Page internet " about blank"
RésoluA l'ouverture d'internet explorer, une autre page publicitaire s'ouvre par dessus ma page orange avec une petite fenêtre au démarrage (About Blank) Comment faire pour empêcher cette publicité forcée. J’ai passé mon anti virus Avira AntiVir à jour, mon anti spyware Spybot et Malwarebyte et rien ne vire ce virus ou expions. Comment faire si vous avez une solution, merci d'avance
Configuration: Windows 7 Internet Explorer 7.0
29 réponses
Le problème décrit une publicité intrusive qui s'ouvre au lancement d'Internet Explorer et s'affiche par-dessus une page orange, avec une fenêtre About Blank bloquant l'affichage normal. Plusieurs pistes techniques ont été proposées, incluant des outils de détection et de suppression, des nettoyeurs et la génération de rapports pour identifier les éléments indésirables. Les solutions recommandent ensuite des étapes en mode sans échec, puis l’utilisation d’outils spécialisés et la suppression de composants ou moteurs de recherche indésirés. D’autres éléments nuancent le diagnostic en évoquant une éventuelle version non à jour ou piratée de Windows 7, ce qui peut expliquer l’absence d’installation correcte des options de sécurité.
-
ContributeurBonjour,
télécharge GenProc http://www.genproc.com/GenProc.exe
double-clique sur GenProc.exe et poste le contenu du rapport qui s'ouvre -
La solution sous Win 7... Outils >>options Internet>>Modifier les paramètres par défaut, cliquer sur "Paramètres", une fenêtre s'ouvre, (normal, c'est Windows). Cliquer sur "moteurs de recheches" à droite;... à gauche s'affichent tous les moteurs de recherches dont "About_Blanck". Clic droit sur le moteur que vous désirez supprimer et dans le menu contectuel cliquer sur supprimer. Et voilou, petit coucou de la Belgique en passant. Petite info supplémentaire... pas la peine de dire "J'ai pas ça chez moi", il y a deux explications possibles. Soit votre version de win 7 n'est pas à jour, soit elle est piratée. Pourquoi ? Parce que ette fonction ne s'installe pas avec le disque Windows mais uniquement avec la mise à jour, et encore pas du premier coup.
-
Je tiens a te remercier de la patience que tu as eu avec moi..
Merci merci
Bonne soirée
Robert -
Contributeurle "about blank" il persiste ? car chez moi je te dis ça s'affiche qques secondes et ensuite une url genre amazon
-
Contributeur
le sypware ou autre est toujours sur mon ordi:
qu'est-ce que c'est qui te fait dire ça ? beaucoup de sites web affichent des pages publicitaires, si le navigateur ne les bloque pas c'est normal que ce soit envahissant, c'est même fait pour ça.
C'est différent d'un spyware, ou plutot d'un adware qui lui serait enfoui dans ton système de fichiers -
en effet en bloquant les publicités, je n'ai plus cette merde de about blank , mais est-ce la solution, le sypware ou autre est toujours sur mon ordi:
-
c'est a dire, que veux tu dire de mon navigateur paramétré comme une merde ? je suis sur Internet explorer 8.0.7100
-
Contributeurje viens de tester ton site, en configurant mon navigateur comme si c'était un navigateur de merde (pas de blocage des popups, ni des pubs).
Conclusion1 : page about:blank, puis qques secondes après pub variable
Conclusion2 : est-ce que ton navigateur ne serait pas paramétré comme une merde ? -
ContributeurAs-tu un fichier texte uninstall.txt dans C:\GenProc\outil\ ?
-
Non pas de fichier uninstall.txt mais un fichier uninstall.bat.
Aussi j'ai fait un scan avec NOD32 et toujours pareil, l'ouverture de 'about blank" ne se fait plus que sur un seul site, qui est le miens, j'ai fais l'ouverture de ce site sur un autre ordinateur, et ça se ce passe pas.
le site est https://www.cpa52.fr/
-
-
n'existe-il pas un anti Spyware pour supprimer ce fichier ou programme caché (about blank) ?
-
Contributeurfais le scan nod32 suggéré
-
ContributeurRelance GenProc et dis moi si tu as toujours ton problème
-
Rapport GenProc 2.637 [2] - 13/10/2009 à 20:37:10
@ Windows 7 - Mode normal
@ Internet Explorer (8.0.7100.0) [Navigateur par défaut]
~~ CM DISK ERROR ~~
GenProc n'a détecté aucune infection caractéristique et suggère de suivre la procédure suivante :
# Etape 1/ Télécharge :
ToolsCleaner! http://pc-system.fr/ (A.Rothstein & Dj QUIOU) sur ton Bureau.
# Etape 2/
- Double-clique sur ToolsCleaner2.exe pour le lancer.
- Clique sur Recherche et laisse le scan agir.
- Clique sur Suppression pour finaliser.
- Tu peux, si tu le souhaites, te servir des Options Facultatives.
- Clique sur Quitter pour obtenir le rapport C:\TCleaner.txt
# Etape 3/
Poste un rapport Nod32 https://www.eset.com/ (il faut utiliser Internet Explorer)
- coche toutes les cases à chaque fois, et lorsque c'est terminé, colle le rapport :
C:\Program Files\EsetOnlineScanner\log.txt
~~~~ INFORMATION COMPLEMENTAIRE ~~~~
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:38:10, on 13/10/2009
Platform: Unknown Windows (WinNT 6.01.3004)
MSIE: Internet Explorer v8.00 (8.00.7100.0000)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskhost.exe
C:\Program Files\ASUS\ASUS Live Update\ALU.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\WTablet\Pen_TabletUser.exe
C:\Windows\System32\oodtray.exe
C:\UTIL\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
D:\Logiciels Divers\Paint shop pro 12\CorelIOMonitor.exe
C:\UTIL\Antivirus\Avira\AntiVir Desktop\avgnt.exe
C:\Windows\ASScrPro.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Windows\RtHDVCpl.exe
D:\Logiciels Divers\Acronis\TrueImageMonitor.exe
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\UTIL\GadWin\PrintScreen.exe
C:\UTIL\RocketDock\RocketDock.exe
C:\Program Files\Windows Sidebar\sidebar.exe
D:\Logiciels Divers\CircleDock0.9.2Alpha8.1\CircleDock.exe
C:\Program Files\Pense-bete\pb79f.exe
C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe
C:\Windows\Explorer.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10c.exe
C:\Program Files\Windows Live\Toolbar\wltuser.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
C:\Windows\system32\cmd.exe
C:\Windows\system32\conhost.exe
C:\GenProc\outil\Robert_GenProc.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.asus.com/fr/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.bing.com/?toHttps=1&redig=F6E03C3CC058415AA40F1BC2D47E2332
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.asus.com/fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - D:\Logiciels Divers\Snagit\SnagItBHO.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\UTIL\SPYBOT~1\SDHelper.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - D:\Logiciels Divers\Snagit\SnagItIEAddin.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [OODefragTray] C:\Windows\system32\oodtray.exe
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\UTIL\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [Corel File Shell Monitor] D:\Logiciels Divers\Paint shop pro 12\CorelIOMonitor.exe
O4 - HKLM\..\Run: [avgnt] "C:\UTIL\Antivirus\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [ASUS Screen Saver Protector] C:\Windows\ASScrPro.exe
O4 - HKLM\..\Run: [ASUS Camera ScreenSaver] C:\Windows\ASScrProlog.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] D:\Logiciels Divers\Acronis\TimounterMonitor.exe
O4 - HKLM\..\Run: [TrueImageMonitor.exe] D:\Logiciels Divers\Acronis\TrueImageMonitor.exe
O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
O4 - HKCU\..\Run: [Gadwin PrintScreen] "C:\UTIL\GadWin\PrintScreen.exe" /nosplash
O4 - HKCU\..\Run: [RocketDock] "C:\UTIL\RocketDock\RocketDock.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - Startup: CircleDock.exe.lnk = D:\Logiciels Divers\CircleDock0.9.2Alpha8.1\CircleDock.exe
O4 - Startup: Pense-Bête 79f.lnk = C:\Program Files\Pense-bete\pb79f.exe
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {400A6CFA-E326-4d61-A90C-9AD75358DC5F} - (no file)
O9 - Extra 'Tools' menuitem: Email ID Préférences - {400A6CFA-E326-4d61-A90C-9AD75358DC5F} - (no file)
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MIF5BA~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {BC3F6B6D-2E49-4603-B028-7411655713F3} - (no file)
O9 - Extra 'Tools' menuitem: À propos de Email ID - {BC3F6B6D-2E49-4603-B028-7411655713F3} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\UTIL\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\UTIL\SPYBOT~1\SDHelper.dll
O9 - Extra button: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra 'Tools' menuitem: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra button: Correcteur - {F7C8E5F6-B6D1-45db-8D91-2BCFA5DF11A9} - D:\Logiciels Divers\Antidote 2008\Internet Explorer\7\Antidote K - IE 7.htm (HKCU)
O9 - Extra button: Dictionnaires - {F9B969E8-58D0-4dd9-AC8A-EE2336FF8F65} - D:\Logiciels Divers\Antidote 2008\Internet Explorer\7\Antidote D - IE 7.htm (HKCU)
O9 - Extra button: Guides - {FA089E36-3F1B-4c51-9A1A-C4E7012483AF} - D:\Logiciels Divers\Antidote 2008\Internet Explorer\7\Antidote G - IE 7.htm (HKCU)
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O13 - Gopher Prefix:
O15 - Trusted Zone: http://www.secuser.com
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} (System Requirements Lab) - https://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.5.1.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...
O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} - http://www.gamespy.com
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - http://www.ma-config.com/activex/hardwaredetection_3_1_2_0.cab
O16 - DPF: {B79A53C0-1DAC-4636-BACE-FD086A7A79BF} (AdSignerLCContrl Class) - https://static.impots.gouv.fr/tdir/static/adpform/AdSignerADP-2.0.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
O23 - Service: Acronis OS Selector Reinstall Service (AcronisOSSReinstallSvc) - Unknown owner - C:\Program Files\Common Files\Acronis\Acronis Disk Director\oss_reinstall_svc.exe
O23 - Service: Service Scheduler2 Acronis (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: ADSM Service (ADSMService) - Unknown owner - C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe
O23 - Service: Acronis Nonstop Backup service (afcdpsrv) - Acronis - C:\Program Files\Common Files\Acronis\CDP\afcdpsrv.exe
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: Avira AntiVir MailGuard (AntiVirMailService) - Avira GmbH - C:\UTIL\Antivirus\Avira\AntiVir Desktop\avmailc.exe
O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\UTIL\Antivirus\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\UTIL\Antivirus\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Avira AntiVir WebGuard (AntiVirWebService) - Avira GmbH - C:\UTIL\Antivirus\Avira\AntiVir Desktop\AVWEBGRD.EXE
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files\ATK Hotkey\ASLDRSrv.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - Unknown owner - C:\Program Files\ATKGFNEX\GFNEXSrv.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Update Service (gupdate1c95c85dab44e17) (gupdate1c95c85dab44e17) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: Iconix Update Service (IconixService) - Unknown owner - C:\Program Files\Common Files\Iconix\IconixService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\UTIL\Ma configue\maconfservice.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\UTIL\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: O&O Defrag - O&O Software GmbH - C:\Windows\system32\oodag.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\Windows\system32\PSIService.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\UTIL\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: Seagate Scheduler2 Service (SgtSch2Svc) - Unknown owner - C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe (file missing)
O23 - Service: spmgr - Unknown owner - C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
O23 - Service: TabletServicePen - Wacom Technology, Corp. - C:\Windows\system32\Pen_Tablet.exe
O23 - Service: TomTomHOMEService - TomTom - D:\Logiciels Divers\TomTom HOME 2\TomTomHOMEService.exe
O23 - Service: Acronis Try And Decide Service (TryAndDecideService) - Unknown owner - C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe (file missing)
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\Windows\System32\TuneUpDefragService.exe
O23 - Service: TuneUp Program Statistics Service (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\Windows\System32\TUProgSt.exe
-
@cachou52frbonjour,
le probleme est toujours présent a l'ouverture d'internet explorer
-
-
ContributeurDans une fenêtre de commande écris cette instruction et poste le résultat
dir C:\Windows\System32\ovfst*.???
-
-
-
Microsoft Windows [version 6.1.7100]
Copyright (c) 2009 Microsoft Corporation. Tous droits réservés.
C:\Users\Robert>dir C:\Windows\system32\ovfst*.???
Le volume dans le lecteur C s'appelle VistaOS
Le numéro de série du volume est DC80-476F
Répertoire de C:\Windows\system32
Fichier introuvable
C:\Users\Robert>
-
-
Contributeur---> Télécharge Gmer http://www2.gmer.net/gmer.zip sur ton Bureau.
---> Extrais le contenu de l'archive puis renomme gmer.exe en tib.exe (Le .exe n'est pas forcément visible).
sur ton burreau
---> Double-clique sur tib.exe.
---> si tu as un message warning
comme celui la
http://www.genproc.com/gmer.JPG
clique non puis save, et enregistre sur ton Bureau "gmer.txt".
---> Double-clique sur "gmer.txt", le rapport apparaît, poste-le.-
GMER 1.0.15.15125 - http://www.gmer.net
Rootkit quick scan 2009-10-13 18:34:48
Windows 6.1.7100
Running: tib.exe; Driver: C:\Users\Robert\AppData\Local\Temp\pwldrpow.sys
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Ntfs \Ntfs AsDsm.sys (Data Security Manager Driver/Windows (R) Codename Longhorn DDK provider)
AttachedDevice \FileSystem\Ntfs \Ntfs tdrpm251.sys (Acronis Try&Decide Volume Filter Driver/Acronis)
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Gestionnaire de filtres de système de fichiers Microsoft/Microsoft Corporation)
AttachedDevice \FileSystem\fastfat \Fat tdrpm251.sys (Acronis Try&Decide Volume Filter Driver/Acronis)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (Runtime de l’infrastructure de pilotes en mode noyau/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (Runtime de l’infrastructure de pilotes en mode noyau/Microsoft Corporation)
---- EOF - GMER 1.0.15 ----
-
-
SysProt AntiRootkit v1.0.1.0
by swatkat
******************************************************************************************
******************************************************************************************
No Hidden Processes found
******************************************************************************************
******************************************************************************************
No Hidden Kernel Modules found
******************************************************************************************
******************************************************************************************
No SSDT Hooks found
******************************************************************************************
******************************************************************************************
No Kernel Hooks found
******************************************************************************************
******************************************************************************************
No IRP Hooks found
******************************************************************************************
******************************************************************************************
Ports:
Local Address: ROBERT:49795
Remote Address: SPYNET2.MICROSOFT.COM:HTTPS
Type: TCP
Process: 6856 (PID)
State: ESTABLISHED
Local Address: ROBERT:49792
Remote Address: WWW-GOOGLE-ANALYTICS.L.GOOGLE.COM:HTTP
Type: TCP
Process: 4356 (PID)
State: ESTABLISHED
Local Address: ROBERT:49786
Remote Address: 81.52.140.16:HTTP
Type: TCP
Process: 4356 (PID)
State: ESTABLISHED
Local Address: ROBERT:49785
Remote Address: 81.52.140.16:HTTP
Type: TCP
Process: 4356 (PID)
State: ESTABLISHED
Local Address: ROBERT:49778
Remote Address: 81.52.140.16:HTTP
Type: TCP
Process: 4356 (PID)
State: ESTABLISHED
Local Address: ROBERT:49770
Remote Address: A350.G.AKAMAI.NET:HTTP
Type: TCP
Process: 4356 (PID)
State: ESTABLISHED
Local Address: ROBERT:49764
Remote Address: PAGEAD.L.GOOGLE.COM:HTTP
Type: TCP
Process: 4356 (PID)
State: ESTABLISHED
Local Address: ROBERT:49762
Remote Address: PAGEAD.L.GOOGLE.COM:HTTP
Type: TCP
Process: 4356 (PID)
State: ESTABLISHED
Local Address: ROBERT:49761
Remote Address: PAGEAD.L.GOOGLE.COM:HTTP
Type: TCP
Process: 4356 (PID)
State: ESTABLISHED
Local Address: ROBERT:49756
Remote Address: A2.X.AKAMAI.NET:HTTP
Type: TCP
Process: 4356 (PID)
State: ESTABLISHED
Local Address: ROBERT:49754
Remote Address: A2.X.AKAMAI.NET:HTTP
Type: TCP
Process: 4356 (PID)
State: ESTABLISHED
Local Address: ROBERT:49753
Remote Address: A2.X.AKAMAI.NET:HTTP
Type: TCP
Process: 4356 (PID)
State: ESTABLISHED
Local Address: ROBERT:49744
Remote Address: A1727.B.AKAMAI.NET:HTTP
Type: TCP
Process: 4356 (PID)
State: ESTABLISHED
Local Address: ROBERT:49738
Remote Address: WWW.ABCOMPTEUR.COM:HTTP
Type: TCP
Process: 0 (PID)
State: TIME_WAIT
Local Address: ROBERT:49717
Remote Address: A4.BING.COM:HTTP
Type: TCP
Process: 4356 (PID)
State: ESTABLISHED
Local Address: ROBERT:49690
Remote Address: C.ATDMT.COM.NSATC.NET:HTTP
Type: TCP
Process: 4356 (PID)
State: ESTABLISHED
Local Address: ROBERT:49686
Remote Address: PAGEAD.L.DOUBLECLICK.NET:HTTP
Type: TCP
Process: 4356 (PID)
State: ESTABLISHED
Local Address: ROBERT:49685
Remote Address: PAGEAD.L.GOOGLE.COM:HTTP
Type: TCP
Process: 4356 (PID)
State: ESTABLISHED
Local Address: ROBERT:49682
Remote Address: C.LIVE.COM.NSATC.NET:HTTP
Type: TCP
Process: 4356 (PID)
State: ESTABLISHED
Local Address: ROBERT:49660
Remote Address: WWW.BING.COM:HTTP
Type: TCP
Process: 4356 (PID)
State: ESTABLISHED
Local Address: ROBERT:49658
Remote Address: PAGEAD.L.GOOGLE.COM:HTTP
Type: TCP
Process: 4356 (PID)
State: ESTABLISHED
Local Address: ROBERT:49646
Remote Address: WWW.BING.COM:HTTP
Type: TCP
Process: 0 (PID)
State: TIME_WAIT
Local Address: ROBERT:49640
Remote Address: WWW.BING.COM:HTTP
Type: TCP
Process: 4356 (PID)
State: ESTABLISHED
Local Address: ROBERT:NETBIOS-SSN
Remote Address: 0.0.0.0:0
Type: TCP
Process: 4 (PID)
State: LISTENING
Local Address: ROBERT:50300
Remote Address: LOCALHOST:49157
Type: TCP
Process: 3148 (PID)
State: ESTABLISHED
Local Address: ROBERT:49791
Remote Address: LOCALHOST:44080
Type: TCP
Process: 6648 (PID)
State: ESTABLISHED
Local Address: ROBERT:49782
Remote Address: LOCALHOST:44080
Type: TCP
Process: 6648 (PID)
State: ESTABLISHED
Local Address: ROBERT:49781
Remote Address: LOCALHOST:44080
Type: TCP
Process: 6648 (PID)
State: ESTABLISHED
Local Address: ROBERT:49780
Remote Address: LOCALHOST:44080
Type: TCP
Process: 6648 (PID)
State: CLOSE_WAIT
Local Address: ROBERT:49779
Remote Address: LOCALHOST:44080
Type: TCP
Process: 6648 (PID)
State: CLOSE_WAIT
Local Address: ROBERT:49776
Remote Address: LOCALHOST:44080
Type: TCP
Process: 6648 (PID)
State: ESTABLISHED
Local Address: ROBERT:49769
Remote Address: LOCALHOST:44080
Type: TCP
Process: 6648 (PID)
State: ESTABLISHED
Local Address: ROBERT:49763
Remote Address: LOCALHOST:44080
Type: TCP
Process: 6648 (PID)
State: ESTABLISHED
Local Address: ROBERT:49760
Remote Address: LOCALHOST:44080
Type: TCP
Process: 6648 (PID)
State: ESTABLISHED
Local Address: ROBERT:49759
Remote Address: LOCALHOST:44080
Type: TCP
Process: 6648 (PID)
State: ESTABLISHED
Local Address: ROBERT:49755
Remote Address: LOCALHOST:44080
Type: TCP
Process: 6648 (PID)
State: ESTABLISHED
Local Address: ROBERT:49752
Remote Address: LOCALHOST:44080
Type: TCP
Process: 6648 (PID)
State: ESTABLISHED
Local Address: ROBERT:49751
Remote Address: LOCALHOST:44080
Type: TCP
Process: 6648 (PID)
State: ESTABLISHED
Local Address: ROBERT:49743
Remote Address: LOCALHOST:44080
Type: TCP
Process: 6648 (PID)
State: ESTABLISHED
Local Address: ROBERT:49715
Remote Address: LOCALHOST:44080
Type: TCP
Process: 6648 (PID)
State: ESTABLISHED
Local Address: ROBERT:49689
Remote Address: LOCALHOST:44080
Type: TCP
Process: 6648 (PID)
State: ESTABLISHED
Local Address: ROBERT:49684
Remote Address: LOCALHOST:44080
Type: TCP
Process: 6648 (PID)
State: ESTABLISHED
Local Address: ROBERT:49683
Remote Address: LOCALHOST:44080
Type: TCP
Process: 6648 (PID)
State: ESTABLISHED
Local Address: ROBERT:49681
Remote Address: LOCALHOST:44080
Type: TCP
Process: 6648 (PID)
State: ESTABLISHED
Local Address: ROBERT:49672
Remote Address: LOCALHOST:44080
Type: TCP
Process: 6648 (PID)
State: CLOSE_WAIT
Local Address: ROBERT:49661
Remote Address: LOCALHOST:44080
Type: TCP
Process: 6648 (PID)
State: CLOSE_WAIT
Local Address: ROBERT:49659
Remote Address: LOCALHOST:44080
Type: TCP
Process: 6648 (PID)
State: ESTABLISHED
Local Address: ROBERT:49656
Remote Address: LOCALHOST:44080
Type: TCP
Process: 6648 (PID)
State: ESTABLISHED
Local Address: ROBERT:49639
Remote Address: LOCALHOST:44080
Type: TCP
Process: 6648 (PID)
State: ESTABLISHED
Local Address: ROBERT:49157
Remote Address: LOCALHOST:50300
Type: TCP
Process: 3048 (PID)
State: ESTABLISHED
Local Address: ROBERT:44080
Remote Address: LOCALHOST:49793
Type: TCP
Process: 0 (PID)
State: TIME_WAIT
Local Address: ROBERT:44080
Remote Address: LOCALHOST:49791
Type: TCP
Process: 4356 (PID)
State: ESTABLISHED
Local Address: ROBERT:44080
Remote Address: LOCALHOST:49787
Type: TCP
Process: 0 (PID)
State: TIME_WAIT
Local Address: ROBERT:44080
Remote Address: LOCALHOST:49782
Type: TCP
Process: 4356 (PID)
State: ESTABLISHED
Local Address: ROBERT:44080
Remote Address: LOCALHOST:49781
Type: TCP
Process: 4356 (PID)
State: ESTABLISHED
Local Address: ROBERT:44080
Remote Address: LOCALHOST:49780
Type: TCP
Process: 4356 (PID)
State: FIN_WAIT2
Local Address: ROBERT:44080
Remote Address: LOCALHOST:49779
Type: TCP
Process: 4356 (PID)
State: FIN_WAIT2
Local Address: ROBERT:44080
Remote Address: LOCALHOST:49776
Type: TCP
Process: 4356 (PID)
State: ESTABLISHED
Local Address: ROBERT:44080
Remote Address: LOCALHOST:49775
Type: TCP
Process: 0 (PID)
State: TIME_WAIT
Local Address: ROBERT:44080
Remote Address: LOCALHOST:49773
Type: TCP
Process: 0 (PID)
State: TIME_WAIT
Local Address: ROBERT:44080
Remote Address: LOCALHOST:49771
Type: TCP
Process: 0 (PID)
State: TIME_WAIT
Local Address: ROBERT:44080
Remote Address: LOCALHOST:49769
Type: TCP
Process: 4356 (PID)
State: ESTABLISHED
Local Address: ROBERT:44080
Remote Address: LOCALHOST:49767
Type: TCP
Process: 0 (PID)
State: TIME_WAIT
Local Address: ROBERT:44080
Remote Address: LOCALHOST:49765
Type: TCP
Process: 0 (PID)
State: TIME_WAIT
Local Address: ROBERT:44080
Remote Address: LOCALHOST:49763
Type: TCP
Process: 4356 (PID)
State: ESTABLISHED
Local Address: ROBERT:44080
Remote Address: LOCALHOST:49760
Type: TCP
Process: 4356 (PID)
State: ESTABLISHED
Local Address: ROBERT:44080
Remote Address: LOCALHOST:49759
Type: TCP
Process: 4356 (PID)
State: ESTABLISHED
Local Address: ROBERT:44080
Remote Address: LOCALHOST:49757
Type: TCP
Process: 0 (PID)
State: TIME_WAIT
Local Address: ROBERT:44080
Remote Address: LOCALHOST:49755
Type: TCP
Process: 4356 (PID)
State: ESTABLISHED
Local Address: ROBERT:44080
Remote Address: LOCALHOST:49752
Type: TCP
Process: 4356 (PID)
State: ESTABLISHED
Local Address: ROBERT:44080
Remote Address: LOCALHOST:49751
Type: TCP
Process: 4356 (PID)
State: ESTABLISHED
Local Address: ROBERT:44080
Remote Address: LOCALHOST:49747
Type: TCP
Process: 0 (PID)
State: TIME_WAIT
Local Address: ROBERT:44080
Remote Address: LOCALHOST:49743
Type: TCP
Process: 4356 (PID)
State: ESTABLISHED
Local Address: ROBERT:44080
Remote Address: LOCALHOST:49715
Type: TCP
Process: 4356 (PID)
State: ESTABLISHED
Local Address: ROBERT:44080
Remote Address: LOCALHOST:49689
Type: TCP
Process: 4356 (PID)
State: ESTABLISHED
Local Address: ROBERT:44080
Remote Address: LOCALHOST:49684
Type: TCP
Process: 4356 (PID)
State: ESTABLISHED
Local Address: ROBERT:44080
Remote Address: LOCALHOST:49683
Type: TCP
Process: 4356 (PID)
State: ESTABLISHED
Local Address: ROBERT:44080
Remote Address: LOCALHOST:49681
Type: TCP
Process: 4356 (PID)
State: ESTABLISHED
Local Address: ROBERT:44080
Remote Address: LOCALHOST:49672
Type: TCP
Process: 4356 (PID)
State: FIN_WAIT2
Local Address: ROBERT:44080
Remote Address: LOCALHOST:49661
Type: TCP
Process: 4356 (PID)
State: FIN_WAIT2
Local Address: ROBERT:44080
Remote Address: LOCALHOST:49659
Type: TCP
Process: 4356 (PID)
State: ESTABLISHED
Local Address: ROBERT:44080
Remote Address: LOCALHOST:49656
Type: TCP
Process: 4356 (PID)
State: ESTABLISHED
Local Address: ROBERT:44080
Remote Address: LOCALHOST:49639
Type: TCP
Process: 4356 (PID)
State: ESTABLISHED
Local Address: ROBERT:27015
Remote Address: 0.0.0.0:0
Type: TCP
Process: 2424 (PID)
State: LISTENING
Local Address: ROBERT:50300
Remote Address: 0.0.0.0:0
Type: TCP
Process: 3148 (PID)
State: LISTENING
Local Address: ROBERT:49161
Remote Address: 0.0.0.0:0
Type: TCP
Process: 4656 (PID)
State: LISTENING
Local Address: ROBERT:49158
Remote Address: 0.0.0.0:0
Type: TCP
Process: 844 (PID)
State: LISTENING
Local Address: ROBERT:49156
Remote Address: 0.0.0.0:0
Type: TCP
Process: 876 (PID)
State: LISTENING
Local Address: ROBERT:49155
Remote Address: 0.0.0.0:0
Type: TCP
Process: 668 (PID)
State: LISTENING
Local Address: ROBERT:49154
Remote Address: 0.0.0.0:0
Type: TCP
Process: 1436 (PID)
State: LISTENING
Local Address: ROBERT:49153
Remote Address: 0.0.0.0:0
Type: TCP
Process: 1264 (PID)
State: LISTENING
Local Address: ROBERT:49152
Remote Address: 0.0.0.0:0
Type: TCP
Process: 792 (PID)
State: LISTENING
Local Address: ROBERT:44110
Remote Address: 0.0.0.0:0
Type: TCP
Process: 3884 (PID)
State: LISTENING
Local Address: ROBERT:44080
Remote Address: 0.0.0.0:0
Type: TCP
Process: 4356 (PID)
State: LISTENING
Local Address: ROBERT:WSD
Remote Address: 0.0.0.0:0
Type: TCP
Process: 4 (PID)
State: LISTENING
Local Address: ROBERT:MS-WBT-SERVER
Remote Address: 0.0.0.0:0
Type: TCP
Process: 1660 (PID)
State: LISTENING
Local Address: ROBERT:MICROSOFT-DS
Remote Address: 0.0.0.0:0
Type: TCP
Process: 4 (PID)
State: LISTENING
Local Address: ROBERT:EPMAP
Remote Address: 0.0.0.0:0
Type: TCP
Process: 1136 (PID)
State: LISTENING
Local Address: ROBERT:64891
Remote Address: NA
Type: UDP
Process: 2644 (PID)
State: NA
Local Address: ROBERT:SSDP
Remote Address: NA
Type: UDP
Process: 2644 (PID)
State: NA
Local Address: ROBERT:138
Remote Address: NA
Type: UDP
Process: 4 (PID)
State: NA
Local Address: ROBERT:NETBIOS-NS
Remote Address: NA
Type: UDP
Process: 4 (PID)
State: NA
Local Address: ROBERT:64892
Remote Address: NA
Type: UDP
Process: 2644 (PID)
State: NA
Local Address: ROBERT:63032
Remote Address: NA
Type: UDP
Process: 6648 (PID)
State: NA
Local Address: ROBERT:61248
Remote Address: NA
Type: UDP
Process: 7408 (PID)
State: NA
Local Address: ROBERT:50957
Remote Address: NA
Type: UDP
Process: 4304 (PID)
State: NA
Local Address: ROBERT:SSDP
Remote Address: NA
Type: UDP
Process: 2644 (PID)
State: NA
Local Address: ROBERT:50955
Remote Address: NA
Type: UDP
Process: 1568 (PID)
State: NA
Local Address: ROBERT:49152
Remote Address: NA
Type: UDP
Process: 2644 (PID)
State: NA
Local Address: ROBERT:LLMNR
Remote Address: NA
Type: UDP
Process: 1660 (PID)
State: NA
Local Address: ROBERT:IPSEC-MSFT
Remote Address: NA
Type: UDP
Process: 1436 (PID)
State: NA
Local Address: ROBERT:WS-DISCOVERY
Remote Address: NA
Type: UDP
Process: 2644 (PID)
State: NA
Local Address: ROBERT:WS-DISCOVERY
Remote Address: NA
Type: UDP
Process: 1568 (PID)
State: NA
Local Address: ROBERT:WS-DISCOVERY
Remote Address: NA
Type: UDP
Process: 1568 (PID)
State: NA
Local Address: ROBERT:WS-DISCOVERY
Remote Address: NA
Type: UDP
Process: 2644 (PID)
State: NA
Local Address: ROBERT:500
Remote Address: NA
Type: UDP
Process: 1436 (PID)
State: NA
******************************************************************************************
******************************************************************************************
No hidden files/folders found -
SysProt AntiRootkit v1.0.1.0
by swatkat
******************************************************************************************
******************************************************************************************
No Hidden Processes found
******************************************************************************************
******************************************************************************************
No Hidden Kernel Modules found
******************************************************************************************
******************************************************************************************
No SSDT Hooks found
******************************************************************************************
******************************************************************************************
No Kernel Hooks found
******************************************************************************************
******************************************************************************************
No IRP Hooks found
******************************************************************************************
******************************************************************************************
Ports:
Local Address: ROBERT:49795
Remote Address: SPYNET2.MICROSOFT.COM:HTTPS
Type: TCP
Process: 6856 (PID)
State: ESTABLISHED
Local Address: ROBERT:49792
Remote Address: WWW-GOOGLE-ANALYTICS.L.GOOGLE.COM:HTTP
Type: TCP
Process: 4356 (PID)
State: ESTABLISHED
Local Address: ROBERT:49786
Remote Address: 81.52.140.16:HTTP
Type: TCP
Process: 4356 (PID)
State: ESTABLISHED
Local Address: ROBERT:49785
Remote Address: 81.52.140.16:HTTP
Type: TCP
Process: 4356 (PID)
State: ESTABLISHED
Local Address: ROBERT:49778
Remote Address: 81.52.140.16:HTTP
Type: TCP
Process: 4356 (PID)
State: ESTABLISHED
Local Address: ROBERT:49770
Remote Address: A350.G.AKAMAI.NET:HTTP
Type: TCP
Process: 4356 (PID)
State: ESTABLISHED
Local Address: ROBERT:49764
Remote Address: PAGEAD.L.GOOGLE.COM:HTTP
Type: TCP
Process: 4356 (PID)
State: ESTABLISHED
Local Address: ROBERT:49762
Remote Address: PAGEAD.L.GOOGLE.COM:HTTP
Type: TCP
Process: 4356 (PID)
State: ESTABLISHED
Local Address: ROBERT:49761
Remote Address: PAGEAD.L.GOOGLE.COM:HTTP
Type: TCP
Process: 4356 (PID)
State: ESTABLISHED
Local Address: ROBERT:49756
Remote Address: A2.X.AKAMAI.NET:HTTP
Type: TCP
Process: 4356 (PID)
State: ESTABLISHED
Local Address: ROBERT:49754
Remote Address: A2.X.AKAMAI.NET:HTTP
Type: TCP
Process: 4356 (PID)
State: ESTABLISHED
Local Address: ROBERT:49753
Remote Address: A2.X.AKAMAI.NET:HTTP
Type: TCP
Process: 4356 (PID)
State: ESTABLISHED
Local Address: ROBERT:49744
Remote Address: A1727.B.AKAMAI.NET:HTTP
Type: TCP
Process: 4356 (PID)
State: ESTABLISHED
Local Address: ROBERT:49738
Remote Address: WWW.ABCOMPTEUR.COM:HTTP
Type: TCP
Process: 0 (PID)
State: TIME_WAIT
Local Address: ROBERT:49717
Remote Address: A4.BING.COM:HTTP
Type: TCP
Process: 4356 (PID)
State: ESTABLISHED
Local Address: ROBERT:49690
Remote Address: C.ATDMT.COM.NSATC.NET:HTTP
Type: TCP
Process: 4356 (PID)
State: ESTABLISHED
Local Address: ROBERT:49686
Remote Address: PAGEAD.L.DOUBLECLICK.NET:HTTP
Type: TCP
Process: 4356 (PID)
State: ESTABLISHED
Local Address: ROBERT:49685
Remote Address: PAGEAD.L.GOOGLE.COM:HTTP
Type: TCP
Process: 4356 (PID)
State: ESTABLISHED
Local Address: ROBERT:49682
Remote Address: C.LIVE.COM.NSATC.NET:HTTP
Type: TCP
Process: 4356 (PID)
State: ESTABLISHED
Local Address: ROBERT:49660
Remote Address: WWW.BING.COM:HTTP
Type: TCP
Process: 4356 (PID)
State: ESTABLISHED
Local Address: ROBERT:49658
Remote Address: PAGEAD.L.GOOGLE.COM:HTTP
Type: TCP
Process: 4356 (PID)
State: ESTABLISHED
Local Address: ROBERT:49646
Remote Address: WWW.BING.COM:HTTP
Type: TCP
Process: 0 (PID)
State: TIME_WAIT
Local Address: ROBERT:49640
Remote Address: WWW.BING.COM:HTTP
Type: TCP
Process: 4356 (PID)
State: ESTABLISHED
Local Address: ROBERT:NETBIOS-SSN
Remote Address: 0.0.0.0:0
Type: TCP
Process: 4 (PID)
State: LISTENING
Local Address: ROBERT:50300
Remote Address: LOCALHOST:49157
Type: TCP
Process: 3148 (PID)
State: ESTABLISHED
Local Address: ROBERT:49791
Remote Address: LOCALHOST:44080
Type: TCP
Process: 6648 (PID)
State: ESTABLISHED
Local Address: ROBERT:49782
Remote Address: LOCALHOST:44080
Type: TCP
Process: 6648 (PID)
State: ESTABLISHED
Local Address: ROBERT:49781
Remote Address: LOCALHOST:44080
Type: TCP
Process: 6648 (PID)
State: ESTABLISHED
Local Address: ROBERT:49780
Remote Address: LOCALHOST:44080
Type: TCP
Process: 6648 (PID)
State: CLOSE_WAIT
Local Address: ROBERT:49779
Remote Address: LOCALHOST:44080
Type: TCP
Process: 6648 (PID)
State: CLOSE_WAIT
Local Address: ROBERT:49776
Remote Address: LOCALHOST:44080
Type: TCP
Process: 6648 (PID)
State: ESTABLISHED
Local Address: ROBERT:49769
Remote Address: LOCALHOST:44080
Type: TCP
Process: 6648 (PID)
State: ESTABLISHED
Local Address: ROBERT:49763
Remote Address: LOCALHOST:44080
Type: TCP
Process: 6648 (PID)
State: ESTABLISHED
Local Address: ROBERT:49760
Remote Address: LOCALHOST:44080
Type: TCP
Process: 6648 (PID)
State: ESTABLISHED
Local Address: ROBERT:49759
Remote Address: LOCALHOST:44080
Type: TCP
Process: 6648 (PID)
State: ESTABLISHED
Local Address: ROBERT:49755
Remote Address: LOCALHOST:44080
Type: TCP
Process: 6648 (PID)
State: ESTABLISHED
Local Address: ROBERT:49752
Remote Address: LOCALHOST:44080
Type: TCP
Process: 6648 (PID)
State: ESTABLISHED
Local Address: ROBERT:49751
Remote Address: LOCALHOST:44080
Type: TCP
Process: 6648 (PID)
State: ESTABLISHED
Local Address: ROBERT:49743
Remote Address: LOCALHOST:44080
Type: TCP
Process: 6648 (PID)
State: ESTABLISHED
Local Address: ROBERT:49715
Remote Address: LOCALHOST:44080
Type: TCP
Process: 6648 (PID)
State: ESTABLISHED
Local Address: ROBERT:49689
Remote Address: LOCALHOST:44080
Type: TCP
Process: 6648 (PID)
State: ESTABLISHED
Local Address: ROBERT:49684
Remote Address: LOCALHOST:44080
Type: TCP
Process: 6648 (PID)
State: ESTABLISHED
Local Address: ROBERT:49683
Remote Address: LOCALHOST:44080
Type: TCP
Process: 6648 (PID)
State: ESTABLISHED
Local Address: ROBERT:49681
Remote Address: LOCALHOST:44080
Type: TCP
Process: 6648 (PID)
State: ESTABLISHED
Local Address: ROBERT:49672
Remote Address: LOCALHOST:44080
Type: TCP
Process: 6648 (PID)
State: CLOSE_WAIT
Local Address: ROBERT:49661
Remote Address: LOCALHOST:44080
Type: TCP
Process: 6648 (PID)
State: CLOSE_WAIT
Local Address: ROBERT:49659
Remote Address: LOCALHOST:44080
Type: TCP
Process: 6648 (PID)
State: ESTABLISHED
Local Address: ROBERT:49656
Remote Address: LOCALHOST:44080
Type: TCP
Process: 6648 (PID)
State: ESTABLISHED
Local Address: ROBERT:49639
Remote Address: LOCALHOST:44080
Type: TCP
Process: 6648 (PID)
State: ESTABLISHED
Local Address: ROBERT:49157
Remote Address: LOCALHOST:50300
Type: TCP
Process: 3048 (PID)
State: ESTABLISHED
Local Address: ROBERT:44080
Remote Address: LOCALHOST:49793
Type: TCP
Process: 0 (PID)
State: TIME_WAIT
Local Address: ROBERT:44080
Remote Address: LOCALHOST:49791
Type: TCP
Process: 4356 (PID)
State: ESTABLISHED
Local Address: ROBERT:44080
Remote Address: LOCALHOST:49787
Type: TCP
Process: 0 (PID)
State: TIME_WAIT
Local Address: ROBERT:44080
Remote Address: LOCALHOST:49782
Type: TCP
Process: 4356 (PID)
State: ESTABLISHED
Local Address: ROBERT:44080
Remote Address: LOCALHOST:49781
Type: TCP
Process: 4356 (PID)
State: ESTABLISHED
Local Address: ROBERT:44080
Remote Address: LOCALHOST:49780
Type: TCP
Process: 4356 (PID)
State: FIN_WAIT2
Local Address: ROBERT:44080
Remote Address: LOCALHOST:49779
Type: TCP
Process: 4356 (PID)
State: FIN_WAIT2
Local Address: ROBERT:44080
Remote Address: LOCALHOST:49776
Type: TCP
Process: 4356 (PID)
State: ESTABLISHED
Local Address: ROBERT:44080
Remote Address: LOCALHOST:49775
Type: TCP
Process: 0 (PID)
State: TIME_WAIT
Local Address: ROBERT:44080
Remote Address: LOCALHOST:49773
Type: TCP
Process: 0 (PID)
State: TIME_WAIT
Local Address: ROBERT:44080
Remote Address: LOCALHOST:49771
Type: TCP
Process: 0 (PID)
State: TIME_WAIT
Local Address: ROBERT:44080
Remote Address: LOCALHOST:49769
Type: TCP
Process: 4356 (PID)
State: ESTABLISHED
Local Address: ROBERT:44080
Remote Address: LOCALHOST:49767
Type: TCP
Process: 0 (PID)
State: TIME_WAIT
Local Address: ROBERT:44080
Remote Address: LOCALHOST:49765
Type: TCP
Process: 0 (PID)
State: TIME_WAIT
Local Address: ROBERT:44080
Remote Address: LOCALHOST:49763
Type: TCP
Process: 4356 (PID)
State: ESTABLISHED
Local Address: ROBERT:44080
Remote Address: LOCALHOST:49760
Type: TCP
Process: 4356 (PID)
State: ESTABLISHED
Local Address: ROBERT:44080
Remote Address: LOCALHOST:49759
Type: TCP
Process: 4356 (PID)
State: ESTABLISHED
Local Address: ROBERT:44080
Remote Address: LOCALHOST:49757
Type: TCP
Process: 0 (PID)
State: TIME_WAIT
Local Address: ROBERT:44080
Remote Address: LOCALHOST:49755
Type: TCP
Process: 4356 (PID)
State: ESTABLISHED
Local Address: ROBERT:44080
Remote Address: LOCALHOST:49752
Type: TCP
Process: 4356 (PID)
State: ESTABLISHED
Local Address: ROBERT:44080
Remote Address: LOCALHOST:49751
Type: TCP
Process: 4356 (PID)
State: ESTABLISHED
Local Address: ROBERT:44080
Remote Address: LOCALHOST:49747
Type: TCP
Process: 0 (PID)
State: TIME_WAIT
Local Address: ROBERT:44080
Remote Address: LOCALHOST:49743
Type: TCP
Process: 4356 (PID)
State: ESTABLISHED
Local Address: ROBERT:44080
Remote Address: LOCALHOST:49715
Type: TCP
Process: 4356 (PID)
State: ESTABLISHED
Local Address: ROBERT:44080
Remote Address: LOCALHOST:49689
Type: TCP
Process: 4356 (PID)
State: ESTABLISHED
Local Address: ROBERT:44080
Remote Address: LOCALHOST:49684
Type: TCP
Process: 4356 (PID)
State: ESTABLISHED
Local Address: ROBERT:44080
Remote Address: LOCALHOST:49683
Type: TCP
Process: 4356 (PID)
State: ESTABLISHED
Local Address: ROBERT:44080
Remote Address: LOCALHOST:49681
Type: TCP
Process: 4356 (PID)
State: ESTABLISHED
Local Address: ROBERT:44080
Remote Address: LOCALHOST:49672
Type: TCP
Process: 4356 (PID)
State: FIN_WAIT2
Local Address: ROBERT:44080
Remote Address: LOCALHOST:49661
Type: TCP
Process: 4356 (PID)
State: FIN_WAIT2
Local Address: ROBERT:44080
Remote Address: LOCALHOST:49659
Type: TCP
Process: 4356 (PID)
State: ESTABLISHED
Local Address: ROBERT:44080
Remote Address: LOCALHOST:49656
Type: TCP
Process: 4356 (PID)
State: ESTABLISHED
Local Address: ROBERT:44080
Remote Address: LOCALHOST:49639
Type: TCP
Process: 4356 (PID)
State: ESTABLISHED
Local Address: ROBERT:27015
Remote Address: 0.0.0.0:0
Type: TCP
Process: 2424 (PID)
State: LISTENING
Local Address: ROBERT:50300
Remote Address: 0.0.0.0:0
Type: TCP
Process: 3148 (PID)
State: LISTENING
Local Address: ROBERT:49161
Remote Address: 0.0.0.0:0
Type: TCP
Process: 4656 (PID)
State: LISTENING
Local Address: ROBERT:49158
Remote Address: 0.0.0.0:0
Type: TCP
Process: 844 (PID)
State: LISTENING
Local Address: ROBERT:49156
Remote Address: 0.0.0.0:0
Type: TCP
Process: 876 (PID)
State: LISTENING
Local Address: ROBERT:49155
Remote Address: 0.0.0.0:0
Type: TCP
Process: 668 (PID)
State: LISTENING
Local Address: ROBERT:49154
Remote Address: 0.0.0.0:0
Type: TCP
Process: 1436 (PID)
State: LISTENING
Local Address: ROBERT:49153
Remote Address: 0.0.0.0:0
Type: TCP
Process: 1264 (PID)
State: LISTENING
Local Address: ROBERT:49152
Remote Address: 0.0.0.0:0
Type: TCP
Process: 792 (PID)
State: LISTENING
Local Address: ROBERT:44110
Remote Address: 0.0.0.0:0
Type: TCP
Process: 3884 (PID)
State: LISTENING
Local Address: ROBERT:44080
Remote Address: 0.0.0.0:0
Type: TCP
Process: 4356 (PID)
State: LISTENING
Local Address: ROBERT:WSD
Remote Address: 0.0.0.0:0
Type: TCP
Process: 4 (PID)
State: LISTENING
Local Address: ROBERT:MS-WBT-SERVER
Remote Address: 0.0.0.0:0
Type: TCP
Process: 1660 (PID)
State: LISTENING
Local Address: ROBERT:MICROSOFT-DS
Remote Address: 0.0.0.0:0
Type: TCP
Process: 4 (PID)
State: LISTENING
Local Address: ROBERT:EPMAP
Remote Address: 0.0.0.0:0
Type: TCP
Process: 1136 (PID)
State: LISTENING
Local Address: ROBERT:64891
Remote Address: NA
Type: UDP
Process: 2644 (PID)
State: NA
Local Address: ROBERT:SSDP
Remote Address: NA
Type: UDP
Process: 2644 (PID)
State: NA
Local Address: ROBERT:138
Remote Address: NA
Type: UDP
Process: 4 (PID)
State: NA
Local Address: ROBERT:NETBIOS-NS
Remote Address: NA
Type: UDP
Process: 4 (PID)
State: NA
Local Address: ROBERT:64892
Remote Address: NA
Type: UDP
Process: 2644 (PID)
State: NA
Local Address: ROBERT:63032
Remote Address: NA
Type: UDP
Process: 6648 (PID)
State: NA
Local Address: ROBERT:61248
Remote Address: NA
Type: UDP
Process: 7408 (PID)
State: NA
Local Address: ROBERT:50957
Remote Address: NA
Type: UDP
Process: 4304 (PID)
State: NA
Local Address: ROBERT:SSDP
Remote Address: NA
Type: UDP
Process: 2644 (PID)
State: NA
Local Address: ROBERT:50955
Remote Address: NA
Type: UDP
Process: 1568 (PID)
State: NA
Local Address: ROBERT:49152
Remote Address: NA
Type: UDP
Process: 2644 (PID)
State: NA
Local Address: ROBERT:LLMNR
Remote Address: NA
Type: UDP
Process: 1660 (PID)
State: NA
Local Address: ROBERT:IPSEC-MSFT
Remote Address: NA
Type: UDP
Process: 1436 (PID)
State: NA
Local Address: ROBERT:WS-DISCOVERY
Remote Address: NA
Type: UDP
Process: 2644 (PID)
State: NA
Local Address: ROBERT:WS-DISCOVERY
Remote Address: NA
Type: UDP
Process: 1568 (PID)
State: NA
Local Address: ROBERT:WS-DISCOVERY
Remote Address: NA
Type: UDP
Process: 1568 (PID)
State: NA
Local Address: ROBERT:WS-DISCOVERY
Remote Address: NA
Type: UDP
Process: 2644 (PID)
State: NA
Local Address: ROBERT:500
Remote Address: NA
Type: UDP
Process: 1436 (PID)
State: NA
******************************************************************************************
******************************************************************************************
No hidden files/folders found -
ContributeurTélécharge Sysprot https://3c416dfc-a-62cb3a1a-s-sites.googlegroups.com/site/sysprotantirootkit/Home/SysProt.zip?attachauth=ANoY7cqxnzQSAOweMB1j1RjBx63qHLQnx1RrB041ebnNnUkA2E7iUZlFXPn94FP1IUHBJSwoSr5WblYwsVBjiyaDOKhebdI3IV9oewennApIgI_z92W9PJmfwsnozJcQn66wJBG1RP0eCl1Xv_HZjeP-n-Pf2uHskwiOLYePagIzgigsE9RUmK40KwAL0DRxju5sEcAU_uOSbkivGezpyqu7eDpAxIo2TUMVmuDywLmABSKQ80dw0gw%3D&attredirects=2
dézippe-le et lance l'exécutable
vas dans l'onglet "Log" et coche ttes les cases, ainsi que "Hidden objects only", puis "create log"
patiente qques instants, sélectionne "all drives " lorsque c'est demandé" et à la fin poste le rapport SysProtLog.txt qui est dans le même dossier que Sysprot.Exe -
ContributeurTDSS:le 12/10/2009 à 14:51:51 "C:\Windows\System32\ovfst*.???"
-
j'ai resolu le probleme avec : outils < option internet > general - suppression de " about blank " et afficher une autre page d'accueil. ensuite > demarrer - executer msconfig et dans la section services et demarrage decocher about blank.
Un logiciel gratuit tel que Glary Utilities et les sections demarrage ou processus en cours peuvent resoudre le pbme. bonne chance -
Contributeurbon, dernier essai, toujours en ss échec, télécharge-le, renomme-le braviax.exe et lance-le
- 1
- 2