Mon PC est probablement infecté

Résolu
Utilisateur anonyme -  
philae83 Messages postés 12854 Statut Contributeur sécurité -
bonjour,
J'ai fais un rapport avec Hijackthis ,j'ai supprimé pas mal de choses que je ne voulais pas au démarrage.
mon pc est devenu lent, parfois des pubs .
Je vous remercie d'avance de vos consiels
Configuration: Windows XP
Firefox 2.0.0.8

22 réponses

  • 1
  • 2
  1. kwaio Messages postés 3423 Date d'inscription   Statut Contributeur Dernière intervention   681
     
    Antivirus ?
    Firewall ?

    Fais un scan avec Adware ET spybot pour voir.

    0
  2. Utilisateur anonyme
     
    salut Kwaio
    merci pour ta reponse
    Je fais un scan avec AD et spybot souvent là j'ai 15 objets négligeables et 1 critique avec ad et a peu près autant avec spybot
    que je viens de corriger je joint mon rapport que j'ai fais avant

    Logfile of HijackThis v1.99.1
    Scan saved at 07:41:00, on 27/10/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16544)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Hijackthis Version Française\hijackthis vf.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - Default URLSearchHook is missing
    O1 - Hosts: 212.150.54.250 dv-networks.com
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~2\SDHelper.dll
    O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - C:\Program Files\eoRezo\EoAdv\EoRezoBHO.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
    O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
    O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
    O11 - Options group: [INTERNATIONAL] International*
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
    O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
    O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe" /service (file missing)
    O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\PROGRA~1\NVIDIA~1\NETWOR~1\bin\nSvcAppFlt.exe
    O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Unknown owner - C:\PROGRA~1\NVIDIA~1\NETWOR~1\Apache Group\Apache2\bin\apache.exe" -k runservice (file missing)
    O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
    O23 - Service: BitDefender Desktop Update Service (LIVESRV) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Update Service\livesrv.exe" /service (file missing)
    O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
    O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA - C:\PROGRA~1\NVIDIA~1\NETWOR~1\bin\nSvcIp.exe
    O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA - C:\PROGRA~1\NVIDIA~1\NETWOR~1\bin\nSvcLog.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe" /service (file missing)
    0
  3. philae83 Messages postés 12854 Statut Contributeur sécurité 206
     
    bonsoir

    télécharge la dernière version d'hijackthis stp

    http://www.commentcamarche.net/telecharger/telecharger 159 hijackthis

    ensuite tu feras

    * Fait un scan antivirus en ligne avec Internet Explorer
    https://www.bitdefender.fr/
    et copie colle le résultat ici
    * En bas, à gauche de la fenêtre, clique sur BitDefender SCAN ONLINE
    * Dans la nouvelle fenêtre, clique sur I agree
    * La fenêtre change encore, clique sur Click here to scan
    * Les signatures se chargent, etc.

    tuto en image

    http://pageperso.aol.fr/rginformatique/mapage/defender.htm
    0
  4. Utilisateur anonyme
     
    salut philae83
    j'ai charger la dernière version de hijack mais je n'arrive pas à accèder a bitdefender je bloc à
    l'accord de licence.Je ne connais pas non plus cette version d'hijack peu tu m'indiquer un tuto
    0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. philae83 Messages postés 12854 Statut Contributeur sécurité 206
     
    tu bloques pourquoi ?
    0
  7. Utilisateur anonyme
     
    la fenêtre ou il faut accepter la licence apparait pendant un dixème de seconde seulement
    0
  8. Utilisateur anonyme
     
    je suis tombé sur une invite pour scaner mais en anglais avec panda je sais pas si je suis con mais je sais que
    l'anglais je le devine à peine durdur
    0
  9. philae83 Messages postés 12854 Statut Contributeur sécurité 206
     
    je t'ai mis un lien vers un tuto, regarde le
    0
  10. Utilisateur anonyme
     
    j'ai bien vu le tuto en premier il est impecable le tuto
    mais le lien pour scanner avec panda et tout en anglais j'ai cru comprendre que la config internet doit etre supperieur a IE5
    je pensais avoir IE 7
    0
  11. Utilisateur anonyme
     
    bonjour,

    j'ai eu bien du mal a faire un scan en ligne
    voilà le rapport avec bitdefender ras, j'en ai fais un autre avec panda qui donne ceci

    :Incident Status Location

    Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\jean louis.JEAN-ACA4AA7263\Application Data\Mozilla\Firefox\Profiles\43r3tg29.default\cookies.txt[.2o7.net/]
    Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\jean louis.JEAN-ACA4AA7263\Application Data\Mozilla\Firefox\Profiles\43r3tg29.default\cookies.txt[.xiti.com/]
    Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\jean louis.JEAN-ACA4AA7263\Application Data\Mozilla\Firefox\Profiles\43r3tg29.default\cookies.txt[.atdmt.com/]
    Spyware:Cookie/Smartadserver Not disinfected C:\Documents and Settings\jean louis.JEAN-ACA4AA7263\Application Data\Mozilla\Firefox\Profiles\43r3tg29.default\cookies.txt[.smartadserver.com/]
    Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\jean louis.JEAN-ACA4AA7263\Application Data\Mozilla\Firefox\Profiles\43r3tg29.default\cookies.txt[.doubleclick.net/]
    Spyware:Cookie/Smartadserver Not disinfected C:\Documents and Settings\jean louis.JEAN-ACA4AA7263\Application Data\Mozilla\Firefox\Profiles\43r3tg29.default\cookies.txt[.smartadserver.com/]
    Spyware:Cookie/Weborama Not disinfected C:\Documents and Settings\jean louis.JEAN-ACA4AA7263\Application Data\Mozilla\Firefox\Profiles\43r3tg29.default\cookies.txt[.weborama.fr/]
    Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\jean louis.JEAN-ACA4AA7263\Application Data\Mozilla\Firefox\Profiles\43r3tg29.default\cookies.txt[.advertising.com/]
    Spyware:Cookie/Tradedoubler Not disinfected C:\Documents and Settings\jean louis.JEAN-ACA4AA7263\Application Data\Mozilla\Firefox\Profiles\43r3tg29.default\cookies.txt[.tradedoubler.com/]
    Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\jean louis.JEAN-ACA4AA7263\Application Data\Mozilla\Firefox\Profiles\43r3tg29.default\cookies.txt[.247realmedia.com/]
    Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\jean louis.JEAN-ACA4AA7263\Application Data\Mozilla\Firefox\Profiles\43r3tg29.default\cookies.txt[.overture.com/]
    Spyware:Cookie/Bluestreak Not disinfected C:\Documents and Settings\jean louis.JEAN-ACA4AA7263\Application Data\Mozilla\Firefox\Profiles\43r3tg29.default\cookies.txt[.bluestreak.com/]
    Spyware:Cookie/Apmebf Not disinfected C:\Documents and Settings\jean louis.JEAN-ACA4AA7263\Application Data\Mozilla\Firefox\Profiles\43r3tg29.default\cookies.txt[.apmebf.com/]
    Spyware:Cookie/Adtech Not disinfected C:\Documents and Settings\jean louis.JEAN-ACA4AA7263\Application Data\Mozilla\Firefox\Profiles\43r3tg29.default\cookies.txt[.adtech.de/]
    Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\jean louis.JEAN-ACA4AA7263\Application Data\Mozilla\Firefox\Profiles\43r3tg29.default\cookies.txt[.mediaplex.com/]
    Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\jean louis.JEAN-ACA4AA7263\Application Data\Mozilla\Firefox\Profiles\43r3tg29.default\cookies.txt[.bs.serving-sys.com/]
    Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\jean louis.JEAN-ACA4AA7263\Application Data\Mozilla\Firefox\Profiles\43r3tg29.default\cookies.txt[.serving-sys.com/]
    Spyware:Cookie/Tickle Not disinfected C:\Documents and Settings\jean louis.JEAN-ACA4AA7263\Application Data\Mozilla\Firefox\Profiles\43r3tg29.default\cookies.txt[.tickle.com/]
    Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\jean louis.JEAN-ACA4AA7263\Application Data\Mozilla\Firefox\Profiles\43r3tg29.default\cookies.txt[ad.yieldmanager.com/]
    Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\jean louis.JEAN-ACA4AA7263\Application Data\Mozilla\Firefox\Profiles\43r3tg29.default\cookies.txt[ad.yieldmanager.com/click,bQIAANd3AwBUrAcA5bsCAAIAFAAAAP8AAAAFDgIACgJ4tAMAQD4EAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAF6CIEcAAAAA,,http://ads.
    Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\jean louis.JEAN-ACA4AA7263\Application Data\Mozilla\Firefox\Profiles\43r3tg29.default\cookies.txt[.tribalfusion.com/]
    Spyware:Cookie/SexList Not disinfected C:\Documents and Settings\jean louis.JEAN-ACA4AA7263\Application Data\Mozilla\Firefox\Profiles\43r3tg29.default\cookies.txt[.sexlist.com/]
    Spyware:Cookie/adultfriendfinder Not disinfected C:\Documents and Settings\jean louis.JEAN-ACA4AA7263\Application Data\Mozilla\Firefox\Profiles\43r3tg29.default\cookies.txt[.adultfriendfinder.com/]
    Spyware:Cookie/Comclick Not disinfected C:\Documents and Settings\jean louis.JEAN-ACA4AA7263\Application Data\Mozilla\Firefox\Profiles\43r3tg29.default\cookies.txt[fl01.ct2.comclick.com/]
    Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\jean louis.JEAN-ACA4AA7263\Application Data\Mozilla\Firefox\Profiles\43r3tg29.default\cookies.txt[.statcounter.com/]
    Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\jean louis.JEAN-ACA4AA7263\Application Data\Mozilla\Firefox\Profiles\43r3tg29.default\cookies.txt[.casalemedia.com/]
    Spyware:Cookie/Toplist Not disinfected C:\Documents and Settings\jean louis.JEAN-ACA4AA7263\Application Data\Mozilla\Firefox\Profiles\43r3tg29.default\cookies.txt[.toplist.cz/]
    Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\jean louis.JEAN-ACA4AA7263\Cookies\jean louis@xiti[1].txt
    Spyware:Cookie/Smartadserver Not disinfected C:\Documents and Settings\jean louis.JEAN-ACA4AA7263\Cookies\jean_louis@smartadserver[2].txt
    Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\jean louis.JEAN-ACA4AA7263\Cookies\jean_louis@tribalfusion[1].txt
    Potentially unwanted tool:Application/Pskill.K Not disinfected C:\Documents and Settings\jean louis.JEAN-ACA4AA7263\Mes documents\jean-louis\eliminer dreaver cleaner\logicieles\eliminer adware secure\clean.zip[clean/pskill.exe]
    Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\jean louis.JEAN-ACA4AA7263\Mes documents\jean-louis\eliminer dreaver cleaner\logicieles\eliminer adware secure\navilog1.zip[Process.exe]
    Virus:Generic Malware Disinfected C:\Documents and Settings\jean louis.JEAN-ACA4AA7263\Mes documents\jean-louis\eliminer dreaver cleaner\logicieles\logicile pour eliminer driver cleaner\SmitfraudFix.exe
    Potentially unwanted tool:Application/Pskill.K Not disinfected C:\Documents and Settings\jean louis.JEAN-ACA4AA7263\Mes documents\Mes documents.rar[jean-louis\eliminer dreaver cleaner\logicieles\eliminer adware secure\clean.zip][clean/pskill.exe]
    Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\jean louis.JEAN-ACA4AA7263\Mes documents\Mes documents.rar[jean-louis\eliminer dreaver cleaner\logicieles\eliminer adware secure\navilog1.zip][Process.exe]
    Virus:Generic Malware Not disinfected C:\Documents and Settings\jean louis.JEAN-ACA4AA7263\Mes documents\Mes documents.rar[jean-louis\eliminer dreaver cleaner\logicieles\logicile pour eliminer driver cleaner\SmitfraudFix.exe]
    Adware:Adware/NaviPromo Not disinfected C:\Documents and Settings\jean louis.JEAN-ACA4AA7263\Mes documents\Mes documents.rar[jean-louis\logiciels\pour virus\navilog 1\Backupnavi\nljrhdao.exe]
    Adware:Adware/NaviPromo Not disinfected C:\Documents and Settings\jean louis.JEAN-ACA4AA7263\Mes documents\Mes documents.rar[jean-louis\logiciels\pour virus\navilog 1\Backupnavi\sajhkc.exe]
    Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\jean louis.JEAN-ACA4AA7263\Mes documents\Mes documents.rar[jean-louis\logiciels\pour virus\navilog 1\navilog1.zip][Process.exe]
    Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\jean louis.JEAN-ACA4AA7263\Mes documents\Mes documents.rar[jean-louis\logiciels\pour virus\navilog 1\Process.exe]
    Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\jean louis.JEAN-ACA4AA7263\Mes documents\Mes documents.rar[jean-louis\logiciels\pour virus\SmitfraudFix\Process.exe]
    Virus:Trj/Rebooter.J Not disinfected C:\Documents and Settings\jean louis.JEAN-ACA4AA7263\Mes documents\Mes documents.rar[jean-louis\logiciels\pour virus\SmitfraudFix\Reboot.exe]
    Potentially unwanted tool:Application/SuperFast Not disinfected C:\Documents and Settings\jean louis.JEAN-ACA4AA7263\Mes documents\Mes documents.rar[jean-louis\logiciels\pour virus\SmitfraudFix\restart.exe]
    Potentially unwanted tool:Application/Processor Not disinfected C:\WINDOWS\system32\Process.exe
    Potentially unwanted tool:Application/SudoPlanet Not disinfected C:\WINDOWS\Temp\NSIS_install_SP.exe[SudoPlanet.exe]
    Potentially unwanted tool:Application/SudoPlanet Not disinfected C:\WINDOWS\Temp\NSIS_install_SP.exe[SudoPlanet.dll]
    0
  12. philae83 Messages postés 12854 Statut Contributeur sécurité 206
     
    bonjour,

    tu as utilisé navilog, smitfraud ? quand ? pourquoi ?

    supprime tout le contenu de :

    C:\WINDOWS\Temp

    poste un rapport hijackthis stp comme demandé plus haut

    0
  13. Utilisateur anonyme
     
    bonjour philae83
    J'ai utilisé navilog et smitfraude pour enlever un
    ou deux virus driver cleaner et doctor secure en début d'année
    j'ai vidé C:\WINDOWS\Temp
    je joint mon rapport hijack

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 18:35:44, on 28/10/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16544)
    Boot mode: Safe mode

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
    O1 - Hosts: 212.150.54.250 dv-networks.com
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~2\SDHelper.dll
    O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - C:\Program Files\eoRezo\EoAdv\EoRezoBHO.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
    O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
    O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe (file missing)
    O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\PROGRA~1\NVIDIA~1\NETWOR~1\bin\nSvcAppFlt.exe
    O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\PROGRA~1\NVIDIA~1\NETWOR~1\Apache Group\Apache2\bin\apache.exe
    O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
    O23 - Service: BitDefender Desktop Update Service (LIVESRV) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Update Service\livesrv.exe (file missing)
    O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
    O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA - C:\PROGRA~1\NVIDIA~1\NETWOR~1\bin\nSvcIp.exe
    O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA - C:\PROGRA~1\NVIDIA~1\NETWOR~1\bin\nSvcLog.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe (file missing)
    0
  14. philae83 Messages postés 12854 Statut Contributeur sécurité 206
     
    un rapport en mode normal stp
    0
  15. Utilisateur anonyme
     
    je te joint un rapport en mode normal

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 19:31:45, on 28/10/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16544)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Ahead\InCD\InCDsrv.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\system32\spoolsv.exe
    c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
    C:\PROGRA~1\NVIDIA~1\NETWOR~1\Apache Group\Apache2\bin\apache.exe
    C:\WINDOWS\System32\FTRTSVC.exe
    C:\PROGRA~1\NVIDIA~1\NETWOR~1\bin\nSvcIp.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\PROGRA~1\NVIDIA~1\NETWOR~1\bin\nSvcLog.exe
    C:\WINDOWS\system32\HPZipm12.exe
    C:\WINDOWS\system32\svchost.exe
    C:\PROGRA~1\NVIDIA~1\NETWOR~1\bin\nSvcAppFlt.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\PROGRA~1\NVIDIA~1\NETWOR~1\Apache Group\Apache2\bin\apache.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\WINDOWS\system32\NOTEPAD.EXE
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
    O1 - Hosts: 212.150.54.250 dv-networks.com
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~2\SDHelper.dll
    O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - C:\Program Files\eoRezo\EoAdv\EoRezoBHO.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
    O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
    O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe (file missing)
    O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\PROGRA~1\NVIDIA~1\NETWOR~1\bin\nSvcAppFlt.exe
    O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\PROGRA~1\NVIDIA~1\NETWOR~1\Apache Group\Apache2\bin\apache.exe
    O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
    O23 - Service: BitDefender Desktop Update Service (LIVESRV) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Update Service\livesrv.exe (file missing)
    O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
    O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA - C:\PROGRA~1\NVIDIA~1\NETWOR~1\bin\nSvcIp.exe
    O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA - C:\PROGRA~1\NVIDIA~1\NETWOR~1\bin\nSvcLog.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe (file missing)
    0
  16. philae83 Messages postés 12854 Statut Contributeur sécurité 206
     
    re

    supprime les logiciels téléchargés tels navilog et smitfraud

    puis

    * Télécharge sur ton bureau RHosts (Merci à S!ri) disponible ici,
    http://siri.urz.free.fr/Softs/RHosts.exe
    * Double-clique sur Rhosts.exe et clique sur "restaurer".

    puis

    * lance hijackthis "do a system scan only" puis coche ces lignes :

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
    R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
    O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - C:\Program Files\eoRezo\EoAdv\EoRezoBHO.dll
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab

    * toutes applications fermées et HORS CONNEXION, clique sur fix checked

    puis

    supprime via ajout et suppression de programmes si tu le trouves

    eoRezo


    puis supprime

    C:\Program Files\eoRezo

    puis

    * Télécharge CCleaner.

    https://www.pcastuces.com/logitheque/ccleaner.htm

    Installe le dans un répertoire dédié.

    Décoche pendant l'installation

    --- les deux cases "Ajouter l'option ... "

    --- Contrôler les mises à jour

    --- Ajouter la Barre d'Outils Yahoo! CCleaner

    * Lance Ccleaner pour un nettoyage complet.

    ------

    * télécharge AVG Anti-Spyware (ewido)

    https://www.avg.com/en-ww/free-antivirus-download

    * tu l'installes

    * lance AVG Anti-Spyware et clique sur le bouton Mise à jour. Patiente

    puis

    Lance AVG Anti-Spyware

    Clique sur le bouton Analyse (de la barre d'outils)

    puis fait dans l'ordre stp. Tu sauvegardes le rapport APRES avoir mis les actions.

    Puis sur l'onglet Paramètres,
    sous : "Comment réagir "clique sur Actions recommandées. Sélectionne Quarantaine.

    Reviens à l'onglet Analyse. Clique sur Analyse complète du système.

    A la fin du scan, choisis l'option 3

    "Appliquer toutes les actions " en bas.

    Clique sur "Enregistrer le rapport".

    Ceci génère un rapport en fichier texte qui se trouve dans le dossier Reports du dossier d'AVG Anti-Spyware.

    Poste le.

    0
  17. Utilisateur anonyme
     
    bonjour,philea83
    je te remercie pour toutes les explications , je dois m'absenter presque toute cette semaine pour le boulot
    et ce soir je suis un peu juste.Je posterai le rapport en fin de semaine
    0
  18. philae83 Messages postés 12854 Statut Contributeur sécurité 206
     
    ok à plus tard donc
    0
  19. Utilisateur anonyme
     
    bonjour Philae83

    je te joint le rapport AVG Anti-Spyware

    ---------------------------------------------------------
    AVG Anti-Spyware - Rapport d'analyse
    ---------------------------------------------------------

    + Créé à: 12:13:00 04/11/2007

    + Résultat de l'analyse:

    :mozilla.16:C:\Documents and Settings\jean louis.JEAN-ACA4AA7263\Application Data\Mozilla\Firefox\Profiles\43r3tg29.default\cookies.txt -> TrackingCookie.Bluestreak : Nettoyé.
    :mozilla.12:C:\Documents and Settings\jean louis.JEAN-ACA4AA7263\Application Data\Mozilla\Firefox\Profiles\43r3tg29.default\cookies.txt -> TrackingCookie.Netflame : Nettoyé.
    :mozilla.9:C:\Documents and Settings\jean louis.JEAN-ACA4AA7263\Application Data\Mozilla\Firefox\Profiles\yjpf7x0v.default\cookies.txt -> TrackingCookie.Webtrends : Nettoyé.

    Fin du rapport
    0
  20. philae83 Messages postés 12854 Statut Contributeur sécurité 206
     
    bonjour,

    où en es tu de tes pubs intempestives ? sont elles toujours présentes ou non ?
    0
  • 1
  • 2