Trojan win 32 bohdf - Page 4

Résolu
  1. voici lnvx raport hijacthis
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 22:06, on 09/12/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Network Associates\McAfee Desktop Firewall for Windows XP\FireSvc.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Network Associates\VirusScan\Mcshield.exe
    C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
    C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
    C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
    C:\Program Files\Fichiers communs\Network Associates\TalkBack\TBMon.exe
    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    C:\WINDOWS\Mixer.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Program Files\Fichiers communs\Logitech\QCDriver2\LVCOMS.EXE
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\Network Associates\McAfee Desktop Firewall for Windows XP\FireTray.exe
    C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    C:\WINDOWS\system32\WgaTray.exe
    C:\Program Files\internet explorer\iexplore.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
    O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\PROGRA~1\Skype\Phone\IEPlugin\SkypeIEPlugin.dll
    O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
    O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
    O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
    O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Fichiers communs\Network Associates\TalkBack\TBMon.exe"
    O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
    O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
    O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
    O4 - HKLM\..\Run: [C-Media Speaker Configuration] C:\PROGRA~1\C-Media\WIN_ME\Setup.exe /SPEAKER
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Fichiers communs\Logitech\QCDriver2\LVCOMS.EXE
    O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
    O4 - HKLM\..\Run: [FmctrlTray] Fmctrl.EXE
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
    O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
    O4 - Global Startup: McAfee Desktop Firewall Tray.lnk = ?
    O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
    O8 - Extra context menu item: Download all links using BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
    O8 - Extra context menu item: Download all videos using BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
    O8 - Extra context menu item: Download link using &BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
    O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\PROGRA~1\Skype\Phone\IEPlugin\SkypeIEPlugin.dll
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\Skype4COM.dll
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: McAfee Desktop Firewall Service (FireSvc) - Networks Associates Technology, Inc. - C:\Program Files\Network Associates\McAfee Desktop Firewall for Windows XP\FireSvc.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
    O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
    O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
    O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
    0
    1. Contributeur sécurité
      jai redemarrer manuellement mon pc kar je n avai plus acces a internet apres avoir fai un scan avec combofix c normal? je tenvoie les rapports de suites

      non pas spécialement.

      Tu vas suivre pas à pas cette procédure
      http://www.malekal.com/Worm.Win32.Delf.ca.php

      on y verra peut être plus clair ensuite

      tu postes ici tous les rapports.

      0
      1. JE NE SUIS PLUS CHEZ MOI JE SUIS CHEZ UN AMI ,TU SERA LA JUSQU A KE L HEUR?
        ET TU CROIS KIL Y A ENCOR DES VIRUS DANS MON PC?
        0
        1. Contributeur sécurité
          je n'ai pas d'heure, quand j'en ai marre, je quitte et je vais me coucher

          je suis là en général (sauf imprévus) tous les soirs de toutes façons.
          si je te ne réponds pas c'est que je ne suis pas présente.
          Tu as du pain sur la planche, et non ce n'est pas terminé encore
          0
          1. re, philae83,

            dsl du retard...(cause travail)
            à ce sujet.
            "hello philo :)

            je te le laisse sans problème
            "
            -------------------------------------------------------------------
            je crois que notre ami g, ou hill n'était pas au courant des convenances en forum (ici ou ailleurs), et qu'il a paniqué, je crois qu'il a bien compris le pourquoi de la chose !
            Ceci dit, merci de ton invitation à continuer, mais tu es prioritaire sur ce topic, je voulais juste le signaler en "live".....;-)
            ------------------------------
            en ce qui concerne le topic, je me permet quelques remarques.
            -----------------------------------
            la version Java est obsolète et de ce fait une porte ouverte au infection!
            jre1.5.0_09 mise à jour indispensable.
            d'autant que cette 04 demande le démarrage de l'application...
            à supprimer:
            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
            ceci aussi ne me semble pas utile:
            O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
            update audio....
            De plus,

            Perso je ferai renommer HijackThis.exe en scanner.exe, on ne sait jamais !
            cordialement.

            0
            1. Contributeur sécurité
              bonjour philo

              pour l'histoire de la multiplication des topics, oui j'ai bien compris aussi, pas de soucis.
              pour acrobat qui n'est pas à jour, je sais mais je pense que ce n'est pas la priorité, je vois ça à la fin.

              pour les autres lignes oui mais c'est pas le plus urgent non +
              quant à hijackthis renommé, certes, mais....j'ai des doutes, avec tous les rapports demandés déjà, je crois qu'on doit avoir ce qui'l nous faut. Mais je pense que c'est une infection delf (peut être que je me trompe)

              pour l'instant qu'il fasse les manips sur le lien que jai donné, on avisera pour la suite après

              bonne journée
              0
          2. bonsoir ,oui j ai bien compris la chose philo2100 et sincerement desoler.
            bonsoir philae83.je vais mis mettre de suite sur ce ke ma demander de faire.
            0
            1. voici le raport de cclean
              Script execute en mode sans echec
              Rapport clean par Malekal_morte - http://www.malekal.com
              Script execute en mode sans echec 10/12/2007 a 19:12:04,18

              Microsoft Windows XP [version 5.1.2600]

              *** Suppression des fichiers dans C:
              tentative de suppression de C:\StubInstaller.exe

              *** Suppression des fichiers dans C:\WINDOWS\

              *** Suppression des fichiers dans C:\WINDOWS\system32
              tentative de suppression de C:\WINDOWS\system32\mcrh.tmp

              *** Suppression des fichiers dans C:\Program Files

              *** Suppression des clefs du registre effectuee..
              *** Fin du rapport !
              0
              1. voici le raport avg
                AVG Anti-Spyware - Rapport d'analyse
                ---------------------------------------------------------

                + Créé à: 21:21 10/12/2007

                + Résultat de l'analyse:

                C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133775.exe -> Adware.180Solutions : Aucune action entreprise.
                C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133780.exe -> Adware.180Solutions : Aucune action entreprise.
                C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll -> Adware.BHO : Aucune action entreprise.
                C:\Program Files\Trend Micro\HijackThis\backups\backup-20071209-211750-676.dll -> Adware.BHO : Aucune action entreprise.
                C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133727.exe -> Adware.HotBar : Aucune action entreprise.
                C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133732.exe -> Adware.HotBar : Aucune action entreprise.
                C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133733.dll -> Adware.HotBar : Aucune action entreprise.
                C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133734.dll -> Adware.Hotbar : Aucune action entreprise.
                C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133736.exe -> Adware.HotBar : Aucune action entreprise.
                C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133737.exe -> Adware.Hotbar : Aucune action entreprise.
                C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133738.dll -> Adware.HotBar : Aucune action entreprise.
                C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133740.exe -> Adware.HotBar : Aucune action entreprise.
                C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133741.exe -> Adware.HotBar : Aucune action entreprise.
                C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133742.dll -> Adware.HotBar : Aucune action entreprise.
                C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133743.dll -> Adware.Hotbar : Aucune action entreprise.
                C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133747.exe -> Adware.HotBar : Aucune action entreprise.
                C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133749.dll -> Adware.HotBar : Aucune action entreprise.
                C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133750.dll -> Adware.HotBar : Aucune action entreprise.
                C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133751.exe -> Adware.HotBar : Aucune action entreprise.
                C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133752.dll -> Adware.HotBar : Aucune action entreprise.
                C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133753.dll -> Adware.Hotbar : Aucune action entreprise.
                C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133754.dll -> Adware.HotBar : Aucune action entreprise.
                C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133755.dll -> Adware.HotBar : Aucune action entreprise.
                C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133756.exe -> Adware.HotBar : Aucune action entreprise.
                C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133757.exe -> Adware.HotBar : Aucune action entreprise.
                C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133758.dll -> Adware.HotBar : Aucune action entreprise.
                C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133760.exe -> Adware.Hotbar : Aucune action entreprise.
                C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133761.exe -> Adware.Hotbar : Aucune action entreprise.
                C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133763.dll -> Adware.HotBar : Aucune action entreprise.
                C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133764.dll -> Adware.HotBar : Aucune action entreprise.
                C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133765.exe -> Adware.HotBar : Aucune action entreprise.
                C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133766.dll -> Adware.HotBar : Aucune action entreprise.
                C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133767.dll -> Adware.Hotbar : Aucune action entreprise.
                C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133768.dll -> Adware.HotBar : Aucune action entreprise.
                C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133769.dll -> Adware.HotBar : Aucune action entreprise.
                C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133770.exe -> Adware.HotBar : Aucune action entreprise.
                C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133771.exe -> Adware.HotBar : Aucune action entreprise.
                C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133772.dll -> Adware.Hotbar : Aucune action entreprise.
                C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133773.dll -> Adware.Hotbar : Aucune action entreprise.
                C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133774.exe -> Adware.HotBar : Aucune action entreprise.
                C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133778.dll -> Adware.HotBar : Aucune action entreprise.
                C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133779.dll -> Adware.Hotbar : Aucune action entreprise.
                C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133781.dll -> Adware.HotBar : Aucune action entreprise.
                C:\Documents and Settings\Administrateur\Cookies\administrateur@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Aucune action entreprise.
                C:\Documents and Settings\Administrateur\Cookies\administrateur@advertising[2].txt -> TrackingCookie.Advertising : Aucune action entreprise.
                C:\Documents and Settings\Administrateur\Cookies\administrateur@doubleclick[1].txt -> TrackingCookie.Doubleclick : Aucune action entreprise.
                C:\Documents and Settings\Administrateur\Cookies\administrateur@ssl-hints.netflame[2].txt -> TrackingCookie.Netflame : Aucune action entreprise.
                C:\Documents and Settings\Administrateur\Cookies\administrateur@bs.serving-sys[2].txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
                C:\Documents and Settings\Administrateur\Cookies\administrateur@serving-sys[1].txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
                C:\Documents and Settings\Administrateur\Cookies\administrateur@smartadserver[1].txt -> TrackingCookie.Smartadserver : Aucune action entreprise.

                Fin du rapport
                0
                1. voici le raport du scan ke j ai effectuer avec pAVG Anti-Spyware - Rapport d'analyse
                  ---------------------------------------------------------

                  + Créé à: 21:21 10/12/2007

                  + Résultat de l'analyse:

                  C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133775.exe -> Adware.180Solutions : Aucune action entreprise.
                  C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133780.exe -> Adware.180Solutions : Aucune action entreprise.
                  C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll -> Adware.BHO : Aucune action entreprise.
                  C:\Program Files\Trend Micro\HijackThis\backups\backup-20071209-211750-676.dll -> Adware.BHO : Aucune action entreprise.
                  C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133727.exe -> Adware.HotBar : Aucune action entreprise.
                  C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133732.exe -> Adware.HotBar : Aucune action entreprise.
                  C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133733.dll -> Adware.HotBar : Aucune action entreprise.
                  C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133734.dll -> Adware.Hotbar : Aucune action entreprise.
                  C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133736.exe -> Adware.HotBar : Aucune action entreprise.
                  C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133737.exe -> Adware.Hotbar : Aucune action entreprise.
                  C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133738.dll -> Adware.HotBar : Aucune action entreprise.
                  C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133740.exe -> Adware.HotBar : Aucune action entreprise.
                  C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133741.exe -> Adware.HotBar : Aucune action entreprise.
                  C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133742.dll -> Adware.HotBar : Aucune action entreprise.
                  C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133743.dll -> Adware.Hotbar : Aucune action entreprise.
                  C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133747.exe -> Adware.HotBar : Aucune action entreprise.
                  C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133749.dll -> Adware.HotBar : Aucune action entreprise.
                  C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133750.dll -> Adware.HotBar : Aucune action entreprise.
                  C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133751.exe -> Adware.HotBar : Aucune action entreprise.
                  C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133752.dll -> Adware.HotBar : Aucune action entreprise.
                  C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133753.dll -> Adware.Hotbar : Aucune action entreprise.
                  C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133754.dll -> Adware.HotBar : Aucune action entreprise.
                  C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133755.dll -> Adware.HotBar : Aucune action entreprise.
                  C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133756.exe -> Adware.HotBar : Aucune action entreprise.
                  C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133757.exe -> Adware.HotBar : Aucune action entreprise.
                  C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133758.dll -> Adware.HotBar : Aucune action entreprise.
                  C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133760.exe -> Adware.Hotbar : Aucune action entreprise.
                  C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133761.exe -> Adware.Hotbar : Aucune action entreprise.
                  C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133763.dll -> Adware.HotBar : Aucune action entreprise.
                  C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133764.dll -> Adware.HotBar : Aucune action entreprise.
                  C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133765.exe -> Adware.HotBar : Aucune action entreprise.
                  C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133766.dll -> Adware.HotBar : Aucune action entreprise.
                  C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133767.dll -> Adware.Hotbar : Aucune action entreprise.
                  C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133768.dll -> Adware.HotBar : Aucune action entreprise.
                  C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133769.dll -> Adware.HotBar : Aucune action entreprise.
                  C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133770.exe -> Adware.HotBar : Aucune action entreprise.
                  C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133771.exe -> Adware.HotBar : Aucune action entreprise.
                  C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133772.dll -> Adware.Hotbar : Aucune action entreprise.
                  C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133773.dll -> Adware.Hotbar : Aucune action entreprise.
                  C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133774.exe -> Adware.HotBar : Aucune action entreprise.
                  C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133778.dll -> Adware.HotBar : Aucune action entreprise.
                  C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133779.dll -> Adware.Hotbar : Aucune action entreprise.
                  C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133781.dll -> Adware.HotBar : Aucune action entreprise.
                  C:\Documents and Settings\Administrateur\Cookies\administrateur@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Aucune action entreprise.
                  C:\Documents and Settings\Administrateur\Cookies\administrateur@advertising[2].txt -> TrackingCookie.Advertising : Aucune action entreprise.
                  C:\Documents and Settings\Administrateur\Cookies\administrateur@doubleclick[1].txt -> TrackingCookie.Doubleclick : Aucune action entreprise.
                  C:\Documents and Settings\Administrateur\Cookies\administrateur@ssl-hints.netflame[2].txt -> TrackingCookie.Netflame : Aucune action entreprise.
                  C:\Documents and Settings\Administrateur\Cookies\administrateur@bs.serving-sys[2].txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
                  C:\Documents and Settings\Administrateur\Cookies\administrateur@serving-sys[1].txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
                  C:\Documents and Settings\Administrateur\Cookies\administrateur@smartadserver[1].txt -> TrackingCookie.Smartadserver : Aucune action entreprise.

                  Fin du rapport

                  anda
                  0
                  1. Contributeur sécurité
                    ok,

                    pour AVG tu ne l'as pas paramétré pour qu'il mette en quarantaine ?

                    si c'est le cas, il te faut recommencer.
                    Lance AVG Anti-Spyware
                    
                    Clique sur le bouton Analyse (de la barre d'outils)
                    
                    puis fait dans l'ordre stp. Tu sauvegardes le rapport APRES avoir mis les actions.
                    
                    Puis sur l'onglet Paramètres,
                    sous : "Comment réagir "clique sur Actions recommandées. Sélectionne Quarantaine.
                    
                    Reviens à l'onglet Analyse. Clique sur Analyse complète du système.
                    
                    A la fin du scan, choisis l'option 3
                    
                    "Appliquer toutes les actions " en bas.
                    
                    Clique sur "Enregistrer le rapport".
                    0
                    1. voila jai fai les manips demaner,j envoie un rapport hijacthis
                      Logfile of Trend Micro HijackThis v2.0.2
                      Scan saved at 23:17, on 10/12/2007
                      Platform: Windows XP SP2 (WinNT 5.01.2600)
                      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                      Boot mode: Normal

                      Running processes:
                      C:\WINDOWS\System32\smss.exe
                      C:\WINDOWS\system32\winlogon.exe
                      C:\WINDOWS\system32\services.exe
                      C:\WINDOWS\system32\lsass.exe
                      C:\WINDOWS\system32\Ati2evxx.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\WINDOWS\system32\spoolsv.exe
                      C:\WINDOWS\system32\Ati2evxx.exe
                      C:\WINDOWS\Explorer.EXE
                      C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
                      C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
                      C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
                      C:\Program Files\Fichiers communs\Network Associates\TalkBack\TBMon.exe
                      C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
                      C:\WINDOWS\Mixer.exe
                      C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                      C:\WINDOWS\SOUNDMAN.EXE
                      C:\Program Files\Fichiers communs\Logitech\QCDriver2\LVCOMS.EXE
                      C:\WINDOWS\system32\Fmctrl.EXE
                      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                      C:\Program Files\Network Associates\McAfee Desktop Firewall for Windows XP\FireTray.exe
                      C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
                      C:\Program Files\Network Associates\McAfee Desktop Firewall for Windows XP\FireSvc.exe
                      C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
                      C:\Program Files\Network Associates\VirusScan\Mcshield.exe
                      C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\system32\WgaTray.exe
                      C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
                      C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
                      C:\Program Files\internet explorer\iexplore.exe
                      C:\Program Files\internet explorer\iexplore.exe
                      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
                      O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\PROGRA~1\Skype\Phone\IEPlugin\SkypeIEPlugin.dll
                      O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO.dll
                      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
                      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
                      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
                      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
                      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
                      O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
                      O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
                      O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Fichiers communs\Network Associates\TalkBack\TBMon.exe"
                      O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
                      O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
                      O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
                      O4 - HKLM\..\Run: [C-Media Speaker Configuration] C:\PROGRA~1\C-Media\WIN_ME\Setup.exe /SPEAKER
                      O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                      O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Fichiers communs\Logitech\QCDriver2\LVCOMS.EXE
                      O4 - HKLM\..\Run: [FmctrlTray] Fmctrl.EXE
                      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\K-Lite Codec Pack\QuickTime\qttask.exe" -atboottime
                      O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                      O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
                      O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
                      O4 - Global Startup: McAfee Desktop Firewall Tray.lnk = ?
                      O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
                      O8 - Extra context menu item: Download all links using BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
                      O8 - Extra context menu item: Download all videos using BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
                      O8 - Extra context menu item: Download link using &BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
                      O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\PROGRA~1\Skype\Phone\IEPlugin\SkypeIEPlugin.dll
                      O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
                      O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
                      O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\Skype4COM.dll
                      O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                      O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                      O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
                      O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                      O23 - Service: McAfee Desktop Firewall Service (FireSvc) - Networks Associates Technology, Inc. - C:\Program Files\Network Associates\McAfee Desktop Firewall for Windows XP\FireSvc.exe
                      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
                      O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
                      O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
                      O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
                      0
                      1. Contributeur sécurité
                        je ne sais pas si tu auras vu ce que je t'ai mis au post 73

                        j'attends ta réponse pour la suite

                        0
                        1. Contributeur sécurité
                          je pense que ce sera pour demain vu l'heure.

                          0
                          1. voici le nouveau rapport avg(en esperant ke jai reussi la manip)lol
                            AVG Anti-Spyware - Rapport d'analyse
                            ---------------------------------------------------------

                            + Créé à: 00:35 11/12/2007

                            + Résultat de l'analyse:

                            C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133775.exe -> Adware.180Solutions : Nettoyé.
                            C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133780.exe -> Adware.180Solutions : Nettoyé.
                            C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll -> Adware.BHO : Nettoyé.
                            C:\Program Files\Trend Micro\HijackThis\backups\backup-20071209-211750-676.dll -> Adware.BHO : Nettoyé.
                            C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133727.exe -> Adware.HotBar : Nettoyé.
                            C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133732.exe -> Adware.HotBar : Nettoyé.
                            C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133733.dll -> Adware.HotBar : Nettoyé.
                            C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133734.dll -> Adware.Hotbar : Nettoyé.
                            C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133736.exe -> Adware.HotBar : Nettoyé.
                            C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133737.exe -> Adware.Hotbar : Nettoyé.
                            C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133738.dll -> Adware.HotBar : Nettoyé.
                            C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133740.exe -> Adware.HotBar : Nettoyé.
                            C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133741.exe -> Adware.HotBar : Nettoyé.
                            C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133742.dll -> Adware.HotBar : Nettoyé.
                            C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133743.dll -> Adware.Hotbar : Nettoyé.
                            C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133747.exe -> Adware.HotBar : Nettoyé.
                            C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133749.dll -> Adware.HotBar : Nettoyé.
                            C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133750.dll -> Adware.HotBar : Nettoyé.
                            C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133751.exe -> Adware.HotBar : Nettoyé.
                            C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133752.dll -> Adware.HotBar : Nettoyé.
                            C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133753.dll -> Adware.Hotbar : Nettoyé.
                            C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133754.dll -> Adware.HotBar : Nettoyé.
                            C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133755.dll -> Adware.HotBar : Nettoyé.
                            C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133756.exe -> Adware.HotBar : Nettoyé.
                            C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133757.exe -> Adware.HotBar : Nettoyé.
                            C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133758.dll -> Adware.HotBar : Nettoyé.
                            C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133760.exe -> Adware.Hotbar : Nettoyé.
                            C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133761.exe -> Adware.Hotbar : Nettoyé.
                            C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133763.dll -> Adware.HotBar : Nettoyé.
                            C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133764.dll -> Adware.HotBar : Nettoyé.
                            C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133765.exe -> Adware.HotBar : Nettoyé.
                            C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133766.dll -> Adware.HotBar : Nettoyé.
                            C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133767.dll -> Adware.Hotbar : Nettoyé.
                            C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133768.dll -> Adware.HotBar : Nettoyé.
                            C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133769.dll -> Adware.HotBar : Nettoyé.
                            C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133770.exe -> Adware.HotBar : Nettoyé.
                            C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133771.exe -> Adware.HotBar : Nettoyé.
                            C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133772.dll -> Adware.Hotbar : Nettoyé.
                            C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133773.dll -> Adware.Hotbar : Nettoyé.
                            C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133774.exe -> Adware.HotBar : Nettoyé.
                            C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133778.dll -> Adware.HotBar : Nettoyé.
                            C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133779.dll -> Adware.Hotbar : Nettoyé.
                            C:\System Volume Information\_restore{F10B95C6-EA74-46AE-9729-9F4CAB51CFD2}\RP455\A0133781.dll -> Adware.HotBar : Nettoyé.
                            C:\Documents and Settings\Administrateur\Cookies\administrateur@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Nettoyé.
                            C:\Documents and Settings\Administrateur\Cookies\administrateur@advertising[2].txt -> TrackingCookie.Advertising : Nettoyé.
                            C:\Documents and Settings\Administrateur\Cookies\administrateur@doubleclick[1].txt -> TrackingCookie.Doubleclick : Nettoyé.
                            C:\Documents and Settings\Administrateur\Cookies\administrateur@bs.serving-sys[2].txt -> TrackingCookie.Serving-sys : Nettoyé.
                            C:\Documents and Settings\Administrateur\Cookies\administrateur@serving-sys[1].txt -> TrackingCookie.Serving-sys : Nettoyé.

                            Fin du rapport
                            0
                            1. re, philae83,
                              ;-)
                              "pour acrobat qui n'est pas à jour, je sais mais je pense que ce n'est pas la priorité, je vois ça à la fin.
                              "
                              tu parlais de Java je suppose ?
                              Ceci dit , ne pas le négliger ni l'oublier !...c'est une porte ouverte, il faut la fermer au plus tôt....
                              ---------
                              perso, j'ai un doute sur la validité des points de restaurations, m'étonnerai qu'un point de resto, fonctionne même après une désinfection...je ne sais ce que tu en pense?
                              (Perso je ferai la manip de suppression de la restauration système, et refaire un point dès que le PC est clean.)

                              (je t'avoue que j'ai déjà eu le cas...après désinfection, le point de resto est inutilisable !)
                              A+
                              cordialement

                              0
                              1. Contributeur sécurité
                                hello philo

                                Ceci dit , ne pas le négliger ni l'oublier !...c'est une porte ouverte, il faut la fermer au plus tôt.... 


                                oui c'est sûr, et oui je parlais de Java, mais comme souvent les 2 ne sont pas à jour....j'ai confondu
                                erso, j'ai un doute sur la validité des points de restaurations, m'étonnerai qu'un point de resto, fonctionne même après une désinfection...je ne sais ce que tu en pense?
                                (Perso je ferai la manip de suppression de la restauration système, et refaire un point dès que le PC est clean.)(je t'avoue que j'ai déjà eu le cas...après désinfection, le point de resto est inutilisable !) 
                                


                                MP
                                0
                            2. Contributeur sécurité
                              bonjour,

                              je n'ai plus souvenir si on a fait un scan en ligne (pas relu les 4 pages)

                              il serait bien d'en effectuer un de toutes façons maintenant

                              * Fait un scan antivirus en ligne Panda et copie colle le résultat ici
                              https://www.pandasecurity.com/en/homeusers/online-antivirus/?ref=activescan
                              (avec Internet Explorer et désactive ton Antivirus pendant le scan)

                              * tuto en image
                              http://pageperso.aol.fr/loraline60/panda_scan.htm

                              et également relance combofix et poste le rapport stp ainsi qu'un nouveau rapport hijackthis pour faire le point de tout tes problèmes
                              0
                              1. bonsoir j espere ke vous allez bien .
                                je vais ce ki es demander
                                0
                                Précédent
                                • 1
                                • 2
                                • 3
                                • 4
                                • 5
                                • 6
                                • 7
                                • 8