envoye merci encore
      Clean Navipromo version 2.0.5 commencé le 05/07/2007 à 14:44:43,77

      Fix lancé depuis C:\Program Files\navilog1
      Mise a jour le 01.07.2007 a 12h00 by IL-MAFIOSO

      Mode suppression automatique avec prise en charge résultats Blacklight


      *** Creation backups fichiers trouvés par Blacklight ***

      Copie vers "C:\Program Files\navilog1\Backupnavi"


      *** Suppression des fichiers trouvés avec Blacklight ***

      c:\WINDOWS\system32\atnaaghsni.dat supprimé !
      C:\windows\system32\atnaaghsni.exe supprimé !
      c:\WINDOWS\system32\atnaaghsni_nav.dat supprimé !
      c:\WINDOWS\system32\atnaaghsni_navps.dat supprimé !

      ** 2ème passage **

      C:\WINDOWS\system32\atnaaghsni.exe absent !
      C:\WINDOWS\system32\atnaaghsni.dat absent !
      C:\WINDOWS\system32\atnaaghsni_nav.dat absent !
      C:\WINDOWS\system32\atnaaghsni_navps.dat absent !
      C:\WINDOWS\system32\atnaaghsni_navup.dat absent !
      C:\WINDOWS\system32\atnaaghsni_navtmp.dat absent !
      C:\WINDOWS\system32\atnaaghsni_m2s.xml absent !


      C:\WINDOWS\prefetch\atnaaghsni*.pf trouvé !
      Copie C:\WINDOWS\prefetch\atnaaghsni*.pf réalise avec succes !
      C:\WINDOWS\prefetch\atnaaghsni*.pf supprimé !

      *** Suppression dossiers dans C:\WINDOWS ***


      *** Suppression dossiers dans C:\Program Files ***

      C:\Program Files\WebMediaPlayer ...suppression...
      C:\Program Files\WebMediaPlayer supprimé !


      *** Suppression dossiers dans C:\Documents and Settings\All Users\Application Data ***


      *** Suppression dossiers dans C:\Documents and Settings\CARLOS\Application Data ***



      *** Suppression fichiers ***

      C:\WINDOWS\pack.epk supprimé !
      C:\WINDOWS\system32\nvs2.inf supprimé !

      *** Suppression fichiers temporaires ***

      Nettoyage contenu C:\WINDOWS\Temp effectué !
      Nettoyage contenu C:\Documents and Settings\CARLOS\Local Settings\Temp effectué !


      *** Sauvegarde du registre vers dossier Backupnavi***


      sauvegarde du registre réalise avec succes !


      *** Nettoyage registre ***


      Nettoyage registre Ok

      *** Traitement Recherche complémentaire ***
      (Recherche fichiers spécifiques)

      1)Recherche fichiers connus:


      2)Recherche et Suppression Heuristique :

      *
      **
      ***
      ****
      *****
      ******
      *******
      ********

      3)Contrôle présence clés Rootkit dans le registre :

      Aucune autre clés présente dans le registre !

      4)Certificats :

      Certificat Egroup supprimé !

      *** Nettoyage termine le 05/07/2007 à 14:57:35,29 ***
      merci je continue lolll
      0
    2. kimmys Messages postés 18 Date d'inscription   Statut Membre Dernière intervention  
       
      dit sur 01.net je ne sais pas ce que je doit telecharger ,je continue zebulon en attendant ta reponse
      merci de ta patience
      0
    3. kimmys Messages postés 18 Date d'inscription   Statut Membre Dernière intervention  
       
      re c est encore moi a premiere vue cela devrai allez malgre le fait que je n aye pas reussi avec smQuick scan: Searching for malicious software
      Scanning
      Searching 1,139,567 viruses, spyware, Trojans and other threats. It also uses heuristic technologies to detect unknown viruses.

      100%


      Item in progress:
      Items scanned:
      4348

      Items with viruses, spyware, Trojans... detected:
      0

      Suspicious files detected:
      0

      Results
      Congratulations!
      No viruses, spyware, Trojans, or any other ACTIVE or LATENT threats have been detected on your PC.
      We detected that Panda Antivirus + Firewall 2007 is enabled and up-to-date.
      El texto que corresponda en cada momento
      After a quick scan of your PC, we have not detected any ACTIVE or LATENT malicious software.
      Become a TotalScan Pro member
      Includes disinfection!
      itfraudix,je viens de faire un scan avec panda voici ce qu il me marque
      je te remerci de tout coeur pour ton aide
      10000 merci
      kimmys
      0