DD externe
Bonjour,
Mon disque dur externe mets des plombes à s'installer sur mon ordinateur, est-il possible que celui-ci soit infecté d'un virus???
Mon disque dur externe mets des plombes à s'installer sur mon ordinateur, est-il possible que celui-ci soit infecté d'un virus???
Configuration: Windows XP Firefox 3.0.11
23 réponses
-
hello,
Juste pour te dire que dr web tourne (depuis 1jour et demi) et c'est toujours pas fini, c'est très lent!!
Je copierai le rapport des que c'est fait -
Je te donne un lien si tu veut convertir ton dd fat32 en ntfs.
http://webdemarcus.free.fr/Faire/WinXPconvertirFat.htm -
Si je suis oblige de le redémarrer (mon ordi) dois- je à chaque fois attendre de réinstaller mon DD externe, car si je le laisse brancher à mon ordi celui-ci redémarre en balancant un programme (sur fond bleu) qui l'analyse.
C'est peut etre du au fait que ton dd externe est en fat32 et les autres en ntfs.
C:\ # Disque fixe local # 30 Go (8,69 Go free) [Windows] # NTFS
# D:\ # Disque fixe local # 44,52 Go (43,34 Go free) [Data] # NTFS
H:\ # Disque fixe local # 596,02 Go (174,36 Go free) [Elements] # FAT32 -
bon, des que mon DD externe sera installé je ferai le scan avec dr web.
Si je suis oblige de le redémarrer (mon ordi) dois- je à chaque fois attendre de réinstaller mon DD externe, car si je le laisse brancher à mon ordi celui-ci redémarre en balancant un programme (sur fond bleu) qui l'analyse.
c'est quand je le redémarre moi je débranche mon DD externe!!! sinon je suis parti pour des heures
je fais comment sinon??
merci -
Donc c'est tout a fait normal qu'il mette des plombes pour le nettoyer??? NON
Laisse tomber findykill.Pour cette nuit fait un scan avec dr web .
Le scan peut être très long.Scan toos tes dd externes.
• Télécharge: ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe sur ton bureau.
• Double-clique sur drweb-cureit.exe et clique sur Commencer le scan.
• Si il trouve des processus infectés, clique sur le bouton Oui pour Tout à l'invite.
• Lorsque le scan rapide est terminé, clique sur Options > Changer la configuration.
• Choisis l'onglet Scanner, et décoche Analyse heuristique.
• De retour à la fenêtre principale : choisis Analyse complète.
• Clique la flèche verte sur la droite et le scan débutera. Une publicité apparaît quelquefois, ferme-la.
• Clique Oui pour Tout si un fichier est détecté.
• A la fin du scan, si des infections sont trouvées, clique sur Tout sélectionner, puis surDésinfecter.
• Si la désinfection est impossible, clique sur Quarantaine.
• Au menu principal de l'outil, en haut à gauche, clique sur le menu Fichier et choisis Enregistrer le rapport.
• Sauvegarde le rapport sur ton Bureau. Ce dernier se nommera DrWeb.csv.
• Ferme Dr.Web CureIt!
• /!\ Important /!\ Redémarre ton ordinateur car certains fichiers peuvent être déplacés/réparés au redémarrage.
• Après le redémarrage, fais un copié/collé du rapport dans ta prochaine réponse
-
Ah ok,
jel'avais déjà fais mais il mettait tellement de temps que je ne trouvais pas cela normal. Mon ordi s'est éteint et quand il a redémarré il m'a mis un fond bleu disant que windows analyserait le disque H FAT 32. cette analyse n'avance pas pour un sou.
Donc c'est tout a fait normal qu'il mette des plombes pour le nettoyer???
je posterai le rapport demain ou dans la nuit (je dois attendre 3h avant que mon DD externe s'installe)
encore merci -
Pour la désinfection tu n'as pas branché H:\ # Disque fixe local # 596,02 Go (174,36 Go free) [Elements] # FAT32
Refait le en connectant H: et post le rapport. -
hello,
voici le rapport:
############################## | FindyKill V6.002 |
# User : Jé (Administrateurs) # LAPTOP
# Update on 03/07/09 by Chiquitine29 & C_XX
# Start at: 21:01:33 | 5/07/2009
# Website : http://pagesperso-orange.fr/NosTools/index.html
# Genuine Intel(R) CPU T2050 @ 1.60GHz
# Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 3
# Internet Explorer 7.0.5730.13
# Windows Firewall Status : Enabled
# AV : ESET NOD32 Antivirus 3.0 3.0 [ Enabled | Updated ]
# C:\ # Disque fixe local # 30 Go (10,26 Go free) [Windows] # NTFS
# D:\ # Disque fixe local # 44,52 Go (43,34 Go free) [Data] # NTFS
# E:\ # Disque CD-ROM # 5,91 Go (0 Mo free) [EURO_TRIP] # UDF
# F:\ # Disque amovible
# G:\ # Disque amovible
# I:\ # Disque CD-ROM
############################## | Processus actifs |
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\WINDOWS\system32\logonui.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
################## | Fichiers # Dossiers infectieux |
################## | C:\Documents and Settings\J‚\Temporary Internet Files |
################## | All Drives ... |
################## | Autres ... |
################## | Registre # Clés Run infectieuses |
Supprimé ! HKCU\Software\Local AppWizard-Generated Applications\PhLeAutoRun
################## | Registre # Mountpoints2 |
################## | Listing des fichiers présent |
[22/02/2009 22:27|--a------|0] - C:\ALZ55FE.tmp
[06/06/2008 18:55|--a------|0] - C:\AUTOEXEC.BAT
[07/06/2008 18:02|-rahs----|211] - C:\boot.ini
[28/08/2001 14:00|-rahs----|4952] - C:\Bootfont.bin
[06/06/2008 18:55|--a------|0] - C:\CONFIG.SYS
[05/07/2009 21:20|--a------|2815] - C:\FindyKill.txt
[06/09/2008 22:24|--a------|2380] - C:\fixnavi.txt
[06/06/2008 18:55|-rahs----|0] - C:\IO.SYS
[17/11/2008 19:28|--a------|0] - C:\log_lobby.txt
[17/11/2008 19:28|--a------|0] - C:\log_lobby_dumper.txt
[06/06/2008 18:55|-rahs----|0] - C:\MSDOS.SYS
[07/06/2008 17:53|-rahs----|47564] - C:\NTDETECT.COM
[08/06/2008 12:22|-rahs----|252240] - C:\ntldr
[||] - C:\pagefile.sys
[06/09/2008 23:14|--a------|2855] - C:\rapport.txt
[08/06/2008 03:07|--ah-----|268] - C:\sqmdata00.sqm
[08/06/2008 03:09|--ah-----|268] - C:\sqmdata01.sqm
[08/06/2008 04:46|--ah-----|268] - C:\sqmdata02.sqm
[12/06/2008 15:44|--ah-----|232] - C:\sqmdata03.sqm
[12/06/2008 15:46|--ah-----|232] - C:\sqmdata04.sqm
[12/06/2008 15:46|--ah-----|232] - C:\sqmdata05.sqm
[12/06/2008 15:46|--ah-----|232] - C:\sqmdata06.sqm
[12/06/2008 15:46|--ah-----|232] - C:\sqmdata07.sqm
[12/06/2008 15:47|--ah-----|232] - C:\sqmdata08.sqm
[12/06/2008 15:47|--ah-----|232] - C:\sqmdata09.sqm
[12/06/2008 19:00|--ah-----|232] - C:\sqmdata10.sqm
[12/06/2008 19:00|--ah-----|232] - C:\sqmdata11.sqm
[12/06/2008 19:00|--ah-----|232] - C:\sqmdata12.sqm
[12/06/2008 19:01|--ah-----|232] - C:\sqmdata13.sqm
[26/07/2008 20:39|--ah-----|232] - C:\sqmdata14.sqm
[10/01/2009 21:38|--ah-----|232] - C:\sqmdata15.sqm
[05/03/2009 18:16|--ah-----|232] - C:\sqmdata16.sqm
[12/04/2009 13:32|--ah-----|232] - C:\sqmdata17.sqm
[12/04/2009 13:33|--ah-----|232] - C:\sqmdata18.sqm
[06/06/2009 10:06|--ah-----|232] - C:\sqmdata19.sqm
[08/06/2008 03:07|--ah-----|244] - C:\sqmnoopt00.sqm
[08/06/2008 03:09|--ah-----|244] - C:\sqmnoopt01.sqm
[08/06/2008 04:46|--ah-----|244] - C:\sqmnoopt02.sqm
[12/06/2008 15:44|--ah-----|244] - C:\sqmnoopt03.sqm
[12/06/2008 15:46|--ah-----|244] - C:\sqmnoopt04.sqm
[12/06/2008 15:46|--ah-----|244] - C:\sqmnoopt05.sqm
[12/06/2008 15:46|--ah-----|244] - C:\sqmnoopt06.sqm
[12/06/2008 15:46|--ah-----|244] - C:\sqmnoopt07.sqm
[12/06/2008 15:47|--ah-----|244] - C:\sqmnoopt08.sqm
[12/06/2008 15:47|--ah-----|244] - C:\sqmnoopt09.sqm
[12/06/2008 19:00|--ah-----|244] - C:\sqmnoopt10.sqm
[12/06/2008 19:00|--ah-----|244] - C:\sqmnoopt11.sqm
[12/06/2008 19:00|--ah-----|244] - C:\sqmnoopt12.sqm
[12/06/2008 19:01|--ah-----|244] - C:\sqmnoopt13.sqm
[26/07/2008 20:39|--ah-----|244] - C:\sqmnoopt14.sqm
[10/01/2009 21:38|--ah-----|244] - C:\sqmnoopt15.sqm
[05/03/2009 18:16|--ah-----|244] - C:\sqmnoopt16.sqm
[12/04/2009 13:32|--ah-----|244] - C:\sqmnoopt17.sqm
[12/04/2009 13:33|--ah-----|244] - C:\sqmnoopt18.sqm
[06/06/2009 10:06|--ah-----|244] - C:\sqmnoopt19.sqm
[05/07/2009 13:20|--a------|5917] - C:\UsbFix.txt
################## | Vaccination |
# C:\autorun.inf ( # Not infected ) -> Folder created by FindyKill.
# D:\autorun.inf ( # Not infected ) -> Folder created by FindyKill.
################## | Etat / Services / Informations |
# Mode sans echec : OK
# Affichage des fichiers cachés : OK
# Ndisuio -> Start = 3 ( Good = 3 | Bad = 4 )
# EapHost -> Start = 2 ( Good = 2 | Bad = 4 )
# Ip6Fw -> Start = 2 ( Good = 2 | Bad = 4 )
# SharedAccess -> Start = 2 ( Good = 2 | Bad = 4 )
# wuauserv -> Start = 2 ( Good = 2 | Bad = 4 )
# wscsvc -> Start = 2 ( Good = 2 | Bad = 4 )
################## | PEH ... |
################## | Cracks / Keygens / Serials |
################## | ! Fin du rapport # FindyKill V6.002 ! | -
Bonjour
• Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) suceptible d avoir été infectés sans les ouvrir
• Double clic sur le raccourci FindyKill sur ton bureau
• Au menu principal,choisi l option 2 (Suppression)
/!\ il y aura 2 redémarrage, laisse travailler l outils jusqu a l apparition du message "nettoyage effectué"
/!\ Ne te sert pas du pc durant la suppression , ton bureau ne sera pas accessible c est normal !
• ensuite post le rapport FindyKill.txt
• Note : le rapport FindyKill.txt est sauvegardé a la racine du disque
• Note : Si le Bureau ne réapparait pas presse Ctrl + Alt + Suppr , Onglet "Fichier" , "Nouvelle tâche" , tapes explorer.exe et valides
-
hello,
voila le rapport findyskill:
############################## | FindyKill V6.002 |
# User : Jé (Administrateurs) # LAPTOP
# Update on 03/07/09 by Chiquitine29 & C_XX
# Start at: 3:39:50 | 5/07/2009
# Website : http://pagesperso-orange.fr/NosTools/index.html
# Genuine Intel(R) CPU T2050 @ 1.60GHz
# Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 3
# Internet Explorer 7.0.5730.13
# Windows Firewall Status : Enabled
# AV : ESET NOD32 Antivirus 3.0 3.0 [ Enabled | Updated ]
# C:\ # Disque fixe local # 30 Go (8,69 Go free) [Windows] # NTFS
# D:\ # Disque fixe local # 44,52 Go (43,34 Go free) [Data] # NTFS
# E:\ # Disque CD-ROM # 5,91 Go (0 Mo free) [EURO_TRIP] # UDF
# F:\ # Disque amovible
# G:\ # Disque amovible
# H:\ # Disque fixe local # 596,02 Go (174,36 Go free) [Elements] # FAT32
# I:\ # Disque CD-ROM
############################## | Processus actifs |
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Sony\ISB Utility\ISBMgr.exe
C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Winamp\winamp.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
################## | Registre Startup |
HKCU_Main: "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
HKCU_Main: "Search Page"="https://www.google.com/?gws_rd=ssl"
HKCU_Main: "Start Page"="https://www.google.com/?gws_rd=ssl"
HKLM_logon: "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
HKLM_logon: "DefaultUserName"="J‚"
HKLM_logon: "AltDefaultUserName"="J‚"
HKLM_logon: "LegalNoticeCaption"=""
HKLM_logon: "LegalNoticeText"=""
HKLM_Run: QuickTime Task="C:\Program Files\QuickTime\QTTask.exe" -atboottime
HKLM_Run: iTunesHelper="C:\Program Files\iTunes\iTunesHelper.exe"
HKLM_Run: SunJavaUpdateSched="C:\Program Files\Java\jre6\bin\jusched.exe"
HKLM_Run: egui="C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
HKLM_Run: Mouse Suite 98 Daemon=ICO.EXE
HKLM_Run: ISBMgr.exe=C:\Program Files\Sony\ISB Utility\ISBMgr.exe
HKLM_Run: SonyPowerCfg="C:\Program Files\Sony\VAIO Power Management\SPMgr.exe"
HKLM_Run: Switcher.exe=C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
HKLM_Run: GrooveMonitor="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
HKLM_Run: AzMixerSel=C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
HKLM_Run: SkyTel=SkyTel.EXE
HKLM_Run: Alcmtr=ALCMTR.EXE
HKLM_Run: NeroFilterCheck=C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
HKLM_Run: igfxtray=C:\WINDOWS\system32\igfxtray.exe
HKLM_Run: igfxhkcmd=C:\WINDOWS\system32\hkcmd.exe
HKLM_Run: igfxpers=C:\WINDOWS\system32\igfxpers.exe
HKCU_Run: updateMgr="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_1_0 -reboot 1
HKCU_Run: ctfmon.exe=C:\WINDOWS\system32\ctfmon.exe
HKCU_Run: BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}="C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
HKCU_Run: swg=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
HKCU_Run: BitTorrent DNA="C:\Program Files\DNA\btdna.exe"
HKCU_Run: SUPERAntiSpyware=C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
################## | Fichiers # Dossiers infectieux |
################## | C:\Documents and Settings\J‚\Temporary Internet Files |
################## | All Drives ... |
Présent ! H:\autorun.inf
################## | Registre # Clés Run infectieuses |
Présent ! HKCU\Software\Local AppWizard-Generated Applications\PhLeAutoRun
Présent ! HKU\S-1-5-21-1123561945-1482476501-725345543-1003\Software\Local AppWizard-Generated Applications\PhLeAutoRun
################## | Registre # Mountpoints2 |
HKCU\...\Explorer\MountPoints2\H\Shell\AutoRun\Command
HKCU\...\Explorer\MountPoints2\{45f22104-423f-11de-ae7f-0016cfa024a8}\Shell\AutoRun\Command
HKCU\...\Explorer\MountPoints2\{c6730a48-fc4c-11dd-ae06-0016cfa024a8}\Shell\AutoRun\Command
################## | Etat / Services / Informations |
# Affichage des fichiers cachés : OK
# Mode sans echec : OK
# Ndisuio -> Start = 3 ( Good = 3 | Bad = 4 )
# EapHost -> Start = 3 ( Good = 2 | Bad = 4 )
# Ip6Fw -> Start = 3 ( Good = 2 | Bad = 4 )
# SharedAccess -> Start = 2 ( Good = 2 | Bad = 4 )
# wuauserv -> Start = 2 ( Good = 2 | Bad = 4 )
# wscsvc -> Start = 2 ( Good = 2 | Bad = 4 )
################## | Cracks / Keygens / Serials |
################## | ! Fin du rapport # FindyKill V6.002 ! | -
• Télécharges :
• http://sd-1.archive-host.com/membres/up/127028005715545653/FindyKill.exe
• \ !/Utilisateurs de Vista, il est nécessaire de désactiver l'UAC (contrôle des comptes utilisateurs) comme expliqué : ici
• Lance l’ installation avec les paramètres par defaut
• Double clic sur le raccourci FindyKill sur ton bureau
• Au menu principal, choisi option 1 (Recherche)
• Post le rapport FindyKill.txt
• Note : le rapport FindyKill.txt est sauvegardé a la racine du disque
-
désolé du retard voila la réponse
SUPERAntiSpyware Scan Log
https://www.superantispyware.com/
Generated 07/03/2009 at 05:31 PM
Application Version : 4.26.1006
Core Rules Database Version : 3969
Trace Rules Database Version: 1909
Scan type : Complete Scan
Total Scan Time : 01:39:36
Memory items scanned : 692
Memory threats detected : 0
Registry items scanned : 6917
Registry threats detected : 0
File items scanned : 103462
File threats detected : 1
Trojan.Agent/Gen-Dropper[Temp]
C:\WINDOWS\SYSTEM32\SET21C.TMP -
Fait superantispyware.
• Télécharge :https://www.superantispyware.com/
• Choisis "enregistrer" et enregistre-le sur ton bureau.
• Double-clique sur l'icône d'installation qui vient de se créer et suis les instructions.
• Créé une icône sur le bureau.
• Double-clique sur l'icône de SAS (une tête dans un cercle rouge barré) pour le lancer.
• Si l'outil te demande de mettre à jour le programme ("update the program definitions", clique sur yes.
• Sous Configuration and Preferences, clique sur le bouton "Preferences"
• Clique sur l'onglet "Scanning Control "
• Dans "Scanner Options ", assure toi que la case devant lles lignes suivantes est cochée :
• Close browsers before scanning
• Scan for tracking cookies
• Terminate memory threats before quarantining
• Laisse les autres lignes décochées.
• Clique sur le bouton "Close" pour quitter l'écran du centre de contrôle.
• Dans la fenêtre principale, clique, dans "Scan for Harmful Software", sur "Scan your computer".
• Dans la colonne de gauche, coche C:\Fixed Drive.
• Dans la colonne de droite, sous "Complete scan", clique sur "Perform Complete Scan"
• Clique sur "next" pour lancer le scan. Patiente pendant la durée du scan.
• A la fin du scan, une fenêtre de résultats s'ouvre . Clique sur OK.
• Assure toi que toutes les lignes de la fenêtre blanche sont cochées et clique sur "Next".
• Tout ce qui a été trouvé sera mis en quarantaine. S'il t'es demandé de redémarrer l'ordi ("reboot"), clique sur Yes.
• Pour recopier les informations sur le forum, fais ceci :
• après le redémarrage de l'ordi, double-clique sur l'icône pour lancer SAS.
• Clique sur "Preferences" puis sur l'onglet "Statistics/Logs ".
• Dans "scanners logs", double-clique sur SUPERAntiSpyware Scan Log.
• Le rapport va s'ouvrir dans ton éditeur de texte par défaut.
• Copie son contenu dans ta réponse.
• Regarde bien le tuto SUPERAntiSpyware il est très bien expliqué.
• https://www.malekal.com/?s=SUPERAntiSpyware
-
lorsque je veux scanner mos disque dur externe (H) Il plante après 2min 3 sec sur:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CurrentVersion\installer\UserData\S-1-5-18\Components\[41565f5t
et après il me dit que le programme ne répond plus.
Que faire? -
• Télécharge et installe Malwarebytes' Anti-Malware
• (NB : S'il te manque"COMCTL32.OCX" lors de l'installe, alors télécharge le ici : https://www.malekal.com/tutorial-aboutbuster/
• A la fin de l'installation, veille à ce que l'option « mettre a jour Malwarebyte's Anti-Malware » soit cochée
• Lance MBAM et laisse les Mises à jour se télécharger (sinon fais les manuellement au lancement du programme)
• Puis va dans l'onglet "Recherche", coche "Exécuter un examen complet" puis "Rechercher"
• Sélectionne tes disques durs" puis clique sur "Lancer l’examen"
• A la fin du scan, clique sur Afficher les résultats
• Coche tous les éléments détectés puis clique sur Supprimer la sélection
• Enregistre le rapport
• S'il t'est demandé de redémarrer, clique sur Yes
• Poste le rapport de scan après la suppression ici
• Si tu as besoin d’aide regarde ce tutorial
https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
-
Bonjour,
voila mon nouveau rapport rsit après nettoyage:
Logfile of random's system information tool 1.06 (written by random/random)
Run by Jé at 2009-07-02 18:32:20
Microsoft Windows XP Professionnel Service Pack 3
System drive C: has 9 GB (29%) free of 31 GB
Total RAM: 502 MB (46% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:32:29, on 2/07/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16850)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Sony\ISB Utility\ISBMgr.exe
C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Jé\Bureau\RSIT.exe
C:\Program Files\trend micro\Jé.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: (no name) - {D0943516-5076-4020-A3B5-AEFAF26AB263} - (no file)
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
O4 - HKLM\..\Run: [ISBMgr.exe] C:\Program Files\Sony\ISB Utility\ISBMgr.exe
O4 - HKLM\..\Run: [SonyPowerCfg] "C:\Program Files\Sony\VAIO Power Management\SPMgr.exe"
O4 - HKLM\..\Run: [Switcher.exe] C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_1_0 -reboot 1
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Startup: OpenOffice.org 3.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: LUMIX Simple Viewer.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O20 - AppInit_DLLs: mhiwuk.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Service Google Update (gupdate1c9afc42926bc28) (gupdate1c9afc42926bc28) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
-
Bonjour
Problème de connexion je ne pouvais pas être présent .A faire dans l'ordre.
1=>Supprime tout ce que superanti spywares a trouvé.Redémarre ton pc.
2=> Télécharge CCleaner : https://www.01net.com/telecharger/windows/Utilitaire/nettoyeurs_et_installeurs/fiches/32599.html
• ou https://www.pcastuces.com/logitheque/ccleaner.htm
• Ce logiciel va permettre de supprimer tous les fichiers temporaires et de corriger ton registre .
• Lors de l'installation choisis bien "français" en langue .
• avant de cliquer sur le bouton "installer", décoche toutes les "options supplémentaires" sauf les 2 premières.
• (attention à l'installation penser à DECOCHER l'installation de Yahoo toolbar discrètement proposé en plus de CCleaner).
• Un tuto ( aide ): http://perso.orange.fr/jesses/Docs/Logiciels/CCleaner.htm
• Utilisation:
• ! déconnecte toi et ferme toutes applications en cours !
• va dans "nettoyeur" : fais -analyse- puis -nettoyage
• va dans "registre": fais -chercher les erreurs- et -réparer toutes les erreurs-
( plusieurs fois jusqu'à ce qu'il n'y est plus d'erreur ) .
• ( CCleaner : soft à garder sur son PC , super utile pour de bons nettoyages ...)
---------------------------------------------------------------------------
3=>Post un nouveau rapport rsit.
-
hello,
Personne ne sait m'aider pour déchiffrer ces deux rapports et regler une fois pour toute ces problèmes.
merci d'avance -
hello,
voila j'ai recopié les deux rappors.
Quelqu'un peut- il m'aider.
Merci d'avance -
bonjour,
voila le rapport apres le scan:
SUPERAntiSpyware Scan Log
https://www.superantispyware.com/
Generated 07/01/2009 at 08:45 PM
Application Version : 4.26.1006
Core Rules Database Version : 3965
Trace Rules Database Version: 1905
Scan type : Custom Scan
Total Scan Time : 01:36:40
Memory items scanned : 692
Memory threats detected : 1
Registry items scanned : 6943
Registry threats detected : 6
File items scanned : 72755
File threats detected : 50
Background Agent Application by Broderbund Software
C:\WINDOWS\BBSTORE\DSS\DSSAGENT.EXE
C:\WINDOWS\BBSTORE\DSS\DSSAGENT.EXE
[DSS] C:\WINDOWS\BBSTORE\DSS\DSSAGENT.EXE
Adware.Tracking Cookie
C:\Documents and Settings\Jé\Cookies\jé@pcprivacycleaner[1].txt
C:\Documents and Settings\Jé\Cookies\jé@virusremover2008[2].txt
C:\Documents and Settings\Jé\Cookies\jé@msnportal.112.2o7[1].txt
C:\Documents and Settings\Jé\Cookies\jé@wmvmedialease[1].txt
C:\Documents and Settings\Jé\Cookies\jé@rotator.adjuggler[2].txt
C:\Documents and Settings\Jé\Cookies\jé@fastclick[2].txt
C:\Documents and Settings\Jé\Cookies\jé@bs.serving-sys[2].txt
C:\Documents and Settings\Jé\Cookies\jé@serving-sys[2].txt
C:\Documents and Settings\Jé\Cookies\jé@ad.dragonstar.dmoglobal[2].txt
C:\Documents and Settings\Jé\Cookies\jé@www.system-defender[1].txt
C:\Documents and Settings\Jé\Cookies\jé@adbrite[1].txt
C:\Documents and Settings\Jé\Cookies\jé@ads.heias[1].txt
C:\Documents and Settings\Jé\Cookies\jé@de.sitestat[1].txt
C:\Documents and Settings\Jé\Cookies\jé@atwola[2].txt
C:\Documents and Settings\Jé\Cookies\jé@webmasterplan[1].txt
C:\Documents and Settings\Jé\Cookies\jé@scanner.vav-x-scanner[2].txt
C:\Documents and Settings\Jé\Cookies\jé@windowsmedia[1].txt
C:\Documents and Settings\Jé\Cookies\jé@adopt.euroclick[1].txt
C:\Documents and Settings\Jé\Cookies\jé@a2.adserver01[2].txt
C:\Documents and Settings\Jé\Cookies\jé@statcounter[1].txt
C:\Documents and Settings\Jé\Cookies\jé@protect.trustedantivirus[3].txt
C:\Documents and Settings\Jé\Cookies\jé@atdmt[1].txt
C:\Documents and Settings\Jé\Cookies\jé@doubleclick[2].txt
C:\Documents and Settings\Jé\Cookies\jé@adtech[2].txt
C:\Documents and Settings\Jé\Cookies\jé@tacoda[1].txt
C:\Documents and Settings\Jé\Cookies\jé@content.yieldmanager.edgesuite[1].txt
C:\Documents and Settings\Jé\Cookies\jé@advertising[2].txt
C:\Documents and Settings\Jé\Cookies\jé@ad.yieldmanager[2].txt
C:\Documents and Settings\Jé\Cookies\jé@fr.sitestat[1].txt
C:\Documents and Settings\Jé\Cookies\jé@tracking.mlsat02[1].txt
C:\Documents and Settings\Jé\Cookies\jé@content.yieldmanager[3].txt
C:\Documents and Settings\Jé\Cookies\jé@adfarm1.adition[1].txt
C:\Documents and Settings\Jé\Cookies\jé@fl01.ct2.comclick[1].txt
C:\Documents and Settings\Jé\Cookies\jé@www.etracker[2].txt
C:\Documents and Settings\Jé\Cookies\jé@himedia.individuad[2].txt
C:\Documents and Settings\Jé\Cookies\jé@smartadserver[1].txt
C:\Documents and Settings\Jé\Cookies\jé@content.yieldmanager[2].txt
C:\Documents and Settings\Jé\Cookies\jé@protect.trustedantivirus[2].txt
C:\Documents and Settings\Jé\Cookies\jé@2o7[2].txt
C:\Documents and Settings\Jé\Cookies\jé@bluestreak[1].txt
C:\Documents and Settings\Jé\Cookies\jé@tradedoubler[2].txt
C:\Documents and Settings\Jé\Cookies\jé@adsrv.admediate[2].txt
C:\Documents and Settings\Jé\Cookies\jé@mediaplex[1].txt
C:\Documents and Settings\Jé\Cookies\jé@statse.webtrendslive[2].txt
C:\Documents and Settings\Jé\Cookies\jé@apmebf[2].txt
C:\Documents and Settings\Jé\Cookies\jé@www.safewebnavigate2008[1].txt
Rogue.Component/Trace
HKLM\Software\Microsoft\4C1AA2D3
HKLM\Software\Microsoft\4C1AA2D3#4c1aa2d3
HKLM\Software\Microsoft\4C1AA2D3#Version
HKLM\Software\Microsoft\4C1AA2D3#4c1a0f53
HKLM\Software\Microsoft\4C1AA2D3#4c1a66b6
Adware.WhenU
C:\PROGRAM FILES\DAEMON TOOLS\SETUPDTSB.EXE
Trojan.Unknown Origin
C:\WINDOWS\SYSTEM32\1.ICO
C:\WINDOWS\SYSTEM32\2.ICO
merci beaucoup
- 1
- 2
Suivant