Probleme sur yahoo
Résoluqui peut m aider.....en effet meme en mon absence mes correspondants recoivent des messages venant de moi alors que je ne suis pas connectee.....se sont des liens a ouvrir.....yahoo me dit de mettre un firewall et un spyware mais je n y connais rien....j ai avast comme anti virus est ce compatible
merci de vos reponses
29 réponses
Un problème de sécurité sur Windows XP est décrit où des contenus semblent émaner de l’utilisateur en son absence, avec des liens à ouvrir et une demande d’assistance concernant Avast et le pare-feu. Plusieurs solutions techniques sont évoquées, notamment l’utilisation de Malwarebytes’ Anti-Malware et de ComboFix, puis l’analyse plus avancée avec GMER et SEAF pour déceler d’éventuels rootkits. Des conseils complémentaires insistent sur le changement des mots de passe et sur la vérification des comptes en ligne, afin de limiter l’usage frauduleux des identifiants compromis. En cas de doute, des rapports détaillés et des scans répétés sont recommandés pour confirmer l’absence de fichiers ou processus malveillants, sans conclure sur l’état final du système.
-
je l espere aussi
-
bon je te remercie ...je vais changer de mot de passe......je te remercie de ta patience....mais on y est arrive........heureusement que vous etes la pour nous aider!!!!!!
-
Contributeur sécuritéle fichier est bon semble t il...
je ne vois rien d'autre !
à part de changer ton mot de passe sur ton compte voire de compte tout court
un logiciel suspect a dû récupérer tes références et les utilise à des fins douteuses
mais tout ca se passe sur internet, pas dans ton pc -
1. ========================= SEAF 1.0.0.7 - C_XX
2.
3. Commencé à: 22:00:04 le 14/06/2010
4.
5. Valeur(s) recherchée(s):
6.
7. iedvtool.dll
8.
9. (!) --- Affichage des ADS
10. (!) --- Informations supplémentaires
11. (!) --- Recherche registre
12.
13. ====== Fichier(s) (TC: Date de création, TM: Date de modification, DA, Dernier accès) ======
14.
15. "c:\WINDOWS\system32\dllcache\iedvtool.dll" [ ----C---- | 743424 ]
16. TC: 11/06/2010,00:31:30 | TM: 06/05/2010,12:33:33 | DA: 14/06/2010,12:42:26
17.
18. CompagnyName: Microsoft Corporation
19. ProductName: Windows® Internet Explorer
20. InternalName: iedvtool.dll
21. OriginalFilename: iedvtool.dll
22. LegalCopyright: © Microsoft Corporation. All rights reserved.
23. ProductVersion: 8.00.6001.18923
24. FileVersion: 8.00.6001.18923 (longhorn_ie8_gdr.100419-1241)
25.
26. =========================
27.
28. "c:\WINDOWS\SoftwareDistribution\Download\680483c3a382de6992d0a3d498725f99\SP3QFE\iedvtool.dll" [ ----A---- | 743424 ]
29. TC: 11/06/2010,00:31:28 | TM: 06/05/2010,12:27:29 | DA: 14/06/2010,12:39:59
30.
31. CompagnyName: Microsoft Corporation
32. ProductName: Windows® Internet Explorer
33. InternalName: iedvtool.dll
34. OriginalFilename: iedvtool.dll
35. LegalCopyright: © Microsoft Corporation. All rights reserved.
36. ProductVersion: 8.00.6001.23014
37. FileVersion: 8.00.6001.23014 (longhorn_ie8_ldr.100419-1507)
38.
39. =========================
40.
41. "c:\WINDOWS\SoftwareDistribution\Download\680483c3a382de6992d0a3d498725f99\SP3GDR\iedvtool.dll" [ ----A---- | 743424 ]
42. TC: 11/06/2010,00:31:30 | TM: 06/05/2010,12:33:33 | DA: 14/06/2010,12:39:54
43.
44. CompagnyName: Microsoft Corporation
45. ProductName: Windows® Internet Explorer
46. InternalName: iedvtool.dll
47. OriginalFilename: iedvtool.dll
48. LegalCopyright: © Microsoft Corporation. All rights reserved.
49. ProductVersion: 8.00.6001.18923
50. FileVersion: 8.00.6001.18923 (longhorn_ie8_gdr.100419-1241)
51.
52. =========================
53.
54. "c:\WINDOWS\ie8updates\KB982381-IE8\iedvtool.dll" [ ----C---- | 742912 ]
55. TC: 11/06/2010,01:15:09 | TM: 08/03/2009,04:35:32 | DA: 14/06/2010,12:44:19
56.
57. CompagnyName: Microsoft Corporation
58. ProductName: Windows® Internet Explorer
59. InternalName: iedvtool.dll
60. OriginalFilename: iedvtool.dll
61. LegalCopyright: © Microsoft Corporation. All rights reserved.
62. ProductVersion: 8.00.6001.18702
63. FileVersion: 8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
64.
65. =========================
66.
67. "c:\WINDOWS\$hf_mig$\KB982381-IE8\SP3QFE\iedvtool.dll" [ ----A---- | 743424 ]
68. TC: 11/06/2010,00:31:28 | TM: 06/05/2010,12:27:29 | DA: 14/06/2010,12:39:32
69.
70. CompagnyName: Microsoft Corporation
71. ProductName: Windows® Internet Explorer
72. InternalName: iedvtool.dll
73. OriginalFilename: iedvtool.dll
74. LegalCopyright: © Microsoft Corporation. All rights reserved.
75. ProductVersion: 8.00.6001.23014
76. FileVersion: 8.00.6001.23014 (longhorn_ie8_ldr.100419-1507)
77.
78. =========================
79.
80. "c:\Program Files\Internet Explorer\iedvtool.dll" [ ----N---- | 743424 ]
81. TC: 08/03/2009,04:35:32 | TM: 06/05/2010,12:33:33 | DA: 14/06/2010,20:22:50
82.
83. CompagnyName: Microsoft Corporation
84. ProductName: Windows® Internet Explorer
85. InternalName: iedvtool.dll
86. OriginalFilename: iedvtool.dll
87. LegalCopyright: © Microsoft Corporation. All rights reserved.
88. ProductVersion: 8.00.6001.18923
89. FileVersion: 8.00.6001.18923 (longhorn_ie8_gdr.100419-1241)
90.
91. =========================
92.
93. "c:\Program Files\Internet Explorer\fr-FR\iedvtool.dll.mui" [ ----N---- | 40960 ]
94. TC: 08/03/2009,14:18:06 | TM: 08/03/2009,14:18:06 | DA: 14/06/2010,12:33:02
95.
96. CompagnyName: Microsoft Corporation
97. ProductName: Windows® Internet Explorer
98. InternalName: iedvtool.dll
99. OriginalFilename: iedvtool.dll.mui
100. LegalCopyright: © Microsoft Corporation. Tous droits réservés.
101. ProductVersion: 8.00.6001.18702
102. FileVersion: 8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
103.
104. =========================
105.
106. ====== Dossier(s) (TC: Date de création, TM: Date de modification, DA, Dernier accès) ======
107.
108. Aucun dossier trouvé
109.
110.
111. ====== Entrée(s) du registre ======
112.
113.
114.
115. [HKEY_CLASSES_ROOT\CLSID\{1a6fe369-f28c-4ad9-a3e6-2bcb50807cf1}\InProcServer32]
116. ""="C:\Program Files\Internet Explorer\iedvtool.dll"
117.
118. [HKEY_CLASSES_ROOT\CLSID\{8fe85d00-4647-40b9-87e4-5eb8a52f4759}\InProcServer32]
119. ""="C:\Program Files\Internet Explorer\iedvtool.dll"
120.
121. [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1a6fe369-f28c-4ad9-a3e6-2bcb50807cf1}\InProcServer32]
122. ""="C:\Program Files\Internet Explorer\iedvtool.dll"
123.
124. [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8fe85d00-4647-40b9-87e4-5eb8a52f4759}\InProcServer32]
125. ""="C:\Program Files\Internet Explorer\iedvtool.dll"
126.
127. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Updates\Windows XP\SP0\KB982381-IE8\Filelist\16]
128. "FileName"="iedvtool.dll"
129.
130. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Updates\Windows XP\SP0\KB982381-IE8\Filelist\31]
131. "FileName"="iedvtool.dll"
132.
133. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Updates\Windows XP\SP0\KB982381-IE8\Filelist\41]
134. "FileName"="iedvtool.dll"
135.
136. =========================
137.
138. Fin à: 22:00:32 le 14/06/2010 ( E.O.F ) -
c est fait je te poste le rapport???
-
Contributeur sécuritéTélécharge SEAF ( de C__XX ) sur ton bureau :
ici http://pagesperso-orange.fr/NosTools/C_XX/SEAF.exe
* Double clique sur "SEAF.exe" ( clique droit et "Exécuter en tant qu'administrateur" pour Vista / 7 ) pour lancer l'outil.
* Dans l'encardré blanc " Entrez ci dessous...." copie/colle ceci :
iedvtool.dll
* Au niveau des " options des fichiers ", fait les réglages suivant :
> A "Calculer le checksum" , choisis : MD5
> Coche la case devant " Info. supplémentaire ".
> Coche la case devant " Afficher les ADS "
* Au niveau des " options du registre " :
> coche " chercher également dans le registre "
( ne touche à aucun autre réglage )
* Clique sur " Lancer la recherche " et laisse travailler l'outil ...
( cela peut-être plus ou moins long suivant les cas ).
--> Une fois terminé, une fenêtre avec un log .txt va s'afficher. Enregistre ce rapport de façon à le retrouver facilement ( sur le bureau par exemple ). Sinon il sera en outre sauvegardé à la racine de ton disque dur ( ici > C:\SEAFLog.txt )
-
je ne trouve rien de ce que tu me demandes!!!!!!
-
Contributeur sécuritétout est normal là aussi
juste un fichier à verifier
Rends toi sur ce site :
https://www.virustotal.com/gui/
Clique sur parcourir et cherche ce fichier :
c:\windows\system32\dllcache\iedvtool.dll
Clique sur Send File.
Un rapport va s'élaborer ligne à ligne.
Attends la fin. Il doit comprendre la taille du fichier envoyé.
Sauvegarde le rapport avec le bloc-note.
Copie le dans ta réponse.
Si tu ne trouves pas le fichier alors
Affiche tous les fichiers et dossiers :
Pour cela :
Clique sur démarrer/panneau de configuration/option des dossiers/affichage
Cocher afficher les dossiers cachés
Décoche la case "Masquer les fichiers protégés du système d'exploitation (recommandé)"
Décocher masquer les extensions dont le type est connu
Puis fais «appliquer» pour valider les changements.
Et OK
-
ComboFix 10-06-14.01 - Acer 14/06/2010 20:33:56.2.1 - x86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.1023.483 [GMT 2:00]
Lancé depuis: c:\documents and settings\Acer\Bureau\ComboFix.exe
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
((((((((((((((((((((((((((((( Fichiers créés du 2010-05-14 au 2010-06-14 ))))))))))))))))))))))))))))))))))))
.
2010-06-14 15:27 . 2010-06-14 15:27 -------- d-----w- C:\Kill'em
2010-06-14 12:21 . 2010-06-14 16:27 -------- d-----w- c:\program files\List_Kill'em
2010-06-14 12:19 . 2010-06-14 12:19 -------- d-----w- c:\windows\system32\LogFiles
2010-06-10 22:31 . 2010-05-06 10:33 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
2010-05-28 16:06 . 2010-05-28 16:06 501872 ----a-w- c:\documents and settings\All Users\Application Data\Google\Google Toolbar\Update\gtb9F.tmp.exe
2010-05-28 16:05 . 2010-05-28 16:05 503808 ----a-w- c:\documents and settings\Acer\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-45e73184-n\msvcp71.dll
2010-05-28 16:05 . 2010-05-28 16:05 499712 ----a-w- c:\documents and settings\Acer\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-45e73184-n\jmc.dll
2010-05-28 16:05 . 2010-05-28 16:05 348160 ----a-w- c:\documents and settings\Acer\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-45e73184-n\msvcr71.dll
2010-05-28 16:05 . 2010-05-28 16:05 61440 ----a-w- c:\documents and settings\Acer\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-6e9cf863-n\decora-sse.dll
2010-05-28 16:05 . 2010-05-28 16:05 12800 ----a-w- c:\documents and settings\Acer\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-6e9cf863-n\decora-d3d.dll
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-14 18:25 . 2010-03-12 17:22 -------- d-----w- c:\documents and settings\Acer\Application Data\HPAppData
2010-06-13 17:11 . 2010-04-21 20:37 -------- d-----w- c:\program files\ZHPDiag
2010-06-12 16:20 . 2010-01-04 17:18 -------- d-----w- c:\program files\MyDSC2
2010-06-10 23:12 . 2008-04-14 12:00 81096 ----a-w- c:\windows\system32\perfc00C.dat
2010-06-10 23:12 . 2008-04-14 12:00 501232 ----a-w- c:\windows\system32\perfh00C.dat
2010-06-07 15:51 . 2009-09-25 09:40 1 ----a-w- c:\documents and settings\Acer\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2010-06-07 05:19 . 2010-02-12 15:40 -------- d-----w- c:\program files\Microsoft Silverlight
2010-06-05 12:37 . 2010-03-06 22:37 -------- d-----w- c:\documents and settings\All Users\Application Data\Norton
2010-05-06 20:59 . 2009-12-05 16:46 165032 ----a-w- c:\windows\system32\aswBoot.exe
2010-05-06 20:39 . 2009-12-05 16:46 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-05-06 20:39 . 2009-12-05 16:46 164048 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-05-06 20:34 . 2009-12-05 16:46 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-05-06 20:33 . 2009-12-05 16:46 100432 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-05-06 20:33 . 2009-12-05 16:46 94800 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-05-06 20:33 . 2009-12-05 16:46 19024 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-05-06 20:33 . 2009-12-05 16:46 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-05-06 10:33 . 2008-04-14 12:00 916480 ----a-w- c:\windows\system32\wininet.dll
2010-05-02 08:08 . 2008-04-14 12:00 1851392 ----a-w- c:\windows\system32\win32k.sys
2010-04-24 12:31 . 2010-04-24 12:31 -------- d-----w- c:\documents and settings\LocalService\Application Data\McAfee
2010-04-24 10:11 . 2009-12-04 13:28 -------- d-----w- c:\program files\McAfee Security Scan
2010-04-22 08:00 . 2010-04-22 08:00 -------- d-----w- c:\documents and settings\Acer\Application Data\Malwarebytes
2010-04-22 08:00 . 2010-04-22 08:00 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-04-22 08:00 . 2010-04-22 08:00 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-04-21 21:18 . 2010-02-24 18:01 -------- d-----w- c:\documents and settings\Acer\Application Data\Azureus
2010-04-21 08:32 . 2010-04-21 08:32 8851392 ----a-w- c:\documents and settings\Acer\Application Data\Azureus\tmp\AZU7101123054723030121.tmp\Vuze_4.4.0.0a_win32.exe
2010-04-20 21:35 . 2010-04-20 21:35 -------- d-----w- c:\documents and settings\Acer\Application Data\com.zoosk.Desktop.096E6A67431258A508A2446A847B240591D2C99B.1
2010-04-20 21:35 . 2010-04-20 21:35 -------- d-----w- c:\program files\Fichiers communs\Adobe AIR
2010-04-20 21:35 . 2010-04-20 21:35 38784 ----a-w- c:\documents and settings\Acer\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2010-04-20 05:30 . 2008-04-14 12:00 285696 ----a-w- c:\windows\system32\atmfd.dll
2010-04-17 08:43 . 2009-09-25 09:30 -------- d-----w- c:\program files\Java
2010-04-14 16:47 . 2009-12-05 16:46 38848 ----a-w- c:\windows\system32\avastSS.scr
2010-04-12 15:29 . 2010-04-17 08:43 411368 ----a-w- c:\windows\system32\deployJava1.dll
2010-04-03 23:35 . 2010-04-03 23:35 0 ----a-w- c:\windows\nsreg.dat
2010-03-31 07:57 . 2010-03-31 07:57 503808 ----a-w- c:\documents and settings\Acer\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-59d973a5-n\msvcp71.dll
2010-03-31 07:57 . 2010-03-31 07:57 499712 ----a-w- c:\documents and settings\Acer\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-59d973a5-n\jmc.dll
2010-03-31 07:57 . 2010-03-31 07:57 348160 ----a-w- c:\documents and settings\Acer\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-59d973a5-n\msvcr71.dll
2010-03-31 07:57 . 2010-03-31 07:57 61440 ----a-w- c:\documents and settings\Acer\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-357e9f0e-n\decora-sse.dll
2010-03-31 07:57 . 2010-03-31 07:57 12800 ----a-w- c:\documents and settings\Acer\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-357e9f0e-n\decora-d3d.dll
2010-03-29 22:46 . 2010-04-22 08:00 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-29 22:45 . 2010-04-22 08:00 20824 ----a-w- c:\windows\system32\drivers\mbam.sys
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-12-04 39408]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2009-09-11 18717696]
"nwiz"="c:\program files\NVIDIA Corporation\nView\nwiz.exe" [2009-08-12 1657376]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-08-17 13877248]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-08-17 86016]
"SunJavaUpdateSched"="c:\program files\Fichiers communs\Java\Java Update\jusched.exe" [2010-02-18 248040]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-04-04 36272]
"Adobe ARM"="c:\program files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-05-06 2815192]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\Acer\Menu D'marrer\Programmes\D'marrage\
OpenOffice.org 3.1.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-8-18 384000]
c:\documents and settings\All Users\Menu D'marrer\Programmes\D'marrage\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2009-5-21 275768]
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfcCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgplgtupl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgpc01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqusgm.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqusgh.exe"=
"c:\\Program Files\\HP\\HP Software Update\\HPWUCli.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\smart web printing\\SmartWebPrintExe.exe"=
R0 m5287;m5287;c:\windows\system32\drivers\m5287.sys [25/09/2009 10:44 103680]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [05/12/2009 18:46 164048]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [05/12/2009 18:46 19024]
S2 gupdate;Service Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [31/01/2010 02:32 135664]
S3 maconfservice;Ma-Config Service;c:\program files\ma-config.com\maconfservice.exe [23/09/2009 14:50 238960]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [15/01/2010 14:49 227232]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contenu du dossier 'Tâches planifiées'
2010-06-14 c:\windows\Tasks\DMEPeriodicTask.job
- c:\program files\HP\Digital Imaging\bin\warrantyextension\HPPromo.exe [2009-06-16 07:17]
2010-06-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-31 00:32]
2010-06-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-31 00:32]
2010-06-14 c:\windows\Tasks\User_Feed_Synchronization-{8AD95A6E-F2E5-4BED-AEBF-C92C57C2E098}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 02:31]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.google.fr/
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_2EC7709873947E87.dll/cmsidewiki.html
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-06-14 20:42
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'explorer.exe'(2528)
c:\windows\system32\webcheck.dll
c:\windows\system32\eappprxy.dll
.
Heure de fin: 2010-06-14 20:44:17
ComboFix-quarantined-files.txt 2010-06-14 18:44
Avant-CF: 108 183 486 464 octets libres
Après-CF: 108 991 967 232 octets libres
- - End Of File - - 85E858868D0F34A537BD87428E456BBC -
Contributeur sécuritéAttention, avant de commencer, lit attentivement la procédure, et imprime la
Aide à l'utilisation
https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix
Télécharge ComboFix de sUBs sur ton Bureau :
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
/!\ Déconnecte-toi du net et DESACTIVES TOUTES LES DEFENSES, antivirus et antispyware y compris /!\
---> Double-clique sur ComboFix.exe
Un "pop-up" va apparaître qui dit que ComboFix est utilisé à vos risques et avec aucune garantie... Clique sur oui pour accepter
SURTOUT INSTALLES LA CONSOLE DE RECUPERATION
(si il te propose de l'installer remets internet)
---> Mets-le en langue française F
Tape sur la touche 1 (Yes) pour démarrer le scan.
Ne touche à rien(souris, clavier) tant que le scan n'est pas terminé, car tu risques de planter ton PC
En fin de scan, il est possible que ComboFix ait besoin de redémarrer le PC pour finaliser la désinfection, laisse-le faire.
Une fois le scan achevé, un rapport va s'afficher : Poste son contenu
/!\ Réactive la protection en temps réel de ton antivirus et de ton antispyware avant de te reconnecter à Internet. /!\
Note : Le rapport se trouve également là : C:\ComboFix.txt
-
je ne peux telecharger car j ai gmer qui s ouvre et j ai in message qui me dit " gmer has found system modification caused by rootkit activity""""ca commence a m enerver dur
-
Contributeur sécuritéok
poste de travail
partition c
on va faire autre chose
/!\ Il faut impérativement désactiver tous tes logiciels de protection pour utiliser ce programme/!\
? Télécharge : Gmer (by Przemyslaw Gmerek)
http://www.gmer.net/
? Dezippe gmer ,cliques sur l'onglet rootkit,lances le scan,des lignes rouges vont apparaitre.
? Les lignes rouges indiquent la presence d'un rootkit.Postes moi le rapport gmer (cliques sur copy,puis vas dans demarrer ,puis ouvres le bloc note,vas dans edition et cliques sur coller,le rapport gmer va apparaitre,postes moi le)
-
c est quoi la partition c je la trouve ou.........de plus quand je fais ce scan mon ordi bloc
-
Contributeur sécuritéok
sur ta partition c tu dois avoir ceci C:\List'em.txt
c'est lui qu'il me faut
s'il n' y est pas
l'examen est à refaire en désactivant bien toutes tes protections pendant celui ci -
essaies de m expliquer autre chose ou une autre solution car je n y arrive pas ...desolee je ne suis pas une experte
-
https://www.cjoint.com/?gosvv1Eptv je ne sais pas si c est cela
-
le seul rapport que j ai c est list'em bloc et ca je n arrive pas a te le poster
-
Contributeur sécuritéregardes sur le bureau ou sur ta partition C si il n'y a pas un rapport
postes le par ci joint -
le scan est fait mais apres "completed" rien n apparait
-
je n arrive pas a te poster le resultat
- 1
- 2