Warning ! spy detected .....sur fond bleu

Résolu
meriem76 Messages postés 16 Statut Membre -  
meriem76 Messages postés 16 Statut Membre -
Bonjour,
svp aidez moi
mon pc redemarre tout seul et j'ai un ecran bleu warning ! spy detected sur fond bleu
que faire ? j'ai passer spybot en sans echec et rien n'y fait et adware
Configuration: Windows XP
Internet Explorer 7.0

14 réponses

  1. Utilisateur anonyme
     
    1) Télécharge Malwarebytes' Anti-Malware.

    *Télécharge et installe Malwarebyte's Anti-Malware
    *http://www.commentcamarche.net/telecharger/telechargement 34055379 malwarebyte s anti malware
    *A la fin de l'installation, veille à ce que l'option « mettre a jour Malwarebyte's Anti-Malware » soit cochée. >>> clique sur OK
    *Lance Malwarebyte's Anti-Malware en double-cliquant sur l'icône sur ton Bureau.
    *Au premier lancement, une fenêtre t'annonce que la version est Free >>> clique sur OK
    *Laisse les Mises à jour se télécharger

    *** Referme le programme ***

    2) Redémarre en "Mode sans échec"

    Au redémarrage de l'ordinateur, une fois le chargement du BIOS terminé, il y a un écran noir qui apparaît rapidement, appuie sur la touche [F8] (ou [F5] sur certains pc) jusqu'à l'affichage du menu des options avancées de Windows.
    Sélectionner "Mode sans échec" et appuie sur [Entrée]
    Il faudra choisir ta session habituelle, pas le compte "Administrateur" ou une autre.
    Regarde ici si besoin : http://pageperso.aol.fr/loraline60/mode_sans_echec.htm

    Ouvre le fichier texte sauvegardé sur le Bureau afin de suivre les instructions comme il faut.

    3) Scan avec Malwarebyte's Anti-Malware

    *Lance Malwarebyte's Anti-Malware
    *Puis vs dans l'onglet "Recherche" puis coche "Exécuter un examen complet" puis "Rechercher sélectionne tes disques durs" puis clique sur "Lancer l’examen"
    *A la fin du scan >>> clique sur Afficher les résultats puis sur Enregistrer le rapport
    *Suppression des éléments détectés >>>> clique sur Supprimer la sélection
    *S'il t'es demandé de redémarrer >>> clique sur "Yes"

    *--> Un rapport de scan s'ouvre, enregistre sur ton Bureau et poste ce rapport en réponse.
    1
    1. meriem76 Messages postés 16 Statut Membre 1
       
      Vraiment merci boy94450 pour votre rapidite
      je vais suivre
      et je colle le rapport
      0
  2. gil le fantom Messages postés 2809 Statut Membre 25
     
    une autre question

    tu utilise PicBlock ,est il efficace ?
    ne fait il pas ralentir la navigation ?
    merci pour ta réponse
    1
  3. meriem76 Messages postés 16 Statut Membre 1
     
    je n'arrive pas à faire un scan complet ca redemarre à chaque fois au bout d'1 heure et comme j'ai undd de 160 go rempli il me fau t plus de temps
    comment faire ?
    sans demarrer windows ?
    0
    1. Utilisateur anonyme
       
      Ok fais le en mode normal.
      0
  4. meriem76 Messages postés 16 Statut Membre 1
     
    bonjour,
    voila mon rapport apres 6h de scan est ce normal ?
    j'ai tjs l'ecran bleu apres redemarrage

    rapport :

    Malwarebytes' Anti-Malware 1.18
    Version de la base de données: 875

    02:58:49 22/06/2008
    mbam-log-6-22-2008 (02-58-49).txt

    Type de recherche: Examen complet (C:\|D:\|E:\|)
    Eléments examinés: 478302
    Temps écoulé: 6 hour(s), 18 minute(s), 37 second(s)

    Processus mémoire infecté(s): 0
    Module(s) mémoire infecté(s): 0
    Clé(s) du Registre infectée(s): 4
    Valeur(s) du Registre infectée(s): 0
    Elément(s) de données du Registre infecté(s): 2
    Dossier(s) infecté(s): 0
    Fichier(s) infecté(s): 1

    Processus mémoire infecté(s):
    (Aucun élément nuisible détecté)

    Module(s) mémoire infecté(s):
    (Aucun élément nuisible détecté)

    Clé(s) du Registre infectée(s):
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{def85c80-216a-43ab-af70-1665edbe2780} (Spyware.Sinowal) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ICF (Trojan.Agent) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Software Notifier (Rogue.Multiple) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ICF (Rootkit.Agent) -> Quarantined and deleted successfully.

    Valeur(s) du Registre infectée(s):
    (Aucun élément nuisible détecté)

    Elément(s) de données du Registre infecté(s):
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\NoDispBackgroundPage (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\NoDispScrSavPage (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

    Dossier(s) infecté(s):
    (Aucun élément nuisible détecté)

    Fichier(s) infecté(s):
    C:\Documents and Settings\admin\results.txt (Malware.Trace) -> Quarantined and deleted successfully.
    0
    1. Utilisateur anonyme
       
      Ok parfait.

      *Télécharge HijackThis: http://www.trendsecure.com/portal/en-US/_download/HJTInstall.exe
      *Puis fais "Install" puis "I accept" puis tu cliques sur "Do a system scan and save a logfile".
      *L'analyse se fait un bloc-note s'ouvrira tu fais copier/coller dans le forum.
      0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. meriem76 Messages postés 16 Statut Membre 1
     
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 14:25:07, on 22/06/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    C:\WINDOWS\system32\netdde.exe
    C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\System32\tcpsvcs.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\key\VOLVOXKEYLOG.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
    C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\ff0e3fb1ca1253a2ee04c645d2c9100d\update\update.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/webhp?sourceid=navclient&hl=fr&ie=UTF-8&gws_rd=ssl
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.carrefour.fr/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = admin
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    R3 - URLSearchHook: (no name) - {0A94B116-4504-4e26-AB05-E61E474AA38B} - C:\Program Files\AskPBar\SrchAstt\1.bin\A9SRCHAS.DLL (file missing)
    R3 - URLSearchHook: Yahoo! ¤u¨ã¦C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
    O2 - BHO: (no name) - {6A373B7E-496E-424f-A9BE-486A5E9AB018} - (no file)
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar5.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
    O2 - BHO: (no name) - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - (no file)
    O2 - BHO: Ask Toolbar BHO - {F4D76F01-7896-458a-890F-E1F05C46069F} - C:\Program Files\AskPBar\bar\1.bin\ASKPBAR.DLL (file missing)
    O3 - Toolbar: Systran40premi.IEPlugIn - {CFB25594-4D5F-11D6-AB7B-00B0D094B576} - C:\Program Files\Systran\4_0\Premium\IEPlugIn.dll
    O3 - Toolbar: (no name) - {A20A76AD-7A29-4756-87FE-70C334CB40C0} - (no file)
    O3 - Toolbar: (no name) - {2E608F70-C430-4bc5-96F6-608E02EBA5B2} - (no file)
    O3 - Toolbar: Ask Toolbar - {F4D76F09-7896-458a-890F-E1F05C46069F} - C:\Program Files\AskPBar\bar\1.bin\ASKPBAR.DLL (file missing)
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar5.dll
    O3 - Toolbar: Yahoo! ¤u¨ã¦C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
    O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
    O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [NMB] "C:\key\VOLVOXKEYLOG.exe" "Ghost"
    O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
    O4 - HKLM\..\Run: [PicBlock] C:\Program Files\PicBlock\picblock.exe
    O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'Default user')
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm
    O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm
    O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm
    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
    O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\WINDOWS\System32\shdocvw.dll
    O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
    O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
    O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
    O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
    O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {9819CC0E-9669-4D01-9CD7-2C66DA43AC6C} - (no file)
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
    O9 - Extra button: (no name) - SolidConverterPDF - (no file) (HKCU)
    O10 - Unknown file in Winsock LSP: icaproxy.dll
    O10 - Unknown file in Winsock LSP: icaproxy.dll
    O10 - Unknown file in Winsock LSP: icaproxy.dll
    O10 - Unknown file in Winsock LSP: icaproxy.dll
    O10 - Unknown file in Winsock LSP: icaproxy.dll
    O10 - Unknown file in Winsock LSP: icaproxy.dll
    O10 - Unknown file in Winsock LSP: icaproxy.dll
    O10 - Unknown file in Winsock LSP: icaproxy.dll
    O10 - Unknown file in Winsock LSP: icaproxy.dll
    O10 - Unknown file in Winsock LSP: icaproxy.dll
    O10 - Unknown file in Winsock LSP: icaproxy.dll
    O10 - Unknown file in Winsock LSP: icaproxy.dll
    O10 - Unknown file in Winsock LSP: icaproxy.dll
    O10 - Unknown file in Winsock LSP: icaproxy.dll
    O10 - Unknown file in Winsock LSP: icaproxy.dll
    O10 - Unknown file in Winsock LSP: icaproxy.dll
    O10 - Unknown file in Winsock LSP: icaproxy.dll
    O10 - Unknown file in Winsock LSP: icaproxy.dll
    O10 - Unknown file in Winsock LSP: icaproxy.dll
    O10 - Unknown file in Winsock LSP: icaproxy.dll
    O10 - Unknown file in Winsock LSP: icaproxy.dll
    O10 - Unknown file in Winsock LSP: icaproxy.dll
    O14 - IERESET.INF: START_PAGE_URL=http://www.carrefour.fr/
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
    O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
    O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - https://www.cult3d.com/
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
    O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1103927360312
    O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
    O16 - DPF: {A73BAEFA-EE65-494D-BEDB-DD3E5A34FA98} (Image Uploader) - http://www.extrafilm.fr/ImageUploader4.cab
    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
    O16 - DPF: {C5E28B9D-0A68-4B50-94E9-E8F6B4697514} -
    O16 - DPF: {ED4E6F97-FA1A-4634-B550-AABFEB8DA009} - http://www.exstream.to/tulip/cab/3,0,5,19/TulipPlayer2.cab
    O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
    O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Client de licence CA (CA_LIC_CLNT) - Unknown owner - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe (file missing)
    O23 - Service: Serveur de licence CA (CA_LIC_SRVR) - Unknown owner - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmtd.exe (file missing)
    O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Event Log Watch (LogWatch) - Unknown owner - C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe (file missing)
    O23 - Service: Card Adapter (NETDown) - Unknown owner - C:\WINDOWS\smss.exe (file missing)
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: Outpost Firewall Service (OutpostFirewall) - Unknown owner - C:\PROGRA~1\Agnitum\OUTPOS~1.0\outpost.exe (file missing)
    O23 - Service: PC Tools AntiVirus Engine (PCTAVSvc) - Unknown owner - C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe (file missing)
    O23 - Service: StarWind iSCSI Service (StarWindService) - MCCI - (no file)
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
    0
  7. meriem76 Messages postés 16 Statut Membre 1
     
    je l'ai deja je dois le refaire à nouveau ?
    0
  8. meriem76 Messages postés 16 Statut Membre 1
     
    je l'utilise dans quel mode ? sans echec ?
    0
    1. Utilisateur anonyme
       
      Ok maintenant fais une mise a jour de Spybot pour cela ouvre "Spybot" puis cliques sur "Recherche de mise a jour" puis tu clique sur "Continuer" puis des mises a jour seront cochés (tu les laisses) puis tu cliques sur "Télécharger" puis tu attends. Apres avoir fait tout cela tu fais un scan avec Spybot en mode sans échec. Tu ouvres "Spybot" puis cliques sur "Vérifier Tout" puis si il détecte des trucs a la fin tu cliques sur "Corriger les problèmes" puis tu cliques sur "Oui pour autoriser Spybot à nettoyer les mouchards". Puis tu redémarre en mode normal puis tu me dis si Spybot a détecté des choses.
      0
  9. meriem76 Messages postés 16 Statut Membre 1
     
    ok j' y vais merci
    0
  10. gil le fantom Messages postés 2809 Statut Membre 25
     
    bonjour

    juste une question meriem c'est toi qui a installé Volvox Keylogger : Enregistreur de frappes ?
    0
  11. Utilisateur anonyme
     
    PicBlock est un outil qui vous permettra de bloquer les images pornographiques reçues sur votre client mail ou à partir des sites Web que vous visitez depuis votre navigateur. Contrairement à la plupart des logiciels qui bloquent du contenu, PicBlock lui détectera les images en analysant le contenu de la page, filtrera l’image en question et floutera celles-ci.
    0
  12. gil le fantom Messages postés 2809 Statut Membre 25
     
    je sais boys ,merci
    je voudrai juste savoir juste son comportement
    0
  13. meriem76 Messages postés 16 Statut Membre 1
     
    voila je reviens
    il fallait reinstaller spybot
    j'ai fait un scan en mode normal ensuite en mode sans echec
    le 1ER m'a corriger 7 erreurs
    le 2nd note aucun mouchard
    je suis en train de scanner avec antivir et j'ai relancer spybot en mode normal

    voila le rapport de spybot :
    22.06.2008 15:49:35 - ##### check started #####
    22.06.2008 15:49:35 - ### Version: 1.5.2
    22.06.2008 15:49:35 - ### Date: 22/06/2008 15:49:35
    22.06.2008 15:49:40 - ##### checking bots #####
    22.06.2008 15:49:54 - found: Adviva Cookie traceur (Internet Explorer: admin)
    22.06.2008 15:49:54 - found: AdRevolver Cookie traceur (Internet Explorer: admin)
    22.06.2008 15:49:54 - found: DoubleClick Cookie traceur (Internet Explorer: admin)
    22.06.2008 15:49:54 - found: HitBox Cookie traceur (Internet Explorer: admin)
    22.06.2008 15:49:54 - found: HitsLink Cookie traceur (Internet Explorer: admin)
    22.06.2008 15:49:54 - found: BlueStreak Cookie traceur (Internet Explorer: admin)
    22.06.2008 15:49:54 - found: FastClick Cookie traceur (Internet Explorer: admin)
    22.06.2008 15:49:54 - found: WebTrends live Cookie traceur (Internet Explorer: admin)
    22.06.2008 15:49:54 - found: Tradedoubler Cookie traceur (Internet Explorer: admin)
    22.06.2008 15:49:54 - found: Zedo Cookie traceur (Internet Explorer: admin)
    22.06.2008 15:49:54 - found: HitBox Cookie traceur (Internet Explorer: admin)
    22.06.2008 15:49:54 - found: HitBox Cookie traceur (Internet Explorer: admin)
    22.06.2008 15:49:55 - found: Statcounter Cookie traceur (Internet Explorer: admin)
    22.06.2008 15:49:55 - found: AdRevolver Cookie traceur (Firefox: default)
    22.06.2008 15:49:55 - found: DoubleClick Cookie traceur (Firefox: default)
    22.06.2008 15:49:55 - found: HitBox Cookie traceur (Firefox: default)
    22.06.2008 15:49:55 - found: FastClick Cookie traceur (Firefox: default)
    22.06.2008 15:49:55 - found: HitBox Cookie traceur (Firefox: default)
    22.06.2008 15:49:55 - found: MediaPlex Cookie traceur (Firefox: default)
    22.06.2008 15:49:55 - found: Tradedoubler Cookie traceur (Firefox: default)
    22.06.2008 15:49:55 - found: AdRevolver Cookie traceur (Firefox: default)
    22.06.2008 15:49:55 - found: AdRevolver Cookie traceur (Firefox: default)
    22.06.2008 15:49:55 - found: AdRevolver Cookie traceur (Firefox: default)
    22.06.2008 15:49:55 - found: CasaleMedia Cookie traceur (Firefox: default)
    22.06.2008 15:49:55 - found: CasaleMedia Cookie traceur (Firefox: default)
    22.06.2008 15:49:55 - found: CasaleMedia Cookie traceur (Firefox: default)
    22.06.2008 15:49:55 - found: MediaPlex Cookie traceur (Firefox: default)
    22.06.2008 15:49:55 - found: MediaPlex Cookie traceur (Firefox: default)
    22.06.2008 15:49:55 - found: Zedo Cookie traceur (Firefox: default)
    22.06.2008 15:49:55 - found: Zedo Cookie traceur (Firefox: default)
    22.06.2008 15:49:55 - found: Zedo Cookie traceur (Firefox: default)

    normal

    --- Report generated: 2008-06-22 15:50 ---

    Adviva: Cookie traceur (Internet Explorer: admin) (Cookie, fixed)

    AdRevolver: Cookie traceur (Internet Explorer: admin) (Cookie, fixed)

    DoubleClick: Cookie traceur (Internet Explorer: admin) (Cookie, fixed)

    HitBox: Cookie traceur (Internet Explorer: admin) (Cookie, fixed)

    HitsLink: Cookie traceur (Internet Explorer: admin) (Cookie, fixed)

    BlueStreak: Cookie traceur (Internet Explorer: admin) (Cookie, fixed)

    FastClick: Cookie traceur (Internet Explorer: admin) (Cookie, fixed)

    WebTrends live: Cookie traceur (Internet Explorer: admin) (Cookie, fixed)

    Tradedoubler: Cookie traceur (Internet Explorer: admin) (Cookie, fixed)

    Zedo: Cookie traceur (Internet Explorer: admin) (Cookie, fixed)

    HitBox: Cookie traceur (Internet Explorer: admin) (Cookie, fixed)

    HitBox: Cookie traceur (Internet Explorer: admin) (Cookie, fixed)

    Statcounter: Cookie traceur (Internet Explorer: admin) (Cookie, fixed)

    AdRevolver: Cookie traceur (Firefox: default) (Cookie, fixed)

    DoubleClick: Cookie traceur (Firefox: default) (Cookie, fixed)

    HitBox: Cookie traceur (Firefox: default) (Cookie, fixed)

    FastClick: Cookie traceur (Firefox: default) (Cookie, fixed)

    HitBox: Cookie traceur (Firefox: default) (Cookie, fixed)

    MediaPlex: Cookie traceur (Firefox: default) (Cookie, fixed)

    Tradedoubler: Cookie traceur (Firefox: default) (Cookie, fixed)

    AdRevolver: Cookie traceur (Firefox: default) (Cookie, fixed)

    AdRevolver: Cookie traceur (Firefox: default) (Cookie, fixed)

    AdRevolver: Cookie traceur (Firefox: default) (Cookie, fixed)

    CasaleMedia: Cookie traceur (Firefox: default) (Cookie, fixed)

    CasaleMedia: Cookie traceur (Firefox: default) (Cookie, fixed)

    CasaleMedia: Cookie traceur (Firefox: default) (Cookie, fixed)

    MediaPlex: Cookie traceur (Firefox: default) (Cookie, fixed)

    MediaPlex: Cookie traceur (Firefox: default) (Cookie, fixed)

    Zedo: Cookie traceur (Firefox: default) (Cookie, fixed)

    Zedo: Cookie traceur (Firefox: default) (Cookie, fixed)

    Zedo: Cookie traceur (Firefox: default) (Cookie, fixed)

    --- Spybot - Search & Destroy version: 1.5.2 (build: 20080128) ---

    2008-01-28 blindman.exe (1.0.0.7)
    2008-01-28 SDDelFile.exe (1.0.2.4)
    2008-01-28 SDMain.exe (1.0.0.5)
    2007-10-07 SDShred.exe (1.0.1.2)
    2008-01-28 SDUpdate.exe (1.0.8.8)
    2008-01-28 SDWinSec.exe (1.0.0.11)
    2008-01-28 SpybotSD.exe (1.5.2.20)
    2008-01-28 TeaTimer.exe (1.5.2.16)
    2008-06-22 unins000.exe (51.49.0.0)
    2008-01-28 Update.exe (1.4.0.6)
    2008-01-28 advcheck.dll (1.5.4.5)
    2007-04-02 aports.dll (2.1.0.0)
    2007-11-17 DelZip179.dll (1.79.7.4)
    2008-01-28 SDFiles.dll (1.5.1.19)
    2008-01-28 SDHelper.dll (1.5.0.11)
    2008-01-28 Tools.dll (2.1.3.3)
    2008-06-17 Includes\Adware.sbi (*)
    2008-06-18 Includes\AdwareC.sbi (*)
    2008-06-03 Includes\Cookies.sbi (*)
    2008-06-03 Includes\Dialer.sbi (*)
    2008-06-10 Includes\DialerC.sbi (*)
    2008-06-03 Includes\HeavyDuty.sbi (*)
    2008-06-16 Includes\Hijackers.sbi (*)
    2008-06-17 Includes\HijackersC.sbi (*)
    2008-06-03 Includes\Keyloggers.sbi (*)
    2008-06-17 Includes\KeyloggersC.sbi (*)
    2008-06-18 Includes\Malware.sbi (*)
    2008-06-17 Includes\MalwareC.sbi (*)
    2008-06-17 Includes\PUPS.sbi (*)
    2008-06-17 Includes\PUPSC.sbi (*)
    2007-11-07 Includes\Revision.sbi (*)
    2008-06-10 Includes\Security.sbi (*)
    2008-06-18 Includes\SecurityC.sbi (*)
    2008-06-03 Includes\Spybots.sbi (*)
    2008-06-03 Includes\SpybotsC.sbi (*)
    2008-06-17 Includes\Spyware.sbi (*)
    2008-06-17 Includes\SpywareC.sbi (*)
    2008-06-03 Includes\Tracks.uti
    2008-06-11 Includes\Trojans.sbi (*)
    2008-06-18 Includes\TrojansC.sbi (*)
    2008-03-04 Plugins\Chai.dll
    2008-03-05 Plugins\Fennel.dll
    2008-02-26 Plugins\Mate.dll
    2007-12-24 Plugins\TCPIPAddress.dll

    ensuite

    --- Report generated: 2008-06-22 16:52 ---

    Félicitations!: Aucun mouchard n'a été trouvé. ()

    --- Spybot - Search & Destroy version: 1.5.2 (build: 20080128) ---

    2008-01-28 blindman.exe (1.0.0.7)
    2008-01-28 SDDelFile.exe (1.0.2.4)
    2008-01-28 SDMain.exe (1.0.0.5)
    2007-10-07 SDShred.exe (1.0.1.2)
    2008-01-28 SDUpdate.exe (1.0.8.8)
    2008-01-28 SDWinSec.exe (1.0.0.11)
    2008-01-28 SpybotSD.exe (1.5.2.20)
    2008-01-28 TeaTimer.exe (1.5.2.16)
    2008-06-22 unins000.exe (51.49.0.0)
    2008-01-28 Update.exe (1.4.0.6)
    2008-01-28 advcheck.dll (1.5.4.5)
    2007-04-02 aports.dll (2.1.0.0)
    2007-11-17 DelZip179.dll (1.79.7.4)
    2008-01-28 SDFiles.dll (1.5.1.19)
    2008-01-28 SDHelper.dll (1.5.0.11)
    2008-01-28 Tools.dll (2.1.3.3)
    2008-06-17 Includes\Adware.sbi (*)
    2008-06-18 Includes\AdwareC.sbi (*)
    2008-06-03 Includes\Cookies.sbi (*)
    2008-06-03 Includes\Dialer.sbi (*)
    2008-06-10 Includes\DialerC.sbi (*)
    2008-06-03 Includes\HeavyDuty.sbi (*)
    2008-06-16 Includes\Hijackers.sbi (*)
    2008-06-17 Includes\HijackersC.sbi (*)
    2008-06-03 Includes\Keyloggers.sbi (*)
    2008-06-17 Includes\KeyloggersC.sbi (*)
    2008-06-18 Includes\Malware.sbi (*)
    2008-06-17 Includes\MalwareC.sbi (*)
    2008-06-17 Includes\PUPS.sbi (*)
    2008-06-17 Includes\PUPSC.sbi (*)
    2007-11-07 Includes\Revision.sbi (*)
    2008-06-10 Includes\Security.sbi (*)
    2008-06-18 Includes\SecurityC.sbi (*)
    2008-06-03 Includes\Spybots.sbi (*)
    2008-06-03 Includes\SpybotsC.sbi (*)
    2008-06-17 Includes\Spyware.sbi (*)
    2008-06-17 Includes\SpywareC.sbi (*)
    2008-06-03 Includes\Tracks.uti
    2008-06-11 Includes\Trojans.sbi (*)
    2008-06-18 Includes\TrojansC.sbi (*)
    2008-03-04 Plugins\Chai.dll
    2008-03-05 Plugins\Fennel.dll
    2008-02-26 Plugins\Mate.dll
    2007-12-24 Plugins\TCPIPAddress.dll

    je pense que le virus est parti mais j'etais obligé de changer moi meme l'arriere plan "fon bleu" en ap perso.
    mes questions ?
    - est ce que c'etait un vrus, un spy ou quoi ? est ce qu'ilest definitivement efface
    - comment se proteger ?
    pour repondre :
    oui c moi qui a installe keylogger pour surveillance du pc
    pour PicBlock je n'ai pas reussi à le faire fonctionnner ni completement desinstaller parceque j'ai mis un mdp que j'ai oublie lent

    MERCI BEAUCOUP boy94450 pour votre aide et votre disponibilite meme un dimanche
    0
  14. meriem76 Messages postés 16 Statut Membre 1
     
    j-attends la fin des scan pour voir et voir si le pb est resolu
    0
  15. meriem76 Messages postés 16 Statut Membre 1
     
    MERCI BEAUCOUPà BOY94450
    0