Solution pour Hijack this.
Blackout Sam Messages postés 195 Statut Membre -
Suite à une ordonnance de Hijack this, j'aurais aimé savoir ce que je dois virer pour alléger mon PC. un Porf D'info ma déjà donné quelques conseils, pouvez vous m'aider?
Merci D'avance...
- Solution pour Hijack this.
- Hijack this - Télécharger - Antivirus & Antimalwares
- Driverpack solution - Télécharger - Divers Utilitaires
- Ou est charlie le livre magique solution - Forum Loisirs / Divertissements
- Solution prs chronopost - Forum Mobile
- Ou est charlie solution tome 1 - Forum Loisirs / Divertissements
80 réponses
Le cas porte sur une infection détectée par HijackThis sur Windows Vista avec Internet Explorer 7, incluant Seekmo et divers BHO/Barres potentiellement malveillants.
Les mesures proposées préconisent d’exécuter Clean.zip pour générer un rapport détaillé et, le cas échéant, de lancer AVG Anti-Spyware 7.5 en analyse complète avec quarantaine.
Des actions manuelles consistent à désinstaller Spyware Doctor et d’autres programmes via Ajout/Suppression, puis à arrêter et désactiver des services problématiques et à fixer les entrées correspondantes dans HijackThis (O2/O3/O15 et BHO).
Enfin, CCleaner est recommandé pour nettoyer les fichiers temporaires et réparer les erreurs du registre, suivie d’un nouveau log HijackThis pour évaluer les éléments restants.
On va désinstaller Avast puis passer à Antivir,
Plus éfficace que ce dernier :
Comparatif par Malekal : http://forum.malekal.com/ftopic3528.php
_____________________________________________________
Pour Désinstaller Avast :
il faut le désinstaller à partir d'un prog :
https://www.avast.com/fr-fr/uninstall-utility
_____________________________________________________
Pour installer Antivir :
Telecharge Antivir: http://www.commentcamarche.net/telecharger/telecharger 55 antivir
Installe le.
Pendant l'installation, cocher la case "generate random serial..."
Lance Antivir,
fais les mises à jours, puis lance un scan (si des virus sont découverts, mets les en quarantaine. Si tu ne peux pas alors supprime les).
A la fin du scan clique sur 'report', enregistre ce rapport sur le bureau (fichier => enregistrer sous), puis fait un copier/coller de ce rapport dans ton prochain message.
----> Relance ton PC
Tutos : https://www.malekal.com/avira-free-security-antivirus-gratuit/
Si problème - mise à jour :
Telecharge la licence sur le site officiel :
http://dl1.avgate.net/down/windows/hbedv.key
Une fois telechargé, déplace le fichier téléchargé (hbedv.key) dans le dossier Antivir.
Par defaut : C:\Program Files\AntiVir PersonalEdition Classic
Refait la mise à jour, puis il ne sera plus périmé.
Et fait le scan comme indiqué plus haut.
_____________________________________________________
Post le rapport du Scan.
++
15.02.2008 21:52:03 - Backup Directory: C:\ProgramData\Avira\AntiVir PersonalEdition Classic\BACKUP\
15.02.2008 21:52:03 - Temp Directory: C:\ProgramData\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_47b5fb73\
15.02.2008 21:52:03 - Start the Update GUI... Displaymode: 0
15.02.2008 21:52:03 - Installation Directory: C:\Program Files\Avira\AntiVir PersonalEdition Classic\
15.02.2008 21:52:03 - Backup Directory: C:\ProgramData\Avira\AntiVir PersonalEdition Classic\BACKUP\
15.02.2008 21:52:03 - Temp Directory: C:\ProgramData\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_47b5fb73\
15.02.2008 21:52:03 - Start the Update GUI... Displaymode: 0
15.02.2008 21:52:04 - Keyfile: OK [FULL Mode]
15.02.2008 21:52:04 - Avira AntiVir PersonalEdition Classic
15.02.2008 21:52:25 - Connection failed while downloading the file http://dl6.avgate.net/upd/idx/master.idx
15.02.2008 21:52:25 - Switching to next update server
15.02.2008 21:52:47 - Connection failed while downloading the file http://dl1.avgate.net/upd/idx/master.idx
15.02.2008 21:52:47 - Switching to next update server
15.02.2008 21:52:48 - Master IDX file has changed
15.02.2008 21:52:51 - Keyfile: OK [FULL Mode]
15.02.2008 21:52:51 - Downloading the product.info file from http://dl3.avgate.net/upd/idx/classic-nt-en.info.gz
15.02.2008 21:52:53 - File basic-nt/2k/avgntflt.sys's operating system doesn't match the current one. File ignored.
15.02.2008 21:52:53 - File basic-nt/avgio64.sys's operating system doesn't match the current one. File ignored.
15.02.2008 21:52:53 - File basic-nt/imp64b.exe's operating system doesn't match the current one. File ignored.
15.02.2008 21:52:53 - File basic-nt/psapi.dll's operating system doesn't match the current one. File ignored.
15.02.2008 21:52:53 - File basic-nt/shlext64.dll's operating system doesn't match the current one. File ignored.
15.02.2008 21:52:53 - File basic-nt/vista64/avgntflt.sys's operating system doesn't match the current one. File ignored.
15.02.2008 21:52:53 - File basic-nt/xp64/avgntflt.sys's operating system doesn't match the current one. File ignored.
15.02.2008 21:52:53 - File basic-nt/2k/avgntdd.sys's operating system doesn't match the current one. File ignored.
15.02.2008 21:52:53 - File basic-nt/2k/avgntmgr.sys's operating system doesn't match the current one. File ignored.
15.02.2008 21:52:53 - File basic-nt/nt/avgntdd.sys's operating system doesn't match the current one. File ignored.
15.02.2008 21:52:53 - File basic-nt/nt/avgntmgr.sys's operating system doesn't match the current one. File ignored.
15.02.2008 21:52:53 - File basic-nt/vista64/avgntflt.sys's operating system doesn't match the current one. File ignored.
15.02.2008 21:52:53 - Downloading the product.info file from http://dl3.avgate.net/upd/idx/vdf.info.gz
15.02.2008 21:52:54 - Keyfile: OK [FULL Mode]
15.02.2008 21:52:54 - Downloading the product.info file from http://dl3.avgate.net/upd/idx/specvir-nt.info.gz
15.02.2008 21:52:55 - Downloading the product.info file from http://dl3.avgate.net/upd/idx/engine.info.gz
15.02.2008 21:52:57 - Downloading the product.info file from http://dl3.avgate.net/upd/idx/engine-nt-en.info.gz
15.02.2008 21:52:59 - Module: SELFUPDATE Source: winwks\en\ Destination: C:\Program Files\Avira\AntiVir PersonalEdition Classic\ Files: 15
15.02.2008 21:52:59 - C:\Program Files\Avira\AntiVir PersonalEdition Classic\updlib.dll 1.2.10.20 < 1.2.10.21
15.02.2008 21:52:59 - Module: MAIN Source: winwks\en\ Destination: C:\Program Files\Avira\AntiVir PersonalEdition Classic\ Files: 77
15.02.2008 21:52:59 - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avcenter.exe 7.2.0.12 < 7.2.0.14
15.02.2008 21:53:00 - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe 7.2.0.13 < 7.2.0.16
15.02.2008 21:53:00 - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe 7.0.0.81 < 7.0.0.82
15.02.2008 21:53:00 - C:\Program Files\Avira\AntiVir PersonalEdition Classic\ccguard.dll 7.0.1.34 < 7.0.1.35
15.02.2008 21:53:00 - C:\Program Files\Avira\AntiVir PersonalEdition Classic\preupd.exe 7.0.0.34 < 7.0.0.36
15.02.2008 21:53:00 - Module: COMMAPPDATA Source: winwks\en\ Destination: C:\ProgramData\ Files: 1
15.02.2008 21:53:00 - Module: TEXT Source: winwks\en\ Destination: C:\Program Files\Avira\AntiVir PersonalEdition Classic\ Files: 3
15.02.2008 21:53:01 - Module: VDF Source: vdf\ Destination: C:\Program Files\Avira\AntiVir PersonalEdition Classic\ Files: 4
15.02.2008 21:53:01 - C:\Program Files\Avira\AntiVir PersonalEdition Classic\antivir1.vdf 7.0.0.0 < 7.0.1.95
15.02.2008 21:53:01 - C:\Program Files\Avira\AntiVir PersonalEdition Classic\antivir2.vdf 7.0.0.1 < 7.0.2.113
15.02.2008 21:53:01 - C:\Program Files\Avira\AntiVir PersonalEdition Classic\antivir3.vdf 7.0.0.2 < 7.0.2.148
15.02.2008 21:53:01 - Module: AVREP_NT Source: engine\nt\ Destination: C:\Program Files\Avira\AntiVir PersonalEdition Classic\ Files: 1
15.02.2008 21:53:01 - Module: ENGINE Source: engine\ Destination: C:\Program Files\Avira\AntiVir PersonalEdition Classic\ Files: 2
15.02.2008 21:53:01 - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avewin32.dll 7.6.0.15 < 7.6.0.67
15.02.2008 21:53:01 - Module: ENGINE_NT_EN Source: engine\nt\ Destination: C:\Program Files\Avira\AntiVir PersonalEdition Classic\ Files: 1
15.02.2008 21:53:01 - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avpack32.dll 7.3.0.15 < 7.6.0.3
15.02.2008 21:53:01 - Module: DRV Source: winwks\en\ Destination: C:\Windows\SYSTEM32\drivers\ Files: 4
15.02.2008 21:53:01 - C:\Windows\SYSTEM32\drivers\avipbb.sys 1.0.2.11 < 1.0.2.13
15.02.2008 21:53:01 - Minifilter is installed
15.02.2008 21:53:01 - Minifilter is possible
15.02.2008 21:53:01 - Reading registry value successful: Software\Avira\AntiVir PersonalEdition Classic | FilterType
15.02.2008 21:53:01 - File basic-nt/xp/avgntdd.sys which was recognized as modified, must not be updated
15.02.2008 21:53:01 - File basic-nt/xp/avgntmgr.sys which was recognized as modified, must not be updated
15.02.2008 21:53:01 - Initialize avnotify.exe
15.02.2008 21:53:01 - Starting avnotify.exe successful
15.02.2008 21:53:01 - Preparing to download files
15.02.2008 21:53:01 - 13 files need to be downloaded / copied from http://dl3.avgate.net/upd/
15.02.2008 21:53:01 - #1: Downloading and extracting http://dl3.avgate.net/upd/winwks/en/basic-nt/updlib.dll.gz to C:\ProgramData\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_47b5fb73\winwks\en\basic-nt/updlib.dll
15.02.2008 21:53:08 - #2: Downloading and extracting http://dl3.avgate.net/upd/winwks/en/basic-nt/avcenter.exe.gz to C:\ProgramData\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_47b5fb73\winwks\en\basic-nt/avcenter.exe
15.02.2008 21:53:17 - #3: Downloading and extracting http://dl3.avgate.net/upd/winwks/en/basic-nt/avgnt.exe.gz to C:\ProgramData\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_47b5fb73\winwks\en\basic-nt/avgnt.exe
15.02.2008 21:53:20 - #4: Downloading and extracting http://dl3.avgate.net/upd/winwks/en/basic-nt/avguard.exe.gz to C:\ProgramData\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_47b5fb73\winwks\en\basic-nt/avguard.exe
15.02.2008 21:53:29 - #5: Downloading and extracting http://dl3.avgate.net/upd/winwks/en/basic-nt/ccguard.dll.gz to C:\ProgramData\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_47b5fb73\winwks\en\basic-nt/ccguard.dll
15.02.2008 21:53:32 - #6: Downloading and extracting http://dl3.avgate.net/upd/winwks/en/basic-nt/preupd.exe.gz to C:\ProgramData\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_47b5fb73\winwks\en\basic-nt/preupd.exe
15.02.2008 21:53:33 - #7: Downloading and extracting http://dl3.avgate.net/upd/winwks/en/basic-nt/addr_file.html.gz to C:\ProgramData\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_47b5fb73\winwks\en\basic-nt/addr_file.html
15.02.2008 21:53:33 - #8: Downloading and extracting http://dl3.avgate.net/upd/vdf/antivir1.vdf.gz to C:\ProgramData\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_47b5fb73\vdf\antivir1.vdf
15.02.2008 21:55:59 - #9: Downloading and extracting http://dl3.avgate.net/upd/vdf/antivir2.vdf.gz to C:\ProgramData\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_47b5fb73\vdf\antivir2.vdf
15.02.2008 21:57:24 - #10: Downloading and extracting http://dl3.avgate.net/upd/vdf/antivir3.vdf.gz to C:\ProgramData\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_47b5fb73\vdf\antivir3.vdf
15.02.2008 21:57:32 - #11: Downloading and extracting http://dl3.avgate.net/upd/engine/avewin32.dll.gz to C:\ProgramData\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_47b5fb73\engine\avewin32.dll
15.02.2008 21:58:15 - #12: Downloading and extracting http://dl3.avgate.net/upd/engine/nt/avpack32.dll.gz to C:\ProgramData\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_47b5fb73\engine\nt\avpack32.dll
15.02.2008 21:58:23 - #13: Downloading and extracting http://dl3.avgate.net/upd/winwks/en/basic-nt/avipbb.sys.gz to C:\ProgramData\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_47b5fb73\winwks\en\basic-nt/avipbb.sys
15.02.2008 21:58:31 - Service AVEService is not installed
15.02.2008 21:58:31 - Service AntiVirMailService is not installed
15.02.2008 21:58:31 - Initialize fwinst.exe
15.02.2008 21:58:31 - Initialize fwinst.exe
15.02.2008 21:58:31 - Service AntiVirFirewallService is not installed
15.02.2008 21:58:31 - Service antivirwebservice is not installed
15.02.2008 21:58:31 - Status of service AntiVirService is running
15.02.2008 21:58:31 - Initialize avgnt.exe
15.02.2008 21:58:31 - Status of service AntiVirScheduler is running
15.02.2008 21:58:31 - Minifilter is installed
15.02.2008 21:58:31 - Minifilter is possible
15.02.2008 21:58:31 - Initialize avscan.exe
15.02.2008 21:58:31 - Initialize avconfig.cpl
15.02.2008 21:58:31 - Initialize avcenter.exe
15.02.2008 21:58:31 - shell extension is installed
15.02.2008 21:58:31 - Reading registry value successful: Software\Avira\AntiVir PersonalEdition Classic | RootkitsInstalled
15.02.2008 21:58:31 - Reading registry value successful: Software\Avira\AntiVir PersonalEdition Classic | RootkitsInstalled
15.02.2008 21:58:31 - Service AVEService is not installed
15.02.2008 21:58:31 - Service AntiVirMailService is not installed
15.02.2008 21:58:31 - Initialize fwinst.exe
15.02.2008 21:58:31 - Initialize fwinst.exe
15.02.2008 21:58:31 - Service AntiVirFirewallService is not installed
15.02.2008 21:58:31 - shell extension is installed
15.02.2008 21:58:31 - Initialize regsvr32.exe
15.02.2008 21:58:31 - shell extension removed successfully
15.02.2008 21:58:31 - avgnt.exe closed.
15.02.2008 21:58:31 - Status of service AntiVirScheduler is running
15.02.2008 21:58:31 - Service AntiVirScheduler successfully stopped
15.02.2008 21:58:31 - Status of service AntiVirService is running
15.02.2008 21:58:33 - Service AntiVirService successfully stopped
15.02.2008 21:58:33 - Starting to install
15.02.2008 21:58:33 - Processing module SELFUPDATE Source: C:\ProgramData\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_47b5fb73\winwks\en\ Destination: C:\Program Files\Avira\AntiVir PersonalEdition Classic\
15.02.2008 21:58:33 - Current Direcory:C:\Program Files\Avira\AntiVir PersonalEdition Classic, About to execute C:\ProgramData\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_47b5fb73\SelfUpdateTemp\update.exe --log-template="${DAY}.${MONTH}.${YEAR} ${HOUR}:${MINUTE}:${SECOND} - ${MSG}".Self Update helper
15.02.2008 21:58:35 - Installation Directory: C:\Program Files\Avira\AntiVir PersonalEdition Classic\
15.02.2008 21:58:35 - Backup Directory: C:\ProgramData\Avira\AntiVir PersonalEdition Classic\BACKUP\
15.02.2008 21:58:35 - Temp Directory: C:\Windows\TEMP\Update_Temp\
15.02.2008 21:58:35 - Avira AntiVir PersonalEdition Classic
15.02.2008 21:58:35 - Self update: Copying file C:\ProgramData\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_47b5fb73\winwks\en\basic-nt/updlib.dll to C:\Program Files\Avira\AntiVir PersonalEdition Classic\updlib.dll
15.02.2008 21:58:35 - Executing original update application
15.02.2008 21:58:35 - Current Direcory:C:\Program Files\Avira\AntiVir PersonalEdition Classic, About to execute C:\Program Files\Avira\AntiVir PersonalEdition Classic\update.exe --config-file="C:\ProgramData\Avira\AntiVir PersonalEdition Classic\update.conf" --install-path="C:\Program Files\Avira\AntiVir PersonalEdition Classic" --log-template="${DAY}.${MONTH}.${YEAR} ${HOUR}:${MINUTE}:${SECOND} - ${MSG}" --NoSelfUpdate "--TmpDir=C:\ProgramData\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_47b5fb73" "--LogFile=C:\ProgramData\Avira\AntiVir PersonalEdition Classic\LOGFILES\Upd-2008-02-15-21-52-03.log" "--TmpFilesList=C:\ProgramData\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_47b5fb73\ToRemove.txt".Executing original update application
15.02.2008 21:58:36 - Installation Directory: C:\Program Files\Avira\AntiVir PersonalEdition Classic\
15.02.2008 21:58:36 - Backup Directory: C:\ProgramData\Avira\AntiVir PersonalEdition Classic\BACKUP\
15.02.2008 21:58:36 - Temp Directory: C:\ProgramData\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_47b5fb73\
15.02.2008 21:58:36 - Start the Update GUI... Displaymode: 0
15.02.2008 21:58:36 - Avira AntiVir PersonalEdition Classic
15.02.2008 21:58:36 - Master IDX file has changed
15.02.2008 21:58:36 - File basic-nt/2k/avgntflt.sys's operating system doesn't match the current one. File ignored.
15.02.2008 21:58:36 - File basic-nt/avgio64.sys's operating system doesn't match the current one. File ignored.
15.02.2008 21:58:36 - File basic-nt/imp64b.exe's operating system doesn't match the current one. File ignored.
15.02.2008 21:58:36 - File basic-nt/psapi.dll's operating system doesn't match the current one. File ignored.
15.02.2008 21:58:36 - File basic-nt/shlext64.dll's operating system doesn't match the current one. File ignored.
15.02.2008 21:58:36 - File basic-nt/vista64/avgntflt.sys's operating system doesn't match the current one. File ignored.
15.02.2008 21:58:36 - File basic-nt/xp64/avgntflt.sys's operating system doesn't match the current one. File ignored.
15.02.2008 21:58:36 - File basic-nt/2k/avgntdd.sys's operating system doesn't match the current one. File ignored.
15.02.2008 21:58:36 - File basic-nt/2k/avgntmgr.sys's operating system doesn't match the current one. File ignored.
15.02.2008 21:58:36 - File basic-nt/nt/avgntdd.sys's operating system doesn't match the current one. File ignored.
15.02.2008 21:58:36 - File basic-nt/nt/avgntmgr.sys's operating system doesn't match the current one. File ignored.
15.02.2008 21:58:36 - File basic-nt/vista64/avgntflt.sys's operating system doesn't match the current one. File ignored.
15.02.2008 21:58:36 - Downloading the product.info file from http://dl4.avgate.net/upd/idx/vdf.info.gz
15.02.2008 21:58:36 - Downloading the product.info file from http://dl4.avgate.net/upd/idx/specvir-nt.info.gz
15.02.2008 21:58:36 - Downloading the product.info file from http://dl4.avgate.net/upd/idx/engine.info.gz
15.02.2008 21:58:36 - Downloading the product.info file from http://dl4.avgate.net/upd/idx/engine-nt-en.info.gz
15.02.2008 21:58:36 - Module: SELFUPDATE Source: winwks\en\ Destination: C:\Program Files\Avira\AntiVir PersonalEdition Classic\ Files: 15
15.02.2008 21:58:36 - Module: MAIN Source: winwks\en\ Destination: C:\Program Files\Avira\AntiVir PersonalEdition Classic\ Files: 77
15.02.2008 21:58:36 - Module: COMMAPPDATA Source: winwks\en\ Destination: C:\ProgramData\ Files: 1
15.02.2008 21:58:36 - Module: TEXT Source: winwks\en\ Destination: C:\Program Files\Avira\AntiVir PersonalEdition Classic\ Files: 3
15.02.2008 21:58:37 - Module: VDF Source: vdf\ Destination: C:\Program Files\Avira\AntiVir PersonalEdition Classic\ Files: 4
15.02.2008 21:58:37 - Module: AVREP_NT Source: engine\nt\ Destination: C:\Program Files\Avira\AntiVir PersonalEdition Classic\ Files: 1
15.02.2008 21:58:37 - Module: ENGINE Source: engine\ Destination: C:\Program Files\Avira\AntiVir PersonalEdition Classic\ Files: 2
15.02.2008 21:58:37 - Module: ENGINE_NT_EN Source: engine\nt\ Destination: C:\Program Files\Avira\AntiVir PersonalEdition Classic\ Files: 1
15.02.2008 21:58:37 - Module: DRV Source: winwks\en\ Destination: C:\Windows\SYSTEM32\drivers\ Files: 4
15.02.2008 21:58:37 - Minifilter is installed
15.02.2008 21:58:37 - Minifilter is possible
15.02.2008 21:58:37 - Reading registry value successful: Software\Avira\AntiVir PersonalEdition Classic | FilterType
15.02.2008 21:58:37 - File basic-nt/xp/avgntdd.sys which was recognized as modified, must not be updated
15.02.2008 21:58:37 - File basic-nt/xp/avgntmgr.sys which was recognized as modified, must not be updated
15.02.2008 21:58:37 - Preparing to download files
15.02.2008 21:58:37 - 12 files need to be downloaded / copied from http://dl4.avgate.net/upd/
15.02.2008 21:58:37 - File C:\ProgramData\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_47b5fb73\winwks\en\basic-nt\avcenter.exe.gz already exists in temporary folder and it will not be downloaded again
15.02.2008 21:58:37 - File C:\ProgramData\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_47b5fb73\winwks\en\basic-nt\avgnt.exe.gz already exists in temporary folder and it will not be downloaded again
15.02.2008 21:58:37 - File C:\ProgramData\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_47b5fb73\winwks\en\basic-nt\avguard.exe.gz already exists in temporary folder and it will not be downloaded again
15.02.2008 21:58:37 - File C:\ProgramData\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_47b5fb73\winwks\en\basic-nt\ccguard.dll.gz already exists in temporary folder and it will not be downloaded again
15.02.2008 21:58:37 - File C:\ProgramData\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_47b5fb73\winwks\en\basic-nt\preupd.exe.gz already exists in temporary folder and it will not be downloaded again
15.02.2008 21:58:37 - File C:\ProgramData\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_47b5fb73\winwks\en\basic-nt\addr_file.html.gz already exists in temporary folder and it will not be downloaded again
15.02.2008 21:58:37 - File C:\ProgramData\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_47b5fb73\vdf\antivir1.vdf.gz already exists in temporary folder and it will not be downloaded again
15.02.2008 21:58:37 - File C:\ProgramData\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_47b5fb73\vdf\antivir2.vdf.gz already exists in temporary folder and it will not be downloaded again
15.02.2008 21:58:37 - File C:\ProgramData\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_47b5fb73\vdf\antivir3.vdf.gz already exists in temporary folder and it will not be downloaded again
15.02.2008 21:58:37 - File C:\ProgramData\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_47b5fb73\engine\avewin32.dll.gz already exists in temporary folder and it will not be downloaded again
15.02.2008 21:58:37 - File C:\ProgramData\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_47b5fb73\engine\nt\avpack32.dll.gz already exists in temporary folder and it will not be downloaded again
15.02.2008 21:58:37 - File C:\ProgramData\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_47b5fb73\winwks\en\basic-nt\avipbb.sys.gz already exists in temporary folder and it will not be downloaded again
15.02.2008 21:58:37 - Starting to install
15.02.2008 21:58:37 - Processing module MAIN Source: C:\ProgramData\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_47b5fb73\winwks\en\ Destination: C:\Program Files\Avira\AntiVir PersonalEdition Classic\
15.02.2008 21:58:37 - File C:\ProgramData\addr_file.html will not be backed up because it doesn't exist
15.02.2008 21:58:37 - Processing module COMMAPPDATA Source: C:\ProgramData\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_47b5fb73\winwks\en\ Destination: C:\ProgramData\
15.02.2008 21:58:37 - Processing module VDF Source: C:\ProgramData\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_47b5fb73\vdf\ Destination: C:\Program Files\Avira\AntiVir PersonalEdition Classic\
15.02.2008 21:58:38 - Processing module ENGINE Source: C:\ProgramData\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_47b5fb73\engine\ Destination: C:\Program Files\Avira\AntiVir PersonalEdition Classic\
15.02.2008 21:58:38 - Processing module ENGINE_NT_EN Source: C:\ProgramData\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_47b5fb73\engine\nt\ Destination: C:\Program Files\Avira\AntiVir PersonalEdition Classic\
15.02.2008 21:58:38 - Processing module DRV Source: C:\ProgramData\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_47b5fb73\winwks\en\ Destination: C:\Windows\SYSTEM32\drivers\
15.02.2008 21:58:38 - A total of 12 files were updated
15.02.2008 21:58:38 - Registry entry created successfully: Software\Avira\AntiVir PersonalEdition Classic |UpdateInProgress
15.02.2008 21:58:38 - Service AVEService is not installed
15.02.2008 21:58:38 - Service AntiVirMailService is not installed
15.02.2008 21:58:38 - Initialize fwinst.exe
15.02.2008 21:58:38 - Initialize fwinst.exe
15.02.2008 21:58:38 - Service AntiVirFirewallService is not installed
15.02.2008 21:58:38 - Service antivirwebservice is not installed
15.02.2008 21:58:38 - Status of service AntiVirService is stopped
15.02.2008 21:58:38 - Initialize avgnt.exe
15.02.2008 21:58:38 - Status of service AntiVirScheduler is stopped
15.02.2008 21:58:38 - Minifilter is installed
15.02.2008 21:58:38 - Minifilter is possible
15.02.2008 21:58:38 - Initialize avscan.exe
15.02.2008 21:58:38 - Initialize avconfig.cpl
15.02.2008 21:58:38 - Initialize avcenter.exe
15.02.2008 21:58:38 - shell extension is installed
15.02.2008 21:58:38 - Reading registry value successful: Software\Avira\AntiVir PersonalEdition Classic | RootkitsInstalled
15.02.2008 21:58:38 - Reading registry value successful: Software\Avira\AntiVir PersonalEdition Classic | RootkitsInstalled
15.02.2008 21:58:44 - Service AntiVirService successfully started
15.02.2008 21:58:45 - Starting avgnt.exe successful
15.02.2008 21:58:45 - Service AntiVirScheduler successfully started
15.02.2008 21:58:45 - shell extension is installed
15.02.2008 21:58:45 - Initialize regsvr32.exe
15.02.2008 21:58:45 - installation of shell extension successful
15.02.2008 21:58:45 - Cannot start the service antivirwebservice
15.02.2008 21:58:45 - Dialup: 0
15.02.2008 21:58:45 - Downloaded bytes: 7443284
15.02.2008 21:58:45 - Downloaded file(s): 13
15.02.2008 21:58:45 - Downloaded file(s): updlib.dll; avcenter.exe; avgnt.exe; avguard.exe; ccguard.dll; preupd.exe; addr_file.html; antivir1.vdf; antivir2.vdf; antivir3.vdf; avewin32.dll; avpack32.dll; avipbb.sys
15.02.2008 21:58:45 - Engine version local : 7.6.0.15
15.02.2008 21:58:45 - Engine version internet: 7.6.0.67
15.02.2008 21:58:45 - 0. VDF version local : 6.40.0.0
15.02.2008 21:58:45 - 0. VDF version internet: 6.40.0.0
15.02.2008 21:58:45 - 1. VDF version local : 7.0.0.0
15.02.2008 21:58:45 - 1. VDF version internet: 7.0.1.95
15.02.2008 21:58:45 - 2. VDF version local : 7.0.0.1
15.02.2008 21:58:45 - 2. VDF version internet: 7.0.2.113
15.02.2008 21:58:45 - 3. VDF version local : 7.0.0.2
15.02.2008 21:58:45 - 3. VDF version internet: 7.0.2.148
15.02.2008 21:58:45 - Required time: 00:09
15.02.2008 21:58:45 - Registry entry created successfully: Software\Avira\AntiVir PersonalEdition Classic |LastUpdate
15.02.2008 21:58:46 - Update finished successfully
le problème c'est que tu m'as envoyé le rapport de la miseà jour,
Il faut que tu fasse un scan avec Antivir.
C'est à dire :
* Lance un scan *
(si des virus sont découverts, mets les en quarantaine. Si tu ne peux pas alors supprime les).
A la fin du scan clique sur 'report', enregistre ce rapport sur le bureau (fichier => enregistrer sous), puis fait un copier/coller de ce rapport dans ton prochain message.
----> Relance ton PC
Report file date: lundi 18 février 2008 18:58
Scanning for 1110678 virus strains and unwanted programs.
Licensed to: Avira AntiVir PersonalEdition Classic
Serial number: 0000149996-ADJIE-0001
Platform: Windows Vista
Windows version: (plain) [6.0.6000]
Username: SYSTEM
Computer name: PC-DE-SAMUEL
Version information:
BUILD.DAT : 270 15603 Bytes 19/09/2007 13:32:00
AVSCAN.EXE : 7.0.6.1 290856 Bytes 23/08/2007 13:16:29
AVSCAN.DLL : 7.0.6.0 49192 Bytes 16/08/2007 12:23:51
LUKE.DLL : 7.0.5.3 147496 Bytes 14/08/2007 15:32:47
LUKERES.DLL : 7.0.6.1 10280 Bytes 21/08/2007 12:35:20
ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 14:27:15
ANTIVIR1.VDF : 7.0.1.95 3367424 Bytes 14/12/2007 20:58:38
ANTIVIR2.VDF : 7.0.2.113 1673728 Bytes 08/02/2008 20:58:38
ANTIVIR3.VDF : 7.0.2.148 201216 Bytes 15/02/2008 20:58:38
AVEWIN32.DLL : 7.6.0.67 3293696 Bytes 15/02/2008 20:58:38
AVWINLL.DLL : 1.0.0.7 14376 Bytes 26/02/2007 10:36:26
AVPREF.DLL : 7.0.2.2 25640 Bytes 18/07/2007 07:39:17
AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 13:16:24
AVPACK32.DLL : 7.6.0.3 360488 Bytes 15/02/2008 20:58:38
AVREG.DLL : 7.0.1.6 30760 Bytes 18/07/2007 07:17:06
AVARKT.DLL : 1.0.0.20 278568 Bytes 28/08/2007 12:26:33
AVEVTLOG.DLL : 7.0.0.20 86056 Bytes 18/07/2007 07:10:18
NETNT.DLL : 7.0.0.0 7720 Bytes 08/03/2007 11:09:42
RCIMAGE.DLL : 7.0.1.30 2342952 Bytes 07/08/2007 12:38:13
RCTEXT.DLL : 7.0.62.0 86056 Bytes 21/08/2007 12:50:37
SQLITE3.DLL : 3.3.17.1 339968 Bytes 23/07/2007 09:37:21
Configuration settings for the scan:
Jobname..........................: Complete system scan
Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
Logging..........................: low
Primary action...................: interactive
Secondary action.................: ignore
Scan master boot sector..........: off
Scan boot sector.................: on
Boot sectors.....................: C:,
Scan memory......................: on
Process scan.....................: on
Scan registry....................: on
Search for rootkits..............: off
Scan all files...................: Intelligent file selection
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Macro heuristic..................: on
File heuristic...................: medium
Start of the scan: lundi 18 février 2008 18:58
The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'SearchFilterHost.exe' - '1' Module(s) have been scanned
Scan process 'SearchProtocolHost.exe' - '1' Module(s) have been scanned
Scan process 'conime.exe' - '1' Module(s) have been scanned
Scan process 'SteamService.exe' - '1' Module(s) have been scanned
Scan process 'Steam.exe' - '1' Module(s) have been scanned
Scan process 'ApntEx.exe' - '1' Module(s) have been scanned
Scan process 'Switcher.exe' - '1' Module(s) have been scanned
Scan process 'VAIOUpdt.exe' - '1' Module(s) have been scanned
Scan process 'taskeng.exe' - '1' Module(s) have been scanned
Scan process 'wmpnetwk.exe' - '1' Module(s) have been scanned
Scan process 'ehmsas.exe' - '1' Module(s) have been scanned
Scan process 'ApMsgFwd.exe' - '1' Module(s) have been scanned
Scan process 'ObjectDock.exe' - '1' Module(s) have been scanned
Scan process 'BTTray.exe' - '1' Module(s) have been scanned
Scan process 'wmpnscfg.exe' - '1' Module(s) have been scanned
Scan process 'ehtray.exe' - '1' Module(s) have been scanned
Scan process 'rundll32.exe' - '1' Module(s) have been scanned
Scan process 'avgnt.exe' - '1' Module(s) have been scanned
Scan process 'avgas.exe' - '1' Module(s) have been scanned
Scan process 'rundll32.exe' - '1' Module(s) have been scanned
Scan process 'ISBMgr.exe' - '1' Module(s) have been scanned
Scan process 'Apoint.exe' - '1' Module(s) have been scanned
Scan process 'MSASCui.exe' - '1' Module(s) have been scanned
Scan process 'SPMgr.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'dwm.exe' - '1' Module(s) have been scanned
Scan process 'taskeng.exe' - '1' Module(s) have been scanned
Scan process 'VESMgrSub.exe' - '1' Module(s) have been scanned
Scan process 'WUDFHost.exe' - '1' Module(s) have been scanned
Scan process 'VzFw.exe' - '1' Module(s) have been scanned
Scan process 'VzCdbSvc.exe' - '1' Module(s) have been scanned
Scan process 'XAudio.exe' - '1' Module(s) have been scanned
Scan process 'SearchIndexer.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'VCSW.exe' - '1' Module(s) have been scanned
Scan process 'VESMgr.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'stacsv.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'PnkBstrA.exe' - '1' Module(s) have been scanned
Scan process 'NBService.exe' - '1' Module(s) have been scanned
Scan process 'MDM.EXE' - '1' Module(s) have been scanned
Scan process 'iviRegMgr.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'guard.exe' - '1' Module(s) have been scanned
Scan process 'sched.exe' - '1' Module(s) have been scanned
Scan process 'PhotoshopElementsFileAgent.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'avguard.exe' - '1' Module(s) have been scanned
Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'SLsvc.exe' - '1' Module(s) have been scanned
Scan process 'audiodg.exe' - '0' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'lsm.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'wininit.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
69 processes with 69 modules were scanned
Start scanning boot sectors:
Boot sector 'C:\'
[NOTE] No virus was found!
Starting to scan the registry.
The registry was scanned ( '12' files ).
Starting the file scan:
Begin scan in 'C:\'
C:\hiberfil.sys
[WARNING] The file could not be opened!
C:\pagefile.sys
[WARNING] The file could not be opened!
C:\Program Files\Common Files\ErreurChasseur\strpmon.exe
[DETECTION] Is the Trojan horse TR/Crypt.CFI.Gen
[INFO] The file was deleted!
C:\Program Files\Panda Security\NanoScan\Engine\psnflg.dll
[DETECTION] Is the Trojan horse TR/Agent.bux.1
[INFO] The file was moved to '4827cede.qua'!
C:\SphinxME\MacrosLexica.dot
[DETECTION] Contains suspicious code HEUR/Macro.Word95
[INFO] The file was moved to '481cd054.qua'!
C:\Users\Samuel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4C2GBJEN\gnida[1].swf
[DETECTION] Contains the SWF virus SWF/Dldr.Gida.A
[INFO] The file was moved to '4822d0f0.qua'!
C:\Windows\System32\drivers\sptd.sys
[WARNING] The file could not be opened!
End of the scan: lundi 18 février 2008 19:57
Used time: 59:11 min
The scan has been done completely.
17228 Scanning directories
444099 Files were scanned
3 viruses and/or unwanted programs were found
1 Files were classified as suspicious:
1 files were deleted
0 files were repaired
3 files were moved to quarantine
0 files were renamed
3 Files cannot be scanned
444096 Files not concerned
2397 Archives were scanned
3 Warnings
0 Notes
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre questionDésinstalle Spyware Doctor :
---> Ordinateur
---> Désinstaller et Modifier un programme
---> Chercher SpyWare Doctor
---> Desinstaller
On arrête le service puis on le désactive :
_____________________________________________________
Arrête ces 4 services
service(s) à arrêter : Symantec Lic NetConnect service - GoogleDesktopManager - Nero BackItUp Scheduler 3 - NMIndexingService
pour ça fais cette manip :
- Clique Droit sur "Ordinateur" sur le bureau
- Gérer
- Services et Applications
- Services
- Clic droit sur le service cité -
- propriétés
- et dans "type de démarrage" et mets le sur « désactivé ».
- Ensuite si le "Status du service" est sur "Démarré" faire : « arrêté »
_____________________________________________________
Fixe les lignes dans Hijackthis :
Relance HijackThis, choisis "do a scan only" coche la case devant les lignes ci-dessous et clic en bas sur "fix checked".
O2 - BHO: Seekmo /fleok=1D8A83A5C5EC107E90AB682A1FBB39BFE4976E26CAEDA120180A196D6093 - {07AA283A-43D7-4CBE-A064-32A21112D94D} - (no file)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O3 - Toolbar: (no name) - {07AA283A-43D7-4CBE-A064-32A21112D94D} - (no file)
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
S'il te demande un redémarrage, relance ton PC.
_____________________________________________________
Télécharger et installer CCleaner.
https://www.01net.com/telecharger/windows/Utilitaire/nettoyeurs_et_installeurs/fiches/32599.html
Clique sur Options, Avancé et décoche la case "Effacer uniquement les fichiers, du dossier Temp de Windows, plus vieux que 48 heures".
Ne touche pas aux autres réglages.
Lancer un nettoyage et répare 3 fois les erreurs
sans installer la barre yahoo.
Aprés, va dans l'onglet Registre puis cherche les erreurs
une fois terminé, Répare les erreurs selectionnées
_____________________________________________________
Repost un log HijackThis .
ensuite j'ai arrété les 4 services, j'ai fixer les lignes dans HJK this.
pour C cleaner, je l'avais déjà, j'ai tout fait.
je te refais un rapport hijack this?
Scan saved at 21:58:21, on 12/02/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16575)
Boot mode: Normal
Running processes:
C:\Windows\System32\smss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Avast\aswUpdSv.exe
C:\Program Files\Avast\ashServ.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\Windows\system32\PnkBstrA.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\Windows\system32\stacsv.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
C:\Windows\system32\WUDFHost.exe
C:\Program Files\Avast\ashMaiSv.exe
C:\Program Files\Avast\ashWebSv.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\winlogon.exe
C:\Program Files\Sony\VAIO Event Service\VESMgrSub.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Sony\ISB Utility\ISBMgr.exe
C:\Windows\system32\taskeng.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Avast\ashDisp.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe
C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Apoint\ApMsgFwd.exe
C:\Program Files\Apoint\Apntex.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Samuel\AppData\Roaming\U3\00001851947470F3\LaunchPad.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\wbem\wmiprvse.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.club-vaio.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.168.44.254:3128
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Seekmo /fleok=1D8A83A5C5EC107E90AB682A1FBB39BFE4976E26CAEDA120180A196D6093 - {07AA283A-43D7-4CBE-A064-32A21112D94D} - (no file)
O2 - BHO: Download Manager Browser Helper Object - {19C8E43B-07B3-49CB-BFFC-6777B593E6F8} - C:\PROGRA~1\COMMON~1\fluxDVD\DOWNLO~1\XEBDLH~1.DLL
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\PROGRA~1\GOOGLE~1\BAE.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: (no name) - {07AA283A-43D7-4CBE-A064-32A21112D94D} - (no file)
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [ISBMgr.exe] "C:\Program Files\Sony\ISB Utility\ISBMgr.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\Avast\ashDisp.exe
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
O4 - Global Startup: BTTray.lnk = ?
O13 - Gopher Prefix:
O15 - Trusted Zone: *.canalplay.com (HKLM)
O15 - Trusted Zone: *.canalplusactive.com (HKLM)
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Avast\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Avast\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Avast\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Avast\ashWebSv.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: Service CANALPLAY - Canal+ Active - C:\Program Files\Lecteur CANALPLAY\CanalPlayService.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Windows\system32\stacsv.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe
O23 - Service: VAIO Media Content Collection (VAIOMediaPlatform-UCLS-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\UCLS.exe
O23 - Service: VAIO Media Content Collection (HTTP) (VAIOMediaPlatform-UCLS-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Content Collection (UPnP) (VAIOMediaPlatform-UCLS-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Content Metadata Intelligent Analyzing Manager (VcmIAlzMgr) - Sony Corporation - C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe
O23 - Service: VAIO Content Metadata XML Interface (VcmXmlIfHelper) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
Fixe les lignes dans Hijackthis :
Relance HijackThis, choisis "do a scan only" coche la case devant les lignes ci-dessous et clic en bas sur "fix checked".
O2 - BHO: Seekmo /fleok=1D8A83A5C5EC107E90AB682A1FBB39BFE4976E26CAEDA120180A196D6093 - {07AA283A-43D7-4CBE-A064-32A21112D94D} - (no file)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O3 - Toolbar: (no name) - {07AA283A-43D7-4CBE-A064-32A21112D94D} - (no file)
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
S'il te demande un redémarrage, relance ton PC.
_____________________________________________________
On arrête le service puis on le désactive :
_____________________________________________________
Arrête ces services
service(s) à arrêter : Symantec Lic NetConnect service - PC Tools Auxiliary - PC Tools Security Service
pour ça fais cette manip :
- Clique Droit sur "Ordinateur" sur le bureau
- Gérer
- Services et Applications
- Services
- Clic droit sur le service cité -
- propriétés
- et dans "type de démarrage" et mets le sur « désactivé ».
- Ensuite si le "Status du service" est sur "Démarré" faire : « arrêté »
_____________________________________________________
OTMoveIt :
Télécharger sur le bureau :
http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe
= Copier le texte en gras:
C:\Program Files\Spyware Doctor
= Double-clic sur OTMoveIt.exe
= Dans le cadre de Gauche ==> clic-droit ==> coller
= Clic MoveIt!
= si redémarrage demandé==> Clic : YES
= Un rapport dans ==> C:\_OTMoveIt\MovedFiles\date du jour à copier/coller sur le forum.
-------
redemarre le PC
_____________________________________________________
OTMoveIt2 v1.0.20 log created on 02272008_085650
par contre quand je fais un hijack il ne me met pas ça:
O2 - BHO: Seekmo /fleok=1D8A83A5C5EC107E90AB682A1FBB39BFE4976E26CAEDA120180A196D6093 - {07AA283A-43D7-4CBE-A064-32A21112D94D} - (no file)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O3 - Toolbar: (no name) - {07AA283A-43D7-4CBE-A064-32A21112D94D} - (no file)
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
je ne les ais pas!
et ce service:
Symantec Lic NetConnect service , je l'ai déjà arrété.
les deux suivants, je ne les ai pas:
PC Tools Auxiliary - PC Tools Security Service
Scan saved at 21:58:21, on 12/02/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16575)
Boot mode: Normal
Running processes:
C:\Windows\System32\smss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Avast\aswUpdSv.exe
C:\Program Files\Avast\ashServ.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\Windows\system32\PnkBstrA.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\Windows\system32\stacsv.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
C:\Windows\system32\WUDFHost.exe
C:\Program Files\Avast\ashMaiSv.exe
C:\Program Files\Avast\ashWebSv.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\winlogon.exe
C:\Program Files\Sony\VAIO Event Service\VESMgrSub.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Sony\ISB Utility\ISBMgr.exe
C:\Windows\system32\taskeng.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Avast\ashDisp.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe
C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Apoint\ApMsgFwd.exe
C:\Program Files\Apoint\Apntex.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Samuel\AppData\Roaming\U3\00001851947470F3\LaunchPad.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\wbem\wmiprvse.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.club-vaio.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.168.44.254:3128
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Seekmo /fleok=1D8A83A5C5EC107E90AB682A1FBB39BFE4976E26CAEDA120180A196D6093 - {07AA283A-43D7-4CBE-A064-32A21112D94D} - (no file)
O2 - BHO: Download Manager Browser Helper Object - {19C8E43B-07B3-49CB-BFFC-6777B593E6F8} - C:\PROGRA~1\COMMON~1\fluxDVD\DOWNLO~1\XEBDLH~1.DLL
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\PROGRA~1\GOOGLE~1\BAE.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: (no name) - {07AA283A-43D7-4CBE-A064-32A21112D94D} - (no file)
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [ISBMgr.exe] "C:\Program Files\Sony\ISB Utility\ISBMgr.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\Avast\ashDisp.exe
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
O4 - Global Startup: BTTray.lnk = ?
O13 - Gopher Prefix:
O15 - Trusted Zone: *.canalplay.com (HKLM)
O15 - Trusted Zone: *.canalplusactive.com (HKLM)
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Avast\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Avast\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Avast\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Avast\ashWebSv.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: Service CANALPLAY - Canal+ Active - C:\Program Files\Lecteur CANALPLAY\CanalPlayService.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Windows\system32\stacsv.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe
O23 - Service: VAIO Media Content Collection (VAIOMediaPlatform-UCLS-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\UCLS.exe
O23 - Service: VAIO Media Content Collection (HTTP) (VAIOMediaPlatform-UCLS-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Content Collection (UPnP) (VAIOMediaPlatform-UCLS-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Content Metadata Intelligent Analyzing Manager (VcmIAlzMgr) - Sony Corporation - C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe
O23 - Service: VAIO Content Metadata XML Interface (VcmXmlIfHelper) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
Je comprend pas,
Tu me dis :
par contre quand je fais un hijack il ne me met pas ça:
O2 - BHO: Seekmo /fleok=1D8A83A5C5EC107E90AB682A1FBB39BFE4976E26CAEDA120180A196D6093 - {07AA283A-43D7-4CBE-A064-32A21112D94D} - (no file)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O3 - Toolbar: (no name) - {07AA283A-43D7-4CBE-A064-32A21112D94D} - (no file)
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
Alors qu'on les vois trés clairement la...
Ok je comprend, Ton Scan date du 12 Février, donc, refait un NOUVEAU scan :)
Colle un Log hijackthis :
HijackThis ici :
Lance le puis:
clique sur "do a system scan and save logfile"
faire un copier coller du log et le poster sur le forum
_____________________________________________________
clique sur "do a system scan and save logfile"
faire un copier coller du log et le poster sur le forum
c'est ce que je fait! mais il laisse le logfile du 12 février!!!
je dois peut être le désinstaller et le réinstaller?
parce que je vois moi aussi dans le log file:
O2 - BHO: Seekmo /fleok=1D8A83A5C5EC107E90AB682A1FBB39BFE4976E26CAEDA120180A196D6093 - {07AA283A-43D7-4CBE-A064-32A21112D94D} - (no file)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O3 - Toolbar: (no name) - {07AA283A-43D7-4CBE-A064-32A21112D94D} - (no file)
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
mais je le vois pas dans le scan!!!
Oui désinstalle le et réinstalle le :
Lance HijackThis :
Open the Misc tools selection
Onglet "Misc Tools"
Fait dérouler jusqu'a : Uninstall Hijackthis & Exit
Oui
Redémarre
Réinstalle le.
Tuto ici: http://cybersecurite.xooit.com/t138-HijackThis-2-0-2.htm
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:49:44, on 28/02/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16609)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Sony\ISB Utility\ISBMgr.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Steam\Steam.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Apoint\ApMsgFwd.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Apoint\Apntex.exe
C:\program files\internet explorer\ieuser.exe
C:\program files\internet explorer\iexplore.exe
C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.club-vaio.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.168.44.254:3128
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Download Manager Browser Helper Object - {19C8E43B-07B3-49CB-BFFC-6777B593E6F8} - C:\PROGRA~1\COMMON~1\fluxDVD\DOWNLO~1\XEBDLH~1.DLL
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [ISBMgr.exe] "C:\Program Files\Sony\ISB Utility\ISBMgr.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
O4 - Global Startup: BTTray.lnk = ?
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
O13 - Gopher Prefix:
O16 - DPF: {512FC5A1-7DE1-43F1-BC0C-371622FCB409} (TotalScan Installer Class) - https://www.pandasecurity.com/en/homeusers/online-antivirus/?ref=activescan
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O16 - DPF: {8436FE12-31DB-48BF-83BF-FE682F9160B4} (NanoInstaller Class) - https://www.pandasecurity.com/en/homeusers/online-antivirus/?ref=activescan
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: Service CANALPLAY - Canal+ Active - C:\Program Files\Lecteur CANALPLAY\CanalPlayService.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Windows\system32\stacsv.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe
O23 - Service: VAIO Media Content Collection (VAIOMediaPlatform-UCLS-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\UCLS.exe
O23 - Service: VAIO Media Content Collection (HTTP) (VAIOMediaPlatform-UCLS-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Content Collection (UPnP) (VAIOMediaPlatform-UCLS-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Content Metadata Intelligent Analyzing Manager (VcmIAlzMgr) - Sony Corporation - C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe
O23 - Service: VAIO Content Metadata XML Interface (VcmXmlIfHelper) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
As tu des problèmes avec ton pc ?
Page qui s'ouvrent ? Alertes virus ? etc...
++
un peu au début mais bon... un peu de patience et c'est bon
Encore merci!!!
pour terminer
Télécharge ToolsCleaner de A.Roshtein sur ton Bureau.
* http://a-rothstein.changelog.fr/TC/ToolsCleaner2.exe
* Clique sur Recherche et laisse le scan se terminer.
* Clique, sur Suppression pour finaliser.
* Tu peux, si tu le souhaites, te servir des Options facultatives.
* Clique sur Quitter, pour que le rapport puisse se créer.
* Poste moi le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur( C:\).
---------------------------------------------
Tu peux le supprimer une fois le rapport sur le forum.
_____________________________________________________
Télécharger et installer CCleaner.
https://www.01net.com/telecharger/windows/Utilitaire/nettoyeurs_et_installeurs/fiches/32599.html
Clique sur Options, Avancé et décoche la case "Effacer uniquement les fichiers, du dossier Temp de Windows, plus vieux que 48 heures".
Ne touche pas aux autres réglages.
Lancer un nettoyage et répare 3 fois les erreurs
sans installer la barre yahoo.
Aprés, va dans l'onglet Registre puis cherche les erreurs
une fois terminé, Répare les erreurs selectionnées
_____________________________________________________