Erreur

Résolu
Hatiiim-x3 Messages postés 72 Statut Membre -  
chefpunky Messages postés 676 Statut Membre -
Bonjour,
J ai un message d erreur a chaque ouverture de windows qui me dit:
Erreur de chargement de C:\PROGRA~1~\MYWEBS~1~\bar\1.bin\M3PLUGIN.DLL
Donc j ai telechargé le logiciel HijackThis comme dit et voici le rapport:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:23:09, on 26/07/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\ALCWZRD.EXE
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\domino.exe
C:\WINDOWS\VMSnap1.exe
C:\Program Files\MessengerPlus! 3\MsgPlus.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Iminent\imbooster.exe
C:\Program Files\Fichiers communs\Nero\Lib\NMBgMonitor.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\NEGO-NILE\Bureau\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.iminent.com/...
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Iminent.SearchTheWeb.HelperObject - {0E896FCA-D07E-45FE-901F-6A26FCF59C02} - mscoree.dll (file missing)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (file missing)
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (file missing)
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [MyWebSearch Plugin] rundll32 C:\PROGRA~1\MYWEBS~1\bar\1.bin\M3PLUGIN.DLL,UPF
O4 - HKLM\..\Run: [domino] C:\WINDOWS\domino.exe
O4 - HKLM\..\Run: [VMSnap1] C:\WINDOWS\VMSnap1.exe
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [IMBooster] C:\Program Files\Iminent\imbooster.exe /warmup
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Nero\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: &Search -
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Abonnés - {AD606452-92D8-490C-AA9D-33AF7BC29222} - http://abonne.menara.ma (file missing) (HKCU)
O14 - IERESET.INF: START_PAGE_URL=https://www.menara.ma/
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Fichiers communs\PCSuite\Services\ServiceLayer.exe
O24 - Desktop Component 0: (no name) - http://www.imagechef.com/ic/imgout/anmb4155312aa04d40a.gif
O24 - Desktop Component 1: (no name) - http://images.google.co.jp/...
O24 - Desktop Component 10: (no name) - http://images.google.co.jp/images?q=tbn:Dd0jc7Wapds97M:http://imalbum.aufeminin.com/stars/fan/D20060110/2235_498847603_ronaldinho_pos1_H200218_L.jpg
O24 - Desktop Component 11: (no name) - http://images.google.co.ma/images?q=tbn:CUi56_FMbs4sIM:http://www.meiko.com.pl/wera/dolsikblum.gif
O24 - Desktop Component 12: (no name) - http://images.google.co.jp/images?q=tbn:sfqjcHQQuvDfaM:http://www.danceheritage.org/images/hip-hop.jpg
O24 - Desktop Component 13: (no name) - http://pics.centerblog.net/pic/gifsmsn/wgan1ddz.gif
O24 - Desktop Component 2: (no name) - http://images.google.co.jp/images?q=tbn:BVxefYDg3TQF9M:http://www.valechumbar.com/media/2/20050418-ronaldinho-nueva-min.jpg
O24 - Desktop Component 3: (no name) - http://images.google.co.jp/images?q=tbn:Pptd7lBtgSyxNM:http://blog.uncovering.org/archives/uploads/2005/seven/ronaldinho.jpg
O24 - Desktop Component 4: (no name) - http://images.google.co.jp/...
O24 - Desktop Component 5: (no name) - http://images.google.co.jp/images?q=tbn:3Q42_iy9eES8CM:http://www.gwiazdyfutbolu.com/metryka/ronaldinho.jpg
O24 - Desktop Component 6: (no name) - http://images.google.co.jp/images?q=tbn:MvH7pB1kpYlyuM:http://www.irancartoon.com/100/daily/Ronaldinho.jpg
O24 - Desktop Component 7: (no name) - http://images.google.co.jp/images?q=tbn:vi01-PMDnFfngM:http://www.aftonbladet.se/sport/0511/26/SPORT-26s06-ronaldinho-887_368.jpg
O24 - Desktop Component 8: (no name) - http://images.google.co.jp/images?q=tbn:yjLSoQSEIQM-FM:http://www.ronaldinho.gool.pl/ronaldinho_barcelona_8.jpg
O24 - Desktop Component 9: (no name) - http://images.google.co.jp/images?q=tbn:5bPj-HqAW4QkTM:http://www.fcbarcelonablog.com/images/Ronaldinho%2520and%2520Henry.jpg

--
End of file - 9426 bytes

Que dois je faire maintenant ?
Aidez mOi !
Configuration: Windows XP
Firefox 3.0.1

22 réponses

  • 1
  • 2
Résumé de la discussion

Le signalement concerne une erreur de chargement récurrente de M3PLUGIN.DLL dans le répertoire MyWebSearch et une liste d’éléments suspects détectés par HijackThis, notamment des barres d’outils et des BHO. Plusieurs conseils préconisent une analyse antivirus et antimalware complète; le rapport MBAM révèle des adware comme MyWebSearch, Navipromo et ShoppingReport, ainsi que des entrées de registre potentiellement nuisibles. Des échanges insistent sur le nettoyage des éléments de démarrage et sur la nécessité d’une mise à jour régulière de l’antivirus, avec des suggestions de solutions complémentaires et d’outils spécialisés. Enfin, un commentaire rappelle l’absence d’antivirus sur le poste, soulignant l’importance d’en installer un et de procéder à une cure complète avant de relancer une vérification et de partager le nouveau rapport.

Bobot (l'IA à votre service)
  1. chefpunky Messages postés 676 Statut Membre 31
     
    Tud ois etre infecter par des trojan downloader trojan fakealert ect..
    0
  2. Hatiiim-x3 Messages postés 72 Statut Membre 1
     
    Merci de ta réponnse chefpunky
    je vais essayer et je te dis quOi!
    0
  3. chefpunky Messages postés 676 Statut Membre 31
     
    voici toute les ligne qui ne va pas

    C:\Program Files\Iminent\imbooster.exe
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.iminent.com/
    O2 - BHO: Iminent.SearchTheWeb.HelperObject - {0E896FCA-D07E-45FE-901F-6A26FCF59C02} - mscoree.dll (file missing)
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll (file missing)
    O4 - HKLM\..\Run: [MyWebSearch Plugin] rundll32 C:\PROGRA~1\MYWEBS~1\bar\1.bin\M3PLUGIN.DLL,UPF
    O4 - HKLM\..\Run: [VMSnap1] C:\WINDOWS\VMSnap1.exe
    O4 - HKCU\..\Run: [IMBooster] C:\Program Files\Iminent\imbooster.exe /warmup
    O8 - Extra context menu item: &Search -
    O9 - Extra button: Abonnés - {AD606452-92D8-490C-AA9D-33AF7BC29222} - http://abonne.menara.ma (file missing) (HKCU)
    O24 - Desktop Component 0: (no name) - http://www.imagechef.com/ic/imgout/anmb4155312aa04d40a.gif
    O24 - Desktop Component 1: (no name) - https://images.google.co.jp/?gws_rd=ssl
    O24 - Desktop Component 10: (no name) - https://images.google.co.jp/?gws_rd=ssl
    O24 - Desktop Component 11: (no name) - https://images.google.co.ma/?gws_rd=ssl
    O24 - Desktop Component 12: (no name) - https://images.google.co.jp/?gws_rd=ssl
    O24 - Desktop Component 13: (no name) - http://pics.centerblog.net/pic/gifsmsn/wgan1ddz.gif
    O24 - Desktop Component 2: (no name) - https://images.google.co.jp/?gws_rd=ssl
    O24 - Desktop Component 3: (no name) - https://images.google.co.jp/?gws_rd=ssl
    O24 - Desktop Component 4: (no name) - https://images.google.co.jp/?gws_rd=ssl
    O24 - Desktop Component 5: (no name) - https://images.google.co.jp/?gws_rd=ssl
    O24 - Desktop Component 6: (no name) - https://images.google.co.jp/?gws_rd=ssl
    O24 - Desktop Component 7: (no name) - https://images.google.co.jp/?gws_rd=ssl
    O24 - Desktop Component 8: (no name) - https://images.google.co.jp/?gws_rd=ssl
    O24 - Desktop Component 9: (no name) - https://images.google.co.jp/?gws_rd=ssl
    0
  4. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  5. Hatiiim-x3 Messages postés 72 Statut Membre 1
     
    Je dois toutes les effacés?
    0
  6. chefpunky Messages postés 676 Statut Membre 31
     
    Non touche a rien pour l' instantfait sa

    Bon pour commencer tout sa:
    1.1telecharge MBAM via l' adresse suivante:
    https://www.commentcamarche.net/telecharger/ 34055379 malwarebyte s anti malware

    1.2 met le a jour

    1.3scan ton pc avec une analyse COMPLETE

    1.4 nettois lesi infections

    1.5 colle le rapport sur ce forum

    0
  7. Hatiiim-x3 Messages postés 72 Statut Membre 1
     
    Ouii je l ai fait
    c est en train de faire l examen
    complet
    4 minutes et déja 10 éléments inféctés!
    0
    1. chefpunky Messages postés 676 Statut Membre 31
       
      Ah en faite ta pas d' antivirus!!
      0
  8. Hatiiim-x3 Messages postés 72 Statut Membre 1
     
    Oui j ai ESET NOD32 antivirus 3.0.650.0
    0
    1. chefpunky Messages postés 676 Statut Membre 31
       
      si tu la payer laisse le sinon si c la version devaluation vire la et remplace le par avira

      eset nod32 3.0 et pourri a par rapport la version 2.7(je peux te le dire j' ai acheter les deux pour les tester
      0
  9. Hatiiim-x3 Messages postés 72 Statut Membre 1
     
    Okéii Je vais telechager avira
    0
  10. chefpunky Messages postés 676 Statut Membre 31
     
    Apres MBAM!!
    0
  11. Hatiiim-x3 Messages postés 72 Statut Membre 1
     
    Quand le balayage est fini?

    Hé tu na pa un lien ou jepourai le telecharger
    en francais?
    0
  12. chefpunky Messages postés 676 Statut Membre 31
     
    Oui,je revien dans 40 min pour la fin de ton scan je te dit ce qui faut faire apres
    0
  13. Hatiiim-x3 Messages postés 72 Statut Membre 1
     
    Okéii merci
    Tu na pas une adresse msn pour me répondre plus facilemnet?
    0
  14. Hatiiim-x3 Messages postés 72 Statut Membre 1
     
    Voila l analyse c est términé
    je fais quoi maintenant?
    0
    1. chefpunky Messages postés 676 Statut Membre 31
       
      tu nettois les elements et tu mes le rapport sur ce forum
      0
  15. Hatiiim-x3 Messages postés 72 Statut Membre 1
     
    comment?
    0
    1. chefpunky Messages postés 676 Statut Membre 31
       
      click sur nettoyer les element en bas a gauche apres tu va avoir un document text qui va s' ouvrir et tu fait copier coller de tout le rpport sur ce forum
      0
  16. Hatiiim-x3 Messages postés 72 Statut Membre 1
     
    J ai rin qu s ést afiché quant l analyse s ést términé
    Dons je vais la recommencer
    0
  17. chefpunky Messages postés 676 Statut Membre 31
     
    Normalement a la fin du rapport, tu voi tout les noms des infections surlignés en rouge.ta u sa?
    0
  18. Hatiiim-x3 Messages postés 72 Statut Membre 1
     
    nOn
    8(
    0
  19. chefpunky Messages postés 676 Statut Membre 31
     
    a la fin du scan en bas a droite tu peux voir le rapport detailler.
    0
  20. Hatiiim-x3 Messages postés 72 Statut Membre 1
     
    Voila le rapport:

    Malwarebytes' Anti-Malware 1.23
    Version de la base de données: 995
    Windows 5.1.2600 Service Pack 2

    20:57:03 26/07/2008
    mbam-log-7-26-2008 (20-57-03).txt

    Type de recherche: Examen complet (A:\|C:\|D:\|E:\|)
    Eléments examinés: 75718
    Temps écoulé: 23 minute(s), 22 second(s)

    Processus mémoire infecté(s): 0
    Module(s) mémoire infecté(s): 0
    Clé(s) du Registre infectée(s): 7
    Valeur(s) du Registre infectée(s): 6
    Elément(s) de données du Registre infecté(s): 0
    Dossier(s) infecté(s): 14
    Fichier(s) infecté(s): 9

    Processus mémoire infecté(s):
    (Aucun élément nuisible détecté)

    Module(s) mémoire infecté(s):
    (Aucun élément nuisible détecté)

    Clé(s) du Registre infectée(s):
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{90b5a95a-afd5-4d11-b9bd-a69d53d22226} (Adware.Hotbar) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{a7cddcdc-beeb-4685-a062-978f5e07ceee} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\Interface\{cf54be1c-9359-4395-8533-1657cf209cfe} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\Typelib\{d518921a-4a03-425e-9873-b9a71756821e} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\CLSID\{9afb8248-617f-460d-9366-d71cdeda3179} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\ugac (Rogue.PCSecureSystem) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.

    Valeur(s) du Registre infectée(s):
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\ShellBrowser\{07aa283a-43d7-4cbe-a064-32a21112d94d} (Adware.Zango) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Products\rdomain (Rogue.PCVirusless) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Products\prodname (Rogue.PCVirusless) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Products\compname (Rogue.PCVirusless) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow\mysearchnow.com (Malware.Trace) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow\www.mysearchnow.com (Malware.Trace) -> Quarantined and deleted successfully.

    Elément(s) de données du Registre infecté(s):
    (Aucun élément nuisible détecté)

    Dossier(s) infecté(s):
    C:\Program Files\ShoppingReport (Adware.Shopping.Report) -> Quarantined and deleted successfully.
    C:\Program Files\ShoppingReport\Bin (Adware.Shopping.Report) -> Quarantined and deleted successfully.
    C:\Program Files\ShoppingReport\Bin\2.0.26 (Adware.Shopping.Report) -> Quarantined and deleted successfully.
    C:\Documents and Settings\All Users\Application Data\SalesMon (Rogue.Multiple) -> Quarantined and deleted successfully.
    C:\Documents and Settings\All Users\Application Data\SalesMon\Data (Rogue.Multiple) -> Quarantined and deleted successfully.
    C:\Program Files\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    C:\Program Files\MyWebSearch\bar (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    C:\Program Files\MyWebSearch\bar\1.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    C:\Program Files\MyWebSearch\bar\Settings (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    C:\Program Files\MyWebSearch\SrchAstt (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    C:\Program Files\MyWebSearch\SrchAstt\1.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    C:\Documents and Settings\NEGO-NILE\Application Data\ShoppingReport (Adware.Shopping.Report) -> Quarantined and deleted successfully.
    C:\Documents and Settings\NEGO-NILE\Application Data\ShoppingReport\cs (Adware.Shopping.Report) -> Quarantined and deleted successfully.
    C:\Documents and Settings\NEGO-NILE\Application Data\ShoppingReport\cs\res2 (Adware.Shopping.Report) -> Quarantined and deleted successfully.

    Fichier(s) infecté(s):
    C:\Documents and Settings\NEGO-NILE\Local Settings\Application Data\umwma_navps.dat (Adware.Navipromo) -> Quarantined and deleted successfully.
    C:\Documents and Settings\NEGO-NILE\Local Settings\Application Data\umwma_nav.dat (Adware.Navipromo) -> Quarantined and deleted successfully.
    C:\Documents and Settings\NEGO-NILE\Local Settings\Application Data\umwma.dat (Adware.Navipromo) -> Quarantined and deleted successfully.
    C:\Documents and Settings\NEGO-NILE\Local Settings\Application Data\umwma.exe (Adware.Navipromo) -> Delete on reboot.
    C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    C:\Program Files\MSN Messenger\riched20.dll (Adware.MyWeb.FunWeb) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{87BA8E41-B43D-4AD9-808E-1D07E9D1FE7A}\RP151\A0100992.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    C:\Program Files\MyWebSearch\bar\Settings\s_pid.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    C:\Documents and Settings\NEGO-NILE\Application Data\ShoppingReport\cs\res2\WhiteList.dbs (Adware.Shopping.Report) -> Quarantined and deleted successfully.
    Maintenant je fais quoi?
    0
  • 1
  • 2