Probléme de trojan
L11232
-
buginformatik Messages postés 2210 Statut Contributeur -
buginformatik Messages postés 2210 Statut Contributeur -
Bonjour,
j'ai apparté des trojans WIN32 et mon anti-virus me qui qu'ils sont
C:\Windows\system32\urqQjkif.dll
C:\Windows\system32\iifcCsQK.dll
C:\Users\olivier\AppData\Local\temp\xxyxULEX.dll
C:\Users\olivier\AppData\Local\temp\kcdqbfhy.dll
j'ai apparté des trojans WIN32 et mon anti-virus me qui qu'ils sont
C:\Windows\system32\urqQjkif.dll
C:\Windows\system32\iifcCsQK.dll
C:\Users\olivier\AppData\Local\temp\xxyxULEX.dll
C:\Users\olivier\AppData\Local\temp\kcdqbfhy.dll
A voir également:
- Probléme de trojan
- Trojan remover - Télécharger - Antivirus & Antimalwares
- Anti trojan - Télécharger - Antivirus & Antimalwares
- Virus trojan al11 ✓ - Forum Virus
- Csrss.exe trojan fr ✓ - Forum Virus
- Trojan win32 - Forum Virus
7 réponses
Bonjour !
Tu vas télécharger la dernière version de Malwarebytes anti malware 1.30 et faire un scan complet de C: : https://www.commentcamarche.net/telecharger/securite/14361-malwarebytes-anti-malware/
Voici un tuto pour bien l'installer et l'utiliser : http://www.infos-du-net.com/forum/278396-11-tuto-malwarebytes-anti-malware-mbam
N'oublie pas de supprimer les menaces à la fin du scan et de poster le log sur le forum !
A+
Tu vas télécharger la dernière version de Malwarebytes anti malware 1.30 et faire un scan complet de C: : https://www.commentcamarche.net/telecharger/securite/14361-malwarebytes-anti-malware/
Voici un tuto pour bien l'installer et l'utiliser : http://www.infos-du-net.com/forum/278396-11-tuto-malwarebytes-anti-malware-mbam
N'oublie pas de supprimer les menaces à la fin du scan et de poster le log sur le forum !
A+
Malwarebytes' Anti-Malware 1.30
Version de la base de données: 1306
Windows 6.0.6001 Service Pack 1
29/10/2008 14:51:44
mbam-log-2008-10-29 (14-51-44).txt
Type de recherche: Examen complet (C:\|D:\|)
Eléments examinés: 131997
Temps écoulé: 33 minute(s), 36 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 9
Valeur(s) du Registre infectée(s): 5
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 6
Fichier(s) infecté(s): 54
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
HKEY_CLASSES_ROOT\lospn (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\lsksaq.bho (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\TotalSecure2009 (Rogue.TotalSecure) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\tdssdata (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\tdss (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\MS Juan (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> Quarantined and deleted successfully.
Valeur(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\totalsecure2009 (Rogue.TotalSecure) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\bf (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\bk (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\iu (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\mu (Trojan.Agent) -> Quarantined and deleted successfully.
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
C:\Program Files\TS-2009 (Rogue.TotalSecure) -> Quarantined and deleted successfully.
C:\Program Files\Smart Antivirus 2009 (Rogue.SmartAntivirus) -> Quarantined and deleted successfully.
C:\Program Files\Smart Antivirus 2009\Infected (Rogue.SmartAntivirus) -> Quarantined and deleted successfully.
C:\Program Files\Smart Antivirus 2009\Suspicious (Rogue.SmartAntivirus) -> Quarantined and deleted successfully.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Smart Antivirus 2009 (Rogue.SmartAntivirus) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Smart Antivirus 2009 (Rogue.SmartAntivirus) -> Quarantined and deleted successfully.
Fichier(s) infecté(s):
C:\Users\olivier\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KWCBTIS1\cntr[1] (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KWCBTIS1\file[1].exe (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KWCBTIS1\nd82m0[1] (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PEV5PRDG\file[1].exe (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PEV5PRDG\upd105320[1] (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZDGLDNV4\cntr[1] (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZDGLDNV4\sa2009[1].exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Temp\ddcYRJaY.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Temp\efcDTMFw.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Temp\hgGyaYPf.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Temp\iifCtqRk.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Temp\iifffFYP.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Temp\jcirnrjg.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Temp\jkkHYqrp.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Temp\kHabYQHb.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Temp\mlJDtqrP.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Temp\nnnLFusS.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Temp\nnnlmMCu.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Temp\nnnNfCrQ.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Temp\opnonkLE.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Temp\othlukiy.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Temp\qtnxpmua.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Temp\rptewibn.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Temp\tmp0000e0eb (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Temp\tmp0000f527 (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Temp\tmp0000f556 (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Temp\tmp00015994 (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Temp\tmp00019a89 (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Temp\tmp0001e011 (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Temp\tmp000224be (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Temp\tmp00025aeb (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Temp\tmp00026853 (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Temp\tmp00027982 (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Temp\tmp00028b9b (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Temp\tmp00029240 (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Temp\tmp0002b3a5 (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Temp\tmp0002bb33 (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Temp\urqPigGX.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Temp\vtUkhGWO.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Temp\wupdmgr.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Temp\yayYrrSl.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Temp\yayyXRJy.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Temp\ynxhkyrg.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Windows\Temp\TMP00000001EA230A791E5391D0 (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Program Files\TS-2009\scan.exe (Rogue.TotalSecure) -> Quarantined and deleted successfully.
C:\Program Files\TS-2009\totalsecure.s2 (Rogue.TotalSecure) -> Quarantined and deleted successfully.
C:\Program Files\TS-2009\totalsecure.s3 (Rogue.TotalSecure) -> Quarantined and deleted successfully.
C:\Program Files\Smart Antivirus 2009\vscan.tsi (Rogue.SmartAntivirus) -> Quarantined and deleted successfully.
C:\Program Files\Smart Antivirus 2009\zlib.dll (Rogue.SmartAntivirus) -> Quarantined and deleted successfully.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Smart Antivirus 2009\Smart Antivirus-2009.lnk (Rogue.SmartAntivirus) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Smart Antivirus 2009\Smart Antivirus-2009.lnk (Rogue.SmartAntivirus) -> Quarantined and deleted successfully.
C:\Windows\k.txt (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Temp\pwrmgr.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Temp\msfont32.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
Version de la base de données: 1306
Windows 6.0.6001 Service Pack 1
29/10/2008 14:51:44
mbam-log-2008-10-29 (14-51-44).txt
Type de recherche: Examen complet (C:\|D:\|)
Eléments examinés: 131997
Temps écoulé: 33 minute(s), 36 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 9
Valeur(s) du Registre infectée(s): 5
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 6
Fichier(s) infecté(s): 54
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
HKEY_CLASSES_ROOT\lospn (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\lsksaq.bho (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\TotalSecure2009 (Rogue.TotalSecure) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\tdssdata (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\tdss (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\MS Juan (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> Quarantined and deleted successfully.
Valeur(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\totalsecure2009 (Rogue.TotalSecure) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\bf (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\bk (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\iu (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\mu (Trojan.Agent) -> Quarantined and deleted successfully.
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
C:\Program Files\TS-2009 (Rogue.TotalSecure) -> Quarantined and deleted successfully.
C:\Program Files\Smart Antivirus 2009 (Rogue.SmartAntivirus) -> Quarantined and deleted successfully.
C:\Program Files\Smart Antivirus 2009\Infected (Rogue.SmartAntivirus) -> Quarantined and deleted successfully.
C:\Program Files\Smart Antivirus 2009\Suspicious (Rogue.SmartAntivirus) -> Quarantined and deleted successfully.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Smart Antivirus 2009 (Rogue.SmartAntivirus) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Smart Antivirus 2009 (Rogue.SmartAntivirus) -> Quarantined and deleted successfully.
Fichier(s) infecté(s):
C:\Users\olivier\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KWCBTIS1\cntr[1] (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KWCBTIS1\file[1].exe (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KWCBTIS1\nd82m0[1] (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PEV5PRDG\file[1].exe (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PEV5PRDG\upd105320[1] (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZDGLDNV4\cntr[1] (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZDGLDNV4\sa2009[1].exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Temp\ddcYRJaY.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Temp\efcDTMFw.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Temp\hgGyaYPf.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Temp\iifCtqRk.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Temp\iifffFYP.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Temp\jcirnrjg.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Temp\jkkHYqrp.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Temp\kHabYQHb.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Temp\mlJDtqrP.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Temp\nnnLFusS.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Temp\nnnlmMCu.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Temp\nnnNfCrQ.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Temp\opnonkLE.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Temp\othlukiy.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Temp\qtnxpmua.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Temp\rptewibn.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Temp\tmp0000e0eb (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Temp\tmp0000f527 (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Temp\tmp0000f556 (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Temp\tmp00015994 (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Temp\tmp00019a89 (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Temp\tmp0001e011 (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Temp\tmp000224be (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Temp\tmp00025aeb (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Temp\tmp00026853 (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Temp\tmp00027982 (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Temp\tmp00028b9b (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Temp\tmp00029240 (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Temp\tmp0002b3a5 (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Temp\tmp0002bb33 (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Temp\urqPigGX.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Temp\vtUkhGWO.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Temp\wupdmgr.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Temp\yayYrrSl.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Temp\yayyXRJy.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Temp\ynxhkyrg.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Windows\Temp\TMP00000001EA230A791E5391D0 (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Program Files\TS-2009\scan.exe (Rogue.TotalSecure) -> Quarantined and deleted successfully.
C:\Program Files\TS-2009\totalsecure.s2 (Rogue.TotalSecure) -> Quarantined and deleted successfully.
C:\Program Files\TS-2009\totalsecure.s3 (Rogue.TotalSecure) -> Quarantined and deleted successfully.
C:\Program Files\Smart Antivirus 2009\vscan.tsi (Rogue.SmartAntivirus) -> Quarantined and deleted successfully.
C:\Program Files\Smart Antivirus 2009\zlib.dll (Rogue.SmartAntivirus) -> Quarantined and deleted successfully.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Smart Antivirus 2009\Smart Antivirus-2009.lnk (Rogue.SmartAntivirus) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Smart Antivirus 2009\Smart Antivirus-2009.lnk (Rogue.SmartAntivirus) -> Quarantined and deleted successfully.
C:\Windows\k.txt (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Temp\pwrmgr.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Users\olivier\AppData\Local\Temp\msfont32.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
Télécharges hijackthis : http://www.trendsecure.com/portal/en-US/_download/HiJackThis.zip
et voici un gif pour bien l'installer : http://pageperso.aol.fr/balltrap34/Hijenr.gif
- Une fois téléchargé, renommer l'éxécutable en HJT.exe pour contrer une éventuelle infection vundo
- Double-clic dessus
- Clic sur "Do a system scan and save the log"
- Copies le rapport, le coller dans la réponse
et voici un gif pour bien l'installer : http://pageperso.aol.fr/balltrap34/Hijenr.gif
- Une fois téléchargé, renommer l'éxécutable en HJT.exe pour contrer une éventuelle infection vundo
- Double-clic dessus
- Clic sur "Do a system scan and save the log"
- Copies le rapport, le coller dans la réponse
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:49:50, on 29/10/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Safe mode
Running processes:
C:\Windows\Explorer.EXE
D:\Hijackthis\HJT.exe.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://fr.rd.yahoo.com/customize/ycomp/defaults/sp/*https://fr.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://fr.fr.acer.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.rd.yahoo.com/customize/ycomp/defaults/su/*https://fr.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
O2 - BHO: (no name) - {7365836D-6E1A-4A4E-BF8E-C21089CAA1B2} - C:\Windows\system32\CIRCoIns.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "c:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
O4 - HKLM\..\Run: [LaunchAp] "C:\Program Files\Launch Manager\LaunchAp.exe"
O4 - HKLM\..\Run: [PowerKey] "C:\Program Files\Launch Manager\PowerKey.exe"
O4 - HKLM\..\Run: [LManager] "C:\Program Files\Launch Manager\HotkeyApp.exe"
O4 - HKLM\..\Run: [LMgrOSD] "C:\Program Files\Launch Manager\OSDCtrl.exe"
O4 - HKLM\..\Run: [Wbutton] "C:\Program Files\Launch Manager\Wbutton.exe"
O4 - HKLM\..\Run: [WarReg_PopUp] C:\Acer\WR_PopUp\WarReg_PopUp.exe
O4 - HKLM\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Empowering Technology Launcher.lnk = ?
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://lezeph.spaces.live.com/PhotoUpload/VistaMsnPUpldfr-fr.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O20 - AppInit_DLLs: eNetHook.dll
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: eDSService.exe (eDataSecurity Service) - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
O23 - Service: eLock Service (eLockService) - Acer Inc. - C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
O23 - Service: eNet Service - Acer Inc. - C:\Acer\Empowering Technology\eNet\eNet Service.exe
O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
O23 - Service: eSettings Service (eSettingsService) - Unknown owner - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Validation de mot de passe Symantec IS (ISPwdSvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: WisLMSvc - Wistron Corp. - C:\Program Files\Launch Manager\WisLMSvc.exe
O23 - Service: ePower Service (WMIService) - acer - C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
Scan saved at 17:49:50, on 29/10/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Safe mode
Running processes:
C:\Windows\Explorer.EXE
D:\Hijackthis\HJT.exe.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://fr.rd.yahoo.com/customize/ycomp/defaults/sp/*https://fr.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://fr.fr.acer.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.rd.yahoo.com/customize/ycomp/defaults/su/*https://fr.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
O2 - BHO: (no name) - {7365836D-6E1A-4A4E-BF8E-C21089CAA1B2} - C:\Windows\system32\CIRCoIns.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "c:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
O4 - HKLM\..\Run: [LaunchAp] "C:\Program Files\Launch Manager\LaunchAp.exe"
O4 - HKLM\..\Run: [PowerKey] "C:\Program Files\Launch Manager\PowerKey.exe"
O4 - HKLM\..\Run: [LManager] "C:\Program Files\Launch Manager\HotkeyApp.exe"
O4 - HKLM\..\Run: [LMgrOSD] "C:\Program Files\Launch Manager\OSDCtrl.exe"
O4 - HKLM\..\Run: [Wbutton] "C:\Program Files\Launch Manager\Wbutton.exe"
O4 - HKLM\..\Run: [WarReg_PopUp] C:\Acer\WR_PopUp\WarReg_PopUp.exe
O4 - HKLM\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Empowering Technology Launcher.lnk = ?
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://lezeph.spaces.live.com/PhotoUpload/VistaMsnPUpldfr-fr.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O20 - AppInit_DLLs: eNetHook.dll
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: eDSService.exe (eDataSecurity Service) - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
O23 - Service: eLock Service (eLockService) - Acer Inc. - C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
O23 - Service: eNet Service - Acer Inc. - C:\Acer\Empowering Technology\eNet\eNet Service.exe
O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
O23 - Service: eSettings Service (eSettingsService) - Unknown owner - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Validation de mot de passe Symantec IS (ISPwdSvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: WisLMSvc - Wistron Corp. - C:\Program Files\Launch Manager\WisLMSvc.exe
O23 - Service: ePower Service (WMIService) - acer - C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
non au mode normal aussi mé cela ne dure d'une a deux minute aprés écran bleu puis redémarage et je choisi en mode sans échec
L'écran bleu il indique un message d'erreur j'imagine, tu as noté ?
et as tu accés au panneau de configuration ?
>>>>>
Sinon, Je peux te proposer de Restaurer le système depuis un point de restauration à une date antérieure à tes problèmes.
Evidemment tous les fichiers créers entre cette date et aujourd'hui seront perdus...
C'est expliquer comment faire ici ==> http://www.vista-xp.fr/forum/topic39.html
et as tu accés au panneau de configuration ?
>>>>>
Sinon, Je peux te proposer de Restaurer le système depuis un point de restauration à une date antérieure à tes problèmes.
Evidemment tous les fichiers créers entre cette date et aujourd'hui seront perdus...
C'est expliquer comment faire ici ==> http://www.vista-xp.fr/forum/topic39.html
svp aide moi