Pc infecté
Mon Pc est infecté,un virus supprime mes cookies régulièrement,a désinstaller certains drivers (que j'ai réinstallé ) et je ne peux plus regarder de vidéos.Par exemple sur you toube,ce message s'affiche :
"Bonjour, vous avez désactivé JavaScript ou bien vous possédez une ancienne version d'Adobe Flash Player. Téléchargez la dernière version de Flash Player. "
C'est ce que je fais ,j'installe adobe flash player ,ça me dit installation réussie pourtant le même message s'affiche quand je retourne sur you tube !
Et comment faire pour réactiver Java ?
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:10:08, on 02/06/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\AskBarDis\bar\bin\AskService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\winsys2.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Hercules\DualPix Exchange\Camservice.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\perso\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Windows Live\Toolbar\wltuser.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe
C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
C:\Program Files\trend micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://hp.mywebsearch.com/mywebsearch/index.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\bar\1.bin\MWSSRCAS.DLL
O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\bar\1.bin\MWSSRCAS.DLL
O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: Yontoo Layers - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files\Yontoo Layers Client for Internet Explorer\YontooIEClient.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: ZoneAlarm Spy Blocker Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O3 - Toolbar: My Web Search - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SW20] C:\WINDOWS\system32\sw20.exe
O4 - HKLM\..\Run: [SW24] C:\WINDOWS\system32\sw24.exe
O4 - HKLM\..\Run: [WinSys2] C:\WINDOWS\system32\winsys2.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [CamserviceDP] C:\Program Files\Hercules\DualPix Exchange\Camservice.exe /startup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [MyWebSearch Plugin] rundll32 C:\PROGRA~1\MYWEBS~1\bar\1.bin\M3PLUGIN.DLL,UPF
O4 - HKLM\..\Run: [My Web Search Bar Search Scope Monitor] "C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe" /m=2 /w /h
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\perso\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZCman000
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei-4/CursorManiaInitialSetup1.0.1.1.cab
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - http://fichiers.touslesdrivers.com/maconfig/MaConfig_3_5_0_0.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Planificateur Avira AntiVir Personal - Free Antivirus (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: ASKService - Unknown owner - C:\Program Files\AskBarDis\bar\bin\AskService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
O23 - Service: My Web Search Service (MyWebSearchService) - MyWebSearch.com - C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwssvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
--
End of file - 9455 bytes
Merci d'avance !!!
Configuration: Windows XP Internet Explorer 7.0
33 réponses
Un utilisateur signale une infection informatique où les cookies sont régulièrement supprimés, des drivers ont été désinstallés puis réinstallés et la lecture de vidéos est bloquée. Un message d’erreur apparaît sur les pages de streaming indiquant une désactivation de JavaScript ou une ancienne version d’Adobe Flash, et l’installation est annoncée comme réussie mais le problème persiste. Le contenu comprend un rapport HijackThis et recommande l’usage d’un outil anti-malware comme Malwarebytes et un redémarrage après la suppression des objets détectés pour finaliser le nettoyage. D'autres éléments évoquent des services et processus potentiellement indésirables dans la liste fournie, soulignant la nécessité d’un diagnostic complet et d’une restauration de sécurité appropriée.
-
relance AD-Remover puis option desinstaller ensuite supprime 'c:\rsit' puis relance-le de ton bureau et essaie de me fournir les deux rapports
-
Mon Pc a 3 ans mais ce problème est apparu il y a 2 mois maintenant,avant tout allait bien !
Tu as 1 idée de ce que je pourrais faire pour y remédier ?
Bonne soirée à toi gene hackman -
-quand je redémarre,les cookies sont effacées d'internet explorer
et bien heureusement !!!
je ne peux pas mettre de vidéos en grand écran sinon l'image s'arrête alors que le son continue, au bout de 10 secondes
il est vieux ton pc ?
peut etre un probleme de congif :) -
Bon déjà,je te remercie car Malwaresbytes me permet de nouveau de visionner des vidéos :)
Bon sinon voilà ce qui ne va pas encore:
-quand je redémarre,les cookies sont effacées d'internet explorer
-je ne peux pas mettre de vidéos en grand écran sinon l'image s'arrête alors que le son continue, au bout de 10 secondes
-au redémarrage,il m'arrive que s'inscrive le message suivant sur fond noir "disk boot failure,insert system disk and press enter" ou sinon une vérification du disque se déclenche automatiquement.
Bon dimanche à toi gene hackman !
SUPERAntiSpyware Scan Log
https://www.superantispyware.com/
Generated 06/06/2009 at 10:31 PM
Application Version : 4.26.1004
Core Rules Database Version : 3925
Trace Rules Database Version: 1869
Scan type : Complete Scan
Total Scan Time : 02:17:29
Memory items scanned : 489
Memory threats detected : 0
Registry items scanned : 4415
Registry threats detected : 0
File items scanned : 61255
File threats detected : 34
Adware.Tracking Cookie
C:\Documents and Settings\perso\Cookies\perso@advertiser.edintorni[1].txt
C:\Documents and Settings\perso\Cookies\perso@mediaplex[1].txt
C:\Documents and Settings\perso\Cookies\perso@ads.ad4game[3].txt
C:\Documents and Settings\perso\Cookies\perso@mediaplex[2].txt
C:\Documents and Settings\perso\Cookies\perso@bs.serving-sys[2].txt
C:\Documents and Settings\perso\Cookies\perso@serving-sys[3].txt
C:\Documents and Settings\perso\Cookies\perso@atdmt[1].txt
C:\Documents and Settings\perso\Cookies\perso@ad.yieldmanager[2].txt
C:\Documents and Settings\perso\Cookies\perso@ad.zanox[1].txt
C:\Documents and Settings\perso\Cookies\perso@fastclick[2].txt
C:\Documents and Settings\perso\Cookies\perso@ads.us.e-planning[1].txt
C:\Documents and Settings\perso\Cookies\perso@tribalfusion[1].txt
C:\Documents and Settings\perso\Cookies\perso@weborama[2].txt
C:\Documents and Settings\perso\Cookies\perso@advertstream[1].txt
C:\Documents and Settings\perso\Cookies\perso@lfstmedia[2].txt
C:\Documents and Settings\perso\Cookies\perso@apmebf[1].txt
C:\Documents and Settings\perso\Cookies\perso@socialmedia[1].txt
C:\Documents and Settings\perso\Cookies\perso@msnportal.112.2o7[1].txt
C:\Documents and Settings\perso\Cookies\perso@smartadserver[3].txt
C:\Documents and Settings\perso\Cookies\perso@advertising[2].txt
C:\Documents and Settings\perso\Cookies\perso@xiti[1].txt
C:\Documents and Settings\perso\Cookies\perso@samsung.solution.weborama[2].txt
C:\Documents and Settings\perso\Cookies\perso@media6degrees[2].txt
C:\Documents and Settings\perso\Cookies\perso@tradedoubler[1].txt
C:\Documents and Settings\perso\Cookies\perso@stats.searchtrack[1].txt
C:\Documents and Settings\perso\Cookies\perso@aimfar.solution.weborama[1].txt
C:\Documents and Settings\perso\Cookies\perso@largus.solution.weborama[2].txt
C:\Documents and Settings\perso\Cookies\perso@bluestreak[1].txt
C:\Documents and Settings\perso\Cookies\perso@fastclick[1].txt
C:\Documents and Settings\perso\Cookies\perso@doubleclick[2].txt
C:\Documents and Settings\perso\Cookies\perso@ads.ad4game[2].txt
C:\Documents and Settings\perso\Cookies\perso@serving-sys[1].txt
C:\Documents and Settings\perso\Cookies\perso@smartadserver[2].txt
C:\Program Files\Ad-remover\QUARANTINE\DOCUME~1\perso\Cookies\perso@mywebsearch[1].txt.vir -
Télécharge Superantispyware (SAS)
Choisis "enregistrer" et enregistre-le sur ton bureau.
Double-clique sur l'icône d'installation qui vient de se créer et suis les instructions.
Créé une icône sur le bureau.
Double-clique sur l'icône de SAS (une tête dans un cercle rouge barré) pour le lancer.
- Si l'outil te demande de mettre à jour le programme ("update the program definitions", clique sur yes.
- Sous Configuration and Preferences, clique sur le bouton "Preferences"
- Clique sur l'onglet "Scanning Control "
- Dans "Scanner Options ", assure toi que la case devant lles lignes suivantes est cochée :
Close browsers before scanning
Scan for tracking cookies
Terminate memory threats before quarantining
- Laisse les autres lignes décochées.
- Clique sur le bouton "Close" pour quitter l'écran du centre de contrôle.
- Dans la fenêtre principale, clique, dans "Scan for Harmful Software", sur "Scan your computer".
Dans la colonne de gauche, coche C:\Fixed Drive.
Dans la colonne de droite, sous "Complete scan", clique sur "Perform Complete Scan"
Clique sur "next" pour lancer le scan. Patiente pendant la durée du scan.
A la fin du scan, une fenêtre de résultats s'ouvre . Clique sur OK.
Assure toi que toutes les lignes de la fenêtre blanche sont cochées et clique sur "Next".
Tout ce qui a été trouvé sera mis en quarantaine. S'il t'es demandé de redémarrer l'ordi ("reboot"), clique sur Yes.
Pour recopier les informations sur le forum, fais ceci :
- après le redémarrage de l'ordi, double-clique sur l'icône pour lancer SAS.
- Clique sur "Preferences" puis sur l'onglet "Statistics/Logs ".
- Dans "scanners logs", double-clique sur SUPERAntiSpyware Scan Log.
- Le rapport va s'ouvrir dans ton éditeur de texte par défaut.
- Copie son contenu dans ta réponse.
Regarde bien le tuto SUPERAntiSpyware il est très bien expliqué. -
Malwarebytes' Anti-Malware 1.37
Version de la base de données: 2227
Windows 5.1.2600 Service Pack 3
04/06/2009 17:48:04
mbam-log-2009-06-04 (17-48-04).txt
Type de recherche: Examen complet (C:\|D:\|E:\|)
Eléments examinés: 164428
Temps écoulé: 1 hour(s), 24 minute(s), 53 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 49
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 31
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
HKEY_CLASSES_ROOT\Interface\{07b18eaa-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{07b18eac-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{1093995a-ba37-41d2-836e-091067c4ad17} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{120927bf-1700-43bc-810f-fab92549b390} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{17de5e5e-bfe3-4e83-8e1f-8755795359ec} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{1f52a5fa-a705-4415-b975-88503b291728} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{247a115f-06c2-4fb3-967d-2d62d3cf4f0a} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{2e3537fc-cf2f-4f56-af54-5a6a3dd375cc} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{2e9937fc-cf2f-4f56-af54-5a6a3dd375cc} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{3e1656ed-f60e-4597-b6aa-b6a58e171495} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{3e53e2cb-86db-4a4a-8bd9-ffeb7a64df82} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{3e720451-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{3e720453-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{63d0ed2b-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{63d0ed2d-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{6e74766c-4d93-4cc0-96d1-47b8e07ff9ca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{72ee7f04-15bd-4845-a005-d6711144d86a} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{741de825-a6f0-4497-9aa6-8023cf9b0fff} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{7473d291-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{7473d293-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{7473d295-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{7473d297-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{90449521-d834-4703-bb4e-d3aa44042ff8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{991aac62-b100-47ce-8b75-253965244f69} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{a626cdbd-3d13-4f78-b819-440a28d7e8fc} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{bbabdc90-f3d5-4801-863a-ee6ae529862d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{cf54be1c-9359-4395-8533-1657cf209cfe} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{d6ff3684-ad3b-48eb-bbb4-b9e6c5a355c1} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{de38c398-b328-4f4c-a3ad-1b5e4ed93477} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{e342af55-b78a-4cd0-a2bb-da7f52d9d25e} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{e342af55-b78a-4cd0-a2bb-da7f52d9d25f} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{e79dfbc9-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{e79dfbcb-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{eb9e5c1c-b1f9-4c2b-be8a-27d6446fdaf8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{f87d7fb5-9dc5-4c8c-b998-d8dfe02e2978} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{147a976f-eee1-4377-8ea7-4716e4cdd239} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{a4730ebe-43a6-443e-9776-36915d323ad3} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{d518921a-4a03-425e-9873-b9a71756821e} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{07b18ea0-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{0d26bc71-a633-4e71-ad31-eadc3a1b6a3a} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{29d67d3c-509a-4544-903f-c8c1b8236554} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{3e720450-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{7473d290-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{8ca01f0e-987c-49c3-b852-2f1ac4a7094c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{8e6f1830-9607-4440-8530-13be7c4b1d14} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{c8cecde3-1ae1-4c4a-ad82-6d5b00212144} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{e47caee0-deea-464a-9326-3f2801535a4d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{e79dfbc0-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{f42228fb-e84e-479e-b922-fbbd096e792c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
(Aucun élément nuisible détecté)
Fichier(s) infecté(s):
c:\program files\ad-remover\quarantine\PROGRA~1\WINDOW~4\MESSEN~1\msimg32.dll.vir (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\ad-remover\quarantine\PROGRA~1\WINDOW~4\MESSEN~1\riched20.dll.vir (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\program files\ad-remover\quarantine\WINDOWS\system32\f3PSSavr.scr.vir (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{1eea41cb-dc57-43e2-9bdf-ffc1941aac0a}\RP168\A0091211.DLL (Adware.MyWeb) -> Quarantined and deleted successfully.
c:\system volume information\_restore{1eea41cb-dc57-43e2-9bdf-ffc1941aac0a}\RP168\A0091229.DLL (Adware.MyWeb) -> Quarantined and deleted successfully.
c:\system volume information\_restore{1eea41cb-dc57-43e2-9bdf-ffc1941aac0a}\RP168\A0091192.DLL (Adware.FunWeb) -> Quarantined and deleted successfully.
c:\system volume information\_restore{1eea41cb-dc57-43e2-9bdf-ffc1941aac0a}\RP168\A0091195.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{1eea41cb-dc57-43e2-9bdf-ffc1941aac0a}\RP168\A0091198.DLL (Adware.MyWeb) -> Quarantined and deleted successfully.
c:\system volume information\_restore{1eea41cb-dc57-43e2-9bdf-ffc1941aac0a}\RP168\A0091202.SCR (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{1eea41cb-dc57-43e2-9bdf-ffc1941aac0a}\RP168\A0091203.DLL (Adware.MyWeb) -> Quarantined and deleted successfully.
c:\system volume information\_restore{1eea41cb-dc57-43e2-9bdf-ffc1941aac0a}\RP168\A0091205.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{1eea41cb-dc57-43e2-9bdf-ffc1941aac0a}\RP168\A0091210.EXE (Adware.MyWeb) -> Quarantined and deleted successfully.
c:\system volume information\_restore{1eea41cb-dc57-43e2-9bdf-ffc1941aac0a}\RP168\A0091212.DLL (Adware.MyWeb) -> Quarantined and deleted successfully.
c:\system volume information\_restore{1eea41cb-dc57-43e2-9bdf-ffc1941aac0a}\RP168\A0091213.EXE (Adware.MyWeb) -> Quarantined and deleted successfully.
c:\system volume information\_restore{1eea41cb-dc57-43e2-9bdf-ffc1941aac0a}\RP168\A0091214.EXE (Adware.MyWeb) -> Quarantined and deleted successfully.
c:\system volume information\_restore{1eea41cb-dc57-43e2-9bdf-ffc1941aac0a}\RP168\A0091215.DLL (Adware.MyWeb) -> Quarantined and deleted successfully.
c:\system volume information\_restore{1eea41cb-dc57-43e2-9bdf-ffc1941aac0a}\RP168\A0091217.DLL (Adware.MyWeb) -> Quarantined and deleted successfully.
c:\system volume information\_restore{1eea41cb-dc57-43e2-9bdf-ffc1941aac0a}\RP168\A0091218.DLL (Adware.MyWeb) -> Quarantined and deleted successfully.
c:\system volume information\_restore{1eea41cb-dc57-43e2-9bdf-ffc1941aac0a}\RP168\A0091219.DLL (Adware.MyWeb) -> Quarantined and deleted successfully.
c:\system volume information\_restore{1eea41cb-dc57-43e2-9bdf-ffc1941aac0a}\RP168\A0091220.EXE (Adware.MyWeb) -> Quarantined and deleted successfully.
c:\system volume information\_restore{1eea41cb-dc57-43e2-9bdf-ffc1941aac0a}\RP168\A0091221.EXE (Adware.MyWeb) -> Quarantined and deleted successfully.
c:\system volume information\_restore{1eea41cb-dc57-43e2-9bdf-ffc1941aac0a}\RP168\A0091222.EXE (Adware.MyWeb) -> Quarantined and deleted successfully.
c:\system volume information\_restore{1eea41cb-dc57-43e2-9bdf-ffc1941aac0a}\RP168\A0091223.DLL (Adware.MyWeb) -> Quarantined and deleted successfully.
c:\system volume information\_restore{1eea41cb-dc57-43e2-9bdf-ffc1941aac0a}\RP168\A0091224.EXE (Adware.MyWeb) -> Quarantined and deleted successfully.
c:\system volume information\_restore{1eea41cb-dc57-43e2-9bdf-ffc1941aac0a}\RP168\A0091225.DLL (Adware.MyWeb) -> Quarantined and deleted successfully.
c:\system volume information\_restore{1eea41cb-dc57-43e2-9bdf-ffc1941aac0a}\RP168\A0091226.DLL (Adware.MyWeb) -> Quarantined and deleted successfully.
c:\system volume information\_restore{1eea41cb-dc57-43e2-9bdf-ffc1941aac0a}\RP168\A0091227.DLL (Adware.MyWeb) -> Quarantined and deleted successfully.
c:\system volume information\_restore{1eea41cb-dc57-43e2-9bdf-ffc1941aac0a}\RP168\A0091228.EXE (Adware.MyWeb) -> Quarantined and deleted successfully.
c:\system volume information\_restore{1eea41cb-dc57-43e2-9bdf-ffc1941aac0a}\RP168\A0091236.scr (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{1eea41cb-dc57-43e2-9bdf-ffc1941aac0a}\RP168\A0091237.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\system volume information\_restore{1eea41cb-dc57-43e2-9bdf-ffc1941aac0a}\RP168\A0091238.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully. -
Imprime ces instructions car il faudra fermer toutes les fenêtres et applications lors de l'installation et de l'analyse.
Télécharges :
Malwarebytes
ou :
Malwarebytes
* Installe le ( choisis bien "francais" ; ne modifie pas les paramètres d'installe ) et mets le à jour .
(NB : S'il te manque "COMCTL32.OCX" lors de l'installe, alors télécharge le ici : COMCTL32.OCX
* Potasses le Tuto pour te familiariser avec le prg :
( cela dit, il est très simple d'utilisation ).
relance malwarebytes en suivant scrupuleusement ces consignes :
! Déconnecte toi et ferme toutes applications en cours !
* Lance Malwarebyte's .
Fais un examen dit "Complet" .
--> Laisse le programme travailler ( et ne rien faire d'autre avec le PC durant le scan ).
--> à la fin tu cliques sur "résultat" .
--> Vérifie que tous les objets infectés soient validés, puis clique sur " suppression " .
Note : si il faut redémarrer ton PC pour finir le nettoyage, fais le !
Poste le rapport sauvegardé après la suppression des objets infectés (dans l'onglet "rapport/log"de Malwarebytes, le dernier en date)
-
Merci
.
======= RAPPORT D'AD-REMOVER 1.1.4.5_C | UNIQUEMENT XP/VISTA =======
.
Mit à jour part C_XX le 02/06/2009 à 8:00 PM
Contact: AdRemover.contact@gmail.com
Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html
.
Lancé à: 15:26:15, 04/06/2009 | Mode sans echec | Option: CLEAN
Exécuté de: C:\Program Files\Ad-remover\
Système d'exploitation: Microsoft® Windows XP™ Service Pack 3 v5.1.2600
Nom du PC: PERSO-8D6644381 | Utilisateur actuel: perso
.
Administrateur: Administrateur
N'est pas administrateur: HelpAssistant *Desactive*
N'est pas administrateur: Invité *Desactive*
Administrateur: perso
N'est pas administrateur: SUPPORT_388945a0 *Desactive*
.
============== ÉLÉMENT(S) NEUTRALISÉ(S) ==============
.
.
.
(!) -- Fichiers temporaires supprimés.
.
============== Scan additionnel ==============
.
* Mozilla FireFox Version [Impossible d'obtenir la version] *
Nom du profil: vvxx4qfk.default (perso)
.
(Prefs.js) user_pref("browser.startup.homepage_override.mstone", "rv:1.9.0.6");
.
.
* Internet Explorer Version 8.0.6001.18702 *
[HKEY_CURRENT_USER\..\Internet Explorer\Main]
Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Start Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
Start Page: hxxp://fr.msn.com/?ocid=iehp
[HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]
Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Search bar: hxxp://search.msn.com/spbasic.htm
Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Start Page: hxxp://fr.msn.com/
[HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]
Tabs: res://ieframe.dll/tabswelcome.htm
============== Suspect (Cracks, Serials ... ) ==============
.
+---------------------------------------------------------------------------+
2193 Octet(s) - C:\Ad-Report-CLEAN.log
2767 Octet(s) - C:\Ad-Report-SCAN.log
54 Fichier(s) - C:\Program Files\Ad-remover\BACKUP
25 Fichier(s) - C:\Program Files\Ad-remover\QUARANTINE
Fin à: 15:31:22 | 04/06/2009
.
============== E.O.F ==============
. -
Le rapport est sauvegardé aussi sous C:\Ad-report.log (le dernier)
-
J'ai fait le nettoyage en mode sans échec ,j'ai redémarré et comment retrouver le rapport ?
-
tu pourrrais refaire l'option L de AD-Remover en mode sans echec stp ?
-
========== PROCESSES ==========
Process explorer.exe killed successfully.
========== SERVICES/DRIVERS ==========
Service\Driver WM System Decode Application not found.
Service\Driver WM System Decode Application not found.
========== FILES ==========
C:\found.002\dir0000.chk moved successfully.
C:\found.002 moved successfully.
C:\found.001 moved successfully.
C:\b6ea012a28b460ef7b3f4f22bf063c\update moved successfully.
C:\b6ea012a28b460ef7b3f4f22bf063c\support moved successfully.
C:\b6ea012a28b460ef7b3f4f22bf063c moved successfully.
C:\WINDOWS\NV31363124.TMP moved successfully.
========== REGISTRY ==========
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}\\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\nwiz deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\msnmsgr deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\MSMSGS deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer\\NoFind deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer\\NoFolderOptions deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer\\NoRun deleted successfully.
========== COMMANDS ==========
User's Temp folder emptied.
User's Internet Explorer cache folder emptied.
File delete failed. C:\Documents and Settings\perso\Local Settings\Temporary Internet Files\Content.IE5\Y6T5K6OF\display[11].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\perso\Local Settings\Temporary Internet Files\Content.IE5\Y6T5K6OF\im[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\perso\Local Settings\Temporary Internet Files\Content.IE5\Y6T5K6OF\SendMessageLight[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\perso\Local Settings\Temporary Internet Files\Content.IE5\Y6T5K6OF\SZ2OT8CAFIOWFTCAFI0E4UCANGYQF2CAC4T01SCAJJ2DPCCAHPT1AGCA1K3T4UCAMHKJKICAWVZ178CAZACULYCA5ZBQRTCAY4O2YXCAHVK0F6CA7EG5HECA2QWC39CATRULVJCAWTJ5KJCATL2ALLCAU3CND5.htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\perso\Local Settings\Temporary Internet Files\Content.IE5\Y6T5K6OF\ToastFull[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\perso\Local Settings\Temporary Internet Files\Content.IE5\Y6T5K6OF\ToastMini[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\perso\Local Settings\Temporary Internet Files\Content.IE5\TZY2UO0Q\yl_160x600_appscatchall_apps_facebook_com[2].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\perso\Local Settings\Temporary Internet Files\Content.IE5\TRSPKW0E\BY8U3BCALGHXMOCAI38XP6CA74FRPQCATURLE2CAL2H0RACAQP3TTACAASQ5MCCAVTTHGLCA69180YCAFQ1C57CADEDSL9CA4PCUGYCAA05OG7CAPL4ZRZCA4X5F3ACAHW1FO5CARXKX41CAVQ5AUQCABGN26X.htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\perso\Local Settings\Temporary Internet Files\Content.IE5\TRSPKW0E\sans-sursis_com[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\perso\Local Settings\Temporary Internet Files\Content.IE5\TMJ5NIHW\YL_728x90_appscatchall_apps_facebook_com[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\perso\Local Settings\Temporary Internet Files\Content.IE5\T92SBPX8\MsgrConfig[1].asmx scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\perso\Local Settings\Temporary Internet Files\Content.IE5\K6CGBCM3\affich-12703245-pc-infecte[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\perso\Local Settings\Temporary Internet Files\Content.IE5\K6CGBCM3\ANK4PICAMJEWS3CARUV1WBCAPTER5MCAM2LYNZCA4Z3B94CATYE8P5CAWNOLL3CA8X6JZCCATE40BSCAP340OCCAGROPNJCASBVQFRCAS2S6PWCAGHS4NMCAXYEL2NCA0QNIHJCA3KCI9RCA7T1589CAZ49EWA.htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\perso\Local Settings\Temporary Internet Files\Content.IE5\K6CGBCM3\default[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\perso\Local Settings\Temporary Internet Files\Content.IE5\K6CGBCM3\index2[3].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\perso\Local Settings\Temporary Internet Files\Content.IE5\K6CGBCM3\index[2].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\perso\Local Settings\Temporary Internet Files\Content.IE5\G7UCGIN4\01[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\perso\Local Settings\Temporary Internet Files\Content.IE5\G7UCGIN4\index[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\perso\Local Settings\Temporary Internet Files\Content.IE5\G7UCGIN4\WO5QQACAYFHDH4CAHLUU5VCASA3JUBCARCW2ZKCARU0WBSCA0TPGGTCA8PLG71CAGXL4HDCANIQ8RNCAR8XIZ6CACC2CF6CAK3VSTCCA4YUY8VCA1VTM5QCAFT4QDWCAZNL9GKCA0H0ZMYCADXR6Q7CAMUO61L.htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\perso\Local Settings\Temporary Internet Files\Content.IE5\8EBP5KLJ\signin[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\perso\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\perso\Local Settings\Temporary Internet Files\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat scheduled to be deleted on reboot.
User's Temporary Internet Files folder emptied.
Local Service Temp folder emptied.
Local Service Temporary Internet Files folder emptied.
Network Service Temp folder emptied.
Network Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_5f4.dat scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\ZLT07336.TMP scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
FireFox cache emptied.
Temp folders emptied.
Explorer started successfully
OTM by OldTimer - Version 2.1.0.0 log created on 06042009_132517
Files moved on Reboot...
File C:\Documents and Settings\perso\Local Settings\Temporary Internet Files\Content.IE5\Y6T5K6OF\display[11].htm not found!
C:\Documents and Settings\perso\Local Settings\Temporary Internet Files\Content.IE5\Y6T5K6OF\im[1].htm moved successfully.
C:\Documents and Settings\perso\Local Settings\Temporary Internet Files\Content.IE5\Y6T5K6OF\SendMessageLight[1].htm moved successfully.
C:\Documents and Settings\perso\Local Settings\Temporary Internet Files\Content.IE5\Y6T5K6OF\SZ2OT8CAFIOWFTCAFI0E4UCANGYQF2CAC4T01SCAJJ2DPCCAHPT1AGCA1K3T4UCAMHKJKICAWVZ178CAZACULYCA5ZBQRTCAY4O2YXCAHVK0F6CA7EG5HECA2QWC39CATRULVJCAWTJ5KJCATL2ALLCAU3CND5.htm moved successfully.
C:\Documents and Settings\perso\Local Settings\Temporary Internet Files\Content.IE5\Y6T5K6OF\ToastFull[1].htm moved successfully.
C:\Documents and Settings\perso\Local Settings\Temporary Internet Files\Content.IE5\Y6T5K6OF\ToastMini[1].htm moved successfully.
File C:\Documents and Settings\perso\Local Settings\Temporary Internet Files\Content.IE5\TZY2UO0Q\yl_160x600_appscatchall_apps_facebook_com[2].htm not found!
File C:\Documents and Settings\perso\Local Settings\Temporary Internet Files\Content.IE5\TRSPKW0E\BY8U3BCALGHXMOCAI38XP6CA74FRPQCATURLE2CAL2H0RACAQP3TTACAASQ5MCCAVTTHGLCA69180YCAFQ1C57CADEDSL9CA4PCUGYCAA05OG7CAPL4ZRZCA4X5F3ACAHW1FO5CARXKX41CAVQ5AUQCABGN26X.htm not found!
File C:\Documents and Settings\perso\Local Settings\Temporary Internet Files\Content.IE5\TRSPKW0E\sans-sursis_com[1].htm not found!
File C:\Documents and Settings\perso\Local Settings\Temporary Internet Files\Content.IE5\TMJ5NIHW\YL_728x90_appscatchall_apps_facebook_com[1].htm not found!
C:\Documents and Settings\perso\Local Settings\Temporary Internet Files\Content.IE5\T92SBPX8\MsgrConfig[1].asmx moved successfully.
File C:\Documents and Settings\perso\Local Settings\Temporary Internet Files\Content.IE5\K6CGBCM3\affich-12703245-pc-infecte[1].htm not found!
File C:\Documents and Settings\perso\Local Settings\Temporary Internet Files\Content.IE5\K6CGBCM3\ANK4PICAMJEWS3CARUV1WBCAPTER5MCAM2LYNZCA4Z3B94CATYE8P5CAWNOLL3CA8X6JZCCATE40BSCAP340OCCAGROPNJCASBVQFRCAS2S6PWCAGHS4NMCAXYEL2NCA0QNIHJCA3KCI9RCA7T1589CAZ49EWA.htm not found!
C:\Documents and Settings\perso\Local Settings\Temporary Internet Files\Content.IE5\K6CGBCM3\default[1].htm moved successfully.
File C:\Documents and Settings\perso\Local Settings\Temporary Internet Files\Content.IE5\K6CGBCM3\index2[3].htm not found!
File C:\Documents and Settings\perso\Local Settings\Temporary Internet Files\Content.IE5\K6CGBCM3\index[2].htm not found!
C:\Documents and Settings\perso\Local Settings\Temporary Internet Files\Content.IE5\G7UCGIN4\01[1].htm moved successfully.
File C:\Documents and Settings\perso\Local Settings\Temporary Internet Files\Content.IE5\G7UCGIN4\index[1].htm not found!
File C:\Documents and Settings\perso\Local Settings\Temporary Internet Files\Content.IE5\G7UCGIN4\WO5QQACAYFHDH4CAHLUU5VCASA3JUBCARCW2ZKCARU0WBSCA0TPGGTCA8PLG71CAGXL4HDCANIQ8RNCAR8XIZ6CACC2CF6CAK3VSTCCA4YUY8VCA1VTM5QCAFT4QDWCAZNL9GKCA0H0ZMYCADXR6Q7CAMUO61L.htm not found!
C:\Documents and Settings\perso\Local Settings\Temporary Internet Files\Content.IE5\8EBP5KLJ\signin[1].htm moved successfully.
C:\Documents and Settings\perso\Local Settings\Temporary Internet Files\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat moved successfully.
File C:\WINDOWS\temp\Perflib_Perfdata_5f4.dat not found!
File C:\WINDOWS\temp\ZLT07336.TMP not found!
Registry entries deleted on Reboot... -
le rapport situé dans ce dossier : C:\_OTM\MovedFiles\
Le nom du rapport correspond au moment de sa création : date_heure.log
tu peux le poster ici :
http://www.cijoinr.fr/
et donner le lien obtenu en echange -
Merci de ton attention !!!
Je n'arrive pas à fermer la fenêtre et dedans il y a pleins de "file deletes failed" (copier coller impossible)
Et où chercher un rapport qui ne s'affiche pas directement sur le bureau ?
Bonne journée à toi ! -
ok la suite :)
-
Fichier winsys2.exe reçu le 2009.06.04 11:19:54 (UTC)Antivirus Version Dernière mise à jour Résultat
a-squared 4.0.0.101 2009.06.04 -
AhnLab-V3 5.0.0.2 2009.06.04 -
AntiVir 7.9.0.180 2009.06.04 -
Antiy-AVL 2.0.3.1 2009.06.04 -
Authentium 5.1.2.4 2009.06.03 -
Avast 4.8.1335.0 2009.06.03 -
AVG 8.5.0.339 2009.06.04 -
BitDefender 7.2 2009.06.04 -
CAT-QuickHeal 10.00 2009.06.04 -
ClamAV 0.94.1 2009.06.04 -
Comodo 1254 2009.06.04 -
DrWeb 5.0.0.12182 2009.06.04 -
eSafe 7.0.17.0 2009.06.03 -
eTrust-Vet 31.6.6538 2009.06.04 -
F-Prot 4.4.4.56 2009.06.03 -
F-Secure 8.0.14470.0 2009.06.04 -
Fortinet 3.117.0.0 2009.06.04 -
GData 19 2009.06.04 -
Ikarus T3.1.1.59.0 2009.06.04 -
K7AntiVirus 7.10.754 2009.06.04 -
Kaspersky 7.0.0.125 2009.06.04 -
McAfee 5635 2009.06.03 -
McAfee+Artemis 5635 2009.06.03 -
McAfee-GW-Edition 6.7.6 2009.06.04 -
Microsoft 1.4701 2009.06.04 -
NOD32 4130 2009.06.04 -
Norman 6.01.09 2009.06.03 -
nProtect 2009.1.8.0 2009.06.04 -
Panda 10.0.0.14 2009.06.03 -
PCTools 4.4.2.0 2009.06.02 -
Prevx 3.0 2009.06.04 -
Rising 21.32.32.00 2009.06.04 -
Sophos 4.42.0 2009.06.04 MadCodeHook
Sunbelt 3.2.1858.2 2009.06.03 -
Symantec 1.4.4.12 2009.06.04 -
TheHacker 6.3.4.3.339 2009.06.03 -
TrendMicro 8.950.0.1092 2009.06.04 -
VBA32 3.12.10.6 2009.06.03 -
ViRobot 2009.6.4.1769 2009.06.04 -
VirusBuster 4.6.5.0 2009.06.03 -
Information additionnelle
File size: 217088 bytes
MD5...: 246ed5328f940e4fdaab0b2fc987da01
SHA1..: d5e2592cf25b48efb1225e37c45bce99a13466c8
SHA256: a12b18fcdd5e76711c8cfd6010ecdb1f6a4bf27cc48f0ecf70291591770cb457
ssdeep: -<BR>
PEiD..: -
TrID..: File type identification<BR>InstallShield setup (42.6%)<BR>Win32 Executable MS Visual C++ (generic) (37.3%)<BR>Win32 Executable Generic (8.4%)<BR>Win32 Dynamic Link Library (generic) (7.5%)<BR>Generic Win/DOS Executable (1.9%)
PEInfo: PE Structure information<BR><BR>( base data )<BR>entrypointaddress.: 0xeee7<BR>timedatestamp.....: 0x45220536 (Tue Oct 03 06:37:42 2006)<BR>machinetype.......: 0x14c (I386)<BR><BR>( 4 sections )<BR>name viradd virsiz rawdsiz ntrpy md5<BR>.text 0x1000 0x1f6d6 0x20000 6.61 d2f22979f1ff4b51abdd7563aeb45bda<BR>.rdata 0x21000 0x7676 0x8000 4.79 2568b87b9e716158c4b0ee05d59ef976<BR>.data 0x29000 0x5a74 0x2000 3.85 6d7f74470b50f6760435bdc1865de721<BR>.rsrc 0x2f000 0x9290 0xa000 5.56 b596ffd3a165cb398764578107bedac4<BR><BR>( 8 imports ) <BR>> MADCHOOK.DLL: InjectLibraryA, UninjectLibraryA<BR>> KERNEL32.dll: SetErrorMode, HeapFree, HeapAlloc, VirtualAlloc, HeapReAlloc, GetCommandLineA, GetProcessHeap, GetStartupInfoA, RaiseException, RtlUnwind, ExitProcess, HeapSize, TerminateProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, HeapDestroy, HeapCreate, VirtualFree, GetStdHandle, Sleep, FreeEnvironmentStringsA, GetEnvironmentStrings, FreeEnvironmentStringsW, GetEnvironmentStringsW, SetHandleCount, GetFileType, QueryPerformanceCounter, GetTickCount, GetSystemTimeAsFileTime, GetACP, GetConsoleCP, GetConsoleMode, LCMapStringA, LCMapStringW, GetStringTypeA, GetStringTypeW, SetStdHandle, WriteConsoleA, GetConsoleOutputCP, WriteConsoleW, GetOEMCP, GetCPInfo, CreateFileA, GetCurrentProcess, GetThreadLocale, FlushFileBuffers, SetFilePointer, WriteFile, ReadFile, GlobalFlags, InterlockedIncrement, TlsFree, DeleteCriticalSection, LocalReAlloc, TlsSetValue, TlsAlloc, InitializeCriticalSection, GlobalHandle, GlobalReAlloc, EnterCriticalSection, TlsGetValue, LeaveCriticalSection, LocalAlloc, GlobalGetAtomNameA, GlobalFindAtomA, lstrcmpW, GetVersionExA, InterlockedDecrement, GetModuleFileNameW, FreeResource, CloseHandle, WritePrivateProfileStringA, GlobalAddAtomA, GetCurrentProcessId, GetCurrentThread, GetCurrentThreadId, ConvertDefaultLocale, GetModuleFileNameA, EnumResourceLanguagesA, GetLocaleInfoA, LoadLibraryA, lstrcmpA, FreeLibrary, GlobalDeleteAtom, GetModuleHandleA, GetProcAddress, GlobalFree, GlobalAlloc, GlobalLock, GlobalUnlock, FormatMessageA, LocalFree, FindResourceA, LoadResource, LockResource, SizeofResource, MulDiv, SetLastError, GetVersion, CompareStringA, GetLastError, InterlockedExchange, MultiByteToWideChar, WideCharToMultiByte, lstrlenA<BR>> USER32.dll: LoadCursorA, GetSysColorBrush, ShowWindow, SetWindowTextA, IsDialogMessageA, RegisterWindowMessageA, SendDlgItemMessageA, WinHelpA, GetCapture, GetClassLongA, GetClassNameA, SetPropA, GetPropA, RemovePropA, SetFocus, GetWindowTextA, GetForegroundWindow, GetTopWindow, GetMessageTime, GetMessagePos, MapWindowPoints, SetForegroundWindow, UpdateWindow, GetMenu, CreateWindowExA, GetClassInfoA, RegisterClassA, AdjustWindowRectEx, CopyRect, PtInRect, GetDlgCtrlID, DefWindowProcA, CallWindowProcA, SetWindowLongA, SetWindowPos, SystemParametersInfoA, GetWindowPlacement, GetWindowRect, GetWindow, UnhookWindowsHookEx, GetSysColor, EndPaint, BeginPaint, ReleaseDC, GetDC, ClientToScreen, GrayStringA, DrawTextExA, DrawTextA, TabbedTextOutA, GetDesktopWindow, SetActiveWindow, CreateDialogIndirectParamA, DestroyWindow, IsWindow, EnableWindow, GetSystemMetrics, GetDlgItem, GetNextDlgTabItem, EndDialog, SetWindowsHookExA, CallNextHookEx, GetMessageA, TranslateMessage, DispatchMessageA, GetActiveWindow, IsWindowVisible, GetKeyState, PeekMessageA, GetCursorPos, DestroyMenu, UnregisterClassA, PostMessageA, SendMessageA, GetClientRect, DrawIcon, LoadIconA, IsIconic, GetSubMenu, GetMenuItemCount, GetMenuItemID, GetMenuState, CheckMenuItem, EnableMenuItem, ModifyMenuA, GetParent, ValidateRect, GetWindowThreadProcessId, GetWindowLongA, GetLastActivePopup, IsWindowEnabled, MessageBoxA, SetCursor, PostQuitMessage, SetMenuItemBitmaps, GetMenuCheckMarkDimensions, LoadBitmapA, GetFocus, GetClassInfoExA<BR>> GDI32.dll: SetWindowExtEx, ScaleWindowExtEx, DeleteDC, GetStockObject, RectVisible, ScaleViewportExtEx, SetViewportExtEx, OffsetViewportOrgEx, SetViewportOrgEx, SelectObject, Escape, ExtTextOutA, GetDeviceCaps, PtVisible, GetObjectA, DeleteObject, GetClipBox, SetMapMode, SetTextColor, SetBkColor, RestoreDC, SaveDC, CreateBitmap, TextOutA<BR>> WINSPOOL.DRV: ClosePrinter, DocumentPropertiesA, OpenPrinterA<BR>> ADVAPI32.dll: RegQueryValueA, RegEnumKeyA, RegDeleteKeyA, RegOpenKeyA, RegCloseKey, RegOpenKeyExA, RegCreateKeyExA, RegQueryValueExA, RegSetValueExA<BR>> SHLWAPI.dll: PathFindFileNameA, PathFindExtensionA<BR>> OLEAUT32.dll: -, -, -<BR><BR>( 0 exports ) <BR>
PDFiD.: -
RDS...: NSRL Reference Data Set<BR>-
ThreatExpert info: <a href='http://www.threatexpert.com/report.aspx?md5=246ed5328f940e4fdaab0b2fc987da01' target='_blank'>https://www.symantec.com?md5=246ed5328f940e4fdaab0b2fc987da01</a>
CWSandbox info: <a href='http://research.sunbelt-software.com/partnerresource/MD5.aspx?md5=246ed5328f940e4fdaab0b2fc987da01' target='_blank'>http://research.sunbelt-software.com/... -
hello
Clique sur le menu Demarrer /Panneau de configuration/Options des dossiers/ puis dans l'onglet Affichage
- Coche Afficher les fichiers et dossiers cachés
- Décoche Masquer les extensions des fichiers dont le type est connu
- Décoche Masquer les fichiers protégés du système d'exploitation (recommandé)
clique sur Appliquer, puis OK.
N'oublie pas de recacher à nouveau les fichiers cachés et protégés du système d'exploitation en fin de désinfection, c'est important
Fais analyser le(s) fichier(s) suivants sur Virustotal :
Virus Total
* Clique sur Parcourir en haut, choisis Poste de travail et cherche ces fichiers :
C:\WINDOWS\system32\winsys2.exe
* Clique maintenant sur Envoyer le fichier. et laisse travailler tant que "Situation actuelle : en cours d'analyse" est affiché.
* Il est possible que le fichier soit mis en file d'attente en raison d'un grand nombre de demandes d'analyses. En ce cas, il te faudra patienter sans actualiser la page.
* Lorsque l'analyse est terminée ("Situation actuelle: terminé"), clique sur Formaté
* Une nouvelle fenêtre de ton navigateur va apparaître
* Clique alors sur les deux fleches
* Fais un clic droit sur la page, et choisis Sélectionner tout, puis copier
* Enfin colle le résultat dans ta prochaine réponse.
ensuite :
---> Désactive ton antivirus le temps de la manipulation car OTM est détecté comme une infection à tort.
---> Télécharge OTM (OldTimer) sur ton Bureau :
---> Double-clique sur OTM.exe afin de le lancer.
---> Copie (Ctrl+C) le texte suivant ci-dessous :
:processes
explorer.exe
:services
WM System Decode Application
:files
C:\found.002
C:\found.001
C:\b6ea012a28b460ef7b3f4f22bf063c
C:\WINDOWS\NV31363124.TMP
:reg
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"nwiz"=-
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"=-
"MSMSGS"=-
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoFind"=-
"NoFolderOptions"=-
"NoRun"=-
:commands
[purity]
[emptytemp]
[start explorer]
[reboot]
---> Colle (Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.
---> Clique maintenant sur le bouton MoveIt! puis ferme OTM
Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
Accepte en cliquant sur YES.
---> Poste le rapport situé dans ce dossier : C:\_OTM\MovedFiles\
Le nom du rapport correspond au moment de sa création : date_heure.log
-
Logfile of random's system information tool 1.06 (written by random/random)
Run by perso at 2009-06-04 11:58:02
Microsoft Windows XP Professionnel Service Pack 3
System drive C: has 128 GB (81%) free of 157 GB
Total RAM: 1022 MB (57% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:58:11, on 04/06/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\perso\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Documents and Settings\perso\Bureau\RSIT.exe
C:\Program Files\trend micro\HijackThis\perso.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: Yontoo Layers - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files\Yontoo Layers Client for Internet Explorer\YontooIEClient.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SW20] C:\WINDOWS\system32\sw20.exe
O4 - HKLM\..\Run: [SW24] C:\WINDOWS\system32\sw24.exe
O4 - HKLM\..\Run: [WinSys2] C:\WINDOWS\system32\winsys2.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [CamserviceDP] C:\Program Files\Hercules\DualPix Exchange\Camservice.exe /startup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\perso\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - http://fichiers.touslesdrivers.com/maconfig/MaConfig_3_5_0_0.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Planificateur Avira AntiVir Personal - Free Antivirus (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
-
Télécharge Random's System Information Tool (RSIT) de random/random et enregistre l'exécutable sur ton Bureau.
! Déconnecte toi et ferme toutes tes applications en cours !
Double-clique sur " RSIT.exe " pour le lancer .
-> Une première fenêtre s'ouvre avec en titre : " Disclaimer of warranty " .
* Devant l'option "List files/folders created ..." , tu choisis : 2 months
* clique ensuite sur " Continue " pour lancer l'analyse ...
-> laisse faire le scan et ne touche pas au PC ...
Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront (probablement avec le bloc-note).
Poste le contenu de " log.txt " (c'est celui qui apparait à l'écran), ainsi que de " info.txt " (que tu verras dans la barre des tâches), pour analyse et attends la suite ...
Important : poste un rapport, puis l'autre dans la réponse suivante
Si tu essaies de poster les deux en même temps, cela risque d'être trop long pour le forum
( Note : les rapports seront en outre sauvegardés dans ce dossier -> C:\rsit )
-
.
======= RAPPORT D'AD-REMOVER 1.1.4.5_C | UNIQUEMENT XP/VISTA =======
.
Mit à jour part C_XX le 02/06/2009 à 8:00 PM
Contact: AdRemover.contact@gmail.com
Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html
.
Lancé à: 19:09:50, 03/06/2009 | Mode Normal | Option: CLEAN
Exécuté de: C:\Program Files\Ad-remover\
Système d'exploitation: Microsoft® Windows XP™ Service Pack 3 v5.1.2600
Nom du PC: PERSO-8D6644381 | Utilisateur actuel: perso
.
Administrateur: Administrateur
N'est pas administrateur: HelpAssistant *Desactive*
N'est pas administrateur: Invité *Desactive*
Administrateur: perso
N'est pas administrateur: SUPPORT_388945a0 *Desactive*
.
============== ÉLÉMENT(S) NEUTRALISÉ(S) ==============
.
.
HKCR\CLSID\{201f27d4-3704-41d6-89c1-aa35e39143ed}
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}
HKCR\CLSID\{1E0DE227-5CE4-4ea3-AB0C-8B03E1AA76BC}
.
(!) -- Fichiers temporaires supprimés.
.
============== Scan additionnel ==============
.
* Mozilla FireFox Version [Impossible d'obtenir la version] *
Nom du profil: vvxx4qfk.default (perso)
.
(Prefs.js) user_pref("browser.startup.homepage_override.mstone", "rv:1.9.0.6");
.
.
* Internet Explorer Version 8.0.6001.18702 *
[HKEY_CURRENT_USER\..\Internet Explorer\Main]
Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Start Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
Start Page: hxxp://fr.msn.com/?ocid=iehp
[HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]
Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Search bar: hxxp://search.msn.com/spbasic.htm
Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Start Page: hxxp://fr.msn.com/
[HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]
Tabs: res://ieframe.dll/tabswelcome.htm
============== Suspect (Cracks, Serials ... ) ==============
.
+---------------------------------------------------------------------------+
2410 Octet(s) - C:\Ad-Report-CLEAN.log
2767 Octet(s) - C:\Ad-Report-SCAN.log
37 Fichier(s) - C:\Program Files\Ad-remover\BACKUP
25 Fichier(s) - C:\Program Files\Ad-remover\QUARANTINE
Fin à: 19:15:56 | 03/06/2009
.
============== E.O.F ==============
.
- 1
- 2