Rapport e scan en ligne

TAUREAU -  
^^Marie^^ Messages postés 41884 Date d'inscription   Statut Membre Dernière intervention   -
Bonjour, J'ai fait un scan en ligne car j'a des fenetre intempestive, quelqun peut-il m'aider merci
KASPERSKY ONLINE SCANNER REPORT
Monday, March 17, 2008 4:00:05 PM
Operating System: Microsoft Windows Vista Home Edition, (Build 6000)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 17/03/2008
Kaspersky Anti-Virus database records: 635761

Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true

Scan Target Critical Areas
C:\Windows
C:\Users\TAUREAU\AppData\Local\Temp\Low\

Scan Statistics
Total number of scanned objects 44003
Number of viruses found 0
Number of infected objects 0
Number of suspicious objects 0
Duration of the scan process 00:21:27

Infected Object Name Virus Name Last Action
C:\Windows\Debug\PASSWD.LOG Object is locked skipped

C:\Windows\Debug\sam.log Object is locked skipped

C:\Windows\Debug\WIA\wiatrace.log Object is locked skipped

C:\Windows\Logs\CBS\CBS.log Object is locked skipped

C:\Windows\Logs\CBS\CBS.persist.log Object is locked skipped

C:\Windows\Logs\DPX\setupact.log Object is locked skipped

C:\Windows\Logs\DPX\setuperr.log Object is locked skipped

C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe.config Object is locked skipped

C:\Windows\Panther\UnattendGC\diagerr.xml Object is locked skipped

C:\Windows\Panther\UnattendGC\diagwrn.xml Object is locked skipped

C:\Windows\Panther\UnattendGC\setupact.log Object is locked skipped

C:\Windows\Panther\UnattendGC\setuperr.log Object is locked skipped

C:\Windows\security\database\secedit.sdb Object is locked skipped

C:\Windows\SoftwareDistribution\EventCache\{2EB369CE-261C-428E-9269-285290B74D0F}.bin Object is locked skipped

C:\Windows\SoftwareDistribution\ReportingEvents.log Object is locked skipped

C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 Object is locked skipped

C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 Object is locked skipped

C:\Windows\System32\catroot2\edb.log Object is locked skipped

C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb Object is locked skipped

C:\Windows\System32\catroot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb Object is locked skipped

C:\Windows\System32\config\COMPONENTS Object is locked skipped

C:\Windows\System32\config\COMPONENTS.LOG1 Object is locked skipped

C:\Windows\System32\config\COMPONENTS.LOG2 Object is locked skipped

C:\Windows\System32\config\DEFAULT Object is locked skipped

C:\Windows\System32\config\DEFAULT.LOG1 Object is locked skipped

C:\Windows\System32\config\DEFAULT.LOG2 Object is locked skipped

C:\Windows\System32\config\SAM Object is locked skipped

C:\Windows\System32\config\SAM.LOG1 Object is locked skipped

C:\Windows\System32\config\SAM.LOG2 Object is locked skipped

C:\Windows\System32\config\SECURITY Object is locked skipped

C:\Windows\System32\config\SECURITY.LOG1 Object is locked skipped

C:\Windows\System32\config\SECURITY.LOG2 Object is locked skipped

C:\Windows\System32\config\SOFTWARE Object is locked skipped

C:\Windows\System32\config\SOFTWARE.LOG1 Object is locked skipped

C:\Windows\System32\config\SOFTWARE.LOG2 Object is locked skipped

C:\Windows\System32\config\SYSTEM Object is locked skipped

C:\Windows\System32\config\SYSTEM.LOG1 Object is locked skipped

C:\Windows\System32\config\SYSTEM.LOG2 Object is locked skipped

C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TM.blf Object is locked skipped

C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped

C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped

C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000003.regtrans-ms Object is locked skipped

C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000004.regtrans-ms Object is locked skipped

C:\Windows\System32\config\TxR\{fead8987-f41e-11dc-a636-0016d35e6957}.TxR.0.regtrans-ms Object is locked skipped

C:\Windows\System32\config\TxR\{fead8987-f41e-11dc-a636-0016d35e6957}.TxR.1.regtrans-ms Object is locked skipped

C:\Windows\System32\config\TxR\{fead8987-f41e-11dc-a636-0016d35e6957}.TxR.2.regtrans-ms Object is locked skipped

C:\Windows\System32\config\TxR\{fead8987-f41e-11dc-a636-0016d35e6957}.TxR.blf Object is locked skipped

C:\Windows\System32\LogFiles\Scm\SCM.EVM Object is locked skipped

C:\Windows\System32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped

C:\Windows\System32\restore\MachineGuid.txt Object is locked skipped

C:\Windows\System32\spool\SpoolerETW.etl Object is locked skipped

C:\Windows\System32\sysprep\Panther\diagerr.xml Object is locked skipped

C:\Windows\System32\sysprep\Panther\diagwrn.xml Object is locked skipped

C:\Windows\System32\sysprep\Panther\setupact.log Object is locked skipped

C:\Windows\System32\sysprep\Panther\setuperr.log Object is locked skipped

C:\Windows\System32\wbem\AutoRecover\2B8B1A8B0ACD3EE28B421D3918DC1F29.mof Object is locked skipped

C:\Windows\System32\wbem\AutoRecover\3460B7617E0429A960E481B197F238A3.mof Object is locked skipped

C:\Windows\System32\wbem\AutoRecover\E478A5DB75C9721E744C05D78DBACFD3.mof Object is locked skipped

C:\Windows\System32\wbem\Logs\WMITracing.log Object is locked skipped

C:\Windows\System32\wbem\repository\INDEX.BTR Object is locked skipped

C:\Windows\System32\wbem\repository\MAPPING1.MAP Object is locked skipped

C:\Windows\System32\wbem\repository\MAPPING2.MAP Object is locked skipped

C:\Windows\System32\wbem\repository\OBJECTS.DATA Object is locked skipped

C:\Windows\System32\winevt\Logs\Antivirus.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Application.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\DFS Replication.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\HardwareEvents.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Internet Explorer.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Key Management Service.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Media Center.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Microsoft-Windows-Bits-Client%4Operational.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Microsoft-Windows-CodeIntegrity%4Operational.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnosis-DPS%4Operational.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnostics-Networking%4Operational.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnostics-Performance%4Operational.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Microsoft-Windows-DiskDiagnosticDataCollector%4Operational.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Microsoft-Windows-DriverFrameworks-UserMode%4Operational.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Microsoft-Windows-GroupPolicy%4Operational.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Microsoft-Windows-Help%4Operational.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Microsoft-Windows-International%4Operational.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Microsoft-Windows-Kernel-WHEA.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Microsoft-Windows-LanguagePackSetup%4Operational.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Microsoft-Windows-MUI%4Operational.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Microsoft-Windows-NetworkAccessProtection%4Operational.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Microsoft-Windows-ParentalControls%4Operational.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Microsoft-Windows-Program-Compatibility-Assistant%4Operational.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Microsoft-Windows-ReadyBoost%4Operational.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Microsoft-Windows-ReliabilityAnalysisComponent%4Operational.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Microsoft-Windows-Resource-Exhaustion-Resolver%4Operational.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Microsoft-Windows-Resource-Leak-Diagnostic%4Operational.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Microsoft-Windows-RestartManager%4Operational.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Microsoft-Windows-TaskScheduler%4Operational.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Microsoft-Windows-UAC%4Operational.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Microsoft-Windows-UAC-FileVirtualization%4Operational.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Microsoft-Windows-WindowsUpdateClient%4Operational.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Microsoft-Windows-WLAN-AutoConfig%4Operational.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\ODiag.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\OSession.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Security.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Setup.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\System.evtx Object is locked skipped

C:\Windows\Tasks\SCHEDLGU.TXT Object is locked skipped

C:\Windows\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job Object is locked skipped

C:\Windows\WindowsUpdate.log Object is locked skipped

C:\Windows\winsxs\x86_microsoft-windows-n..n_service_datastore_31bf3856ad364e35_6.0.6000.16386_none_cef7ceb03914a67f\dnary.xsd Object is locked skipped

Scan process completed.
Configuration: Windows Vista
Internet Explorer 7.0

4 réponses

  1. martine03 Messages postés 2128 Date d'inscription   Statut Membre Dernière intervention   17
     
    telecharge navilog
    0
    1. TAUREAU759
       
      Merci de me répondre Martine, après avoir téléchargé navilog je fait quoi?

      bien à toi

      Taureau
      0
  2. martine03 Messages postés 2128 Date d'inscription   Statut Membre Dernière intervention   17
     
    lance le et choisi 1 et mets le raport qu il va te donner ds le forum pour que je le regarde
    0
    1. TAUREAU759
       
      Merci beaucoup pour ton aide Martine mais je suis vraiment dans le jus, je t'explique........
      J'ai téléchargé navilog sans probleme jusqu'au moment ou il me demande de choisir ma langue sur le tableau noir et lail me marque erreur et il ne continu pas !!!
      j'ai fait un scan avec totalscan, je t'envoi le rapport.......
      Regarde si tu vois quelque chose !

      En fait j'ai des pub intempestive stile la redoute ou casino et aussi comme quoi je suis infecté ect ect...
      Tu vois le genre, c'est désespérant.

      En tout les cas merci pour ta patiente

      bisous
      Taureau
      ;***********************************************************************************************************************************************************************************
      ANALYSIS: 2008-03-18 14:47:56
      PROTECTIONS: 2
      MALWARE: 9
      SUSPECTS: 2
      ;***********************************************************************************************************************************************************************************
      PROTECTIONS
      Description Version Active Updated
      ;===================================================================================================================================================================================
      avast! antivirus 4.7.1098 [VPS 080318-0] 4.7.1098 No Yes
      Norton Internet Security 2007 No No
      ;===================================================================================================================================================================================
      MALWARE
      Id Description Type Active Severity Disinfectable Disinfected Location
      ;===================================================================================================================================================================================
      00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No C:\Users\TAUREAU\AppData\Roaming\Microsoft\Windows\Cookies\Low\taureau@doubleclick[1].txt
      00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No C:\Users\TAUREAU\AppData\Roaming\Microsoft\Windows\Cookies\Low\taureau@atdmt[1].txt
      00145393 Cookie/Tradedoubler TrackingCookie No 0 Yes No C:\Users\TAUREAU\AppData\Roaming\Microsoft\Windows\Cookies\Low\taureau@tradedoubler[2].txt
      00167704 Cookie/Xiti TrackingCookie No 0 Yes No C:\Users\TAUREAU\AppData\Roaming\Microsoft\Windows\Cookies\Low\taureau@xiti[1].txt
      00168106 Cookie/Weborama TrackingCookie No 0 Yes No C:\Users\TAUREAU\AppData\Roaming\Microsoft\Windows\Cookies\Low\taureau@weborama[2].txt
      00168114 Cookie/onestat.com TrackingCookie No 0 Yes No C:\Users\TAUREAU\AppData\Roaming\Microsoft\Windows\Cookies\Low\taureau@stat.onestat[2].txt
      00172449 Cookie/MetriWeb TrackingCookie No 0 Yes No C:\Users\TAUREAU\AppData\Roaming\Microsoft\Windows\Cookies\Low\taureau@metriweb[1].txt
      00273339 Cookie/Smartadserver TrackingCookie No 0 Yes No C:\Users\TAUREAU\AppData\Roaming\Microsoft\Windows\Cookies\Low\taureau@smartadserver[1].txt
      00375171 Application/SweetBar HackTools Yes 0 Yes No C:\PROGRAM FILES\MACROGAMING\SWEETIMBARFORIE\TOOLBAR.DLL
      ;===================================================================================================================================================================================
      SUSPECTS
      Location
      ;===================================================================================================================================================================================
      C:\PROGRAM FILES\ADSSITE ADVANCED TOOLBAR\TOOLBAR.DLL
      C:\WINDOWS\SYSTEM32\MSJAVA32.DLL
      ;===================================================================================================================================================================================
      0
  3. martine03 Messages postés 2128 Date d'inscription   Statut Membre Dernière intervention   17
     
    je ne sais pas lire celui là tu ne doit pas avoir installè comme il faut navilog je pense
    0
    1. TAUREAU759 Messages postés 12 Statut Membre
       
      Search Navipromo version 3.4.9 commencé le mar. 18/03/2008 à 23:07:08,30

      !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
      !!! Postez ce rapport sur le forum pour le faire analyser !!!
      !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

      Outil exécuté depuis C:\Program Files\navilog1
      Mise à jour le 03.03.2008 à 18h00 par IL-MAFIOSO

      Microsoft Windows Vista 6.0.6000
      Internet Explorer : 7.0.6000.16609
      Système de fichiers : NTFS

      Executé en mode normal

      *** Recherche Programmes installés ***




      *** Recherche dossiers dans C:\Windows ***



      *** Recherche dossiers dans C:\Program Files ***


      *** Recherche dossiers dans C:\ProgramData ***


      *** Recherche dossiers dans C:\ProgramData\Microsoft\Windows\Start Menu\Programs ***


      *** Recherche dossiers dans c:\users\taureau\appdata\roaming\microsoft\windows\start menu\programs ***


      *** Recherche dossiers dans C:\Users\TAUREAU\AppData\Local\virtualstore\Program Files ***



      *** Recherche dossiers dans C:\Users\TAUREAU\AppData\Roaming ***


      *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
      pour + d'infos : http://www.gmer.net

      Fichier(s) caché(s) :

      C:\Users\TAUREAU\AppData\Local\etsjhx.dat
      C:\Users\TAUREAU\AppData\Local\etsjhx.exe
      C:\Users\TAUREAU\AppData\Local\etsjhx_nav.dat
      C:\Users\TAUREAU\AppData\Local\etsjhx_navps.dat



      *** Recherche avec GenericNaviSearch ***
      !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
      !!! A vérifier impérativement avant toute suppression manuelle !!!

      * Recherche dans C:\Windows\system32 *

      * Recherche dans C:\Users\TAUREAU\AppData\Local\Microsoft *

      * Recherche dans C:\Users\TAUREAU\AppData\Local\virtualstore\windows\system32 *

      * Recherche dans C:\Users\TAUREAU\AppData\Local *

      Fichiers suspects :

      etsjhx.exe trouvé !



      *** Recherche fichiers ***


      C:\Windows\system32\nvs2.inf trouvé !
      C:\Windows\prefetch\WEBMEDIAPLAYER.EXE-43FFD6AC.pf trouvé !


      *** Recherche clés spécifiques dans le Registre ***


      *** Module de Recherche complémentaire ***
      (Recherche fichiers spécifiques)

      1)Recherche nouveaux fichiers Instant Access :


      2)Recherche Heuristique :

      * Dans C:\Windows\system32 :


      * Dans C:\Users\TAUREAU\AppData\Local\Microsoft :


      * Dans C:\Users\TAUREAU\AppData\Local\virtualstore\windows\system32 :


      * Dans C:\Users\TAUREAU\AppData\Local :

      etsjhx.dat trouvé !

      3)Recherche Certificats :

      Certificat Egroup trouvé !

      4)Recherche fichiers connus :



      *** Analyse terminée le mar. 18/03/2008 à 23:12:41,11 ***

      --Voila Martine, j'ai enfin réussi ! ouf merci de ton aide
      Comment ca marche ? un site utile et pratique, une question ! des réponses.
                                                          Taureau759
      0
      1. martine03 Messages postés 2128 Date d'inscription   Statut Membre Dernière intervention   17 > TAUREAU759 Messages postés 12 Statut Membre
         
        relance le et choisi 2 et il va tout nettoyer
        0
      2. TAUREAU759 > martine03 Messages postés 2128 Date d'inscription   Statut Membre Dernière intervention  
         
        Merci beaucoup Martine03, ca à l'air de fonctionner, génial,
        J'ai encore une petite question, lorsque j'allume mon PC j'ai toujours le message suivant.......
        c:\Windows\system32\gzmrotate.dll et je n'arrive pas à m'en débarrassé !

        as tu une solution ???

        Encore merci
        0
      3. ^^Marie^^ Messages postés 41884 Date d'inscription   Statut Membre Dernière intervention   3 280 > TAUREAU759
         
        Envoie le rapport, y'a des méthodes pour supprimer les infections

        0
  4. martine03 Messages postés 2128 Date d'inscription   Statut Membre Dernière intervention   17
     
    regarde au demarage et supprime le
    0
    1. TAUREAU759 Messages postés 12 Statut Membre
       
      dans le demarrage ?
      0