12gn6id2.exe
Je n'arrive pas à me débarrasser de 12gn6id2.ex ainsi que d'autres fichiers transmis par entrées usb.
Merci pour votre aide.
Nordberg
32 réponses
Problème récurrent sous Windows XP et Firefox 18.0 : il est difficile de supprimer des fichiers infectieux tels que 12gn6id2.ex transmis par des entrées USB, et d'autres éléments malveillants. Des conseils orientent vers l'utilisation d'un antivirus et d'outils dédiés, notamment Malwarebytes' Anti-Malware, pour lancer un examen rapide ou complet, supprimer les menaces et générer un rapport après redémarrage si nécessaire. En cas d'échec des nettoyages basiques, des outils de diagnostic comme ZHPDiag peuvent être utilisés pour générer un rapport détaillé et faciliter l'identification des éléments malveillants. Par ailleurs, certaines recommandations évoquent la mise à jour des sauvegardes et le gros nettoyage des périphériques USB pour prévenir une réinfection ultérieure et sécuriser le navigateur et le système par des pratiques simples.
-
¡El Desaparecido! bonjour,
En fait mon ordi ne fait que tourner, un bruit pas possible.
Les démarrages sont très, très, très long.
Avast semble ralentir toutes les taches.
J'ai défragmenté hier cela ne change rien. -
¡El Desaparecido! bonsoir,
Mon ordi semble aller mieux.
Seul problème, les temps de réaction sont très long entre le clic ou le double clic et l'ouverture du fichier ou du programme, ex :
- icone mozilla et ouverture ;
- fichier office et ouverture ;
- icone outlook et ouverture programme...
Kess t'en penses ?
Nordberg -
Bonjour ¡El Desaparecido!
J'ai installé Avast.
Je continue le nettoyage des entrées usb.
Merci encore pour le partage de toute ton expertise. -
Avast en version gratuite sans hésiter ;)
http://redir.iavs5x.u.avcdn.net/iavs5x/avast_free_antivirus_setup.exe
-
Quel AV me conseilles-tu ?
-
Je continue de nettoyer tous les appareils connexion usb, il me reste les appareils photo, les téléphones, le disque dur amovible... Donc je réinstalle usbfix si j'ai bien compris !
Oui, en plus y'a une nouvelle maj :)
Il va falloir penser à installer un AV aussi ..
-
Ok c'est bon pour l'insallation Adobe Reader depuis le lien "comment ça marche ?".
L'ordi a l'air de mieux tourné, il réagi plus vite par exemple ds outlook.
Par contre le tps de latence est grand entre le clic sur l'icone Mozilla Firefox et l'ouverture de la fenêtre du navigateur.
Idem pour les fichiers word, ou excel...
En ce qui concerne l'antivirus, je n'ai rien réinstallé depuis lgtps, je vérifiai régulièrement avec Malware.
En ce qui concerne le parefeu rien d'installé non plus.
Je continue de nettoyer tous les appareils connexion usb, il me reste les appareils photo, les téléphones, le disque dur amovible... Donc je réinstalle usbfix si j'ai bien compris ! -
Fait ch*** ce adobe reader ^^
Essai depuis ce lien :
https://www.commentcamarche.net/telecharger/bureautique/2625-adobe-reader/
Télécharge le et ensuite instal le-
Contributeur sécuritéSalut Cédric,
Laisse tomber AdobeReader.
Passe à FoxitReader plus léger < http://www.foxitreader.fr/ > (et c'est gratuit) ;)
Amitiés.
Albert -
-
-
-
Contributeur sécuritéHello ;)
https://www.generation-nt.com/adobe-reader-vulnerabilite-securite-attaque-actualite-1694202.html
Amusant, non ?
Albert
-
-
De nouveau le même message pour Adobe Reader : "Impossible de décompresser le fichier de métadonnées".
-
Pas de rapport après l'exécution de Delfix !
-
# Télécharge DelFix par Xplode.
# Exécute delfix.exe
# Clique sur Suppression.
# Patiente pendant le scan jusqu'à l'ouverture du rapport.
# Poste le contenu du rapport dans ta prochaine réponse sur le forum.
# Note : Le rapport se trouve sous C:\DelFix[S1].txt
( CTRL+A pour sélectionner, CTRL+C pour copier et CTRL+V pour coller )
Ensuite redémarre et retente l'installation de Adobe Reader
-
Rapport de ZHPFix 1.3.14 par Nicolas Coolman, Update du 05/02/2013
Fichier d'export Registre :
Run by mega boss at 16/02/2013 15:33:26
Windows XP Home Edition Service Pack 2 (Build 2600)
========== Processus mémoire ==========
SUPPRIME Memory Process: C:\Documents and Settings\mega boss\Bureau\rkill.exe
========== Clé(s) du Registre ==========
SUPPRIME Key: Mozilla Plugin: @checkpoint.com/FFApi
SUPPRIME Key: Mozilla Plugin: @facebook.com/FBPlugin,version=1.0.3
SUPPRIME Key: CLSID Extra Buttons: {FB5F1910-F110-11d2-BB9E-00C04F795683}
SUPPRIME Key: HKCU\Software\zkhfwydu
SUPPRIME Key: HKLM\Software\zkhfwydu
ABSENT Key: StartupReg: SunJavaUpdateSched
SUPPRIME Key: SearchScopes :{CD8D7E9E-6DCA-4E43-83FA-67510DA08434}
SUPPRIME Key: HKLM\Software\Classes\CLSID\{35b8892d-c3fb-4d88-990d-31db2ebd72bd}
SUPPRIME Key: HKLM\Software\Classes\Interface\{3f607e46-0d3c-4442-b1de-de7fa4768f5c}
SUPPRIME Key: HKLM\Software\Classes\TypeLib\{93e3d79c-0786-48ff-9329-93bc9f6dc2b3}
SUPPRIME Key: HKLM\Software\Classes\Interface\{fe0273d1-99df-4ac0-87d5-1371c6271785}
SUPPRIME Key: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}
SUPPRIME Key: HKLM\Software\Classes\CLSID\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}
SUPPRIME Key: HKLM\Software\Microsoft\Internet Explorer\extensions\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}
SUPPRIME Key: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
SUPPRIME Key: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
SUPPRIME Key: HKLM\Software\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
SUPPRIME Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
SUPPRIME Key: HKLM\Software\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56}
SUPPRIME Key: HKLM\Software\Classes\AppID\secman.DLL
ABSENT Key: HKLM\SoftwareMartin Prikryl\OpenCandy
========== Valeur(s) du Registre ==========
SUPPRIME [HKCU\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser]:{4e7bd74f-2b8d-469e-8da9-fd60bb9aae33}
SUPPRIME [HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]:{4e7bd74f-2b8d-469e-8da9-fd60bb9aae33}
========== Elément(s) de donnée du Registre ==========
SUPPRIME StartMenuInternet: C:\Program Files\Opera\Opera.exe
========== Préférences navigateur ==========
ABSENT C:\Documents and Settings\mega boss\Local Settings\Application Data\Opera\Opera\operaprefs.ini
========== Dossier(s) ==========
========== Fichier(s) ==========
ABSENT File: c:\program files\checkpoint\zaforcefield\trustchecker\bin\npffapi.dll
ABSENT File: c:\documents and settings\mega boss\application data\facebook\npfbplugin_1_0_3.dll
SUPPRIME c:\documents and settings\all users\application data\microsoft\internet explorer\quick launch\myspaceim.lnk
ABSENT File: c:\program files\myspace\im\myspaceim.exe
ABSENT File: c:\program files\messenger\msmsgs.exe
ABSENT File: c:\program files\java\jre1.5.0_06\bin\jusched.exe
SUPPRIME File: C:\Documents and Settings\mega boss\Application Data\vj699okrjvrjal4b.dat
SUPPRIME File: c:\documents and settings\mega boss\bureau\rkill.exe
SUPPRIME Temporaires Windows:
SUPPRIME Flash Cookies:
========== Récapitulatif ==========
1 : Processus mémoire
21 : Clé(s) du Registre
2 : Valeur(s) du Registre
1 : Elément(s) de donnée du Registre
10 : Fichier(s)
1 : Préférences navigateur
End of clean in 00mn 21s
========== Chemin de fichier rapport ==========
C:\ZHP\ZHPFix[R1].txt - 16/02/2013 15:33:26 [3595] -
Il est en bas à gauche
-
J'ai collé les ligne ds ZHPFix mais je n'ai pas de bouton "Go".
En ht à dte j'ai le bouton :
- A : nettoyeur de tools ;
- Windows clean manager ;
- Q : restaurer la quarantaine... -
Adobe reader fonctionne sous 64 bit ;)
Passe à la suite on verra ça au final
-
Si j'ai bien compris d'après mes recherches : mon OS fonctionne en 32 bits et la seule version proposée en téléchargement est Reader 9.5 french for Windows.
Que fais-je docteur ? -
Bonjour ¡El Desaparecido!
Problème avec le programme d'installation Adobe Reader, j'ai la fenêtre suivante :
"Impossible de décompresser le fichier de métadonnées". -
Hello ,
On commence à y voir plus clair :)
Niveau antivirus et parefeu , tu fonctionnes comment ?
Désinstal les programmes suivant :
Java 7 Update 9
Java(TM) 6 Update 35
Adobe Reader X (10.1.4)
Instal la dernière version de Java : https://www.java.com/fr/download/
Instal la dernière version de Adobe reader : http://get.adobe.com/fr/reader/( décoché Oui, installer Google Chrome (facultatif) )
###############
# Copie tout le texte présent ci-dessous ( clic sur doit ("Tout sélectionner") / Clique droit ("copier").
B0 - SPO: operaprefs.ini [mega boss] Home URL=http://fr.blackle.com/ P2 - FPN: [HKLM] [@checkpoint.com/FFApi] - (...) -- C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\npFFApi.dll (.not file.) P2 - FPN: [HKCU] [@facebook.com/FBPlugin,version=1.0.3] - (...) -- C:\Documents and Settings\mega boss\Application Data\Facebook\npfbplugin_1_0_3.dll (.not file.) O4 - Global Startup: C:\Documents And Settings\All Users\Application Data\Microsoft\Internet Explorer\Quick Launch\MySpaceIM.lnk . (...) -- C:\Program Files\MySpace\IM\MySpaceIM.exe (.not file.) O9 - Extra button: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -- C:\Program Files\Messenger\msmsgs.exe (.not file.) [HKCU\Software\zkhfwydu] [HKLM\Software\zkhfwydu] O43 - CFD: 09/03/2006 - 16:02:35 - [11,617] ----D C:\Documents and Settings\mega boss\Local Settings\Application Data\{3248F0A6-6813-11D6-A77B-00B0D0150060} O43 - CFD: 19/08/2012 - 16:13:15 - [0,003] -SH-D C:\Documents and Settings\mega boss\Local Settings\Application Data\{559f2757-518d-d670-0246-21a0ddba224a} O53 - SMSR:HKLM\...\startupreg\SunJavaUpdateSched [Key] . (...) -- C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe (.not file.) O68 - StartMenuInternet: <Opera> <Opera>[HKLM\..\Shell\open\Command] (...) -- C:\Program Files\Opera\Opera.exe (.not file.) O68 - StartMenuInternet: <Opera.exe> <>[HKLM\..\Shell\open\Command] (...) -- C:\Program Files\Opera\Opera.exe (.not file.) O69 - SBI: SearchScopes [HKCU] {CD8D7E9E-6DCA-4E43-83FA-67510DA08434} - (Ask Search) - http://www.search.ask.com/?o=10148&l=dis [MD5.91FF2DAFB549EF6852AA4868BB124CF6] [SPRF][14/12/2011] (...) -- C:\Documents and Settings\mega boss\Application Data\vj699okrjvrjal4b.dat [8] [MD5.A51F3D95F3A29BCAE0B5BBCCEA9FC54C] [SPRF][11/02/2013] (.Bleeping Computer, LLC - Terminates malware processes so that you can run your normal security programs..) -- C:\Documents and Settings\mega boss\Bureau\rkill.exe [1752992] [HKLM\Software\Classes\CLSID\{35b8892d-c3fb-4d88-990d-31db2ebd72bd}] =>Adware.RecordNRip [HKLM\Software\Classes\Interface\{3f607e46-0d3c-4442-b1de-de7fa4768f5c}] =>Adware.RecordNRip [HKLM\Software\Classes\TypeLib\{93e3d79c-0786-48ff-9329-93bc9f6dc2b3}] =>Adware.RecordNRip [HKLM\Software\Classes\Interface\{fe0273d1-99df-4ac0-87d5-1371c6271785}] =>Adware.RecordNRip [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}] =>Toolbar.Agent [HKLM\Software\Classes\CLSID\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}] =>Toolbar.Agent [HKLM\Software\Microsoft\Internet Explorer\extensions\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}] =>Toolbar.Agent [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}] =>Toolbar.Agent [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}] =>Toolbar.Agent [HKLM\Software\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}] =>Toolbar.Agent [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}] =>Toolbar.Agent [HKLM\Software\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56}] =>Toolbar.Babylon [HKLM\Software\Classes\AppID\secman.DLL] =>Toolbar.Babylon [HKLM\SoftwareMartin Prikryl\OpenCandy] =>Adware.OpenCandy [HKCU\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser]:{4e7bd74f-2b8d-469e-8da9-fd60bb9aae33} =>Adware.BHO [HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]:{4e7bd74f-2b8d-469e-8da9-fd60bb9aae33} =>Adware.BHO EmptyTemp EmptyFlash EMPTYCLSID
# Lance ZHPFix à partir du raccourci sur ton Bureau (si tu es sous Windows Vista ou 7, fais un clic-droit -> Exécuter en temps qu'administrateur).
# Clique sur l'icone représentant la lettre H (« coller les lignes Helper »).
# Les lignes se collent automatiquement dans ZHPFix, sinon colle les lignes.
# Clique sur le bouton « GO » pour lancer le nettoyage.
# S'il t'est demandé de redémarrer l'ordinateur, accepte.
# Copie/colle la totalité du rapport dans ta prochaine réponse.
# Le rapport est en outre sauvegardé sous C:\Program files\ZHPDiag\ZHPFixReport.txt.
# Attention : Ce script a été spécialement fait pour ce PC . Toute réutilisation peut endommager sévèrement votre système.
# Si le rapport ne passe pas, héberge-le :
# Rend toi sur Pjjoint de Malekal.
# Clique sur Parcourir et cherche le document à transmettre.
# Clique ensuite sur Envoyer le fichier].
# Tu obtiendras un message de confirmation avec un lien.
# Transmet ce lien dans ta prochaine réponse.
-
Bonsoir ¡El Desaparecido!
Mon PC semble aller un peu mieux, il devient plus silencieux. Je continue de nettoyer ttes mes entrées usb (cléfs, lecteur mp3, téléphone, disque externe...) grâce à UsbFix.
Sinon tu trouveras ci-dessous le rapport demandé :
ComboFix 13-02-15.01 - mega boss 16/02/2013 0:00.1.1 - x86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.33.1036.18.1014.478 [GMT 1:00]
Lancé depuis: c:\documents and settings\mega boss\Bureau\ComboFix.exe
FW: ZoneAlarm Firewall *Enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
.
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\mega boss\WINDOWS
c:\windows\system32\cffebbb5_g.dll
c:\windows\system32\URTTemp
c:\windows\system32\URTTemp\fusion.dll
c:\windows\system32\URTTemp\mscoree.dll
c:\windows\system32\URTTemp\mscoree.dll.local
c:\windows\system32\URTTemp\mscorsn.dll
c:\windows\system32\URTTemp\mscorwks.dll
c:\windows\system32\URTTemp\msvcr71.dll
c:\windows\system32\URTTemp\regtlib.exe
.
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_NPF
-------\Legacy_SSHNAS
-------\Legacy_WINDOWS_INTERNET_NAME_SERVICE
.
.
((((((((((((((((((((((((((((( Fichiers créés du 2013-01-15 au 2013-02-15 ))))))))))))))))))))))))))))))))))))
.
.
2013-02-14 21:56 . 2013-02-15 22:45 -------- d-----w- C:\UsbFix
2013-02-13 08:57 . 2013-02-13 08:57 1233 ----a-w- c:\documents and settings\mega boss\Local Settings\Application Data\JunkAtx.bin
2013-02-12 21:43 . 2013-02-13 08:30 -------- d-----w- c:\documents and settings\mega boss\Doctor Web
2013-02-12 17:52 . 2013-02-12 17:57 316940 ------w- C:\Update_UsbFix.exe
2013-02-12 10:03 . 2013-02-14 22:11 -------- d-----w- c:\program files\ZHPDiag
2013-02-12 10:03 . 2013-02-14 22:11 -------- d-----w- C:\ZHP
2013-02-11 22:46 . 2013-02-11 22:49 -------- d-----w- c:\documents and settings\mega boss\Application Data\ExpressFiles
2013-02-11 22:40 . 2013-02-11 23:03 -------- d-----w- c:\program files\RegUtility
.
.
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-02-11 09:02 . 2012-04-21 07:48 697712 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-02-11 09:02 . 2011-06-28 08:21 74096 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-12-14 15:49 . 2011-01-01 21:09 21104 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-02-06 13:29 . 2013-02-06 13:28 262552 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
2004-02-23 18:42 1386496 --sh--r- c:\windows\system32\msvbvm60.dll
.
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Synchronizer"="c:\program files\Adobe\Reader 10.0\Reader\AdobeCollabSync.exe" [2012-07-27 1261512]
"KiesPDLR"="c:\program files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe" [2012-03-29 21416]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Mouse Suite 98 Daemon"="ICO.EXE" [2002-03-14 45056]
"tsnp2std"="c:\windows\tsnp2std.exe" [2006-06-19 262144]
"snp2std"="c:\windows\vsnp2std.exe" [2006-05-15 675840]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-01-13 131072]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-01-13 163840]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-01-13 135168]
"RTHDCPL"="RTHDCPL.EXE" [2010-11-02 19580520]
"Adobe ARM"="c:\program files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2012-06-28 74752]
"SunJavaUpdateSched"="c:\program files\Fichiers communs\Java\Java Update\jusched.exe" [2012-07-03 252848]
"APSDaemon"="c:\program files\Fichiers communs\Apple\Apple Application Support\APSDaemon.exe" [2012-11-28 59280]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2012-12-12 152544]
"VAIO Update Self Repair"="c:\program files\Sony\VAIO Update\VUSR.exe" [2012-10-26 586400]
"VAIO Update"="c:\program files\Sony\VAIO Update\VAIOUpdt.exe" [2012-10-26 1038496]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
2005-05-20 16:42 73728 ----a-w- c:\windows\system32\VESWinlogon.dll
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Lancement rapide d'Adobe Reader.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Lancement rapide d'Adobe Reader.lnk
backup=c:\windows\pss\Lancement rapide d'Adobe Reader.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^WDDMStatus.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\WDDMStatus.lnk
backup=c:\windows\pss\WDDMStatus.lnkCommon Startup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FixCamera
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AzMixerSel]
2005-06-11 10:51 53248 ----a-w- c:\program files\Realtek\InstallShield\AzMixerSel.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"HPDJ Taskbar Utility"=c:\windows\system32\spool\drivers\w32x86\3\hpztsb05.exe
"ISBMgr.exe"=c:\program files\Sony\ISB Utility\ISBMgr.exe
"High Definition Audio Property Page Shortcut"=HDAShCut.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
.
R2 WDDMService;WD SmartWare Drive Manager;c:\program files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe [04/09/2009 15:22 98304]
R2 WDSmartWareBackgroundService;WD SmartWare Background Service;c:\program files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe [16/06/2009 09:58 20480]
R3 bbcap;bbcap;c:\windows\system32\drivers\bbcap.sys [06/11/2008 00:38 4096]
R3 SonyImgF;Sony Image Conversion Filter Driver;c:\windows\system32\drivers\SonyImgF.sys [09/03/2006 03:40 29184]
R3 VUAgent;VUAgent;c:\program files\Sony\VAIO Update\VUAgent.exe [06/02/2013 23:37 957056]
S0 nxuq;nxuq; [x]
S1 zxblxwhhffq9;zxblxwhhffq9.sys; [x]
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\drivers\ssudbus.sys [29/03/2012 19:57 80184]
S3 DMSKSSRh;DMSKSSRh; [x]
S3 FsUsbExDisk;FsUsbExDisk; [x]
S3 maconfservice;Ma-Config Service;c:\program files\ma-config.com\maconfservice.exe [10/06/2010 16:15 253808]
S3 NDISKIO;NDISKIO; [x]
S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\drivers\ssudmdm.sys [29/03/2012 19:57 181432]
S3 ssudserd;SAMSUNG Mobile USB Diagnostic Serial Port(DEVGURU Ver.);c:\windows\system32\drivers\ssudserd.sys [29/03/2012 19:57 181432]
S3 WCGOPHAL;WCGOPHAL;c:\windows\system32\drivers\Wcgophal.sys [13/02/2009 16:12 13576]
S3 WCGOPVID;Video Blaster WebCam Go Plus (WDM);c:\windows\system32\drivers\Wcgopvid.sys [13/02/2009 16:12 91077]
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [28/11/2009 23:26 11520]
.
--- Autres Services/Pilotes en mémoire ---
.
*NewlyCreated* - BITS
*NewlyCreated* - WS2IFSL
*NewlyCreated* - WUAUSERV
.
Contenu du dossier 'Tâches planifiées'
.
2013-02-15 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-21 09:02]
.
2013-02-11 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 16:57]
.
2012-09-21 c:\windows\Tasks\debutDowngrade.job
- c:\program files\NCH Software\Debut\debut.exe [2011-02-03 23:08]
.
2012-09-21 c:\windows\Tasks\debutShakeIcon.job
- c:\program files\NCH Software\Debut\debut.exe [2011-02-03 23:08]
.
2013-01-21 c:\windows\Tasks\ExpressRipReminder.job
- c:\program files\NCH Software\ExpressRip\expressrip.exe [2013-01-20 16:32]
.
2012-09-18 c:\windows\Tasks\GoogleUpdateTaskMachineCore1cd7aed77a91287.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-11-02 10:07]
.
2012-09-26 c:\windows\Tasks\PixillionReminder.job
- c:\program files\NCH Software\Pixillion\pixillion.exe [2012-09-26 14:31]
.
2012-12-08 c:\windows\Tasks\videopadShakeIcon.job
- c:\program files\NCH Software\VideoPad\videopad.exe [2012-12-08 11:18]
.
2012-12-08 c:\windows\Tasks\WavePadDowngrade.job
- c:\program files\NCH Software\WavePad\wavepad.exe [2012-12-08 11:32]
.
2012-12-08 c:\windows\Tasks\WavePadReminder.job
- c:\program files\NCH Software\WavePad\wavepad.exe [2012-12-08 11:32]
.
.
------- Examen supplémentaire -------
.
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
IE: Transfert par Image Converter 2 Plus - c:\program files\Sony\Image Converter 2\menu.htm
Trusted Zone: sony-europe.com
Trusted Zone: sonystyle-europe.com
Trusted Zone: vaio-link.com
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\documents and settings\mega boss\Application Data\Mozilla\Firefox\Profiles\ngsisesf.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.lemonde.fr/sciences/
FF - prefs.js: network.proxy.type - 4
.
- - - - ORPHELINS SUPPRIMES - - - -
.
Toolbar-{3EA8D036-C9E7-4721-BCDF-C13D00C4CC39} - (no file)
MSConfigStartUp-SunJavaUpdateSched - c:\program files\Java\jre1.5.0_06\bin\jusched.exe
AddRemove-Creative Video Blaster WebCam Go Plus - c:\windows\CtDrvIns.exe -uninstall usb\vid_041e&pid_4003 -plugin wcgoppin.dll
AddRemove-01_Simmental - c:\program files\Samsung\USB Drivers\01_Simmental\Uninstall.exe
AddRemove-02_Siberian - c:\program files\Samsung\USB Drivers\02_Siberian\Uninstall.exe
AddRemove-03_Swallowtail - c:\program files\Samsung\USB Drivers\03_Swallowtail\Uninstall.exe
AddRemove-04_semseyite - c:\program files\Samsung\USB Drivers\04_semseyite\Uninstall.exe
AddRemove-05_Sloan - c:\program files\Samsung\USB Drivers\05_Sloan\Uninstall.exe
AddRemove-06_Spencer - c:\program files\Samsung\USB Drivers\06_Spencer\Uninstall.exe
AddRemove-07_Schorl - c:\program files\Samsung\USB Drivers\07_Schorl\Uninstall.exe
AddRemove-08_EMPChipset - c:\program files\Samsung\USB Drivers\08_EMPChipset\Uninstall.exe
AddRemove-09_Hsp - c:\program files\Samsung\USB Drivers\09_Hsp\Uninstall.exe
AddRemove-11_HSP_Plus_Default - c:\program files\Samsung\USB Drivers\11_HSP_Plus_Default\Uninstall.exe
AddRemove-16_Shrewsbury - c:\program files\Samsung\USB Drivers\16_Shrewsbury\Uninstall.exe
AddRemove-17_EMP_Chipset2 - c:\program files\Samsung\USB Drivers\17_EMP_Chipset2\Uninstall.exe
AddRemove-18_Zinia_Serial_Driver - c:\program files\Samsung\USB Drivers\18_Zinia_Serial_Driver\Uninstall.exe
AddRemove-19_VIA_driver - c:\program files\Samsung\USB Drivers\19_VIA_driver\Uninstall.exe
AddRemove-20_NXP_Driver - c:\program files\Samsung\USB Drivers\20_NXP_Driver\Uninstall.exe
AddRemove-21_Searsburg - c:\program files\Samsung\USB Drivers\21_Searsburg\Uninstall.exe
AddRemove-22_WiBro_WiMAX - c:\program files\Samsung\USB Drivers\22_WiBro_WiMAX\Uninstall.exe
AddRemove-24_flashusbdriver - c:\program files\Samsung\USB Drivers\24_flashusbdriver\Uninstall.exe
AddRemove-25_escape - c:\program files\Samsung\USB Drivers\25_escape\Uninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-02-16 00:21
Windows 5.1.2600 Service Pack 2 NTFS
.
Recherche de processus cachés ...
.
Recherche d'éléments en démarrage automatique cachés ...
.
Recherche de fichiers cachés ...
.
Scan terminé avec succès
Fichiers cachés: 0
.
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
.
[HKEY_USERS\S-1-5-21-4192526640-160983031-377855418-1011\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- DLLs chargées dans les processus actifs ---------------------
.
- - - - - - - > 'winlogon.exe'(200)
c:\windows\system32\VESWinlogon.dll
.
- - - - - - - > 'explorer.exe'(2096)
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\WinSCP\DragExt.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\windows\system32\browselc.dll
c:\program files\Fichiers communs\Adobe\Acrobat\ActiveX\PDFShell.dll
c:\program files\Fichiers communs\Adobe\Acrobat\ActiveX\PDFShell.FRA
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
c:\program files\Fichiers communs\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\progra~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
c:\program files\Java\jre7\bin\jqs.exe
c:\program files\CDBurnerXP\NMSAccessU.exe
c:\program files\Sony\VAIO Event Service\VESMgr.exe
c:\windows\system32\igfxext.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
c:\program files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
c:\program files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
c:\program files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
c:\program files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
c:\windows\system32\ICO.EXE
c:\windows\RTHDCPL.EXE
c:\windows\system32\wbem\wmiapsrv.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\wscntfy.exe
c:\program files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
.
**************************************************************************
.
Heure de fin: 2013-02-16 00:29:47 - La machine a redémarré
ComboFix-quarantined-files.txt 2013-02-15 23:29
.
Avant-CF: 16 033 845 248 octets libres
Après-CF: 16 174 505 984 octets libres
.
WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP dition familiale" /noexecute=optin /fastdetect
.
- - End Of File - - 0D6F7D6EF83B4DB85C6FA8D04422BBA4
Quel Antivirus me conseilles-tu ?
Bonne nuit à demain ou plus tard. -
Re,
Comment va le PC ?
Il reste encore quelques merdouilles :
Télécharges ComboFix à partir de ce lien et enregistres le sur ton bureau :
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
Avant d'utiliser ComboFix :
? ferme les fenêtres de tous les programmes en cours.
? Désactive provisoirement et seulement le temps de l'utilisation de ComboFix, la protection en temps réel de ton Antivirus et de tes Antispywares, qui peuvent gêner fortement la procédure de recherche et de nettoyage de l'outil.
Une fois fait, sur ton bureau double-clic sur Combofix.exe.
/!\Utilisateur de Vista : Clique droit sur le logo de Combofix, « exécuter en tant qu'Administrateur »
- Répond oui au message d'avertissement, pour que le programme commence à procéder à l'analyse du pc.
- il se peut que Combofix ait besoin de se connecter à internet pour trouver les mises à jour, donc il faut l'autoriser.
/!\ Pendant la durée de cette étape, ne te sert pas du pc et n'ouvre aucun programmes.
- En fin de scan il est possible que ComboFix ait besoin de redémarrer le pc pour finaliser la désinfection\recherche, laisses-le faire.
- Un rapport s'ouvrira ensuite dans le bloc notes, ce fichier rapport Combofix.txt, est automatiquement sauvegardé et rangé à C:\ComboFix\ComboFix.txt)
? Réactive la protection en temps réel de ton Antivirus et de tes Antispywares, avant de te reconnecter à internet.
? Reviens sur le forum, et copie et colle la totalité du contenu de C:\Combofix.txt dans ton prochain message.
- 1
- 2