Problème de scan au démarrage
je vous contacte car je suis une novice en informatique et j'ai grand besoin de votre aide.
J'ai acheté un pc HP dv6000 il y à maintenant 2 ans et jamais de soucis jusque la semaine dernière!!!
En effet il me demande constamment de faire un scan du disque local C, apparemment le disque dur. J'ai la possibilité d'annuler ce scan en tapant sur une touche avant 10 secondes!!!
J'ai tout essayé et il y a rien à faire il me le demande constamment!!!
Aidez moi je vous en supplie je suis étudiante et mon ordi est trop imp!!!
Merci à tous et bonne journée
Configuration: Windows Vista Internet Explorer 7.0
50 réponses
La problématique centrale est qu’un PC sous Windows Vista demande un scan du disque C au démarrage, évoquant un souci du disque dur ou une vérification automatisée. Plusieurs intervenants recommandent de désinstaller Sophos et d’installer un antivirus gratuit alternatif, comme Avira, puis d’effectuer une mise à jour et un scan complet, sans négliger le passage par CCleaner. D’autres conseils ciblent l’identification des programmes qui déclenchent le scan et l’usage d’outils comme HijackThis pour nettoyer les éléments indésirables, ainsi que la vérification SMART du disque. À noter, des échanges indiquent que le comportement peut varier selon le jour et que des vérifications matérielles (SMART) et les rapports du fabricant peuvent résoudre le mystère sans réinstallations répétées.
-
Morning,
Ce n'est pas mal du tout. Tu as toutefois 2 applications HijackThis en exécution: C:\Users\CLOTHI~1\AppData\Local\Temp\hijackthis-2.0.2.exe et c:\Users\clothilde\Downloads\hijackthis-2.0.2.exe. Je pense que l'install a foiré d'une certaine manière... Si Hijackthis apparaît parmi dans Ajout/Suppr des programmes, supprime-le. Crée un dossier HJT à la racine de C: et télécharge Hijack à nouveau à partir de cette adresse: http://www.trendsecure.com/portal/fr/_download/HiJackThis.exe Fais clic droit / enregistrer sous et renomme-le en HJT.exe (au lieu de HiJackThis.exe). Sauvegarde-le dans le dossier C:\HJT que tu viens de créer. A l'avenir, lorsque tu fais un rapport hijack, tu lances donc C:\HJT\HJT.exe. Il est recommandé, pour Hijack:
- de le renommer (pour contrer certains infections, comme Vundo)
- de le laisser seul dans son propre dossier (d'où la création de C:\HJT)
Suite des opérations:
1. Désinstallation des barres d'outils inutiles. T'en as plein: Windows Live, Yahoo, Google. Commence par désactiver l'UAC, tu le réactiveras après. Tuto: https://forums.cnetfrance.fr/tutoriels-windows-7-8-et-autres-sytemes/104271-comment-desactiver-uac-dans-vista Ensuite, suis les instructions ici https://www.commentcamarche.net/faq/9685-supprimer-les-barres-d-outils-toolbars-indesirables pour la suppression en mode sans échec et la génération d'un rapport Toolbar S&D que tu colleras avec ta réponse
2. Vire Adobe Acrobar Reader. Plus gourmand que la concurrence. Installe ceci à la place: https://download.cnet.com/Foxit-Reader/3000-18497_4-10313206.html?part=dl-116442&subj=dl&tag=button Lors de l'install, fais une installation personnalisée et décoche l'installation de je-ne-sais-plus-quelle-autre barre d'outils (Ask ?) ou encore la modification de la page de démarrage... Il sera en anglais (les traductions ont toujours une version de retard), mais ça ne devrait pas poser problème car tu l'utiliseras généralement en cliquant sur un pdf et en faisant un scroll... Pas souvent besoin d'aller se balader dans ses menus.
3. Comme tu as un antivirus décent à présent, tu peux désactiver Windows Defender: https://www.tayo.fr/desactiver-windows-defender--anti-virus-aide.php
4. Je n'aime pas Tuneup Utilities, mais bon, c'est une question de goût. Tu peux le garder si tu veux, mais désactive sa défragmentation automatique et installe un défragmenteur de disque digne de ce nom à la place. Tu as 3 produits excellents, PerfectDisk, Diskeeper et O&O Defrag (tous les 3 payants, mais bon ;-))
5. Désactive et réactive par la suite la restauration. Tuto: https://www.tayo.fr/desactiver-restauration-windows-vista-tutoriel.php
6. Fais une mise à jour. Installe le SP2 de Vista, IE 8... (pour l'install de IE 8: install personnalisé, tu dis que tu souhaites Google comme moteur de recherche par défaut et tu refuses toutes les options qu'il te propose à part la protection contre le phising).
7. Une fois installé, abandonne IE 8 (lol !). Navigue avec Firefox à la place. http://www.mozilla-europe.org/fr/firefox/ A l'installation, il te proposera d'importer des choses à partir d'IE; refuse. Tu peux exporter manuellement les favoris IE plus tard. Installe Adblock Plus comme add-on Firefox http://slimgus.blogspot.com/2009/06/tuto-adblock.html
8. Mmm, il y a aussi la config des services et je n'ai pas de tuto en fr. Par contre, bien expliqué ici: http://www.blackviper.com/service-configurations/black-vipers-windows-vista-service-pack-2-service-configurations/
9. Si tu envisages utiliser des programmes qui demandent beaucoup beaucoup de mémoire, faudra acheter encore 1 Go de RAM.
Walà, avec tout ceci ça devra mieux tourner
Bon cours :-) -
et voici lelog hijak:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:05:12, on 22/10/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18813)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPStart.exe
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\WINDOWS\RtHDVCpl.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Hp\QuickPlay\QPService.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser.exe
C:\Program Files\Windows Live\Toolbar\wltuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10c.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Windows\system32\SearchProtocolHost.exe
c:\Users\clothilde\Downloads\hijackthis-2.0.2.exe
C:\Users\CLOTHI~1\AppData\Local\Temp\hijackthis-2.0.2.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dailymotion.com/fr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/...
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr?cobrand=hp-notebook.msn.com&ocid=HPDHP&pc=HPNTDF
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [OnScreenDisplay] C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [WAWifiMessage] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Plugin Control) - http://appldnld.apple.com/QuickTime/qtactivex/qtplugin.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: QuickPlay Background Capture Service (QBCS) (QPCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
O23 - Service: QuickPlay Task Scheduler (QTS) (QPSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe
O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software - C:\Windows\System32\TuneUpDefragService.exe
O23 - Service: @%SystemRoot%\System32\TUProgSt.exe,-1 (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\Windows\System32\TUProgSt.exe
-
coucou,
voila le scan est fini jte donne le rapport:
Avira AntiVir Personal
Date de création du fichier de rapport : jeudi 22 octobre 2009 19:53
La recherche porte sur 1815437 souches de virus.
Détenteur de la licence : Avira AntiVir Personal - FREE Antivirus
Numéro de série : 0000149996-ADJIE-0000001
Plateforme : Windows Vista
Version de Windows : (Service Pack 1) [6.0.6001]
Mode Boot : Démarré normalement
Identifiant : SYSTEM
Nom de l'ordinateur : PC-DE-CLOTHILDE
Informations de version :
BUILD.DAT : 9.0.0.70 18071 Bytes 25/09/2009 12:03:00
AVSCAN.EXE : 9.0.3.7 466689 Bytes 22/10/2009 17:52:13
AVSCAN.DLL : 9.0.3.0 49409 Bytes 03/03/2009 09:21:02
LUKE.DLL : 9.0.3.2 209665 Bytes 20/02/2009 10:35:11
LUKERES.DLL : 9.0.2.0 13569 Bytes 03/03/2009 09:21:31
ANTIVIR0.VDF : 7.1.0.0 15603712 Bytes 27/10/2008 11:30:36
ANTIVIR1.VDF : 7.1.4.132 5707264 Bytes 24/06/2009 17:52:12
ANTIVIR2.VDF : 7.1.6.112 4833792 Bytes 15/10/2009 17:52:12
ANTIVIR3.VDF : 7.1.6.139 238080 Bytes 22/10/2009 17:52:12
Version du moteur : 8.2.1.44
AEVDF.DLL : 8.1.1.2 106867 Bytes 22/10/2009 17:52:13
AESCRIPT.DLL : 8.1.2.40 487804 Bytes 22/10/2009 17:52:13
AESCN.DLL : 8.1.2.5 127346 Bytes 22/10/2009 17:52:13
AERDL.DLL : 8.1.3.2 479604 Bytes 22/10/2009 17:52:13
AEPACK.DLL : 8.2.0.2 422263 Bytes 22/10/2009 17:52:13
AEOFFICE.DLL : 8.1.0.38 196987 Bytes 22/10/2009 17:52:13
AEHEUR.DLL : 8.1.0.167 2011511 Bytes 22/10/2009 17:52:13
AEHELP.DLL : 8.1.7.0 237940 Bytes 22/10/2009 17:52:12
AEGEN.DLL : 8.1.1.68 364918 Bytes 22/10/2009 17:52:12
AEEMU.DLL : 8.1.1.0 393587 Bytes 22/10/2009 17:52:12
AECORE.DLL : 8.1.8.1 184693 Bytes 22/10/2009 17:52:12
AEBB.DLL : 8.1.0.3 53618 Bytes 09/10/2008 13:32:40
AVWINLL.DLL : 9.0.0.3 18177 Bytes 12/12/2008 07:47:30
AVPREF.DLL : 9.0.3.0 44289 Bytes 22/10/2009 17:52:13
AVREP.DLL : 8.0.0.3 155905 Bytes 20/01/2009 13:34:28
AVREG.DLL : 9.0.0.0 36609 Bytes 07/11/2008 14:24:42
AVARKT.DLL : 9.0.0.3 292609 Bytes 24/03/2009 14:05:22
AVEVTLOG.DLL : 9.0.0.7 167169 Bytes 30/01/2009 09:36:37
SQLITE3.DLL : 3.6.1.0 326401 Bytes 28/01/2009 14:03:49
SMTPLIB.DLL : 9.2.0.25 28417 Bytes 02/02/2009 07:20:57
NETNT.DLL : 9.0.0.0 11521 Bytes 07/11/2008 14:40:59
RCIMAGE.DLL : 9.0.0.25 2438913 Bytes 22/10/2009 17:52:12
RCTEXT.DLL : 9.0.37.0 88321 Bytes 15/04/2009 09:07:05
Configuration pour la recherche actuelle :
Nom de la tâche...............................: Contrôle intégral du système
Fichier de configuration......................: c:\program files\avira\antivir desktop\sysscan.avp
Documentation.................................: bas
Action principale.............................: interactif
Action secondaire.............................: ignorer
Recherche sur les secteurs d'amorçage maître..: marche
Recherche sur les secteurs d'amorçage.........: marche
Secteurs d'amorçage...........................: C:, D:,
Recherche dans les programmes actifs..........: marche
Recherche en cours sur l'enregistrement.......: marche
Recherche de Rootkits.........................: marche
Contrôle d'intégrité de fichiers système......: arrêt
Fichier mode de recherche.....................: Tous les fichiers
Recherche sur les archives....................: marche
Limiter la profondeur de récursivité..........: 20
Archive Smart Extensions......................: marche
Heuristique de macrovirus.....................: marche
Heuristique fichier...........................: moyen
Catégories de dangers divergentes.............: +APPL,+GAME,+JOKE,+PCK,+SPR,
Début de la recherche : jeudi 22 octobre 2009 19:53
La recherche d'objets cachés commence.
'98987' objets ont été contrôlés, '0' objets cachés ont été trouvés.
La recherche sur les processus démarrés commence :
Processus de recherche 'avscan.exe' - '1' module(s) sont contrôlés
Processus de recherche 'avscan.exe' - '1' module(s) sont contrôlés
Processus de recherche 'avcenter.exe' - '1' module(s) sont contrôlés
Processus de recherche 'sched.exe' - '1' module(s) sont contrôlés
Processus de recherche 'avguard.exe' - '1' module(s) sont contrôlés
Processus de recherche 'avgnt.exe' - '1' module(s) sont contrôlés
Processus de recherche 'FlashUtil10c.exe' - '1' module(s) sont contrôlés
Processus de recherche 'infocard.exe' - '1' module(s) sont contrôlés
Processus de recherche 'iexplore.exe' - '1' module(s) sont contrôlés
Processus de recherche 'wltuser.exe' - '1' module(s) sont contrôlés
Processus de recherche 'GoogleToolbarUser.exe' - '1' module(s) sont contrôlés
Processus de recherche 'iexplore.exe' - '1' module(s) sont contrôlés
Processus de recherche 'wuauclt.exe' - '1' module(s) sont contrôlés
Processus de recherche 'HPHC_Service.exe' - '1' module(s) sont contrôlés
Processus de recherche 'HpqToaster.exe' - '1' module(s) sont contrôlés
Processus de recherche 'SynTPEnh.exe' - '1' module(s) sont contrôlés
Processus de recherche 'rundll32.exe' - '1' module(s) sont contrôlés
Processus de recherche 'wmpnetwk.exe' - '1' module(s) sont contrôlés
Processus de recherche 'wmpnscfg.exe' - '1' module(s) sont contrôlés
Processus de recherche 'msnmsgr.exe' - '1' module(s) sont contrôlés
Processus de recherche 'LightScribeControlPanel.exe' - '1' module(s) sont contrôlés
Processus de recherche 'WmiPrvSE.exe' - '1' module(s) sont contrôlés
Processus de recherche 'sidebar.exe' - '1' module(s) sont contrôlés
Processus de recherche 'rundll32.exe' - '1' module(s) sont contrôlés
Processus de recherche 'WiFiMsg.exe' - '1' module(s) sont contrôlés
Processus de recherche 'HPWAMain.exe' - '1' module(s) sont contrôlés
Processus de recherche 'MSASCui.exe' - '1' module(s) sont contrôlés
Processus de recherche 'HPKBDAPP.exe' - '1' module(s) sont contrôlés
Processus de recherche 'QLBCTRL.exe' - '1' module(s) sont contrôlés
Processus de recherche 'QPService.exe' - '1' module(s) sont contrôlés
Processus de recherche 'IAAnotif.exe' - '1' module(s) sont contrôlés
Processus de recherche 'RtHDVCpl.exe' - '1' module(s) sont contrôlés
Processus de recherche 'sm56hlpr.exe' - '1' module(s) sont contrôlés
Processus de recherche 'SynTPStart.exe' - '1' module(s) sont contrôlés
Processus de recherche 'explorer.exe' - '1' module(s) sont contrôlés
Processus de recherche 'taskeng.exe' - '1' module(s) sont contrôlés
Processus de recherche 'dwm.exe' - '1' module(s) sont contrôlés
Processus de recherche 'taskeng.exe' - '1' module(s) sont contrôlés
Processus de recherche 'QPSched.exe' - '1' module(s) sont contrôlés
Processus de recherche 'hpqWmiEx.exe' - '1' module(s) sont contrôlés
Processus de recherche 'SearchIndexer.exe' - '1' module(s) sont contrôlés
Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
Processus de recherche 'TUProgSt.exe' - '1' module(s) sont contrôlés
Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
Processus de recherche 'SeaPort.exe' - '1' module(s) sont contrôlés
Processus de recherche 'QPCapSvc.exe' - '1' module(s) sont contrôlés
Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
Processus de recherche 'LSSrvc.exe' - '1' module(s) sont contrôlés
Processus de recherche 'IAANTmon.exe' - '1' module(s) sont contrôlés
Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
Processus de recherche 'spoolsv.exe' - '1' module(s) sont contrôlés
Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
Processus de recherche 'SLsvc.exe' - '1' module(s) sont contrôlés
Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
Processus de recherche 'audiodg.exe' - '0' module(s) sont contrôlés
Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
Processus de recherche 'winlogon.exe' - '1' module(s) sont contrôlés
Processus de recherche 'lsm.exe' - '1' module(s) sont contrôlés
Processus de recherche 'lsass.exe' - '1' module(s) sont contrôlés
Processus de recherche 'services.exe' - '1' module(s) sont contrôlés
Processus de recherche 'wininit.exe' - '1' module(s) sont contrôlés
Processus de recherche 'csrss.exe' - '1' module(s) sont contrôlés
Processus de recherche 'csrss.exe' - '1' module(s) sont contrôlés
Processus de recherche 'smss.exe' - '1' module(s) sont contrôlés
'69' processus ont été contrôlés avec '69' modules
La recherche sur les secteurs d'amorçage maître commence :
Secteur d'amorçage maître HD0
[INFO] Aucun virus trouvé !
La recherche sur les secteurs d'amorçage commence :
Secteur d'amorçage 'C:\'
[INFO] Aucun virus trouvé !
Secteur d'amorçage 'D:\'
[INFO] Aucun virus trouvé !
La recherche sur les renvois aux fichiers exécutables (registre) commence :
Le registre a été contrôlé ( '47' fichiers).
La recherche sur les fichiers sélectionnés commence :
Recherche débutant dans 'C:\'
C:\hiberfil.sys
[AVERTISSEMENT] Impossible d'ouvrir le fichier !
[REMARQUE] Ce fichier est un fichier système Windows.
[REMARQUE] Il est correct que ce fichier ne puisse pas être ouvert pour la recherche.
C:\pagefile.sys
[AVERTISSEMENT] Impossible d'ouvrir le fichier !
[REMARQUE] Ce fichier est un fichier système Windows.
[REMARQUE] Il est correct que ce fichier ne puisse pas être ouvert pour la recherche.
C:\Downloads\Software\gamingharbor_installer.exe
[RESULTAT] Contient le modèle de détection du logiciel espion ou publicitaire ADSPY/PopMenu.B.1
C:\HP\HPQWare\EasySetup\SetACL.exe
[RESULTAT] Contient le modèle de détection de l'application APPL/ACLSet
Recherche débutant dans 'D:\' <HP_RECOVERY>
Début de la désinfection :
C:\Downloads\Software\gamingharbor_installer.exe
[RESULTAT] Contient le modèle de détection du logiciel espion ou publicitaire ADSPY/PopMenu.B.1
[REMARQUE] Le fichier a été déplacé dans le répertoire de quarantaine sous le nom '4b4dac5f.qua' !
C:\HP\HPQWare\EasySetup\SetACL.exe
[RESULTAT] Contient le modèle de détection de l'application APPL/ACLSet
[REMARQUE] Le fichier a été déplacé dans le répertoire de quarantaine sous le nom '4b54ac63.qua' !
Fin de la recherche : jeudi 22 octobre 2009 21:01
Temps nécessaire: 1:03:04 Heure(s)
La recherche a été effectuée intégralement
21488 Les répertoires ont été contrôlés
429398 Des fichiers ont été contrôlés
2 Des virus ou programmes indésirables ont été trouvés
0 Des fichiers ont été classés comme suspects
0 Des fichiers ont été supprimés
0 Des virus ou programmes indésirables ont été réparés
2 Les fichiers ont été déplacés dans la quarantaine
0 Les fichiers ont été renommés
2 Impossible de contrôler des fichiers
429394 Fichiers non infectés
3736 Les archives ont été contrôlées
2 Avertissements
4 Consignes
98987 Des objets ont été contrôlés lors du Rootkitscan
0 Des objets cachés ont été trouvés -
re, ouai kel idée mais bon la cause principale est ma mere lol!!!je plaisante!
c ok g suppr sophos g pris l'antivirus ke tu ma conseillé et la je suis en train de faire le scan et trop bizarre il me trouve 2 trucs alors ke dpuis mon probleme g fait des 10aines de scan avec sophos et rien!!!merci :)) -
oki doki... Bon cours !!
(pfff, quelle idée, que celle d'aller en cours !) -
ok pas de soucis!!par contre je ferai ca dans la soirée car la je v en cours!!
je te tiens o courant et encore mille merci pour ton aide précieuse c super gentil de ta part!!!!!:))) -
OK. Télécharge ceci: http://dlce.antivir.com/package/wks_avira/win32/fr/pecl/avira_antivir_personal_fr.zip
Désinstalle Sophos. Regarde ici http://www.sophos.com/support/knowledgebase/article/12360.html la section Vista pour voir l'ordre de désinstallation (c'est important). Tu redémarreras le PC autant de fois qu'il te le demande.
Si pas OK, pour une raison ou une autre, ne continue pas et fais signe.
Passe un coup de CCleaner (fichiers + registres)
Installe le programme que tu as téléchargé en suivant ce tuto: https://www.malekal.com/avira-free-security-antivirus-gratuit/ Fais le paramétrage, la mise à jour et un scan complet avec, histoire de.
Reviens avec
- le log de scan Antivir
- un nouveau log hijackthis
++ -
voila g fait les fixed chek d 2 lignes
-
pour kk1 ki pige rien t fort!!!:))
alors pour l'anglais je pige léger sauf les truc courant lol
voila les info de sophos je fait tout de suite ce ke tu m'a dit
[Général]
Etat du contrôle sur accès = Actif
Droits utilisateur actuels = Administrateur Sophos
[Logiciel]
Sophos Anti-Virus = 7.6.12
Statut de la publication = Complet
Moteur de détection = 3.0.1
Données de détection = 4.46E
Eléments détectés = 1060863
Identités de détection = 247
Version des règles HIPS = 2.2.0
Version de la configuration HIPS = 1.0.4
Dernière mise à jour = 22/10/2009 13:55:09
[Fichiers d'identité de détection]
agen-ldn.ide
tdss-av.ide
fakea-pz.ide
silly-dv.ide
agen-lef.ide
bredo-d.ide
agen-lcw.ide
injec-jp.ide
spy-dv.ide
dloa-ctr.ide
fake-abm.ide
auto-aqv.ide
expiro-f.ide
tdss-au.ide
agen-lep.ide
bank-euf.ide
mdro-cfl.ide
bank-u.ide
fake-abr.ide
injec-jn.ide
injec-jr.ide
talsab-a.ide
bank-euk.ide
dldr-bl.ide
sbot-b.ide
swfdl-b.ide
servu-fx.ide
fake-aar.ide
hoster-a.ide
fakev-ou.ide
fakea-pq.ide
killa-ga.ide
fake-aai.ide
dloa-cto.ide
fakeal-l.ide
vb-ehp.ide
dwnl-hws.ide
agen-lcy.ide
injec-jo.ide
fake-abq.ide
autoi-gf.ide
fakev-oz.ide
fake-abg.ide
ddos-ad.ide
zbot-ht.ide
zbot-hx.ide
agen-lci.ide
agen-ldd.ide
expjs-g.ide
cariez-a.ide
bredo-g.ide
docdro-k.ide
agen-lcz.ide
pdfex-bz.ide
autoi-gg.ide
auto-arl.ide
dropr-bz.ide
fakea-pp.ide
mdro-cft.ide
dloa-ctd.ide
fakev-pb.ide
fake-aca.ide
fakea-qc.ide
silly-dw.ide
palevo-a.ide
auto-aro.ide
selges-a.ide
agen-lfx.ide
fakea-qh.ide
fake-aco.ide
fake-acb.ide
fake-acl.ide
drop-dq.ide
zbot-ia.ide
fake-acq.ide
auto-ars.ide
spy-dw.ide
dwnl-hwx.ide
fake-act.ide
sispro-a.ide
dldr-br.ide
forcud-a.ide
pws-bek.ide
dloa-cuh.ide
fake-ace.ide
auto-arv.ide
ircb-afh.ide
start-ce.ide
mdro-cge.ide
agen-lge.ide
agen-lgk.ide
vb-eif.ide
ircb-afj.ide
rbot-gyd.ide
renos-dq.ide
dnsch-mt.ide
zipcar-d.ide
vb-eil.ide
vb-eik.ide
vb-eii.ide
tdss-bc.ide
agen-lgr.ide
dldr-bt.ide
bredo-i.ide
agen-lgz.ide
agen-lgu.ide
sedjja-a.ide
bckd-qyr.ide
renos-dw.ide
zbot-ic.ide
agen-lhn.ide
mdro-cgj.ide
mdro-cgi.ide
auto-ufo.ide
hixpet-a.ide
auto-asa.ide
injec-jx.ide
palevo-c.ide
zbot-id.ide
bckd-qyx.ide
fakev-pi.ide
fake-ady.ide
fake-aea.ide
vkkont-a.ide
clomp-l.ide
vb-eip.ide
auto-asb.ide
zbot-ij.ide
bredoz-h.ide
mdro-cgr.ide
agen-lig.ide
agen-lij.ide
dloa-cus.ide
plank-b.ide
fujac-bf.ide
murlo-bj.ide
agen-lil.ide
dloa-cut.ide
agen-lio.ide
agen-lir.ide
clomp-m.ide
dloa-cuw.ide
fake-ael.ide
vb-eiw.ide
agen-lis.ide
kolab-d.ide
drop-dw.ide
zbot-il.ide
agen-liw.ide
vb-ejc.ide
banc-bgf.ide
vb-eja.ide
killba-c.ide
fake-aeq.ide
fake-aer.ide
agen-liy.ide
agen-lje.ide
zbot-io.ide
fake-aev.ide
fakere-e.ide
spy-dy.ide
zbot-ip.ide
dloa-cvd.ide
alure-e.ide
zbot-iq.ide
agen-ljn.ide
fake-aey.ide
pdfex-ce.ide
agen-ljr.ide
drop-dz.ide
bank-euo.ide
fake-afb.ide
sasfis-a.ide
vbinje-k.ide
agen-lka.ide
pdload-a.ide
swfdlr-q.ide
pdfjs-ds.ide
agen-lkm.ide
pws-ben.ide
fake-afe.ide
zbot-iu.ide
hiloti-h.ide
zipcar-e.ide
rimecu-b.ide
fakea-qp.ide
bancdl-e.ide
auto-ast.ide
zbot-iv.ide
zbot-jb.ide
auto-asx.ide
jsdown-s.ide
agen-lkx.ide
zbot-jg.ide
fake-afh.ide
realbo-b.ide
zbot-jj.ide
fakea-qq.ide
agen-lky.ide
downln-h.ide
dload-gy.ide
agen-llj.ide
agen-lli.ide
bckd-qzo.ide
agen-lkz.ide
pdfjs-ea.ide
psw-hh.ide
buzus-bk.ide
fakev-pk.ide
fake-afm.ide
lnkzip-b.ide
pws-bex.ide
psyme-ks.ide
xed-b.ide
dwnl-hxo.ide
dloa-cvp.ide
bredo-m.ide
vbinje-l.ide
dloa-cvo.ide
ircb-afr.ide
tdss-bh.ide
vbinje-m.ide
bank-eus.ide
start-cj.ide
harni-bz.ide
start-ci.ide
mdro-cgx.ide
dloa-cvr.ide
docdro-n.ide
dloa-cvs.ide
fake-afo.ide
renos-dy.ide
zipmal-b.ide
gpcode-e.ide
litis-a.ide
agen-lmx.ide
voter-f.ide
dldr-cb.ide
dnschg-a.ide
fake-afw.ide
agen-lne.ide
bank-eut.ide
vb-ejl.ide
bho-oc.ide
agen-lng.ide
dloa-cvx.ide
ifram-dd.ide
[Composants]
BackgroundScanClient.exe 1.0.0.3970 , taille 45608 octets
sav32cli.exe 2.28.000 , taille 232488 octets
SAVAdminService.exe 1.0.0.4000 , taille 80936 octets
SAVCleanupService.exe 1.0.0.3090 , taille 90112 octets
SavMain.exe 1.0.0.3980 , taille 2010152 octets
SavProgress.exe 1.0.0.3980 , taille 556072 octets
SavService.exe 1.0.0.3921 , taille 98304 octets
sdcdevcon.exe 1.0.0.3821 , taille 49152 octets
sdcservice.exe 1.0.0.4000 , taille 393216 octets
WSCClient.exe 1.0.0.4010 , taille 128056 octets
AuthorisedLists.dll 1.0.0.3921 , taille 147456 octets
BackgroundScanning.dll 1.0.0.3921 , taille 77824 octets
BHOManagement.dll 1.0.0.3980 , taille 180224 octets
Categories.dll 1.0.0.3090 , taille 7168 octets
ComponentManager.dll 1.0.0.3921 , taille 90112 octets
Configuration.dll 1.0.0.3980 , taille 286720 octets
DCManagement.dll 1.0.0.3970 , taille 94208 octets
DesktopMessaging.dll 1.0.0.3921 , taille 331776 octets
DriveProcessor.dll 1.0.0.3921 , taille 147456 octets
EEConsumer.dll 1.0.0.3921 , taille 110592 octets
FilterProcessors.dll 1.0.0.4021 , taille 233472 octets
FSDecomposer.dll 1.0.0.3921 , taille 98304 octets
ICAdapter.dll 1.0.0.3970 , taille 102400 octets
ICManagement.dll 1.0.0.4010 , taille 299008 octets
ICProcessors.dll 1.0.0.3980 , taille 258048 octets
LegacyConsumers.dll 1.0.0.3921 , taille 139264 octets
Localisation.dll 1.0.0.3921 , taille 126976 octets
Logging.dll 1.0.0.3921 , taille 462848 octets
msvcp71.dll 7.10.3077.0 , taille 499712 octets
msvcr71.dll 7.10.3052.4 , taille 348160 octets
osdp.dll 1.44.0.1461 , taille 121968 octets
Persistance.dll 1.0.0.3921 , taille 98304 octets
rkdisk.dll 1.4.1 , taille 102400 octets
SavAdapter.dll 1.0.0.4043 , taille 675840 octets
SAVI.dll 7.1.9.1461 , taille 490608 octets
SAVMSCM.DLL 2.00.1502 , taille 131072 octets
SavNeutralRes.dll 1.0.0.3090 , taille 651264 octets
SavRes.dll 1.0.0.4043 , taille 548864 octets
SavResChs.dll 1.0.0.3921 , taille 151552 octets
SavResCht.dll 1.0.0.3921 , taille 151552 octets
SavResDeu.dll 1.0.0.3921 , taille 163840 octets
SavResEng.dll 1.0.0.3921 , taille 151552 octets
SavResEsp.dll 1.0.0.3921 , taille 155648 octets
SavResFra.dll 1.0.0.3921 , taille 167936 octets
SavResIt.dll 1.0.0.3921 , taille 163840 octets
SavResJap.dll 1.0.0.3921 , taille 151552 octets
SavShellExt.dll 1.0.0.3921 , taille 315392 octets
ScanEditExports.dll 1.0.0.3755 , taille 29696 octets
ScanEditFacade.dll 1.0.0.3980 , taille 188416 octets
ScanManagement.dll 1.0.0.3980 , taille 237568 octets
Security.dll 1.0.0.3921 , taille 114688 octets
SIPSManagement.dll 1.0.0.3980 , taille 499712 octets
SophosBHO.dll 2.4.2.4020 , taille 240680 octets
SophosBHORes.dll 1.0.0.3800 , taille 65536 octets
sophos_detoured.dll 1.0.0.4030 , taille 195072 octets
SophtainerAdapter.dll 1.0.0.3921 , taille 110592 octets
SystemInformation.dll 1.0.0.3921 , taille 147456 octets
ThreatDetection.dll 1.0.0.4031 , taille 491520 octets
ThreatManagement.dll 1.0.0.4043 , taille 598016 octets
Translators.dll 1.0.0.3921 , taille 204800 octets
veex.dll 3.00.1.1461 , taille 1805424 octets
VirusDetection.dll 1.0.0.4010 , taille 466944 octets
sdccoinstaller.dll 1.0.0.3821 , taille 130104 octets
savonaccess.sys 3.10.0.300 , taille 93192 octets
SophosBootDriver.sys 1.0.0.101 , taille 20288 octets
SophosBootTasks.exe 2.0.0.3921 , taille 23552 octets
[Système]
Description = x64 Family 6 Model 23 Stepping 6
Revision = 5894
AddressWidth = 32
LoadPercentage = 13
Level = 6
DeviceID = CPU0
CurrentVoltage = 33
PowerManagementSupported = False
SocketDesignation = U2E1
StatusInfo = 3
Family = 190
Name = Intel(R) Core(TM)2 Duo CPU T8100 @ 2.10GHz
Manufacturer = GenuineIntel
DataWidth = 64
Stepping = 6
InstallDate =
ProcessorType = 3
Caption = x64 Family 6 Model 23 Stepping 6
L2CacheSize = 3072
VoltageCaps = 2
L3CacheSpeed = 0
CreationClassName = Win32_Processor
Architecture = 9
ErrorDescription =
Availability = 3
SystemName = PC-DE-CLOTHILDE
Role = CPU
NumberOfCores = 2
CurrentClockSpeed = 2101
SystemCreationClassName = Win32_ComputerSystem
PowerManagementCapabilities =
ConfigManagerUserConfig =
ErrorCleared =
L3CacheSize = 0
UniqueId =
ProcessorId = BFEBFBFF00010676
L2CacheSpeed = 2101
ExtClock = 800
CpuStatus = 1
ConfigManagerErrorCode =
OtherFamilyDescription =
Version = Modèle 7, niveau 6
Status = OK
NumberOfLogicalProcessors = 2
PNPDeviceID =
UpgradeMethod = 9
MaxClockSpeed = 2101
LastErrorCode =
Description =
CurrentTimeZone = 120
CSCreationClassName = Win32_ComputerSystem
DataExecutionPrevention_Available = True
ServicePackMinorVersion = 0
PAEEnabled = True
Debug = False
MUILanguages =
BuildNumber = 6001
TotalVisibleMemorySize = 2094780
DataExecutionPrevention_SupportPolicy = 2
Name = Microsoft® Windows Vista™ Édition Familiale Premium |C:\Windows|\Device\Harddisk0\Partition1
CSName = PC-DE-CLOTHILDE
BuildType = Multiprocessor Free
Manufacturer = Microsoft Corporation
PlusVersionNumber =
OSType = 18
InstallDate = 20080310 161027
RegisteredUser = clothilde
ProductType = 1
NumberOfUsers = 2
Caption = Microsoft® Windows Vista™ Édition Familiale Premium
QuantumType = 1
NumberOfProcesses = 77
LocalDateTime = 20091022 154920
TotalVirtualMemorySize = 4436368
WindowsDirectory = C:\Windows
OSArchitecture = 32 bits
SystemDrive = C:
CreationClassName = Win32_OperatingSystem
OSLanguage = 1036
ServicePackMajorVersion = 1
LargeSystemCache =
TotalSwapSpaceSize =
SizeStoredInPagingFiles = 2401980
Primary = True
SystemDirectory = C:\Windows\system32
NumberOfLicensedUsers = 0
DataExecutionPrevention_Drivers = True
CSDVersion = Service Pack 1
CountryCode = 33
OtherTypeDescription =
BootDevice = \Device\HarddiskVolume1
MaxProcessMemorySize = 2097024
SerialNumber = 89578-OEM-7332157-00061
QuantumLength = 1
OperatingSystemSKU = 3
MaxNumberOfProcesses = 4294967295
LastBootUpTime = 20091022 152001
FreeSpaceInPagingFiles = 2213336
SystemDevice = \Device\HarddiskVolume1
DataExecutionPrevention_32BitApplications = True
Organization = Hewlett-Packard
PlusProductID =
SuiteMask = 784
FreeVirtualMemory = 3120020
ForegroundApplicationBoost = 2
Version = 6.0.6001
Status = OK
FreePhysicalMemory = 1029224
EncryptionLevel = 256
Locale = 040c
Distributed = False
CodeSet = 1252
OSProductSuite = 768 -
je c pas comment tarrive a comprendre tout ce ke je te poste
J'pige pas grand-chose, en fait, mais je fais semblant de tout comprendre =)
Ton log s'améliore. Lance hijackthis à nouveau, coche ces lignes
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
et
O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
ferme les autres applis, clique sur "Fix checked" et ferme hijack. Pas besoin de redémarrer ta bécane cette fois-ci (comme quoi, l'informatique n'est pas si compliqué :-))
Bon, maintenant la suite:
1. Tu piges +/- l'anglais? (Lecture seulement)
2. M'as pas dit quelle est la version Sophos
++ -
voila c fait: et si c complexe serieux je c pas comment tarrive a comprendre tout ce ke je te poste!!lol
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:32:52, on 22/10/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18813)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPStart.exe
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\WINDOWS\RtHDVCpl.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Hp\QuickPlay\QPService.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
C:\WINDOWS\System32\rundll32.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\Sophos\AutoUpdate\ALMon.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser.exe
C:\Program Files\Windows Live\Toolbar\wltuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10c.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
c:\Users\clothilde\Downloads\hijackthis-2.0.2.exe
C:\Users\CLOTHI~1\AppData\Local\Temp\hijackthis-2.0.2.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.dailymotion.com/fr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=hp-notebook.msn.com&ocid=HPDHP&pc=HPNTDF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr?cobrand=hp-notebook.msn.com&ocid=HPDHP&pc=HPNTDF
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Sophos Web Content Scanner - {39EA7695-B3F2-4C44-A4BC-297ADA8FD235} - C:\Program Files\Sophos\Sophos Anti-Virus\SophosBHO.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [OnScreenDisplay] C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [WAWifiMessage] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - Global Startup: AutoUpdate Monitor.lnk = C:\Program Files\Sophos\AutoUpdate\ALMon.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Plugin Control) - http://appldnld.apple.com/QuickTime/qtactivex/qtplugin.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: QuickPlay Background Capture Service (QBCS) (QPCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
O23 - Service: QuickPlay Task Scheduler (QTS) (QPSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe
O23 - Service: Créateur de rapports d'état Sophos Anti-Virus (SAVAdminService) - Sophos Plc - C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
O23 - Service: Sophos Anti-Virus (SAVService) - Sophos Plc - C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe
O23 - Service: Sophos AutoUpdate Service - Sophos Plc - C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software - C:\Windows\System32\TuneUpDefragService.exe
O23 - Service: @%SystemRoot%\System32\TUProgSt.exe,-1 (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\Windows\System32\TUProgSt.exe
-
g fait un hijak mais il me propose pas la page notes comme tal
Fais la 1ère option "do a system scan & save a log" (scan + log)
mdr c complexe l'informatique
Meuh, nan, les apparences sont trompeuses comme toujours
Kan je clik info il me donne ca:
M'voyons, suffit de ne pas cliquer un peu n'importe où... :P
Laisse donc tomber le scan MBAM et poste le dernier log hijack -
kan je clik info il me donne ca:
* Trend Micro HijackThis v2.0.2 *
See bottom for version history.
The different sections of hijacking possibilities have been separated into the following groups.
You can get more detailed information about an item by selecting it from the list of found items OR highlighting the relevant line below, and clicking 'Info on selected item'.
R - Registry, StartPage/SearchPage changes
R0 - Changed registry value
R1 - Created registry value
R2 - Created registry key
R3 - Created extra registry value where only one should be
F - IniFiles, autoloading entries
F0 - Changed inifile value
F1 - Created inifile value
F2 - Changed inifile value, mapped to Registry
F3 - Created inifile value, mapped to Registry
N - Netscape/Mozilla StartPage/SearchPage changes
N1 - Change in prefs.js of Netscape 4.x
N2 - Change in prefs.js of Netscape 6
N3 - Change in prefs.js of Netscape 7
N4 - Change in prefs.js of Mozilla
O - Other, several sections which represent:
O1 - Hijack of auto.search.msn.com with Hosts file
O2 - Enumeration of existing MSIE BHO's
O3 - Enumeration of existing MSIE toolbars
O4 - Enumeration of suspicious autoloading Registry entries
O5 - Blocking of loading Internet Options in Control Panel
O6 - Disabling of 'Internet Options' Main tab with Policies
O7 - Disabling of Regedit with Policies
O8 - Extra MSIE context menu items
O9 - Extra 'Tools' menuitems and buttons
O10 - Breaking of Internet access by New.Net or WebHancer
O11 - Extra options in MSIE 'Advanced' settings tab
O12 - MSIE plugins for file extensions or MIME types
O13 - Hijack of default URL prefixes
O14 - Changing of IERESET.INF
O15 - Trusted Zone Autoadd
O16 - Download Program Files item
O17 - Domain hijack
O18 - Enumeration of existing protocols and filters
O19 - User stylesheet hijack
O20 - AppInit_DLLs autorun Registry value, Winlogon Notify Registry keys
O21 - ShellServiceObjectDelayLoad (SSODL) autorun Registry key
O22 - SharedTaskScheduler autorun Registry key
O23 - Enumeration of NT Services
O24 - Enumeration of ActiveX Desktop Components
Command-line parameters:
* /autolog - automatically scan the system, save a logfile and open it
* /ihatewhitelists - ignore all internal whitelists
* /uninstall - remove all HijackThis Registry entries, backups and quit
* /silentautuolog - the same as /autolog, except with no required user intervention
* Version history *
[v2.00.0]
* AnalyzeThis added for log file statistics
* Recognizes Windows Vista and IE7
* Fixed a few bugs in the O23 method
* Fixed a bug in the O22 method (SharedTaskScheduler)
* Did a few tweaks on the log format
* Fixed and improved ADS Spy
* Improved Itty Bitty Procman (processes are frozen before they are killed)
* Added listing of O4 autoruns from other users
* Added listing of the Policies Run items in O4 method, used by SmitFraud trojan
* Added /silentautolog parameter for system admins
* Added /deleteonreboot [file] parameter for system admins
* Added O24 - ActiveX Desktop Components enumeration
* Added Enhanced Security Confirguration (ESC) Zones to O15 Trusted Sites check
[v1.99.1]
* Added Winlogon Notify keys to O20 listing
* Fixed crashing bug on certain Win2000 and WinXP systems at O23 listing
* Fixed lots and lots of 'unexpected error' bugs
* Fixed lots of inproper functioning bugs (i.e. stuff that didn't work)
* Added 'Delete NT Service' function in Misc Tools section
* Added ProtocolDefaults to O15 listing
* Fixed MD5 hashing not working
* Fixed 'ISTSVC' autorun entries with garbage data not being fixed
* Fixed HijackThis uninstall entry not being updated/created on new versions
* Added Uninstall Manager in Misc Tools to manage 'Add/Remove Software' list
* Added option to scan the system at startup, then show results or quit if nothing found
[v1.99]
* Added O23 (NT Services) in light of newer trojans
* Integrated ADS Spy into Misc Tools section
* Added 'Action taken' to info in 'More info on this item'
[v1.98]
* Definitive support for Japanese/Chinese/Korean systems
* Added O20 (AppInit_DLLs) in light of newer trojans
* Added O21 (ShellServiceObjectDelayLoad, SSODL) in light of newer trojans
* Added O22 (SharedTaskScheduler) in light of newer trojans
* Backups of fixed items are now saved in separate folder
* HijackThis now checks if it was started from a temp folder
* Added a small process manager (Misc Tools section)
[v1.96]
* Lots of bugfixes and small enhancements! Among others:
* Fix for Japanese IE toolbars
* Fix for searchwww.com fake CLSID trick in IE toolbars and BHO's
* Attributes on Hosts file will now be restored when scanning/fixing/restoring it.
* Added several files to the LSP whitelist
* Fixed some issues with incorrectly re-encrypting data, making R0/R1 go undetected until a restart
* All sites in the Trusted Zone are now shown, with the exception of those on the nonstandard but safe domain list
[v1.95]
* Added a new regval to check for from Whazit hijack (Start Page_bak).
* Excluded IE logo change tweak from toolbar detection (BrandBitmap and SmBrandBitmap).
* New in logfile: Running processes at time of scan.
* Checkmarks for running StartupList with /full and /complete in HijackThis UI.
* New O19 method to check for Datanotary hijack of user stylesheet.
* Google.com IP added to whitelist for Hosts file check.
[v1.94]
* Fixed a bug in the Check for Updates function that could cause corrupt downloads on certain systems.
* Fixed a bug in enumeration of toolbars (Lop toolbars are now listed!).
* Added imon.dll, drwhook.dll and wspirda.dll to LSP safelist.
* Fixed a bug where DPF could not be deleted.
* Fixed a stupid bug in enumeration of autostarting shortcuts.
* Fixed info on Netscape 6/7 and Mozilla saying '%shitbrowser%' (oops).
* Fixed bug where logfile would not auto-open on systems that don't have .log filetype registered.
* Added support for backing up F0 and F1 items (d'oh!).
[v1.93]
* Added mclsp.dll (McAfee), WPS.DLL (Sygate Firewall), zklspr.dll (Zero Knowledge) and mxavlsp.dll (OnTrack) to LSP safelist.
* Fixed a bug in LSP routine for Win95.
* Made taborder nicer.
* Fixed a bug in backup/restore of IE plugins.
* Added UltimateSearch hijack in O17 method (I think).
* Fixed a bug with detecting/removing BHO's disabled by BHODemon.
* Also fixed a bug in StartupList (now version 1.52.1).
[v1.92]
* Fixed two stupid bugs in backup restore function.
* Added DiamondCS file to LSP files safelist.
* Added a few more items to the protocol safelist.
* Log is now opened immediately after saving.
* Removed rd.yahoo.com from NSBSD list (spammers are starting to use this, no doubt spyware authors will follow).
* Updated integrated StartupList to v1.52.
* In light of SpywareNuker/BPS Spyware Remover, any strings relevant to reverse-engineers are now encrypted.
* Rudimentary proxy support for the Check for Updates function.
[v1.91]
* Added rd.yahoo.com to the Nonstandard But Safe Domains list.
* Added 8 new protocols to the protocol check safelist, as well as showing the file that handles the protocol in the log (O18).
* Added listing of programs/links in Startup folders (O4).
* Fixed 'Check for Update' not detecting new versions.
[v1.9]
* Added check for Lop.com 'Domain' hijack (O17).
* Bugfix in URLSearchHook (R3) fix.
* Improved O1 (Hosts file) check.
* Rewrote code to delete BHO's, fixing a really nasty bug with orphaned BHO keys.
* Added AutoConfigURL and proxyserver checks (R1).
* IE Extensions (Button/Tools menuitem) in HKEY_CURRENT_USER are now also detected.
* Added check for extra protocols (O18).
[v1.81]
* Added 'ignore non-standard but safe domains' option.
* Improved Winsock LSP hijackers detection.
* Integrated StartupList updated to v1.4.
[v1.8]
* Fixed a few bugs.
* Adds detecting of free.aol.com in Trusted Zone.
* Adds checking of URLSearchHooks key, which should have only one value.
* Adds listing/deleting of Download Program Files.
* Integrated StartupList into the new 'Misc Tools' section of the Config screen!
[v1.71]
* Improves detecting of O6.
* Some internal changes/improvements.
[v1.7]
* Adds backup function! Yay!
* Added check for default URL prefix
* Added check for changing of IERESET.INF
* Added check for changing of Netscape/Mozilla homepage and default search engine.
[v1.61]
* Fixes Runtime Error when Hosts file is empty.
[v1.6]
* Added enumerating of MSIE plugins
* Added check for extra options in 'Advanced' tab of 'Internet Options'.
[v1.5]
* Adds 'Uninstall & Exit' and 'Check for update online' functions.
* Expands enumeration of autoloading Registry entries (now also scans for .vbs, .js, .dll, rundll32 and service)
[v1.4]
* Adds repairing of broken Internet access (aka Winsock or LSP fix) by New.Net/WebHancer
* A few bugfixes/enhancements
[v1.3]
* Adds detecting of extra MSIE context menu items
* Added detecting of extra 'Tools' menu items and extra buttons
* Added 'Confirm deleting/ignoring items' checkbox
[v1.2]
* Adds 'Ignorelist' and 'Info' functions
[v1.1]
* Supports BHO's, some default URL changes
[v1.0]
* Original release
A good thing to do after version updates is clear your Ignore list and re-add them, as the format of detected items sometimes changes. -
voila g suppr tout ce ke tu ma dit g redémarrer et enc scan!!!mdr c complexe l'informatique.!g fait un hijak mais il me propose pas la page notes comme tal du coup jarrive pas a la poster!!
-
Voila g redémarrer l'ordi et il ma encore demander de faire un scan!!!
C'est à cause de cette ligne:
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
MBAM n'a pas fini - pour une raison ou une autre - son boulot et se reprogramme lui-même au démarrage. Il faudrait le laisser finir, théoriquement.
Oui, tu fais "do a system scan only" et dans la fenêtre qui s'ouvre tu cocheras les lignes mentionnées. -
voila g redémarrer l'ordi et il ma encore demander de faire un scan!!!
g réouvert hijak mais il ne me propose pas ce ke tu ma demandé de décocher il me met juste la page avec do a systemescan, systeme scan only,view the lists of backups....etc -
Ah, oui, coche cette ligne aussi avec les autres:
- O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
avant de faire fix checked -
L'ordi :-)
-
lol tu vas me trouver bete mais kan tu me dit redemarre tu me dit l'ordi ou un nouvo scan mbam????lol
-
Mmmm, MBAM n'a pas encore fini, redémarre encore une fois pour lui permettre de finir.
Après le redémarrage: ouvre à nouveau hijackthis, fais un scan. Coche les lignes suivantes:
- O4 - HKCU\..\Run: [Software Informer] "C:\Program Files\Software Informer\softinfo.exe" -autorun
- O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
- O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
- O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\\Messengermsnmsgr.exe" /background
- O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
- O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\\Reader9.0\Reader\Reader_sl.exe"
Si tu n'utilises pas les raccourcis clavier HP (et je parie que non, car complètment inutiles), coche également ceci:
- O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
Ferme toutes les autres applications (y compris ton navigateur Internet ou l'explorateur de fichiers) en laissant uniquement hijack ouvert
Clique sur "fix checked". Ferme par la suite hijackthis et redémarre
Reposte un nouveau hijackthis.
Et dis-moi également quelle est ta version Sophos (tu devrais dénicher quelque part un "About Sophos" ou "A propos de" dans son menu)
Pas de nouveau scan disque au démarrage, n'est-ce pas ? La vie est belle :-)
++
- 1
- 2
- 3