Virus ou pas ?
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:12:45, on 08/11/2009
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18828)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\mobsync.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\hp\support\hpsysdrv.exe
C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
C:\Program Files\Labtec\Desktop\V5.1\KBDAP32A.EXE
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Windows\System32\oodtray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\RocketDock\RocketDock.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Users\GEANT\Program Files\DNA\btdna.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Windows\system32\taskeng.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\hp\kbd\kbd.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Users\GEANT\Desktop\7\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.01net.com/telecharger/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.01net.com/telecharger/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.01net.com/telecharger/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
O3 - Toolbar: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE
O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
O4 - HKLM\..\Run: [OFFICEKB] C:\Program Files\Labtec\Desktop\V5.1\kbdap32a.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [B2C_AGENT] C:\ProgramData\LGMOBILEAX\B2C_Client\B2CNotiAgent.exe"
O4 - HKLM\..\Run: [OODefragTray] C:\Windows\system32\oodtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
O4 - HKCU\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Users\GEANT\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [EPSON SX100 Series] C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIEDE.EXE /FU "C:\Windows\TEMP\E_SAB0D.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [TurboNet] C:\Users\GEANT\AppData\Local\Temp\b.exe
O4 - Startup: Adobe Media Player.lnk = C:\Program Files\Adobe Media Player\Adobe Media Player.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/MessengerGamesContent/GameContent/fr/uno1/GAME_UNO1.cab
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - https://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - http://fichiers.touslesdrivers.com/maconfig/MaConfig_3_1_2_1.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Crypkey License - CrypKey (Canada) Ltd. - C:\Windows\SYSTEM32\crypserv.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Service Google Update (gupdate1c9f63449c4a6af) (gupdate1c9f63449c4a6af) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: LibUsb-Win32 - Daemon, Version 0.1.10.1 (libusbd) - https://sourceforge.net/p/libusb-win32/wiki/Home/ - C:\Windows\system32\libusbd-nt.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: O&O Defrag - O&O Software GmbH - C:\Windows\system32\oodag.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
--
End of file - 8396 bytes
Configuration: Windows Vista Firefox 3.5.5
28 réponses
Le message initial combine un journal HijackThis et une question générale sur une éventuelle infection virale, alors que le système tourne sous Windows Vista SP2 et affiche de nombreux processus. Plusieurs réponses recommandent des outils dédiés tels que USBFix et l'exécution de procédures de nettoyage, puis partagent des tutoriels et des rapports pour guider l'utilisateur dans l'analyse et la suppression éventuelle. D'autres interventions évoquent l'utilisation de ComboFix et détaillent des suppressions liées à des fichiers système et à des répertoires temporaires, afin d'endiguer les traces d'infection et d'améliorer la stabilité. En complément, la discussion conseille de redémarrer à partir d'un support fiable et de vérifier l'intégrité du système avec des outils de sécurité, pour éviter faux positifs et suppressions involontaires.
-
c'est fini ou pas ?
-
verdict ?
-
ComboFix 09-11-07.04 - GEANT 08/11/2009 18:54.1.2 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6002.2.1252.33.1036.18.3582.2300 [GMT 1:00]
Lancé depuis: c:\users\GEANT\Desktop\7\ComboFix.exe
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin\S-1-5-21-1731295395-4246128571-3123795557-500
c:\$recycle.bin\S-1-5-21-192345369-2729201545-2745846667-1000
c:\$recycle.bin\S-1-5-21-1997964325-2578506214-2549165720-1000(0)
c:\$recycle.bin\S-1-5-21-2152478756-3922319563-605102323-500
c:\windows\system32\uninstall.exe
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-10-08 au 2009-11-08 ))))))))))))))))))))))))))))))))))))
.
2009-11-08 18:08 . 2009-11-08 18:09 -------- d-----w- c:\users\GEANT\AppData\Local\temp
2009-11-08 18:08 . 2009-11-08 18:08 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-11-08 18:08 . 2009-11-08 18:08 -------- d-----w- c:\users\Administrateur\AppData\Local\temp
2009-11-08 18:08 . 2009-11-08 18:08 -------- d-----w- c:\users\Administrateur.PATRICK\AppData\Local\temp
2009-11-08 16:00 . 2009-11-08 16:21 8192 d-----w- C:\ToolBar SD
2009-11-08 15:52 . 2009-11-08 16:36 4096 d-----w- c:\program files\ZHPDiag
2009-11-08 15:22 . 2009-11-08 15:46 4096 d-----w- C:\UsbFix
2009-11-08 11:30 . 2009-11-08 11:30 -------- d-----w- c:\users\GEANT\AppData\Roaming\VitySoft
2009-11-08 09:55 . 2009-11-08 13:59 4096 d-----w- c:\program files\JDownloader
2009-11-01 18:03 . 2009-11-01 18:03 -------- d-----w- c:\programdata\Sony Corporation
2009-10-31 17:42 . 2009-10-31 17:42 88 --sha-r- c:\windows\system32\F79E52E228.sys
2009-10-31 17:42 . 2009-10-31 17:42 1682 --sha-w- c:\windows\system32\KGyGaAvL.sys
2009-10-31 17:32 . 2009-10-31 17:32 -------- d-----w- c:\users\GEANT\AppData\Roaming\Corel
2009-10-31 17:29 . 2009-10-31 17:29 4096 d-----w- c:\program files\Corel(R) Painter(TM) IX.5 TBYB EN
2009-10-28 19:54 . 2009-10-28 19:54 -------- d-----w- c:\program files\Windows Portable Devices
2009-10-28 07:21 . 2009-09-10 02:00 92672 ----a-w- c:\windows\system32\UIAnimation.dll
2009-10-28 07:21 . 2009-09-10 02:00 1164800 ----a-w- c:\windows\system32\UIRibbonRes.dll
2009-10-28 07:21 . 2009-09-10 02:01 3023360 ----a-w- c:\windows\system32\UIRibbon.dll
2009-10-28 07:19 . 2009-10-01 01:02 30208 ----a-w- c:\windows\system32\WPDShextAutoplay.exe
2009-10-28 07:19 . 2009-10-01 01:02 31232 ----a-w- c:\windows\system32\BthMtpContextHandler.dll
2009-10-28 07:19 . 2009-10-01 01:01 81920 ----a-w- c:\windows\system32\wpdbusenum.dll
2009-10-28 07:19 . 2009-10-01 01:01 60928 ----a-w- c:\windows\system32\PortableDeviceConnectApi.dll
2009-10-28 07:19 . 2009-10-01 01:02 2537472 ----a-w- c:\windows\system32\wpdshext.dll
2009-10-28 07:19 . 2009-10-01 01:01 546816 ----a-w- c:\windows\system32\wpd_ci.dll
2009-10-28 07:19 . 2009-10-01 01:02 334848 ----a-w- c:\windows\system32\PortableDeviceApi.dll
2009-10-28 07:19 . 2009-10-01 01:02 87552 ----a-w- c:\windows\system32\WPDShServiceObj.dll
2009-10-28 07:19 . 2009-10-01 01:01 160256 ----a-w- c:\windows\system32\PortableDeviceTypes.dll
2009-10-28 07:19 . 2009-10-01 01:01 350208 ----a-w- c:\windows\system32\WPDSp.dll
2009-10-28 07:19 . 2009-10-01 01:01 196608 ----a-w- c:\windows\system32\PortableDeviceWMDRM.dll
2009-10-28 07:19 . 2009-10-01 01:01 100864 ----a-w- c:\windows\system32\PortableDeviceClassExtension.dll
2009-10-28 07:17 . 2009-10-08 21:07 4096 ----a-w- c:\windows\system32\oleaccrc.dll
2009-10-28 07:17 . 2009-10-08 21:08 555520 ----a-w- c:\windows\system32\UIAutomationCore.dll
2009-10-28 07:17 . 2009-10-08 21:08 234496 ----a-w- c:\windows\system32\oleacc.dll
2009-10-28 07:03 . 2009-09-10 14:58 310784 ----a-w- c:\windows\system32\unregmp2.exe
2009-10-28 07:03 . 2009-09-10 14:59 8147456 ----a-w- c:\windows\system32\wmploc.DLL
2009-10-23 08:27 . 2009-10-23 08:27 -------- d-----w- c:\users\GEANT\AppData\Roaming\InfraRecorder
2009-10-23 08:27 . 2009-10-23 08:27 4096 d-----w- c:\program files\InfraRecorder
2009-10-20 06:00 . 2009-08-07 02:24 44768 ----a-w- c:\windows\system32\wups2.dll
2009-10-20 06:00 . 2009-08-07 02:24 53472 ----a-w- c:\windows\system32\wuauclt.exe
2009-10-20 06:00 . 2009-08-07 02:23 1929952 ----a-w- c:\windows\system32\wuaueng.dll
2009-10-20 06:00 . 2009-08-07 01:45 2421760 ----a-w- c:\windows\system32\wucltux.dll
2009-10-20 06:00 . 2009-08-07 02:24 35552 ----a-w- c:\windows\system32\wups.dll
2009-10-20 06:00 . 2009-08-07 02:23 575704 ----a-w- c:\windows\system32\wuapi.dll
2009-10-20 06:00 . 2009-08-07 01:44 87552 ----a-w- c:\windows\system32\wudriver.dll
2009-10-20 06:00 . 2009-08-06 17:23 171608 ----a-w- c:\windows\system32\wuwebv.dll
2009-10-20 06:00 . 2009-08-06 16:44 33792 ----a-w- c:\windows\system32\wuapp.exe
2009-10-19 14:08 . 2009-10-19 14:13 4096 d-----w- c:\users\GEANT\UBCD
2009-10-15 06:08 . 2009-09-10 16:48 218624 ----a-w- c:\windows\system32\msv1_0.dll
2009-10-15 06:07 . 2009-08-04 12:34 3548216 ----a-w- c:\windows\system32\ntoskrnl.exe
2009-10-15 06:07 . 2009-08-04 12:34 3600456 ----a-w- c:\windows\system32\ntkrnlpa.exe
2009-10-15 06:07 . 2009-08-27 05:22 916480 ----a-w- c:\windows\system32\wininet.dll
2009-10-12 12:18 . 2009-10-12 12:18 4096 d-----w- c:\program files\FileZilla FTP Client
2009-10-12 12:18 . 2009-10-16 09:16 4096 d-----w- c:\users\GEANT\AppData\Roaming\FileZilla
2009-10-12 11:40 . 1997-01-31 18:24 941840 ----a-w- c:\windows\system\MFC42.DLL
2009-10-12 11:40 . 1997-01-23 04:07 271632 ----a-w- c:\windows\system\MSVCRT.DLL
2009-10-12 11:40 . 1996-06-14 16:50 65024 ----a-w- c:\windows\system\MSVCRT40.DLL
2009-10-12 11:40 . 1996-06-14 16:50 74752 ----a-w- c:\windows\system\MSVCIRT.DLL
2009-10-12 11:09 . 2009-10-12 11:11 -------- d-----w- c:\users\GEANT\EurekaLog
2009-10-12 11:07 . 2009-10-12 11:15 -------- d-----w- c:\users\GEANT\AppData\Roaming\ESTsoft
2009-10-12 11:07 . 2009-10-12 11:15 -------- d-----w- c:\programdata\ESTsoft
2009-10-12 11:07 . 2009-10-12 11:07 -------- d-----w- c:\program files\ESTsoft
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-08 18:01 . 2009-05-02 06:42 4096 d-----w- c:\users\GEANT\AppData\Roaming\DNA
2009-11-08 17:28 . 2009-01-19 14:51 4096 d-----w- c:\program files\IncrediMail
2009-11-08 17:27 . 2007-11-23 10:22 679180 ----a-w- c:\windows\system32\perfh00C.dat
2009-11-08 17:27 . 2007-11-23 10:22 128212 ----a-w- c:\windows\system32\perfc00C.dat
2009-11-08 17:23 . 2009-03-05 13:44 4096 d-----w- c:\programdata\Google Updater
2009-11-08 17:21 . 2007-11-23 02:13 4096 d-----w- c:\programdata\NVIDIA
2009-11-08 17:21 . 2009-08-31 17:02 32879 ----a-w- c:\programdata\nvModes.dat
2009-11-08 17:19 . 2009-05-02 06:43 32768 d-----w- c:\users\GEANT\AppData\Roaming\BitTorrent
2009-11-08 17:19 . 2009-03-30 09:25 20480 d-----w- c:\program files\Glary Utilities
2009-11-08 17:19 . 2009-02-05 12:38 4096 d-----w- c:\programdata\FLEXnet
2009-11-08 17:19 . 2007-11-23 02:19 8192 d-----w- c:\program files\Common Files\Adobe
2009-11-08 15:14 . 2009-01-19 14:38 4096 d-----w- c:\programdata\Spybot - Search & Destroy
2009-11-07 11:41 . 2009-07-07 18:27 -------- d-----w- c:\program files\Sony
2009-11-03 15:40 . 2009-07-24 17:52 -------- d-----w- c:\program files\NirSoft
2009-11-02 19:42 . 2009-10-03 06:20 195456 ------w- c:\windows\system32\MpSigStub.exe
2009-11-01 15:39 . 2009-05-20 11:01 -------- d-----w- c:\programdata\eMule
2009-10-28 19:54 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2009-10-28 19:54 . 2009-10-28 19:54 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2009-10-26 08:12 . 2009-01-19 16:29 1 ----a-w- c:\users\GEANT\AppData\Roaming\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-10-15 14:27 . 2006-11-02 11:18 4096 d-----w- c:\program files\Windows Mail
2009-10-15 06:20 . 2009-01-23 13:35 12288 d-----w- c:\programdata\Microsoft Help
2009-10-08 18:03 . 2009-02-15 08:25 -------- d-----w- c:\users\GEANT\AppData\Roaming\DivX
2009-10-08 18:01 . 2009-10-08 18:01 -------- d-----w- c:\program files\Common Files\Sony Shared
2009-10-08 18:00 . 2009-07-07 18:27 10134 ----a-r- c:\users\GEANT\AppData\Roaming\Microsoft\Installer\{0E532C84-4275-41B3-9D81-D4A1A20D8EE7}\ARPPRODUCTICON.exe
2009-10-08 07:21 . 2009-03-11 14:11 4096 d-----w- c:\program files\Fraps
2009-10-07 08:59 . 2009-01-19 15:02 4096 d-----w- c:\program files\Windows Live
2009-10-07 08:56 . 2009-01-22 13:30 -------- d-----w- c:\program files\Microsoft
2009-10-02 11:34 . 2009-10-02 11:29 -------- d-----w- c:\program files\Eurobarre
2009-10-02 11:29 . 2009-10-02 11:29 15872 ------w- c:\windows\system32\winskfr.dll
2009-10-01 13:55 . 2009-10-01 08:45 4096 d-----w- c:\program files\DRPU PC Data Manager(Basic)
2009-10-01 13:53 . 2009-03-03 09:08 4096 d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-10-01 12:08 . 2009-06-01 12:29 16164756 ----a-w- c:\users\GEANT\AppData\Roaming\kmsjsx32.sys
2009-10-01 12:08 . 2009-06-01 12:29 16164756 ----a-w- c:\users\GEANT\AppData\Roaming\kmsjsx32.sys
2009-10-01 11:38 . 2009-03-27 14:43 4045527 ----a-w- c:\programdata\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-09-25 21:17 . 2009-01-22 14:27 4096 d-----w- c:\program files\Google
2009-09-25 18:14 . 2008-07-09 08:59 8192 d-----w- c:\program files\DivX
2009-09-25 18:14 . 2009-09-25 18:14 4096 d-----w- c:\program files\Common Files\DivX Shared
2009-09-25 16:02 . 2009-01-19 14:38 8192 d-----w- c:\program files\Spybot - Search & Destroy
2009-09-25 08:18 . 2009-02-17 13:48 8192 d-----w- c:\program files\ma-config.com
2009-09-25 08:18 . 2009-02-17 13:48 -------- d-----w- c:\programdata\ma-config.com
2009-09-25 02:10 . 2009-10-28 07:20 974848 ----a-w- c:\windows\system32\WindowsCodecs.dll
2009-09-25 02:07 . 2009-10-28 07:20 189440 ----a-w- c:\windows\system32\WindowsCodecsExt.dll
2009-09-25 02:04 . 2009-10-28 07:20 321024 ----a-w- c:\windows\system32\PhotoMetadataHandler.dll
2009-09-25 01:49 . 2009-10-28 07:20 1554432 ----a-w- c:\windows\system32\xpsservices.dll
2009-09-25 01:48 . 2009-10-28 07:20 351232 ----a-w- c:\windows\system32\XpsPrint.dll
2009-09-25 01:38 . 2009-10-28 07:20 847360 ----a-w- c:\windows\system32\OpcServices.dll
2009-09-25 01:36 . 2009-10-28 07:20 280064 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2009-09-25 01:35 . 2009-10-28 07:20 135680 ----a-w- c:\windows\system32\XpsRasterService.dll
2009-09-25 01:33 . 2009-10-28 07:20 195584 ----a-w- c:\windows\system32\dxdiagn.dll
2009-09-25 01:33 . 2009-10-28 07:20 829440 ----a-w- c:\windows\system32\d3d10warp.dll
2009-09-25 01:33 . 2009-10-28 07:20 369664 ----a-w- c:\windows\system32\WMPhoto.dll
2009-09-25 01:32 . 2009-10-28 07:20 252928 ----a-w- c:\windows\system32\dxdiag.exe
2009-09-25 01:31 . 2009-10-28 07:20 519680 ----a-w- c:\windows\system32\d3d11.dll
2009-09-25 01:31 . 2009-10-28 07:20 486912 ----a-w- c:\windows\system32\d3d10level9.dll
2009-09-25 01:31 . 2009-10-28 07:20 161280 ----a-w- c:\windows\system32\d3d10_1.dll
2009-09-25 01:31 . 2009-10-28 07:20 218112 ----a-w- c:\windows\system32\d3d10_1core.dll
2009-09-25 01:31 . 2009-10-28 07:20 1030144 ----a-w- c:\windows\system32\d3d10.dll
2009-09-25 01:31 . 2009-10-28 07:20 828928 ----a-w- c:\windows\system32\d2d1.dll
2009-09-25 01:30 . 2009-10-28 07:20 481792 ----a-w- c:\windows\system32\dxgi.dll
2009-09-25 01:30 . 2009-10-28 07:20 190464 ----a-w- c:\windows\system32\d3d10core.dll
2009-09-25 01:27 . 2009-10-28 07:20 634880 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2009-09-25 01:27 . 2009-10-28 07:20 37888 ----a-w- c:\windows\system32\cdd.dll
2009-09-25 01:27 . 2009-10-28 07:20 793088 ----a-w- c:\windows\system32\FntCache.dll
2009-09-25 01:27 . 2009-10-28 07:20 1064448 ----a-w- c:\windows\system32\DWrite.dll
2009-09-24 22:54 . 2009-10-28 07:20 258048 ----a-w- c:\windows\system32\winspool.drv
2009-09-24 22:54 . 2009-10-28 07:20 667648 ----a-w- c:\windows\system32\printfilterpipelinesvc.exe
2009-09-24 22:54 . 2009-10-28 07:20 26112 ----a-w- c:\windows\system32\printfilterpipelineprxy.dll
2009-09-24 12:15 . 2009-09-24 12:15 93 ----a-w- c:\users\GEANT\AppData\Local\fusioncache.dat
2009-09-15 21:09 . 2009-09-15 21:09 823296 ----a-w- c:\windows\system32\divx_xx0c.dll
2009-09-15 21:09 . 2009-09-15 21:09 823296 ----a-w- c:\windows\system32\divx_xx07.dll
2009-09-15 21:09 . 2009-09-15 21:09 815104 ----a-w- c:\windows\system32\divx_xx0a.dll
2009-09-15 21:09 . 2009-09-15 21:09 811008 ----a-w- c:\windows\system32\divx_xx16.dll
2009-09-15 21:09 . 2009-09-15 21:09 802816 ----a-w- c:\windows\system32\divx_xx11.dll
2009-09-15 21:09 . 2009-09-15 21:09 685056 ----a-w- c:\windows\system32\DivX.dll
2009-09-15 08:13 . 2009-09-15 07:13 4096 d-----w- c:\program files\File Scavenger 3.2
2009-09-15 08:13 . 2009-05-12 07:07 -------- d-----w- c:\program files\OO Software
2009-09-14 09:29 . 2009-10-15 06:06 144896 ----a-w- c:\windows\system32\drivers\srv2.sys
2009-09-10 12:54 . 2009-03-03 09:08 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 12:53 . 2009-03-03 09:08 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-10 06:04 . 2009-09-09 11:16 -------- d-----w- c:\users\GEANT\AppData\Roaming\play2p
2009-09-10 06:04 . 2009-09-09 11:16 -------- d--h--w- c:\program files\InstallJammer Registry
2009-09-04 11:41 . 2009-10-15 06:06 60928 ----a-w- c:\windows\system32\msasn1.dll
2009-09-01 01:15 . 2009-09-01 01:15 90112 ----a-w- c:\windows\system32\dpl100.dll
2009-08-31 16:23 . 2009-03-12 09:20 1356 ----a-w- c:\users\GEANT\AppData\Local\d3d9caps.dat
2009-08-31 16:09 . 2007-11-23 02:11 319456 ----a-w- c:\windows\DIFxAPI.dll
2009-08-29 14:43 . 2009-08-29 14:43 6516755 ----a-w- c:\users\GEANT\AppData\Roaming\Azureus\plugins\vuzexcode\ffmpeg.exe
2009-08-29 14:43 . 2009-08-29 14:43 4141117 ----a-w- c:\users\GEANT\AppData\Roaming\Azureus\plugins\vuzexcode\mediainfo.exe
2009-08-29 07:12 . 2009-08-29 07:12 99678 ----a-r- c:\users\GEANT\AppData\Roaming\Microsoft\Installer\{22ACF3BE-56F6-49B1-824B-0C29528D9B76}\_B8DC617E7A2EE9641C49BA.exe
2009-08-29 07:12 . 2009-08-29 07:12 99678 ----a-r- c:\users\GEANT\AppData\Roaming\Microsoft\Installer\{22ACF3BE-56F6-49B1-824B-0C29528D9B76}\_4773399D562D487406E571.exe
2009-08-29 07:02 . 2009-08-29 07:02 99678 ----a-r- c:\users\GEANT\AppData\Roaming\Microsoft\Installer\{ECDF8120-703D-4A96-B36C-A565419B3900}\_61C9EF2163613C810CF5A2.exe
2009-08-29 07:02 . 2009-08-29 07:02 4286 ----a-r- c:\users\GEANT\AppData\Roaming\Microsoft\Installer\{ECDF8120-703D-4A96-B36C-A565419B3900}\_B89C7D3C6FDF73A877DF9B.exe
2009-08-29 00:27 . 2009-09-03 06:53 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2009-08-29 00:14 . 2009-09-03 06:53 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2009-08-27 05:17 . 2009-10-15 06:06 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-08-27 05:17 . 2009-10-15 06:06 109056 ----a-w- c:\windows\system32\iesysprep.dll
2009-08-27 03:42 . 2009-10-15 06:06 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-08-22 15:12 . 2009-08-22 15:12 858682 ----a-w- c:\users\GEANT\AppData\Roaming\Hide IP NG\hideipng-update.exe
2009-08-18 17:16 . 2009-08-31 16:09 1289760 ----a-w- c:\windows\system32\RtkPgExt.dll
2009-08-18 17:16 . 2009-08-31 16:09 53280 ----a-w- c:\windows\system32\RtkCoInst.dll
2009-08-18 17:15 . 2009-08-31 16:09 326176 ----a-w- c:\windows\system32\RtkApoApi.dll
2007-11-23 10:35 . 2007-11-23 10:24 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-18 125952]
"IncrediMail"="c:\program files\IncrediMail\bin\IncMail.exe" [2009-09-07 251336]
"RocketDock"="c:\program files\RocketDock\RocketDock.exe" [2007-09-02 495616]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"BitTorrent DNA"="c:\users\GEANT\Program Files\DNA\btdna.exe" [2009-05-03 321344]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-18 1008184]
"hpsysdrv"="c:\hp\support\hpsysdrv.exe" [2007-04-18 65536]
"KBD"="c:\hp\KBD\KbdStub.EXE" [2006-12-08 65536]
"OsdMaestro"="c:\program files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe" [2007-02-15 118784]
"OFFICEKB"="c:\program files\Labtec\Desktop\V5.1\kbdap32a.exe" [2008-07-15 387584]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-08-17 81000]
"B2C_AGENT"="c:\programdata\LGMOBILEAX\B2C_Client\B2CNotiAgent.exe" [2008-06-17 179536]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"OODefragTray"="c:\windows\system32\oodtray.exe" [2009-04-07 2553088]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" - c:\windows\KHALMNPR.Exe [2009-06-17 55824]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2009-3-18 813584]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0OODBS
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Y'z Shadow.lnk]
backup=c:\windows\pss\Y'z Shadow.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^Users^GEANT^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Logitech . Enregistrement du produit.lnk]
backup=c:\windows\pss\Logitech . Enregistrement du produit.lnk.Startup
backupExtension=.Startup
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
"FLMOFFICE4DMOUSE"=c:\program files\Labtec\Desktop\V5.1\moffice.exe
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
"VistaSp2"=hex(b):38,12,23,46,77,df,c9,01
R1 aswSP;avast! Self Protection;c:\windows\System32\drivers\aswSP.sys [19/01/2009 15:19 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\System32\drivers\aswFsBlk.sys [19/01/2009 15:19 20560]
R2 aswMonFlt;aswMonFlt;c:\windows\System32\drivers\aswMonFlt.sys [19/01/2009 15:18 53328]
R2 libusbd;LibUsb-Win32 - Daemon, Version 0.1.10.1;system32\libusbd-nt.exe --> system32\libusbd-nt.exe [?]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\System32\drivers\LMIRfsDriver.sys [22/01/2009 18:19 47640]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [17/08/2009 00:32 239648]
R2 wlidsvc;Windows Live ID Sign-in Assistant;c:\program files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE [30/03/2009 15:28 1533808]
R3 libusb0;LibUsb-Win32 - Kernel Driver, Version 0.1.10.1;c:\windows\System32\drivers\libusb0.sys [24/02/2009 10:33 33792]
S2 gupdate1c9f63449c4a6af;Service Google Update (gupdate1c9f63449c4a6af);c:\program files\Google\Update\GoogleUpdate.exe [26/06/2009 09:01 133104]
S3 FlashUSB;Flash Loader utility driver;c:\windows\System32\drivers\FlashUSB.sys [07/03/2009 08:17 15453]
S3 FontCache;Service de cache de police Windows;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [22/01/2009 10:11 21504]
S3 Ltn_stk7070P;PCTV based TV tuner device;c:\windows\System32\drivers\Ltn_stk7070P.sys [09/07/2008 09:58 466048]
S3 Ltn_stkrc;PCTV Infrared Receiver;c:\windows\System32\drivers\Ltn_stkrc.sys [09/07/2008 09:58 13440]
S3 maconfservice;Ma-Config Service;c:\program files\ma-config.com\maconfservice.exe [23/09/2009 13:50 238960]
S3 PCD5SRVC{BD6912E3-AC9D80E8-05040000};PCD5SRVC{BD6912E3-AC9D80E8-05040000} - PCDR Kernel Mode Service Helper Driver;c:\progra~1\PC-DOC~1\PCD5SRVC.pkms [13/09/2007 02:35 25760]
--- Autres Services/Pilotes en mémoire ---
*NewlyCreated* - MBR
*NewlyCreated* - PROCEXP113
*Deregistered* - mbr
*Deregistered* - PROCEXP113
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
Contenu du dossier 'Tâches planifiées'
2009-11-08 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2009-03-30 07:49]
2009-11-08 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-05 16:37]
2009-11-08 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-06-26 08:01]
2009-11-08 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-06-26 08:01]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://mystart.incredimail.com/
mStart Page = hxxp://www.01net.com/telecharger/
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\GEANT\AppData\Roaming\Mozilla\Firefox\Profiles\q0qeimvf.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.fr
FF - prefs.js: keyword.URL - hxxp://mystart.incredimail.com/?loc=ff_address_bar&search=
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\ma-config.com\nphardwaredetection.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\VideoLAN\npvlc.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: c:\users\GEANT\Program Files\DNA\plugins\npbtdna.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- PARAMETRES FIREFOX ----
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-11-08 19:09
Windows 6.0.6002 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll >>UNKNOWN [0x858A61F8]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\atapi -> 0x858a51f8
Warning: possible MBR rootkit infection !
user & kernel MBR OK
Use "Recovery Console" command "fixmbr" to clear infection !
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\PCD5SRVC{BD6912E3-AC9D80E8-05040000}]
"ImagePath"="\??\c:\progra~1\PC-DOC~1\PCD5SRVC.pkms"
.
Heure de fin: 2009-11-08 19:13
ComboFix-quarantined-files.txt 2009-11-08 18:13
Avant-CF: 204 205 477 888 octets libres
Après-CF: 204 206 886 912 octets libres
- - End Of File - - 232CE7385733E74BA3EC9C4A04C2B6D0 -
c'est pas fini encore . oki je ferrais sa plus tard car mon pere et sur son ordi portable
-
Contributeur sécurité-+-+-+-+-> ComboFix <-+-+-+-
[x] Télécharge ComboFix ( de sUBs ) à cette adresse.
[x] /!\ Fermez toutes les fenêtres de programme ouvertes /!\
[x] /!\ Désactivez toutes les protections résidentes ( Antivirus, Pare-Feu, AntiSpyware ) /!\
[x] Double clique sur " Combofix.exe "
[x] Suis les indications qui sont données à l'écran, à un moment tu auras un message te demandant d'installer la console de récupération, fais le
[x] Combofix va maintenant déconnecter ton PC d'internet
[x] Pendant le scan, ne touche à rien ( souris, clavier )
[x] A la fin du scan, le rapport s'ouvrira automatiquement, copie/colle le dans ton prochain message.
[o] Nb : Si jamais il ne s'ouvrait pas, il se trouve sous C:\Combofix.txt -
c'est bon ?
-
-
Contributeur sécuritéBon, pas grave.
Refais un rapport ZHPDiag stp -
wé j'ai un rapport tb.txt:
-----------\\ ToolBar S&D 1.2.9 XP/Vista
Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6002 ) Service Pack 2
X86-based PC ( Multiprocessor Free : AMD Athlon(tm) 64 X2 Dual Core Processor 6000+ )
BIOS : Phoenix - AwardBIOS v6.00PG
USER : GEANT ( Administrator )
BOOT : Normal boot
B:\ (Local Disk) - NTFS - Total:102 Go (Free:52 Go)
C:\ (Local Disk) - NTFS - Total:319 Go (Free:188 Go)
D:\ (Local Disk) - NTFS - Total:10 Go (Free:0 Go)
E:\ (CD or DVD)
F:\ (USB)
G:\ (USB)
H:\ (USB)
I:\ (USB)
J:\ (Local Disk) - NTFS - Total:34 Go (Free:23 Go)
K:\ (CD or DVD)
"C:\ToolBar SD" ( MAJ : 22-08-2009|18:42 )
Option : [2] ( 08/11/2009|17:20 )
[ UAC => 1 ]
-----------\\ Recherche de Fichiers / Dossiers ...
-----------\\ [..\Internet Explorer\Main]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Local Page"="C:\\Windows\\system32\\blank.htm"
"Default_Page_URL"="https://www.01net.com/telecharger/"
"Url"="http://go.microsoft.com/fwlink/?LinkId=75720"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Start Page"="https://www.msn.com/fr-fr/"
"Default_Page_URL"="https://www.01net.com/telecharger/"
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Local Page"="C:\\Windows\\System32\\blank.htm"
--------------------\\ Recherche d'autres infections
le programme qui bloque a recherche d'autre infection c'est: utilitaire de recherches de chaines de caractere -
Contributeur sécuritétu as un rapport sous C:\TB.txt ?
-
oki mais a recherche d'autre infection sa bloque a chaque fichier et j'ai un message comme quoi un programme ne repond plus et c'est toujours le meme .
-
Contributeur sécuritédirectement suppression
-
je fais une recherche avant ou je fais direct supression ?
-
Contributeur sécuritéIl faut que tu passes toolbar S&D comme indiqué dans mon dernier message.
-
a ok desoler
-
mecano je l'ai déja fais.
laisse xplode m'aidez pour le moment car sinon si tout le monde s'y met je vais me perdre -
bonjour telechargez ceci https://www.androidworld.fr/
puis ceun petit tutoriel la https://www.malekal.com/usbfix-supprimer-virus-usb/
installe le puis
Branche tout tes médias amovibles ( clés USB, DD externe, Cartes SD )
Lance USBfix en cliquant sur l'icône qui est sur ton bureau ( Clique droit -> Executer en tant qu'administrateur pour vista )
Choisis l'option F ( pour français ) et valide en appuyant sur entrée.
Au menu principal, choisis l'option 2
Laisse l'outil travailler puis poste le rapport dans ton prochain message
et voila normalement sa marche -
Malwarebyte's Anti-Malware je l'ai déja , j'ai fais un test rapide , il a rien trouve
-
Contributeur sécurité-+-+-+-> Toolbar S&D <-+-+-+-
[x]Télécharge Toolbar S&D sur ton bureau
[x] Suis le tutoriel disponible à cette adresse
/!\ Si tu es sous vista, lance le en cliquant droit dessus puis " Executer en tant qu'administrateur " /!\
[x] Lance l'option 2 ( Suppression )
[x] Puis copie/colle le rapport dans ton prochain message ( Il se trouve sous C:\TB.txt )
======================================================================
-+-+-+-> Malwarebyte's Anti-Malware <-+-+-+-
[x] Télécharge Malwarebyte's anti-malware
[x] Installe le en prenant soin de le mettre à jour à la fin de l'installation.
[x] Lance un scan complet.
[x] Coche bien tout les éléments trouvés et supprime les.
[x] A la fin du scan, copie/colle le contenu du rapport qui s'ouvrira. S'il ne s'ouvre pas, il se trouve dans la partie " Rapports/Logs " de malwarebyte's.
[x] N'oublie pas de vider la quarantaine de malwarebyte's.
Nb : Un tutoriel pour son utilisation est disponible à cette adresse -
- 1
- 2