Virus SYSTEM32 - Page 2

Précédent
  • 1
  • 2
  1. wolvv
     
    Ok je te fais coniance ;-)

    Que dois-je faire pour Mc Afee et Messenger plus?
    Non je n'ai pas installé les sponsors si j'ai bon souvenir!

    Et pour les commandes?
    0
  2. g!rly Messages postés 18462 Statut Contributeur 407
     
    re,

    pour m´avoir repondu aussi vite tu n´as pas du lire le lien que je t´ai donné concernant avast au post 19, ou les messages se sont croisés...

    Desinstaller McAfee:
    http://tools.mcafeehelp.com/doc.php?siteid=1&docid=71541&support=ts

    je t´ai demandé si tu avais des pubs cid si tu n´en as pas et que tu ´as pas installé le sponssor avec messenger plus dans ce cas tu peux le garder...

    oui tu n´as plus de trojant detecté par avast mais regarde le lien que je t´ai donné au post 19, tu realiseras par toi meme qu´avast, no comment

    @+
    0
  3. wolvv
     
    Si je viens de lire mais je ne m'y connait pas beaucoup alors je te fais confiance!
    Je vais esayer de desinstaller completement Mc Afee et puis je desinstalle avast , j'installe Antivir et je fais le scan en MSE
    0
  4. wolvv
     
    Le lien vers le site de mc Afee ne marche pas
    0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. g!rly Messages postés 18462 Statut Contributeur 407
     
    merci de me signaler...

    il a l´air vraiment difficile a desinstaller car je ne trouve pas le desinstalleur...

    tous ce que j´ai trouvé c´est ceci :

    http://knowledge.mcafee.com/...

    @+
    0
  7. wolvv
     
    J'ai utiliser un removal tools fourni par Mc Afee j'espere qu'il ne reste plus de trace
    J'ai fait le scan ca a pris plus de 3 heures et voila le rapport

    AntiVir PersonalEdition Classic
    Report file date: 2008-01-26 13:47

    Scanning for 1070348 virus strains and unwanted programs.

    Licensed to: Avira AntiVir PersonalEdition Classic
    Serial number: 0000149996-ADJIE-0001
    Platform: Windows XP
    Windows version: (Service Pack 2) [5.1.2600]
    Username: François
    Computer name: PAVILION

    Version information:
    BUILD.DAT : 270 15603 Bytes 19/09/2007 13:32:00
    AVSCAN.EXE : 7.0.6.1 290856 Bytes 23/08/2007 13:16:29
    AVSCAN.DLL : 7.0.6.0 49192 Bytes 16/08/2007 12:23:51
    LUKE.DLL : 7.0.5.3 147496 Bytes 14/08/2007 15:32:47
    LUKERES.DLL : 7.0.6.1 10280 Bytes 21/08/2007 12:35:20
    ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 12:39:17
    ANTIVIR1.VDF : 7.0.1.95 3367424 Bytes 14/12/2007 12:39:18
    ANTIVIR2.VDF : 7.0.2.49 1339904 Bytes 25/01/2008 12:39:18
    ANTIVIR3.VDF : 7.0.2.50 2048 Bytes 25/01/2008 12:39:18
    AVEWIN32.DLL : 7.6.0.56 3215872 Bytes 26/01/2008 12:39:20
    AVWINLL.DLL : 1.0.0.7 14376 Bytes 26/02/2007 10:36:26
    AVPREF.DLL : 7.0.2.2 25640 Bytes 18/07/2007 07:39:17
    AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 13:16:24
    AVPACK32.DLL : 7.6.0.3 360488 Bytes 26/01/2008 12:39:20
    AVREG.DLL : 7.0.1.6 30760 Bytes 18/07/2007 07:17:06
    AVARKT.DLL : 1.0.0.20 278568 Bytes 28/08/2007 12:26:33
    AVEVTLOG.DLL : 7.0.0.20 86056 Bytes 18/07/2007 07:10:18
    NETNT.DLL : 7.0.0.0 7720 Bytes 08/03/2007 11:09:42
    RCIMAGE.DLL : 7.0.1.30 2342952 Bytes 07/08/2007 12:38:13
    RCTEXT.DLL : 7.0.62.0 86056 Bytes 21/08/2007 12:50:37
    SQLITE3.DLL : 3.3.17.1 339968 Bytes 23/07/2007 09:37:21

    Configuration settings for the scan:
    Jobname..........................: Complete system scan
    Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
    Logging..........................: low
    Primary action...................: interactive
    Secondary action.................: ignore
    Scan master boot sector..........: off
    Scan boot sector.................: on
    Boot sectors.....................: D:,
    Scan memory......................: on
    Process scan.....................: on
    Scan registry....................: on
    Search for rootkits..............: off
    Scan all files...................: All files
    Scan archives....................: on
    Recursion depth..................: 20
    Smart extensions.................: on
    Macro heuristic..................: on
    File heuristic...................: high

    Start of the scan: 2008-01-26 13:47

    The scan of running processes will be started
    Scan process 'avscan.exe' - '1' Module(s) have been scanned
    Scan process 'avcenter.exe' - '1' Module(s) have been scanned
    Scan process 'explorer.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'lsass.exe' - '1' Module(s) have been scanned
    Scan process 'services.exe' - '1' Module(s) have been scanned
    Scan process 'winlogon.exe' - '1' Module(s) have been scanned
    Scan process 'csrss.exe' - '1' Module(s) have been scanned
    Scan process 'smss.exe' - '1' Module(s) have been scanned
    11 processes with 11 modules were scanned

    Start scanning boot sectors:
    Boot sector 'C:\'
    [NOTE] No virus was found!
    Boot sector 'D:\'
    [NOTE] No virus was found!

    Starting to scan the registry.
    The registry was scanned ( '43' files ).

    Starting the file scan:

    Begin scan in 'C:\' <HP_PAVILION>
    C:\pagefile.sys
    [WARNING] The file could not be opened!
    C:\Documents and Settings\François\Bureau\catchme.zip
    [0] Archive type: ZIP
    --> ljjhghh.dll
    [DETECTION] Is the Trojan horse TR/Vundo.Gen
    [WARNING] The file was ignored!
    C:\Documents and Settings\François\Bureau\MSNFix\MSNFix\mer. 23012008_18280467.zip
    [0] Archive type: ZIP
    --> backup/b128.exe
    [DETECTION] Is the Trojan horse TR/Dldr.Agent.ezc.1
    --> backup/mrofinu1000106.exe
    [DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
    --> backup/mrofinu572.exe
    [DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
    --> backup/mrofinu572.exe.tmp
    [DETECTION] Is the Trojan horse TR/Crypt.ULPM.Gen
    [INFO] The file was moved to '480d31d7.qua'!
    C:\Documents and Settings\François\Bureau\SDFix\backups\backups.zip
    [0] Archive type: ZIP
    --> backups/kernInst.exe
    [DETECTION] Is the Trojan horse TR/Agent.edq
    [INFO] The file was moved to '47fe31dc.qua'!
    C:\Documents and Settings\François\Local Settings\Temporary Internet Files\Content.IE5\61GHW1MT\css4[1]
    [DETECTION] Is the Trojan horse TR/Vundo.DWK
    [INFO] The file was moved to '480e32da.qua'!
    C:\Documents and Settings\François\Local Settings\Temporary Internet Files\Content.IE5\EYK2ZL0F\css4[1]
    [DETECTION] Is the Trojan horse TR/Vundo.DWK
    [INFO] The file was moved to '480e33b1.qua'!
    C:\Documents and Settings\François\Local Settings\Temporary Internet Files\Content.IE5\HYDYT568\css4[1]
    [DETECTION] Is the Trojan horse TR/Vundo.DWK
    [INFO] The file was moved to '480e33cc.qua'!
    C:\Documents and Settings\François\Local Settings\Temporary Internet Files\Content.IE5\LJI4GWCQ\css4[1]
    [DETECTION] Is the Trojan horse TR/Vundo.DWK
    [INFO] The file was moved to '480e33f1.qua'!
    C:\Documents and Settings\Propriétaire\Local Settings\Temporary Internet Files\Content.IE5\C5UB8D2F\css4[1]
    [DETECTION] Is the Trojan horse TR/Vundo.DWK
    [INFO] The file was moved to '480e3f1d.qua'!
    C:\Documents and Settings\Propriétaire\Local Settings\Temporary Internet Files\Content.IE5\Q3IBUTIF\css4[1]
    [DETECTION] Is the Trojan horse TR/Vundo.DWK
    [INFO] The file was moved to '480e4188.qua'!
    C:\QooBox\Quarantine\C\WINDOWS\system32\ljjhghh.dll.vir
    [DETECTION] Is the Trojan horse TR/Trash.Gen
    [INFO] The file was moved to '4805520e.qua'!
    C:\QooBox\Quarantine\C\WINDOWS\system32\xxyvvsp.dll.vir
    [DETECTION] Is the Trojan horse TR/Vundo.Gen
    [INFO] The file was moved to '4814521e.qua'!
    C:\WINDOWS\$NtUninstallKB824141$\user32.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB824141$\win32k.sys
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB826939$\accwiz.exe
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB826939$\crypt32.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB826939$\cryptsvc.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB826939$\hh.exe
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB826939$\hhsetup.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB826939$\itss.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB826939$\locator.exe
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB826939$\magnify.exe
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB826939$\migwiz.exe
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB826939$\mrxsmb.sys
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB826939$\msconv97.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB826939$\narrator.exe
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB826939$\newdev.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB826939$\ntdll.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB826939$\ntkrnlpa.exe
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB826939$\ntoskrnl.exe
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB826939$\osk.exe
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB826939$\pchshell.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB826939$\raspptp.sys
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB826939$\shell32.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB826939$\shmedia.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB826939$\srrstr.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB826939$\srv.sys
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB826939$\user32.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB826939$\win32k.sys
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB826939$\winsrv.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB826939$\zipfldr.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB826942$\dhcpcsvc.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB826942$\ndis.sys
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB826942$\ndisuio.sys
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB826942$\netshell.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB826942$\wzcdlg.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB826942$\wzcsapi.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB826942$\wzcsvc.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB828028$\msasn1.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB828035$\msgsvc.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB828035$\wkssvc.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB828741$\catsrv.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB828741$\catsrvut.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB828741$\clbcatex.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB828741$\clbcatq.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB828741$\colbact.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB828741$\comadmin.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB828741$\comrepl.exe
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB828741$\comsvcs.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB828741$\comuid.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB828741$\es.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB828741$\migregdb.exe
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB828741$\msdtcprx.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB828741$\msdtctm.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB828741$\msdtcuiu.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB828741$\mtxclu.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB828741$\mtxoci.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB828741$\ole32.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB828741$\rpcrt4.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB828741$\rpcss.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB828741$\txflog.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB829558$\dao360.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB829558$\expsrv.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB829558$\msexch40.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB829558$\msexcl40.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB829558$\msjet40.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB829558$\msjetol1.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB829558$\msjetoledb40.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB829558$\msjint40.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB829558$\msjter40.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB829558$\msjtes40.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB829558$\msltus40.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB829558$\mspbde40.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB829558$\msrd2x40.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB829558$\msrd3x40.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB829558$\msrepl40.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB829558$\mstext40.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB829558$\mswdat10.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB829558$\mswstr10.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB829558$\msxbde40.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB829558$\vbajet32.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB835732$\callcont.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB835732$\gdi32.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB835732$\h323msp.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB835732$\helpctr.exe
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB835732$\ipnathlp.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB835732$\lsasrv.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB835732$\mf3216.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB835732$\msasn1.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB835732$\msgina.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB835732$\mst120.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB835732$\netapi32.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB835732$\nmcom.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB835732$\rtcdll.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB835732$\schannel.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB835732$\xpsp2res.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB837001$\dao360.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB837001$\msexcl40.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB837001$\msjet40.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB837001$\msjetol1.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB837001$\msjetoledb40.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB837001$\msjtes40.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB839645$\fldrclnr.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB839645$\shell32.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB839645$\shlwapi.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB839645$\sxs.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallKB839645$\xpsp2res.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\$NtUninstallQ828026$\wmp.dll
    [WARNING] The file could not be opened!
    C:\WINDOWS\Downloaded Program Files\McUpdatePortal.dll
    [DETECTION] Contains suspicious code HEUR/Malware
    [INFO] The file was moved to '47f054d9.qua'!
    C:\WINDOWS\system32\nGpxx01\nGpxx011065.exe
    [DETECTION] Is the Trojan horse TR/Dldr.VB.cge
    [INFO] The file was moved to '480b5a6a.qua'!
    Begin scan in 'D:\'

    End of the scan: 2008-01-26 17:23
    Used time: 3:35:47 min

    The scan has been done completely.

    10724 Scanning directories
    806377 Files were scanned
    15 viruses and/or unwanted programs were found
    1 Files were classified as suspicious:
    0 files were deleted
    0 files were repaired
    12 files were moved to quarantine
    0 files were renamed
    107 Files cannot be scanned
    806362 Files not concerned
    20304 Archives were scanned
    108 Warnings
    4 Notes

    PS: j'ai oublier d'installer Zone Alarm
    Je n'ai pas encore supprimer les programmes que j'ai du installer
    0
  8. g!rly Messages postés 18462 Statut Contributeur 407
     
    salut wolvv,

    tres bien pour mc afee

    fais ceci :

    Désactive ta restauration système:
    pour cela :
    Click droit sur poste de travail, dans l´arborescence sur propriétés;
    dans la nouvelle fenettre click sur l´onglet restauration système;
    coche la case désactiver la restauration systèm et applique.
    puis redemarre le pc et click droit sur poste de travail, dans l´arborescence sur propriétés;
    dans la nouvelle fenettre click sur l´onglet restauration systèm
    décoche la case désactiver la restauration systèm et applique.

    comment va ton pc a present ?

    montres moi encore un hijack this stp

    @+
    0
  9. wolvv
     
    Juste avant de désactivé puis réactiver la restauration systeme Antivir m'a detecter un virus
    dans :C\System Volume Information\restore...

    Est ce grave ou est ce simplement du au fait que je n'ai pas encore effectuer l'operation que tu m'avais dit de faire??

    Voila le log Hijackthis:
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 22:04, on 2008-01-27
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16574)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    C:\WINDOWS\Explorer.EXE
    C:\windows\system\hpsysdrv.exe
    C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
    C:\WINDOWS\System32\hphmon05.exe
    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\Program Files\Multimedia Card Reader\shwicon2k.exe
    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADE.EXE
    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    C:\HP\KBD\KBD.EXE
    C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe
    C:\WINDOWS\system32\ezSP_Px.exe
    C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Microsoft ActiveSync\wcescomm.exe
    C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
    C:\WINDOWS\System32\svchost.exe
    C:\PROGRA~1\MI3AA1~1\rapimgr.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.be/?gws_rd=ssl
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
    O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
    O3 - Toolbar: &Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
    O4 - HKLM\..\Run: [CamMonitor] c:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
    O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
    O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
    O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [Sunkist2k] C:\Program Files\Multimedia Card Reader\shwicon2k.exe
    O4 - HKLM\..\Run: [EPSON Stylus DX4800 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADE.EXE /P26 "EPSON Stylus DX4800 Series" /O6 "USB001" /M "Stylus DX4800"
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
    O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" /r
    O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\system32\ezSP_Px.exe
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
    O4 - HKCU\..\Run: [BackupNotify] c:\Program Files\Hewlett-Packard\Digital Imaging\bin\backupnotify.exe
    O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe" /WinStart
    O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
    O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
    O4 - HKUS\S-1-5-18\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'Default user')
    O4 - .DEFAULT User Startup: mod_sm.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
    O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
    O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
    O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
    O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-BE/a-UNO1/GAME_UNO1.cab
    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
    O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
    O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://belgacom.extrafilm.be/ImageUploader4.cab
    O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - https://www.touslesdrivers.com/index.php?v_page=29
    O16 - DPF: {A73BAEFA-EE65-494D-BEDB-DD3E5A34FA98} (Image Uploader) - http://belgacom.extrafilm.be/ImageUploader4.cab
    O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
    O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    O23 - Service: lgfpeiylefnf (gffqmhdh6) - Unknown owner - C:\WINDOWS\system32\nkwgtxwy6.exe (file missing)
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Fichiers communs\Macromedia Shared\Service\Macromedia Licensing.exe
    O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
    O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\FICHIE~1\SONYSH~1\AVLib\Sptisrv.exe
    O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
    0
  10. g!rly Messages postés 18462 Statut Contributeur 407
     
    salut wolvv,

    c´est bien pour cela que je t´ai demandé de desactiver la restauration system ;-)

    volume system information = restauration system-

    maintenant fix et coche les ligne ci dessous

    O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
    O3 - Toolbar: &Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
    O23 - Service: lgfpeiylefnf (gffqmhdh6) - Unknown owner - C:\WINDOWS\system32\nkwgtxwy6.exe (file missing)

    comment fixer :

    Tutoriel d´utilisation (video) :

    -> http://pageperso.aol.fr/balltrap34/demohijack.htm

    puis :

    1°- « Démarrer » > « Executer » > taper cmd > valide par ok

    sc stop "lgfpeiylefnf" ==> [Enter]

    sc delete "lgfpeiylefnf" ==> [Enter]

    note : respect les espaces...

    instales un par feu :

    par feu : kerio

    http://www.malekal.com/kerio_firewall.php#mozTocId721480

    https://www.vulgarisation-informatique.com/kerio.php

    https://kerio.probb.fr/f2-sunbelt-kerio-personal-firewall

    ou zone alarm plus facil a configurer mais moins performant

    https://www.malekal.com/tutoriel-zonealarm-firewall/

    ta version de acrobat reader n´est pas a jour, tu veux la version 8.1 derniere en date alors desinstale ta version par le panneau de configuration / ajoue et suppression de programme

    et instale la derniere :

    https://get2.adobe.com/reader/otherversions/

    ou foxit plus léger :

    https://www.clubic.com/telecharger-fiche13808-foxit-reader.html

    @+
    0
  11. wolvv
     
    Je n'ai pas su effectuer :

    1°- « Démarrer » > « Executer » > taper cmd > valide par ok

    sc stop "lgfpeiylefnf" ==> [Enter]

    sc delete "lgfpeiylefnf" ==> [Enter]

    note : respect les espaces...

    il me dit le service spécifié n'est pas installé!

    j'ai installé zone alarm et je crois avoir la version 8.1.1 de Acrobat Reader (selon le panneau ajout/suppresion de prog)

    sinon je n'ai plus de probleme

    Un tout tout grand merci a toi!
    0
  12. g!rly Messages postés 18462 Statut Contributeur 407
     
    salut wolf,

    essaie comme ca :

    1°- « Démarrer » > « Executer » > taper cmd > valide par ok

    sc stop "gffqmhdh6" ==> [Enter]

    sc delete "gffqmhdh6" ==> [Enter]

    note : respect les espaces...

    dis moi quoi

    @+
    0
  13. wolvv
     
    Ca a marcher il m'a mit DeleteService SUCESS apres la deuxieme commande!

    Un tout tout grand merci pour ton aide

    Je peux supprimer OTMoveit, Msn Fix, SDFIx et ComboFix??
    0
  14. g!rly Messages postés 18462 Statut Contributeur 407
     
    salut wolvv,

    cool ;-)

    tout va bien alors?!

    dans ce cas :

    oui tu peux supprimer msnfix, sdfix, ot_move it et combofix...

    @+
    0
Précédent
  • 1
  • 2