Aide pour analyse hijhackthis SVP

Résolu
Bonjour a tous, je vous présente mon problème :

Depuis hier soir mon pc rencontre de gros ralentissements,j'ai donc fait une analyse de virus avec mon antivirus antivir puis il a trouver certain virus dans le dossier c:\windows\sysWOW64. Après les avoir nettoyés le pc se comporté déjà un peu mieux mais toujours quelques ralentissements.
Il y a aussi depuis quelques temps le problème avec internet, quand je fais une recherche sur google et que je clique sur un lien proposé, firefox me renvoi sur une autre page qui n'a rien a voir ( souvent des pub ).
J'ai donc décidé de faire une analyse hijackthis mais ne comprenant rien a ce logiciel je voudrais , SVP, que quelqu'un m'aide a y voir plus claire.
Je vous remercie d'avance pour vos futurs réponses et vous souhaite une agréable journée.

analyse hijackthis :

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:12:35, on 14/02/2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v7.00 (7.00.6002.18005)
Boot mode: Normal

Running processes:
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\backWeb-8876480.exe
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe­
C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSOEMON.EXE
C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Users\Alexandre\AppData\Roaming\SystemProc\lsass.exe
C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files (x86)\Logitech\QuickCam\Quickcam.exe
C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3SRCHMN.EXE
C:\Program Files (x86)\Java\jre6\bin\jusched.exe
C:\Program Files (x86)\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDSMSNLoader32.exe
D:\programmes\firefox\firefox.exe
C:\Users\Alexandre\Downloads\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&l=040c&s=1&o=vp64&d=1006&m=aspire_x1700
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://hp.mywebsearch.com/mywebsearch/index.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&l=040c&s=1&o=vp64&d=1006&m=aspire_x1700
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&l=040c&s=1&o=vp64&d=1006&m=aspire_x1700
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = localhost:8800
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSSRCAS.DLL
F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {00609A15-6FE9-4F89-A355-B8EE368184F1} - C:\Windows\SysWow64\GameUXLegacyGDFs32.dll
O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSSRCAS.DLL
O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSBAR.DLL
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll
O3 - Toolbar: My Web Search - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Program Files (x86)\MyWebSearch\bar\1.bin\MWSBAR.DLL
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [PCMMediaSharing] "C:\Program Files (x86)\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe"
O4 - HKLM\..\Run: [BkupTray] "C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files (x86)\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [MyWebSearch Plugin] rundll32 C:\PROGRA~2\MYWEBS~1\bar\1.bin\M3PLUGIN.DLL,UPF
O4 - HKLM\..\Run: [My Web Search Bar Search Scope Monitor] "C:\PROGRA~2\MYWEBS~1\bar\1.bin\m3SrchMn.exe" /m=2 /w /h
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~2\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\programmes\adobe reader\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~2\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - HKCU\..\Run: [FlashGet 3] "C:\Program Files (x86)\FlashGet Network\FlashGet 3\Flashget3.exe" -minimize
O4 - HKCU\..\Run: [FlashGetBHO] "C:\Program Files (x86)\FlashGet Network\FlashGet 3\mxhelper.exe"
O4 - HKCU\..\Run: [PPAP] C:\ProgramData\PPLiveVA\Application\PPAP.exe
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [RTHDBPL] C:\Users\Alexandre\AppData\Roaming\SystemProc\lsass.exe
O4 - HKCU\..\Run: [Sony Ericsson PC Companion] "C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe" /systray /nologon
O4 - Startup: Eurobarre.lnk = C:\Program Files (x86)\Eurobarre\eb.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZJxdm351YYFR
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\Windows\System32\glu3232.dll,C:\Windows\System32\dpwsockx32.dll,C:\Windows\System32\GuidedHelp32.dll,C:\Windows\System32\drmmgrtn32.dll,C:\Windows\System32\fontsub32.dll,C:\Windows\System32\GuidedHelp3232.dll,C:\Windows\System32\dot3api32.dll,C:\Windows\System32\drprov32.dll,C:\Windows\System32\fphc32.dll,C:\Windows\System32\jly2wkfsn32.dll,C:\Windows\System32\dot3dlg32.dll,C:\Windows\System32\tdwxv5aj432.dll,C:\Windows\System32\framedyn32.dll,C:\Windows\System32\8a6dyvmb32.dll,C:\Windows\System32\dot3gpclnt32.dll,C:\Windows\System32\huc16o3zdp1tmz32.dll,C:\Windows\System32\rhzmy5d32.dll,C:\Windows\System32\3kcip2h32.dll,C:\Windows\System32\cznwia32.dll,C:\Windows\System32\mj49bs3fp32.dll
O23 - Service: Acer HomeMedia Connect Service - CyberLink - C:\Program Files (x86)\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Service d'état ASP.NET (aspnet_state) - Unknown owner - C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: NTI Backup Now 5 Agent Service (BUNAgentSvc) - NewTech Infosystems, Inc. - C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: eDataSecurity Service - Egis Incorporated - C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
O23 - Service: Empowering Technology Service (ETService) - Unknown owner - C:\Program Files\Acer\Empowering Technology\Service\ETService.exe
O23 - Service: Service Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LogMeIn Hamachi 2.0 Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - D:\programmes\hamachi\hamachi-2.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Process Monitor (LVPrcS64) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: My Web Search Service (MyWebSearchService) - MyWebSearch.com - C:\PROGRA~2\MYWEBS~1\bar\1.bin\mwssvc.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)
O23 - Service: NTI Backup Now 5 Backup Service (NTIBackupSvc) - NewTech InfoSystems, Inc. - C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
O23 - Service: NTI Backup Now 5 Scheduler Service (NTISchedulerSvc) - Unknown owner - C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: Sony Ericsson OMSI download service (OMSI download service) - Unknown owner - C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files (x86)\CyberLink\Shared Files\RichVideo.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: wampapache - Apache Software Foundation - D:\programmes\wamp\bin\apache\apache2.2.11\bin\httpd.exe
O23 - Service: wampmysqld - Unknown owner - D:\programmes\wamp\bin\mysql\mysql5.1.36\bin\mysqld.exe
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
Configuration: Windows Vista
Firefox 3.5.7

48 réponses

Résumé de la discussion

Ralentissements importants et redirections vers des pages publicitaires surviennent après la détection de virus dans le dossier c:\Windows\SysWOW64 et l’analyse antivirus initiale sur l’ordinateur personnel. Des éléments de réponse essentiels indiquent que le problème pourrait être dû à des barres d’outils indésirables et à des modifications du navigateur, comme des BHO et un proxy local configuré sur localhost:8800. Le rapport HijackThis signale de nombreux composants potentiellement indésirables, notamment MyWebSearch, Google Toolbar et des pages de démarrage modifiées, ainsi que des services et processus s’exécutant au démarrage. En complément, le fichier AppInit_DLLs et d’autres entrées de registre associées soulignent des modifications profondes; un nettoyage complet nécessite souvent une remise à zéro des paramètres du navigateur et la suppression des extensions indésirables.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    Cela a été avec plaisir ;)
    0
    1. Je te remercie énormément.

      Bonne soirée a toi.
      0
      1. Contributeur sécurité
        Ok c'est bon

        Vide la quarantaine de ZHPfix.

        Dans Hijackthis j'ai oublié une ligne a fixer.

        -> Relance Hijackthis
        -> Clique sur Do a system scan only
        -> Coche cette ligne

        O20 - AppInit_DLLs: C:\Windows\System32\glu3232.dll,C:\Windows\System32\dpwsockx32.dll,C:\Windows\System32\GuidedHelp32.dll,C:\Windows\System32\drmmgrtn32.dll,C:\Windows\System32\fontsub32.dll,C:\Windows\System32\GuidedHelp3232.dll,C:\Windows\System32\dot3api32.dll,C:\Windows\System32\drprov32.dll,C:\Windows\System32\fphc32.dll,C:\Windows\System32\jly2wkfsn32.dll,C:\Windows\System32\dot3dlg32.dll,C:\Windows\System32\tdwxv5aj432.dll,C:\Windows\System32\framedyn32.dll,C:\Windows\System32\8a6dyvmb32.dll,C:\Windows\System32\dot3gpclnt32.dll,C:\Windows\System32\huc16o3zdp1tmz32.dll,C:\Windows\System32\rhzmy5d32.dll,C:\Windows\System32\3kcip2h32.dll,C:\Windows\System32\cznwia32.dll,C:\Windows\System32\mj49bs3fp32.dll

        -> Clique sur Fix checked

        Si tu n'a plus rien a me signaler tu peux mettre ton sujet en résolu.

        Il me reste plus qu'a te souhaiter un bon surf sur le web et a être vigilent ;)

        NicoVA
        0
        1. Je vien de le lancer en administrateur :

          ZHPFix v1.12.302 by Nicolas Coolman - Rapport de suppression du 16/02/2010 16:25:25
          Fichier d'export Registre :
          Web site : http://www.premiumorange.com/zeb-help-process/zhpfix.html

          Processus mémoire :
          (Néant)

          Module mémoire :

          Clé du Registre :

          Valeur du Registre :

          Elément de données du Registre :

          Dossier :

          Fichier :
          O4 - Global Startup: Eurobarre.lnk . (.Pas de propriétaire - Pas de description.) -- C:\Program Files (x86)\Eurobarre\eb.exe => Supprimé et mis en quarantaine

          Logiciel :
          O42 - Logiciel: Eurobarre - (.Pas de propriétaire.) => Logiciel absent

          Script Registre :

          Autre :

          Récapitulatif :
          Processus mémoire : 0
          Module mémoire : 0
          Clé du Registre : 0
          Valeur du Registre : 0
          Elément de données du Registre : 0
          Dossier : 0
          Fichier : 1
          Logiciel : 1
          Autre : 0

          End of the scan
          0
          1. zhpfix me dit acces refusé.
            0
            1. Contributeur sécurité
              Salut

              1)

              -> Relance Hijackthis

              -> Clique sur Do a system scan only

              -> Coche les lignes suivantes


              O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\programmes\adobe reader\Reader\Reader_sl.exe"
              O4 - HKCU\..\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
              O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
              O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
              O4 - Startup: Eurobarre.lnk = C:\Program Files (x86)\Eurobarre\eb.exe
              O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
              O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)


              2) Désolé j'ai oublié de faire faire une manip avec ZHPfix

              +-+-+-+-+> ZHPDiag <+-+-+-+-+

              ▶ Télécharge lZHPDiag

              ▶ Laisse toi guider lors de l'installation, il se lancera automatiquement à la fin.

              Clique sur le Bouclier ou ouvre ZHPFix via le raccourci présent.

              Clique sur le H ( coller les lignes Helper )

              ▶ Copie et colle ces lignes

              O4 - Global Startup: Eurobarre.lnk . (.Pas de propriétaire - Pas de description.) -- C:\Program Files (x86)\Eurobarre\eb.exe
              O42 - Logiciel: Eurobarre - (.Pas de propriétaire.)


              ▶ Clique sur Tous puis Nettoyer

              ▶ Copie et colle le rapport de ZHPfix
              0
              1. Hijackthis :

                Logfile of Trend Micro HijackThis v2.0.2
                Scan saved at 11:15:09, on 16/02/2010
                Platform: Windows Vista SP2 (WinNT 6.00.1906)
                MSIE: Internet Explorer v7.00 (7.00.6002.18005)
                Boot mode: Normal

                Running processes:
                C:\Program Files\Logitech\Desktop Messenger\8876480\Program\backWeb-8876480.exe
                C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe
                C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe
                C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
                C:\Program Files (x86)\Logitech\QuickCam\Quickcam.exe
                C:\Program Files (x86)\Java\jre6\bin\jusched.exe
                C:\Program Files (x86)\Common Files\Logishrd\LQCVFX\COCIManager.exe
                C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDSMSNLoader32.exe
                D:\programmes\firefox\firefox.exe
                C:\Program Files (x86)\Trend Micro\HijackThis\HijackThis.exe

                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://go.microsoft.com/fwlink/?linkid=54896
                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
                R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
                R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer
                R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = localhost:8800
                R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                O1 - Hosts: ::1 localhost
                O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
                O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
                O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll
                O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
                O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll
                O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll
                O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll
                O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
                O4 - HKLM\..\Run: [PCMMediaSharing] "C:\Program Files (x86)\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe"
                O4 - HKLM\..\Run: [BkupTray] "C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe"
                O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
                O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files (x86)\Logitech\QuickCam\Quickcam.exe" /hide
                O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
                O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre6\bin\jusched.exe"
                O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\programmes\adobe reader\Reader\Reader_sl.exe"
                O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
                O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
                O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                O4 - HKCU\..\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
                O4 - HKCU\..\Run: [FlashGet 3] "C:\Program Files (x86)\FlashGet Network\FlashGet 3\Flashget3.exe" -minimize
                O4 - HKCU\..\Run: [FlashGetBHO] "C:\Program Files (x86)\FlashGet Network\FlashGet 3\mxhelper.exe"
                O4 - HKCU\..\Run: [PPAP] C:\ProgramData\PPLiveVA\Application\PPAP.exe
                O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
                O4 - HKCU\..\Run: [Sony Ericsson PC Companion] "C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe" /systray /nologon
                O4 - HKCU\..\Run: [FileHippo.com] "C:\Program Files (x86)\FileHippo.com\UpdateChecker.exe" /background
                O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                O4 - Startup: Eurobarre.lnk = C:\Program Files (x86)\Eurobarre\eb.exe
                O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
                O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
                O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
                O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
                O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
                O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
                O13 - Gopher Prefix:
                O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/...
                O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
                O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
                O20 - AppInit_DLLs: C:\Windows\System32\glu3232.dll,C:\Windows\System32\dpwsockx32.dll,C:\Windows\System32\GuidedHelp32.dll,C:\Windows\System32\drmmgrtn32.dll,C:\Windows\System32\fontsub32.dll,C:\Windows\System32\GuidedHelp3232.dll,C:\Windows\System32\dot3api32.dll,C:\Windows\System32\drprov32.dll,C:\Windows\System32\fphc32.dll,C:\Windows\System32\jly2wkfsn32.dll,C:\Windows\System32\dot3dlg32.dll,C:\Windows\System32\tdwxv5aj432.dll,C:\Windows\System32\framedyn32.dll,C:\Windows\System32\8a6dyvmb32.dll,C:\Windows\System32\dot3gpclnt32.dll,C:\Windows\System32\huc16o3zdp1tmz32.dll,C:\Windows\System32\rhzmy5d32.dll,C:\Windows\System32\3kcip2h32.dll,C:\Windows\System32\cznwia32.dll,C:\Windows\System32\mj49bs3fp32.dll
                O23 - Service: Acer HomeMedia Connect Service - CyberLink - C:\Program Files (x86)\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe
                O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
                O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
                O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
                O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
                O23 - Service: Service d'état ASP.NET (aspnet_state) - Unknown owner - C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
                O23 - Service: NTI Backup Now 5 Agent Service (BUNAgentSvc) - NewTech Infosystems, Inc. - C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
                O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
                O23 - Service: eDataSecurity Service - Egis Incorporated - C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
                O23 - Service: Empowering Technology Service (ETService) - Unknown owner - C:\Program Files\Acer\Empowering Technology\Service\ETService.exe
                O23 - Service: Service Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
                O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
                O23 - Service: LogMeIn Hamachi 2.0 Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - D:\programmes\hamachi\hamachi-2.exe
                O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
                O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
                O23 - Service: Process Monitor (LVPrcS64) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
                O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
                O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
                O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
                O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)
                O23 - Service: NTI Backup Now 5 Backup Service (NTIBackupSvc) - NewTech InfoSystems, Inc. - C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
                O23 - Service: NTI Backup Now 5 Scheduler Service (NTISchedulerSvc) - Unknown owner - C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
                O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
                O23 - Service: Sony Ericsson OMSI download service (OMSI download service) - Unknown owner - C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe
                O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
                O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
                O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files (x86)\CyberLink\Shared Files\RichVideo.exe
                O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
                O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
                O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
                O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
                O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
                O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
                O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
                O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
                O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
                O23 - Service: wampapache - Apache Software Foundation - D:\programmes\wamp\bin\apache\apache2.2.11\bin\httpd.exe
                O23 - Service: wampmysqld - Unknown owner - D:\programmes\wamp\bin\mysql\mysql5.1.36\bin\mysqld.exe
                O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
                O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
                0
                1. Contributeur sécurité
                  Et ba c'est parfait ca !

                  Bon maintenant suis cette procédure pour finaliser c'est très important si tu ne veut pas revenir avec une infection ;)

                  1: ToolsCleaner

                  Pour supprimer toutes les traces des logiciels qui ont servi à traiter les infections spécifiques :

                  ▶ Télécharge Toolscleaner sur ton Bureau

                  Sous XP : Double-clique sur ToolsCleaner2.exe
                  Sous Vista : Fais un clic droit sur ToolsCleaner2.exe et sélectionne "Exécuter en tant qu'administrateur"

                  ▶ Clique sur Recherche et laisse le scan se terminer.
                  ▶ Clique sur Suppression pour finaliser.
                  ▶ Tu peux, si tu le souhaites, te servir des Options facultatives.
                  ▶ Clique sur Quitter, pour que le rapport puisse se créer.
                  ▶ Le rapport (TCleaner.txt) se trouve à la racine de votre disque dur (C:\)...colle le dans ta réponse

                  ------------------------------------------------------------------------

                  2: Nettoyage des fichiers temporaires

                  Télécharge ATFcleaner par Atribune

                  ♠ Sous XP : Double-clique sur ATF-Cleaner.exe
                  ♠ Sous Vista : Fais un clic droit sur ATF-Cleaner.exe et choisis " Exécuter en tant qu'administrateur "

                  ▶ Voici un Tutorial pour bien l'utiliser

                  ------------------------------------------------------------------------

                  3: Purger la restauration système

                  ♠ Sous XP

                  → Désactiver la restauration du système

                  ♦ Clic droit sur le Poste de travailPropriétésOnglet Restauration du système ⇒ coche la case Désactiver la Restauration du système sur tous les lecteursAppliquerOk

                  → Ré-activer la restauration du système

                  Suis le même chemin ⇒ décoche la case Désactiver la Restauration du système sur tous les lecteursAppliquer

                  ♠ Sous Vista/Seven

                  → Désactiver la restauration du système

                  ♦ Clique droit sur OrdinateurPropriétésParamètres système avancés ⇒ onglet Protection du Système
                  Décoche tes partitions, un message de confirmation va apparaître clique sur Désactiver la protection du systèmeAppliquerOK.

                  → Ré-activer la restauration du système

                  ♦ Suis le même chemin , décoche Désactiver la protection du système
                  Appliquer
                  OK.

                  Redémarre le PC

                  ------------------------------------------------------------------------

                  4: Créer un point de restauration

                  Sous XP et VISTA

                  ------------------------------------------------------------------------

                  5: Mises à Jour importantes

                  ♠ Pour Windows

                  ♦ Rends toi ICI

                  ♦ Ferme toutes les applications en cours

                  ♠ Télécharge Update Checker

                  ♠ Voici un tutorial pour t'aider

                  --> Regarde ceci qui est très intéréssant

                  ------------------------------------------------------------------------

                  6: Hijackthis de TrendMicro

                  ♠ Télécharge Hijackthis de TredMicro

                  ♠ Fais un double-clic sur HJTInstall.exe

                  ♠ Clique sur Install puis sur I Accept

                  ♠ Clique sur do a system scan and save the logfile

                  Copie et colle le contenu du log qui apparaitra

                  Tutorial animée ( De baltrap34 merci ! )

                  ♠ Donc pour ta prochaine réponse oublie pas

                  ♦ Le rapport Hijackthis
                  ♦ Le rapport ToolsCleaner2
                  0
                  1. Scan MBAM :

                    Malwarebytes' Anti-Malware 1.44
                    Version de la base de données: 3741
                    Windows 6.0.6002 Service Pack 2
                    Internet Explorer 7.0.6002.18005

                    15/02/2010 21:35:56
                    mbam-log-2010-02-15 (21-35-56).txt

                    Type de recherche: Examen complet (C:\|)
                    Eléments examinés: 306227
                    Temps écoulé: 1 hour(s), 1 minute(s), 38 second(s)

                    Processus mémoire infecté(s): 0
                    Module(s) mémoire infecté(s): 0
                    Clé(s) du Registre infectée(s): 0
                    Valeur(s) du Registre infectée(s): 0
                    Elément(s) de données du Registre infecté(s): 0
                    Dossier(s) infecté(s): 0
                    Fichier(s) infecté(s): 0

                    Processus mémoire infecté(s):
                    (Aucun élément nuisible détecté)

                    Module(s) mémoire infecté(s):
                    (Aucun élément nuisible détecté)

                    Clé(s) du Registre infectée(s):
                    (Aucun élément nuisible détecté)

                    Valeur(s) du Registre infectée(s):
                    (Aucun élément nuisible détecté)

                    Elément(s) de données du Registre infecté(s):
                    (Aucun élément nuisible détecté)

                    Dossier(s) infecté(s):
                    (Aucun élément nuisible détecté)

                    Fichier(s) infecté(s):
                    (Aucun élément nuisible détecté)
                    0
                    1. Contributeur sécurité
                      Bon alors

                      ▶ Télécharge Ccleaner

                      Tutorial ici pour l'utiliser

                      -------------------------------------------------------------------------------------

                      Relance MBAM

                      ▶ Fait la mise à jour

                      ▶ Exécute un scan complet

                      ▶ Poste le rapport qui apparaitra
                      0
                      1. Eurobarre a était désinstallé il y a plusieurs mois.

                        Je viens de vider les quarantaine et oui j'ai supprimé les cracks et Keygens.
                        0
                        1. Contributeur sécurité
                          Hum bizarre.

                          1) Désinstalle Eurobarre

                          2) Supprime C:\Program Files (x86)\Eurobarre

                          3) Vide la quarantaine de MBAM et de Antivir si ce n'est déjà fait.

                          4) A tu supprimé tous les cracks et Keygens que tu a téléchargé ? Car c'est un véritable vecteur d'infection.

                          Ps: j'attends confirmation au sujet du rapport ZHPdiag et je te posterais la suite ;)
                          0
                          1. rapport ZHPDiag :

                            http://www.cijoint.fr/cjlink.php?file=cj201002/cijkivkgW8.txt
                            0
                            1. dot3api :

                              http://www.virustotal.com/fr/analisis/cd9b0ae2fdf22b694fd2e3fd92c751aaecddd85779d6f8ccd7efcd3cc8c1161b-1239896899

                              drprov :

                              http://www.virustotal.com/fr/analisis/569f05dc50651165fd734c19767c10e7c9dff03157b8222c59544a35a38e1c75-1254232634

                              dot3dlg :

                              http://www.virustotal.com/fr/analisis/77dd622a6b4a6f62ee9d735afa979f9babb5d332623140aec8d728037cc5e2c7-1255121557

                              Pas de fichier jly2wkfsn.
                              0
                              1. Contributeur sécurité
                                1)

                                Fait la procédure avec VirusTotal pour les fichiers que tu a ( sans le 32 ) pour voir si ils sont infectieux.

                                2)


                                Peut tu faire un ZHPdiag ? Car OTM n'a pas trouvé les fichiers donc normalement ils ne devraient pas être sur le rapport.

                                A++
                                0
                                1. rapport OTM :

                                  All processes killed
                                  ========== FILES ==========
                                  File/Folder c:\windows\system32\GuidedHelp3232.dll not found.
                                  File/Folder C:\Windows\System32\dot3api32.dll not found.
                                  File/Folder C:\Windows\System32\drprov32.dll not found.
                                  File/Folder C:\Windows\System32\fphc32.dll not found.
                                  File/Folder C:\Windows\System32\jly2wkfsn32.dll not found.
                                  File/Folder C:\Windows\System32\dot3dlg32.dll not found.
                                  File/Folder C:\Windows\System32\tdwxv5aj432.dll not found.
                                  File/Folder C:\Windows\System32\framedyn32.dll not found.
                                  File/Folder C:\Windows\System32\8a6dyvmb32.dll not found.
                                  File/Folder C:\Windows\System32\dot3gpclnt32.dll not found.
                                  File/Folder C:\Windows\System32\huc16o3zdp1tmz32.dll not found.
                                  File/Folder C:\Windows\System32\rhzmy5d32.dll not found.
                                  File/Folder C:\Windows\System32\3kcip2h32.dll not found.
                                  File/Folder C:\Windows\System32\cznwia32.dll not found.
                                  File/Folder C:\Windows\System32\mj49bs3fp32.dll not found.
                                  File/Folder C:\Program Files (x86)\Eurobarre not found.
                                  C:\Program Files (x86)\DAEMON Tools Toolbar folder moved successfully.
                                  ========== COMMANDS ==========

                                  [EMPTYTEMP]

                                  User: Alexandre
                                  ->Temp folder emptied: 4653433107 bytes
                                  ->Temporary Internet Files folder emptied: 54615499 bytes
                                  ->Java cache emptied: 53807036 bytes
                                  ->FireFox cache emptied: 94453312 bytes

                                  User: All Users

                                  User: Default
                                  ->Temp folder emptied: 0 bytes
                                  ->Temporary Internet Files folder emptied: 33170 bytes

                                  User: Default User
                                  ->Temp folder emptied: 0 bytes
                                  ->Temporary Internet Files folder emptied: 0 bytes

                                  User: Public

                                  %systemdrive% .tmp files removed: 0 bytes
                                  %systemroot% .tmp files removed: 466944 bytes
                                  %systemroot%\System32 .tmp files removed: 0 bytes
                                  %systemroot%\System32 (64bit) .tmp files removed: 0 bytes
                                  %systemroot%\System32\drivers .tmp files removed: 0 bytes
                                  Windows Temp folder emptied: 46720563 bytes
                                  %systemroot%\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 12173434 bytes
                                  %systemroot%\system32\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 755 bytes
                                  %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33170 bytes
                                  RecycleBin emptied: 0 bytes

                                  Total Files Cleaned = 4 688,00 mb

                                  OTM by OldTimer - Version 3.1.8.0 log created on 02152010_190814

                                  Files moved on Reboot...
                                  File C:\Windows\temp\logishrd\LVPrcInj03.dll not found!
                                  File C:\Windows\temp\logishrd\LVPrcInj04.dll not found!
                                  C:\Windows\temp\CLDigitalHome\CLMS_AGENT_LOG1.txt moved successfully.
                                  File move failed. C:\Windows\temp\CLDigitalHome\PCMMediaServer.log scheduled to be moved on reboot.

                                  Registry entries deleted on Reboot...
                                  0
                                  1. Contributeur sécurité
                                    Fait ceci

                                    ▶ Télécharge OTM (de Old_Timer) sur ton Bureau

                                    ▶ Double-clique sur OTM.exe pour le lancer.

                                    ▶ Assure toi que la case Unregister Dll's and Ocx's soit bien cochée.

                                    ▶ Copie la liste qui se trouve en gras dans la citation ci-dessous et colle-la dans le cadre de gauche de OTM sous "Paste instructions for item to be moved".

                                    -----------------------------------------------------------------------------

                                    :files
                                    c:\windows\system32\GuidedHelp3232.dll
                                    C:\Windows\System32\dot3api32.dll
                                    C:\Windows\System32\drprov32.dll
                                    C:\Windows\System32\fphc32.dll
                                    C:\Windows\System32\jly2wkfsn32.dll
                                    C:\Windows\System32\dot3dlg32.dll
                                    C:\Windows\System32\tdwxv5aj432.dll
                                    C:\Windows\System32\framedyn32.dll
                                    C:\Windows\System32\8a6dyvmb32.dll
                                    C:\Windows\System32\dot3gpclnt32.dll
                                    C:\Windows\System32\huc16o3zdp1tmz32.dll
                                    C:\Windows\System32\rhzmy5d32.dll
                                    C:\Windows\System32\3kcip2h32.dll
                                    C:\Windows\System32\cznwia32.dll
                                    C:\Windows\System32\mj49bs3fp32.dll
                                    C:\Program Files (x86)\Eurobarre
                                    C:\Program Files (x86)\DAEMON Tools Toolbar

                                    :commands
                                    [purity]
                                    [emptytemp]
                                    [reboot]


                                    -----------------------------------------------------------------------------

                                    ▶ Clique sur MoveIt! pour lancer la suppression.

                                    ▶ Le résultat apparaitra dans le cadre "Results".

                                    ▶ Clique sur Exit pour fermer.

                                    ▶ Poste le rapport situé dans C:\_OTM\MovedFiles.

                                    ▶ Il te sera peut-être demandé de redémarrer le pc pour achever la suppression. Si c'est le cas accepte par Yes.

                                    Ps: Merci Ric025 ;)
                                    0
                                    1. Les fichiers que tu m'indique pour l'upload, je l'est ai mais pas avec le 32 a la fin.
                                      Je te les UP quand même ?
                                      0
                                      1. Contributeur sécurité
                                        Alex02390 fait ceci stp :

                                        ▶ Affiche les fichiers et dossiers cachés ( si ils le sont déjà, continue )

                                        ▶ Rends toi sur Virustotal

                                        Upload ces fichiers puis poste les rapports :


                                        C:\Windows\System32\dot3api32.dll
                                        C:\Windows\System32\drprov32.dll
                                        C:\Windows\System32\dot3dlg32.dll
                                        C:\Windows\System32\jly2wkfsn32.dll
                                        0
                                        • 1
                                        • 2
                                        • 3