Pub + rame virus ?
Configuration: Windows Vista Internet Explorer 7.0
28 réponses
Des publicités intempestives et un ralentissement système surviennent sur Windows Vista et Internet Explorer 7 après une réinstallation, suscitant la crainte d’un virus et de perte de performances initiales. Plusieurs réponses proposent des outils et procédures de décontamination comme Navilog, Navilog1, Clean.zip, et OTMoveIt pour identifier et supprimer des éléments suspects dans ProgramData et les dossiers temporaires. D'autres réponses suggèrent des analyses plus fines via des scans d'outils comme HijackThis/Lop S&D, Catchme et GMER, vérifiant le registre, le fichier Hosts et les éléments Run pour éviter de supprimer des composants légitimes. Le fil montre aussi des rapports Navilog et DiagHelp qui nécessitent une analyse par un spécialiste avant toute suppression, et note que les résultats peuvent révéler des fichiers légitimes.
-
ContributeurBonsoir
Va dans "demarrer" "tous les programmes" tu vas sur spybot tu ouvres le dossier et la tu as 3 choix: "spybot S&D", "uninstall" et "update" tu cliques droit sur le premier et tu as "executer en tant qu'administrateur" tu cliques dessus et la tu peux tout controler -
Quand je clique sur corriger les probleme il me dit que l'action ne peut pas s'effectuer car je ne suis pas administrateur.J'comprend pas pourtant je le suis !
-
ContributeurTrès bien
Télécharge ATF Cleaner par Atribune.
http://www.atribune.org/ccount/click.php?id=1
Double-clique ATF-Cleaner.exe afin de lancer le programme.
Sous l'onglet Main, choisis : Select All
Clique sur le bouton Empty Selected
Si tu utilises le navigateur Firefox :
Clique Firefox au haut et choisis : Select All
Clique le bouton Empty Selected
NOTE : Si tu veux conserver tes mots de passe sauvegardés, clique No à l'invite.
Si tu utilises le navigateur Opera :
Clique Opera au haut et choisis : Select All
Clique le bouton Empty Selected
NOTE : Si tu veux conserver tes mots de passe sauvegardés, clique No à l'invite.
Clique Exit, du menu prinicipal, afin de fermer le programme.
Pour obtenir du Support technique, double-clique l'adresse électronique située au bas de chacun des menus.
ensuite
Télécharge sur ton Bureau ==> SpyBot-S&D => https://www.safer-networking.org/download/
Pour son installation regarde ==> ici =>https://www.malekal.com/spybot-search-destroy-proteger-desinfecter-pc-virus/
- Fais un double clique sur Spybot-S&D afin de lancer le programme.
- Clique sur le bouton Vérifier tout.
- Une fois le balayage terminé, Spybot affichera tous les mouchards, dialers et autres indésirables en rouge.
- Assure-toi qu'ils soient tous cochés, puis clique sur Corriger les problèmes.
- Clique sur Oui pour autoriser Spybot à nettoyer les mouchards.
- Clique sur le menu vaccination à gauche et ensuite sur ok
- Clique sur le bouton + Vacciner
Passe c'est outils et refais un nouveau hijack pour vérif stp
et dit moi si tu as encore des soucis -
-----------------------[ Lop S&D 4.2.1-6 XP/Vista ]---------------------
[ Windows 'Longhorn' (NT 6.0) Workstation Build 6000 ]
[ USER : Sophie ] [ "C:\Lop SD" ] [ Selection : 2 ]
[ 17/06/2008 | 23:02:58,43 ] [ PC : PC-DE-SOPHIE ]
[ MAJ : 16-06-2008 | 23:01 ]
[ UAC => 0 ]
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ SUPPRESSION /////////////////////////////
Supprimé! - C:\ProgramData\Long slow road itch\Does Camp.exe
Supprimé! - C:\Program Files\Circle Developement\Uninstall.exe
Supprimé! - C:\ProgramData\idle enc enc.ex9ysx7
Supprimé! - C:\ProgramData\idle enc enc.gglux4
Supprimé! - C:\ProgramData\idle enc enc.tkngbb8
Supprimé! - C:\ProgramData\idle enc enc.y2m2w6x
Supprimé! - C:\ProgramData\Long slow road itch
Supprimé! - C:\Program Files\Circle Developement
Restauré! - Fichier Hosts
//////////////////////////////////////-\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
-------------[ Listing des dossiers dans Application Data ]------------
[14/05/2008|12:37] C:\Users\Sophie\AppData\Roaming\Adobe\Flash Player
[12/05/2008|21:34] C:\Users\Sophie\AppData\Roaming\Adobe\Acrobat
[16/06/2008|17:54] C:\Users\Sophie\AppData\Roaming\Google\Local Search History
[02/11/2006|15:03] C:\Users\Sophie\AppData\Roaming\Identities\{F09DEB20-C877-4C92-A4F4-B30EA5DF074C}
[19/05/2008|12:50] C:\Users\Sophie\AppData\Roaming\InstallShield\ISEngine12.0
[14/05/2008|10:27] C:\Users\Sophie\AppData\Roaming\LimeWire\xml
[14/05/2008|10:25] C:\Users\Sophie\AppData\Roaming\LimeWire\.AppSpecialShare
[14/05/2008|10:25] C:\Users\Sophie\AppData\Roaming\LimeWire\themes
[15/06/2008|00:46] C:\Users\Sophie\AppData\Roaming\Macromedia\Flash Player
[12/06/2008|15:29] C:\Users\Sophie\AppData\Roaming\Malwarebytes\Malwarebytes' Anti-Malware
[14/06/2008|22:58] C:\Users\Sophie\AppData\Roaming\Microsoft\Windows Photo Gallery
[10/06/2008|18:48] C:\Users\Sophie\AppData\Roaming\Microsoft\Credentials
[05/06/2008|18:39] C:\Users\Sophie\AppData\Roaming\Microsoft\HTML Help
[03/06/2008|12:14] C:\Users\Sophie\AppData\Roaming\Microsoft\MSN Messenger
[30/05/2008|08:35] C:\Users\Sophie\AppData\Roaming\Microsoft\Windows
[16/05/2008|20:44] C:\Users\Sophie\AppData\Roaming\Microsoft\Installer
[13/05/2008|17:19] C:\Users\Sophie\AppData\Roaming\Microsoft\eHome
[13/05/2008|17:12] C:\Users\Sophie\AppData\Roaming\Microsoft\Crypto
[13/05/2008|17:03] C:\Users\Sophie\AppData\Roaming\Microsoft\IdentityCRL
[13/05/2008|12:42] C:\Users\Sophie\AppData\Roaming\Microsoft\Internet Explorer
[13/05/2008|12:42] C:\Users\Sophie\AppData\Roaming\Microsoft\Protect
[12/05/2008|20:40] C:\Users\Sophie\AppData\Roaming\Microsoft\CLR Security Config
[02/11/2006|15:04] C:\Users\Sophie\AppData\Roaming\Microsoft\SystemCertificates
[14/05/2008|08:55] C:\Users\Sophie\AppData\Roaming\Microsoft Games\ZT2Launcher
[12/05/2008|21:35] C:\Users\Sophie\AppData\Roaming\Microsoft Games\Vince
[12/05/2008|21:02] C:\Users\Sophie\AppData\Roaming\Microsoft Games\Zoo Tycoon 2
[27/05/2008|13:04] C:\Users\Sophie\AppData\Roaming\OpenOffice.org2\user
[14/06/2008|21:05] C:\Users\Sophie\AppData\Roaming\Toshiba\TOPI
----------------[ Tâches planifiées dans C:\Windows\tasks ]---------------
[16/06/2008 23:19][--ah-----] C:\Windows\tasks\SA.DAT
[16/06/2008 23:17][--a------] C:\Windows\tasks\SCHEDLGU.TXT
------[ Listing des dossiers dans C:\ProgramData ]------
[20/12/2006|14:27] C:\ProgramData\Adobe
[02/11/2006|15:02] C:\ProgramData\Application Data
[16/05/2008|19:09] C:\ProgramData\Avira
[12/05/2008|20:36] C:\ProgramData\Bureau
[02/11/2006|15:02] C:\ProgramData\Desktop
[02/11/2006|15:02] C:\ProgramData\Documents
[14/05/2008|20:35] C:\ProgramData\Downloaded Installations
[12/05/2008|20:36] C:\ProgramData\Favoris
[02/11/2006|15:02] C:\ProgramData\Favorites
[13/05/2008|18:14] C:\ProgramData\Google
[17/06/2008|11:48] C:\ProgramData\Logishrd
[16/05/2008|20:39] C:\ProgramData\Logitech
[12/06/2008|15:29] C:\ProgramData\Malwarebytes
[12/05/2008|20:36] C:\ProgramData\Menu D‚marrer
[13/05/2008|18:27] C:\ProgramData\Messenger Plus!
[05/06/2008|18:39] C:\ProgramData\Microsoft
[12/05/2008|20:51] C:\ProgramData\Microsoft Games
[12/05/2008|20:36] C:\ProgramData\ModŠles
[20/12/2006|14:47] C:\ProgramData\NVIDIA
[12/06/2008|16:43] C:\ProgramData\SlowDownload
[02/11/2006|15:02] C:\ProgramData\Start Menu
[13/06/2008|20:33] C:\ProgramData\Symantec
[02/11/2006|15:02] C:\ProgramData\Templates
[20/12/2006|12:22] C:\ProgramData\Toshiba
[12/05/2008|20:39] C:\ProgramData\ToshibaEurope
[20/12/2006|13:17] C:\ProgramData\Ulead Systems
[13/05/2008|16:55] C:\ProgramData\WLInstaller
---------------[ Listing des dossiers dans C:\Program Files ]--------------
[20/12/2006|14:26] C:\Program Files\Adobe
[16/05/2008|19:09] C:\Program Files\Avira
[12/06/2008|15:14] C:\Program Files\CCleaner
[17/06/2008|11:35] C:\Program Files\Common Files
[20/12/2006|10:13] C:\Program Files\CONEXANT
[14/05/2008|10:04] C:\Program Files\desktop.ini
[12/05/2008|20:36] C:\Program Files\Fichiers communs [C:\Program Files\Common Files]
[14/06/2008|20:37] C:\Program Files\Google
[15/06/2008|00:44] C:\Program Files\happynote
[04/06/2008|20:27] C:\Program Files\HP
[19/05/2008|12:51] C:\Program Files\InstallShield Installation Information
[12/06/2008|09:19] C:\Program Files\Internet Explorer
[20/12/2006|13:18] C:\Program Files\InterVideo
[29/05/2008|21:16] C:\Program Files\Java
[13/05/2008|16:59] C:\Program Files\LimeWire
[17/06/2008|11:35] C:\Program Files\Logitech
[14/06/2008|23:56] C:\Program Files\Malwarebytes' Anti-Malware
[13/06/2008|10:19] C:\Program Files\Messenger Plus! Live
[14/05/2008|09:27] C:\Program Files\Microsoft CAPICOM 2.1.0.2
[12/05/2008|20:42] C:\Program Files\Microsoft Games
[02/11/2006|14:42] C:\Program Files\Movie Maker
[02/11/2006|14:37] C:\Program Files\MSBuild
[02/11/2006|14:37] C:\Program Files\MSN
[14/05/2008|08:50] C:\Program Files\MSXML 4.0
[20/12/2006|09:54] C:\Program Files\My Company Name
[14/06/2008|21:50] C:\Program Files\Navilog1
[15/06/2008|20:18] C:\Program Files\Neuf
[26/05/2008|20:22] C:\Program Files\OneStopSoft.com
[14/06/2008|22:32] C:\Program Files\OpenOffice.org 2.4
[15/06/2008|00:23] C:\Program Files\PhotoScape
[02/11/2006|14:37] C:\Program Files\Reference Assemblies
[16/05/2008|22:40] C:\Program Files\Satsuki Decoder Pack
[14/05/2008|16:02] C:\Program Files\Sibelius Software
[20/12/2006|10:08] C:\Program Files\Synaptics
[20/12/2006|16:01] C:\Program Files\TOSHIBA
[14/06/2008|20:50] C:\Program Files\Trend Micro
[08/06/2008|20:54] C:\Program Files\Trymedia
[20/12/2006|13:15] C:\Program Files\Ulead Systems
[02/11/2006|15:01] C:\Program Files\Uninstall Information
[14/05/2008|09:58] C:\Program Files\Windows Calendar
[02/11/2006|14:42] C:\Program Files\Windows Collaboration
[14/05/2008|09:58] C:\Program Files\Windows Defender
[02/11/2006|14:42] C:\Program Files\Windows Journal
[13/05/2008|17:02] C:\Program Files\Windows Live
[12/06/2008|09:19] C:\Program Files\Windows Mail
[20/12/2006|13:18] C:\Program Files\Windows Media Components
[14/05/2008|09:58] C:\Program Files\Windows Media Player
[12/05/2008|20:36] C:\Program Files\Windows NT
[02/11/2006|14:42] C:\Program Files\Windows Photo Gallery
[14/05/2008|09:58] C:\Program Files\Windows Sidebar
[31/05/2008|22:04] C:\Program Files\WinRAR
------[ Listing des dossiers dans C:\Program Files\Common Files ]------
[20/12/2006|14:27] C:\Program Files\Common Files\Adobe
[15/06/2008|00:49] C:\Program Files\Common Files\BitDefender
[04/06/2008|20:27] C:\Program Files\Common Files\HP
[20/12/2006|13:18] C:\Program Files\Common Files\InstallShield
[20/12/2006|09:52] C:\Program Files\Common Files\Java
[17/06/2008|11:43] C:\Program Files\Common Files\LogiShrd
[17/06/2008|11:38] C:\Program Files\Common Files\Logitech
[12/05/2008|20:51] C:\Program Files\Common Files\Microsoft Games
[13/05/2008|17:05] C:\Program Files\Common Files\microsoft shared
[02/11/2006|13:18] C:\Program Files\Common Files\Services
[02/11/2006|13:18] C:\Program Files\Common Files\SpeechEngines
[13/06/2008|22:15] C:\Program Files\Common Files\Symantec Shared
[14/05/2008|09:58] C:\Program Files\Common Files\System
[20/12/2006|13:18] C:\Program Files\Common Files\Ulead Systems
[13/05/2008|17:02] C:\Program Files\Common Files\WindowsLiveInstaller
---------------------------[ Process ]--------------------------
... 75
... OK !
----------------------[ Recherche avec S_Lop ]---------------------
Aucun fichier / dossier Lop trouvé !
-----------------[ Recherche de Fichiers / Dossiers Lop ]-----------------
Aucun fichier / dossier Lop trouvé !
----------------------[ Verification du Registre ]----------------------
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
..... OK !
--------------------[ Verification du fichier Hosts ]---------------------
Fichier Hosts PROPRE
----------------[ Recherche de fichiers avec Catchme ]-----------------
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-17 23:03:42
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 0
--------------------[ Recherche d'autres infections ]---------------------
Aucune autre infection trouvée !
[F:266][D:50]-> C:\Users\Sophie\AppData\Local\Temp
[F:787][D:1]-> C:\Users\Sophie\AppData\Roaming\MICROS~1\Windows\Cookies
[F:801][D:7]-> C:\Users\Sophie\AppData\Local\MICROS~1\Windows\TEMPOR~1\content.IE5
[F:3][D:3]-> C:\$Recycle.Bin
[ UAC => 1 ]
--------------------[ Fin du rapport a 23:04:17,91 ]---------------------- -
ContributeurTélécharge LOP S&D d'Eric71 ici https://sites.google.com/site/eric71mespages/lop.sd.exe
Double-clique dessus pour lancer l'installation.
Puis double-clique sur le raccourci Lop S&D présent sur ton Bureau.
Séléctionne la langue souhaitée , puis choisis l'Option 2 ( suppression )
Patiente jusqu'à la fin du scan.
Poste le rapport généré (situé aussi ici C:\lopR.txt )
( Si le Bureau ne réapparaît pas, lance le gestionnaire des tâches en cliquant sur Ctrl + Alt + Suppr , puis Onglet Fichier , Nouvelle tâche , tape explorer.exe et valide ) -
voila lool
DiagHelp version v1.4 - http://www.malekal.com
excute le 17/06/2008 à 22:41:09,05
Liste des derniers fichies modifies/crees dans windir\system32 et prefetch
C:\Windows\prefetch\AVWSC.EXE-18A3FCA0.pf -->17/06/2008 22:33:08
C:\Windows\prefetch\AURORA.SCR-082F40F8.pf -->17/06/2008 22:33:06
C:\Windows\prefetch\AgGlFgAppHistory.db -->17/06/2008 22:12:55
C:\Windows\prefetch\AgGlFaultHistory.db -->17/06/2008 22:12:54
C:\Windows\prefetch\AgGlGlobalHistory.db -->17/06/2008 22:12:53
C:\Windows\prefetch\AgRobust.db -->17/06/2008 22:12:52
C:\Windows\prefetch\AgGlUAD_S-1-5-21-1097218276-1889954354-71906903-1000.db -->17/06/2008 22:08:40
C:\Windows\prefetch\AgGlUAD_P_S-1-5-21-1097218276-1889954354-71906903-1000.db -->17/06/2008 22:08:40
C:\Windows\prefetch\TASKENG.EXE-48D4E289.pf -->17/06/2008 22:04:50
C:\Windows\prefetch\AgCx_SC1.db -->17/06/2008 20:44:09
C:\Windows\System32\drivers\mbamcatchme.sys -->10/06/2008 19:02:44
C:\Windows\System32\drivers\mbam.sys -->10/06/2008 19:02:40
C:\Windows\System32\drivers\WdfLdr.sys -->16/05/2008 08:06:20
C:\Windows\System32\drivers\Wdf01000.sys -->16/05/2008 08:06:20
C:\Windows\System32\drivers\sermouse.sys -->16/05/2008 08:06:18
C:\Windows\System32\drivers\mouclass.sys -->16/05/2008 08:06:18
C:\Windows\System32\drivers\kbdclass.sys -->16/05/2008 08:06:18
C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 -->17/06/2008 22:04:24
C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 -->17/06/2008 22:04:24
C:\Windows\System32\perfh00C.dat -->17/06/2008 12:34:35
C:\Windows\System32\perfh009.dat -->17/06/2008 12:34:35
C:\Windows\System32\perfc00C.dat -->17/06/2008 12:34:35
C:\Windows\System32\perfc009.dat -->17/06/2008 12:34:35
C:\Windows\System32\PerfStringBackup.INI -->17/06/2008 12:34:33
C:\Windows\System32\lvcoinst.log -->17/06/2008 11:44:04
C:\Windows\System32\GDIPFONTCACHEV1.DAT -->15/06/2008 10:17:55
C:\Windows\System32\FNTCACHE.DAT -->15/06/2008 10:14:53
C:\Windows\System32\coh.cache -->13/06/2008 20:17:51
C:\Windows\System32\mrt.exe -->30/05/2008 01:35:11
C:\Windows\System32\jupdate-1.6.0_05-b13.log -->29/05/2008 21:16:38
C:\Windows\System32\jupdate-1.6.0_04-b12.log -->27/05/2008 12:56:48
C:\Windows\System32\satsukidecodersettings.ini -->16/05/2008 22:40:51
C:\Windows\System32\setupapi.dll -->16/05/2008 08:07:32
C:\Windows\System32\srdelayed.exe -->16/05/2008 08:06:38
C:\Windows\System32\srcore.dll -->16/05/2008 08:06:38
C:\Windows\System32\srclient.dll -->16/05/2008 08:06:38
C:\Windows\System32\rstrui.exe -->16/05/2008 08:06:38
C:\Windows\System32\wpd_ci.dll -->16/05/2008 08:06:37
C:\Windows\System32\winresume.exe -->16/05/2008 08:06:36
C:\Windows\System32\kd1394.dll -->16/05/2008 08:06:36
C:\Windows\System32\winload.exe -->16/05/2008 08:06:35
C:\Windows\System32\ci.dll -->16/05/2008 08:06:32
C:\Windows\WindowsUpdate.log -->17/06/2008 20:46:26
C:\Windows\bootstat.dat -->17/06/2008 20:42:59
C:\Windows\setupact.log -->17/06/2008 12:31:27
C:\Windows\setuperr.log -->15/06/2008 12:20:49
C:\Windows\Sol.ini -->14/05/2008 20:17:30
C:\Windows\pp-oneclick-repertoire.ini -->14/05/2008 20:16:17
C:\Windows\WindowsShell.Manifest -->14/05/2008 10:04:52
C:\Windows\explorer.exe -->14/05/2008 09:44:01
C:\Windows\bdoscandellang.ini -->09/01/2008 15:01:48
C:\Windows\bdoscandel.exe -->09/01/2008 15:01:48
C:\Windows\csup.txt -->22/12/2006 10:34:39
C:\Windows\NDSTray.INI -->20/12/2006 12:22:22
C:\Windows\oemlogo.bmp -->03/11/2006 14:30:08
C:\Windows\win.ini -->02/11/2006 15:04:04
C:\Windows\WMSysPr9.prx -->02/11/2006 14:35:57
winlogon.exe
Verified: Signed
svchost.exe
Verified: Signed
ws2_32.dll
Verified: Signed
user32.dll
Verified: Signed
tcpip.sys
Verified: Signed
ndis.sys
Verified: Signed
null.sys
Verified: Signed
ListDLLs v2.25 - DLL lister for Win9x/NT
Copyright (C) 1997-2004 Mark Russinovich
Sysinternals - www.sysinternals.com
------------------------------------------------------------------------------
explorer.exe pid: 1744
Command line: C:\Windows\Explorer.EXE
Base Size Version Path
0x00600000 0x2cd000 6.00.6000.16549 C:\Windows\Explorer.EXE
0x779b0000 0x11e000 6.00.6000.16386 C:\Windows\system32\ntdll.dll
0x76a80000 0xd8000 6.00.6000.16386 C:\Windows\system32\kernel32.dll
0x769c0000 0xbf000 6.00.6000.16386 C:\Windows\system32\ADVAPI32.dll
0x77780000 0xc3000 6.00.6000.16525 C:\Windows\system32\RPCRT4.dll
0x76270000 0x4b000 6.00.6000.16643 C:\Windows\system32\GDI32.dll
0x76920000 0x9e000 6.00.6000.16438 C:\Windows\system32\USER32.dll
0x763a0000 0xaa000 7.00.6000.16386 C:\Windows\system32\msvcrt.dll
0x76770000 0x55000 6.00.6000.16386 C:\Windows\system32\SHLWAPI.dll
0x76cb0000 0xace000 6.00.6000.16513 C:\Windows\system32\SHELL32.dll
0x767d0000 0x144000 6.00.6000.16386 C:\Windows\system32\ole32.dll
0x77b60000 0x8c000 6.00.6000.16609 C:\Windows\system32\OLEAUT32.dll
0x735f0000 0x107000 6.00.6000.16386 C:\Windows\system32\SHDOCVW.dll
0x75310000 0x3f000 6.00.6000.16386 C:\Windows\system32\UxTheme.dll
0x755c0000 0x1a000 6.00.6000.16386 C:\Windows\system32\POWRPROF.dll
0x739d0000 0xc000 6.00.6000.16386 C:\Windows\system32\dwmapi.dll
0x74ac0000 0x1aa000 5.02.6000.16386 C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16386_none_9ea0ac9ec96e7127\gdiplus.dll
0x75b90000 0x39000 6.00.6000.16509 C:\Windows\system32\slc.dll
0x74900000 0xb7000 6.00.6000.16386 C:\Windows\system32\PROPSYS.dll
0x734a0000 0x145000 6.00.6000.16386 C:\Windows\system32\BROWSEUI.dll
0x77b00000 0x1e000 6.00.6000.16386 C:\Windows\system32\IMM32.dll
0x778e0000 0xc7000 6.00.6000.16386 C:\Windows\system32\MSCTF.dll
0x752e0000 0x30000 6.00.6000.16386 C:\Windows\system32\DUser.dll
0x76390000 0x9000 6.00.6000.16386 C:\Windows\system32\LPK.DLL
0x762c0000 0x7d000 1.626.6000.16386 C:\Windows\system32\USP10.dll
0x75010000 0x194000 6.10.6000.16386 C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6000.16386_none_5d07289e07e1d100\comctl32.dll
0x73f70000 0xb2000 6.00.6000.16493 C:\Windows\system32\WindowsCodecs.dll
0x73480000 0x6000 6.00.6000.16386 C:\Windows\system32\IconCodecService.dll
0x760a0000 0x2c000 6.00.6000.16386 C:\Windows\system32\apphelp.dll
0x76100000 0x14000 6.00.6000.16386 C:\Windows\system32\Secur32.dll
0x77850000 0x84000 2001.12.6930.16386 C:\Windows\system32\CLBCatQ.DLL
0x75660000 0x38000 6.00.6000.16386 C:\Windows\system32\rsaenh.dll
0x72ba0000 0xb2000 6.00.6000.16549 C:\Windows\system32\timedate.cpl
0x74710000 0x14000 3.05.2284.0000 C:\Windows\system32\ATL.DLL
0x75f70000 0x6a000 6.00.6000.16386 C:\Windows\system32\NETAPI32.dll
0x76260000 0x7000 6.00.6000.16386 C:\Windows\system32\PSAPI.DLL
0x74de0000 0x38000 4.02.5406.0000 C:\Windows\system32\OLEACC.dll
0x72ae0000 0x53000 6.00.6000.16386 C:\Windows\system32\actxprxy.dll
0x76120000 0x1e000 6.00.6000.16386 C:\Windows\system32\USERENV.dll
0x75940000 0x8000 6.00.6000.16386 C:\Windows\system32\VERSION.dll
0x72b40000 0x2b000 6.00.6000.16386 C:\Windows\system32\msutb.dll
0x72b80000 0x1b000 11.00.6000.6324 C:\PROGRA~1\WI4EB4~1\wmpband.dll
0x75cd0000 0x14000 6.00.6000.16386 C:\Windows\system32\MPR.dll
0x75720000 0xd7000 6.00.6000.16386 C:\Windows\system32\WINBRAND.dll
0x75d40000 0x11000 6.00.6000.16386 C:\Windows\System32\SAMLIB.dll
0x72a60000 0x38000 6.00.6000.16386 C:\Windows\System32\msshsq.dll
0x728c0000 0xc5000 6.00.6000.16386 C:\Windows\System32\NaturalLanguage6.dll
0x75bd0000 0xf1000 6.00.6000.16425 C:\Windows\System32\CRYPT32.dll
0x75d20000 0x12000 6.00.6000.16386 C:\Windows\System32\MSASN1.dll
0x74e20000 0x1e7000 6.00.6000.16513 C:\Windows\system32\authui.dll
0x755b0000 0x5000 6.00.6000.16386 C:\Windows\system32\MSIMG32.dll
0x72720000 0x19f000 6.00.6000.16651 C:\Windows\System32\gameux.dll
0x72e50000 0x5f000 6.00.6000.16386 C:\Windows\System32\WINHTTP.dll
0x76b60000 0xd0000 7.00.6000.16681 C:\Windows\system32\WININET.dll
0x764a0000 0x3000 6.00.6000.16386 C:\Windows\system32\Normaliz.dll
0x76340000 0x45000 7.00.6000.16386 C:\Windows\system32\iertutil.dll
0x737e0000 0x148000 6.10.1200.0000 C:\Windows\System32\msxml6.dll
0x729c0000 0x4c000 1.00.0000.0001 C:\Windows\System32\Wpc.dll
0x75400000 0x9000 6.00.6000.16553 C:\Windows\System32\WTSAPI32.dll
0x76640000 0x127000 7.00.6000.16681 C:\Windows\system32\urlmon.dll
0x72fa0000 0x8a000 6.00.6000.16386 C:\Windows\System32\fwpuclnt.dll
0x75b50000 0x3e000 6.00.6000.16386 C:\Windows\System32\wevtapi.dll
0x77ad0000 0x2d000 6.00.6000.16386 C:\Windows\system32\WS2_32.dll
0x77b20000 0x6000 6.00.6000.16386 C:\Windows\system32\NSI.dll
0x72f90000 0x7000 4.00.6000.16386 C:\Windows\system32\msiltcfg.dll
0x72190000 0x204000 4.00.6000.16386 C:\Windows\system32\msi.dll
0x755e0000 0x21000 6.00.6000.16386 C:\Windows\system32\NTMARTA.DLL
0x76450000 0x49000 6.00.6000.16386 C:\Windows\system32\WLDAP32.dll
0x72f80000 0x9000 6.00.6000.16386 C:\Windows\system32\LINKINFO.dll
0x711d0000 0x5cd000 7.00.6000.16681 C:\Windows\system32\ieframe.dll
0x74d30000 0x33000 6.00.6000.16386 C:\Windows\system32\WINMM.dll
0x74870000 0x30000 6.00.6000.16386 C:\Windows\system32\wdmaud.drv
0x74cc0000 0x4000 6.00.6000.16386 C:\Windows\system32\ksuser.dll
0x74db0000 0x7000 6.00.6000.16386 C:\Windows\system32\AVRT.dll
0x74cd0000 0x27000 6.00.6000.16386 C:\Windows\system32\MMDevAPI.DLL
0x72eb0000 0xa000 6.00.6000.16386 C:\Windows\system32\cscapi.dll
0x764b0000 0x189000 6.00.6000.16609 C:\Windows\system32\SETUPAPI.dll
0x75410000 0x2d000 6.00.6000.16386 C:\Windows\system32\WINTRUST.dll
0x77b30000 0x29000 6.00.6000.16470 C:\Windows\system32\imagehlp.dll
0x72b70000 0x9000 6.00.6000.16386 C:\Windows\system32\ExplorerFrame.dll
0x741d0000 0x21000 6.00.6000.16386 C:\Windows\System32\audioses.dll
0x74070000 0x66000 6.00.6000.16386 C:\Windows\System32\audioeng.dll
0x72990000 0x30000 6.00.6000.16386 C:\Windows\system32\MLANG.dll
0x74860000 0x9000 6.00.6000.16386 C:\Windows\system32\msacm32.drv
0x74180000 0x15000 6.00.6000.16386 C:\Windows\system32\MSACM32.dll
0x74170000 0x7000 6.00.6000.16386 C:\Windows\system32\midimap.dll
0x71da0000 0x92000 6.00.6000.16386 C:\Windows\system32\stobject.dll
0x71080000 0xb6000 6.00.6000.16386 C:\Windows\system32\BatMeter.dll
0x75950000 0x24000 6.00.6000.16386 C:\Windows\system32\WINSTA.dll
0x73ed0000 0x45000 2001.12.6930.16386 C:\Windows\system32\es.dll
0x70f20000 0x30000 6.00.6000.16386 C:\Windows\System32\SndVolSSO.dll
0x70dc0000 0x21000 6.00.6000.16386 C:\Windows\ehome\ehSSO.dll
0x748c0000 0x9000 6.00.6000.16386 C:\Windows\system32\HID.DLL
0x754f0000 0x63000 6.00.6000.16501 C:\Windows\system32\FirewallAPI.dll
0x70610000 0x30b000 6.00.6000.16386 C:\Windows\System32\netshell.dll
0x75b30000 0x19000 6.00.6000.16386 C:\Windows\System32\IPHLPAPI.DLL
0x75af0000 0x35000 6.00.6000.16512 C:\Windows\System32\dhcpcsvc.DLL
0x75d60000 0x2b000 6.00.6000.16615 C:\Windows\System32\DNSAPI.dll
0x75ae0000 0x7000 6.00.6000.16386 C:\Windows\System32\WINNSI.DLL
0x75ac0000 0x20000 6.00.6000.16512 C:\Windows\System32\dhcpcsvc6.DLL
0x748d0000 0xf000 6.00.6000.16386 C:\Windows\System32\nlaapi.dll
0x70a70000 0x1bf000 6.00.6000.16386 C:\Windows\system32\pnidui.dll
0x70e00000 0x17000 6.00.6000.16386 C:\Windows\system32\QUtil.dll
0x73a80000 0x6000 6.00.6000.16386 C:\Windows\system32\wlanutil.dll
0x75fe0000 0x5f000 6.00.6000.16386 C:\Windows\system32\SXS.DLL
0x6ea40000 0x8000 6.00.6000.16386 C:\Windows\System32\npmproxy.dll
0x01c80000 0x17000 C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll
0x752d0000 0xe000 6.00.6000.16551 C:\Windows\system32\Wlanapi.dll
0x73af0000 0x2d000 6.00.6000.16386 C:\Windows\system32\OneX.DLL
0x73f20000 0xd000 6.00.6000.16386 C:\Windows\system32\eappprxy.dll
0x73ac0000 0x28000 6.00.6000.16386 C:\Windows\system32\eappcfg.dll
0x75a20000 0x44000 6.00.6000.16386 C:\Windows\system32\bcrypt.dll
0x72610000 0xd000 6.00.6000.16386 C:\Windows\System32\AltTab.dll
0x72570000 0x23000 6.00.6000.16386 C:\Windows\system32\wpdshserviceobj.dll
0x724f0000 0x40000 6.00.6000.16386 C:\Windows\System32\srchadmin.dll
0x724b0000 0x3c000 7.00.6000.16386 C:\Windows\system32\webcheck.dll
0x6e300000 0x4a000 6.00.6000.16386 C:\Windows\system32\ntshrui.dll
0x6ccf0000 0x21c000 6.00.6000.16386 C:\Windows\System32\SyncCenter.dll
0x723f0000 0x51000 6.00.6000.16386 C:\Windows\system32\imapi2.dll
0x72600000 0xb000 6.00.6000.16386 C:\Windows\system32\mssprxy.dll
0x72540000 0x2b000 6.00.6000.16386 C:\Windows\system32\PortableDeviceTypes.dll
0x6e830000 0x46000 6.00.6000.16386 C:\Windows\system32\PortableDeviceApi.dll
0x72470000 0x39000 6.00.6000.16386 C:\Windows\system32\wscntfy.dll
0x72620000 0xb000 6.00.6000.16386 C:\Windows\system32\WSCAPI.dll
0x71ca0000 0xf9000 6.00.6000.16386 C:\Windows\system32\bthprops.cpl
0x6ec00000 0x12000 6.00.6000.16386 C:\Windows\System32\ntlanman.dll
0x6f1f0000 0x8000 6.00.6000.16386 C:\Windows\System32\drprov.dll
0x6eea0000 0xf000 6.00.6000.16386 C:\Windows\System32\davclnt.dll
0x6dac0000 0x2c000 6.00.6000.16386 C:\Windows\System32\QAgent.dll
0x73450000 0xb000 6.00.6000.16386 C:\Windows\system32\wbem\wbemprox.dll
0x72d80000 0x59000 6.00.6000.16553 C:\Windows\system32\wbem\wbemcomn.dll
0x6e750000 0x10000 6.00.6000.16386 C:\Windows\system32\wbem\wbemsvc.dll
0x6e3b0000 0x99000 6.00.6000.16386 C:\Windows\system32\wbem\fastprox.dll
0x75d00000 0x18000 6.00.6000.16386 C:\Windows\system32\NTDSAPI.dll
0x01b00000 0x1b000 11.05.0000.1158 C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll
0x748e0000 0x14000 6.00.6000.16386 C:\Windows\system32\Cabinet.dll
0x75a70000 0x32000 6.00.6000.16386 C:\Windows\system32\ncrypt.dll
0x75640000 0x15000 6.00.6000.16386 C:\Windows\system32\GPAPI.dll
0x72ac0000 0x19000 6.00.6000.16386 C:\Windows\system32\cryptnet.dll
0x74d20000 0x6000 6.00.6000.16386 C:\Windows\system32\SensApi.dll
0x70df0000 0x6000 6.00.6000.16386 C:\Windows\system32\dciman32.dll
0x725d0000 0x24000 11.00.6000.6324 C:\Windows\System32\wmpps.dll
0x6bab0000 0xa2f000 11.00.6000.6344 C:\Windows\system32\wmp.dll
0x6d290000 0x23000 6.00.6000.16513 C:\Windows\system32\MSVFW32.dll
0x74600000 0xdc000 6.00.6000.16386 C:\Windows\system32\dbghelp.dll
0x6b2e0000 0x7c7000 11.00.6000.6344 C:\Windows\system32\wmploc.dll
0x701b0000 0x78000 5.07.0000.6000 C:\Windows\system32\jscript.dll
0x6b070000 0x26e000 6.00.6000.16386 C:\Windows\system32\wpdshext.dll
0x74730000 0x18000 6.00.6000.16513 C:\Windows\system32\AVIFIL32.dll
0x10000000 0x77d000 7.15.0010.9748 C:\Windows\system32\nvcpl.dll
0x76c30000 0x74000 6.00.6000.16386 C:\Windows\system32\comdlg32.dll
0x72ca0000 0x41000 6.00.6000.16386 C:\Windows\system32\WINSPOOL.DRV
0x03880000 0x4c000 7.15.0010.9748 C:\Windows\system32\nvapi.dll
0x70c30000 0x126000 8.90.1101.0000 C:\Windows\System32\msxml3.dll
0x6aa40000 0x28c000 6.00.6000.16386 C:\Windows\System32\NLSData000c.dll
0x69320000 0x5f4000 6.00.6000.16386 C:\Windows\System32\NLSLexicons000c.dll
0x723d0000 0x12000 6.00.6000.16386 C:\Windows\system32\thumbcache.dll
0x03060000 0x2e000 C:\Program Files\WinRAR\rarext.dll
0x023f0000 0x8000 1.00.0000.0000 C:\Program Files\Malwarebytes' Anti-Malware\mbamext.dll
0x02fe0000 0x13000 7.00.0000.0011 C:\Program Files\Avira\AntiVir PersonalEdition Classic\shlext.dll
0x7c250000 0x102000 7.10.3077.0000 C:\Program Files\Avira\AntiVir PersonalEdition Classic\MFC71U.DLL
0x03930000 0x56000 7.10.3052.0004 C:\Program Files\Avira\AntiVir PersonalEdition Classic\MSVCR71.dll
0x7c3a0000 0x7b000 7.10.3077.0000 C:\Program Files\Avira\AntiVir PersonalEdition Classic\MSVCP71.dll
0x5d360000 0xf000 7.10.3077.0000 C:\Windows\system32\MFC71FRA.DLL
0x6f4c0000 0x2e000 6.00.6000.16386 C:\Windows\system32\syncui.dll
0x717a0000 0x15000 6.00.6000.16386 C:\Windows\system32\SYNCENG.dll
0x71960000 0x60000 6.00.6000.16386 C:\Program Files\Common Files\microsoft shared\ink\tiptsf.dll
0x02560000 0xe000 7.00.0007.0142 C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
0x75280000 0x22000 1.01.1002.0000 C:\Windows\system32\xmllite.dll
ListDLLs v2.25 - DLL lister for Win9x/NT
Copyright (C) 1997-2004 Mark Russinovich
Sysinternals - www.sysinternals.com
------------------------------------------------------------------------------
winlogon.exe pid: 680
Command line: winlogon.exe
Base Size Version Path
0x00b70000 0x4e000 6.00.6000.16386 C:\Windows\system32\winlogon.exe
0x779b0000 0x11e000 6.00.6000.16386 C:\Windows\system32\ntdll.dll
0x76a80000 0xd8000 6.00.6000.16386 C:\Windows\system32\kernel32.dll
0x769c0000 0xbf000 6.00.6000.16386 C:\Windows\system32\ADVAPI32.dll
0x77780000 0xc3000 6.00.6000.16525 C:\Windows\system32\RPCRT4.dll
0x76920000 0x9e000 6.00.6000.16438 C:\Windows\system32\USER32.dll
0x76270000 0x4b000 6.00.6000.16643 C:\Windows\system32\GDI32.dll
0x763a0000 0xaa000 7.00.6000.16386 C:\Windows\system32\msvcrt.dll
0x76100000 0x14000 6.00.6000.16386 C:\Windows\system32\Secur32.dll
0x75950000 0x24000 6.00.6000.16386 C:\Windows\system32\WINSTA.dll
0x76260000 0x7000 6.00.6000.16386 C:\Windows\system32\PSAPI.DLL
0x76120000 0x1e000 6.00.6000.16386 C:\Windows\system32\USERENV.dll
0x77b00000 0x1e000 6.00.6000.16386 C:\Windows\system32\IMM32.DLL
0x778e0000 0xc7000 6.00.6000.16386 C:\Windows\system32\MSCTF.dll
0x76390000 0x9000 6.00.6000.16386 C:\Windows\system32\LPK.DLL
0x762c0000 0x7d000 1.626.6000.16386 C:\Windows\system32\USP10.dll
0x760a0000 0x2c000 6.00.6000.16386 C:\Windows\system32\apphelp.dll
0x755e0000 0x21000 6.00.6000.16386 C:\Windows\system32\NTMARTA.DLL
0x76450000 0x49000 6.00.6000.16386 C:\Windows\system32\WLDAP32.dll
0x77ad0000 0x2d000 6.00.6000.16386 C:\Windows\system32\WS2_32.dll
0x77b20000 0x6000 6.00.6000.16386 C:\Windows\system32\NSI.dll
0x75d40000 0x11000 6.00.6000.16386 C:\Windows\system32\SAMLIB.dll
0x767d0000 0x144000 6.00.6000.16386 C:\Windows\system32\ole32.dll
0x74030000 0x3e000 6.00.6000.16386 C:\Windows\system32\SHSVCS.dll
0x75310000 0x3f000 6.00.6000.16386 C:\Windows\system32\uxtheme.dll
0x75660000 0x38000 6.00.6000.16386 C:\Windows\system32\rsaenh.dll
0x73f70000 0xb2000 6.00.6000.16493 C:\Windows\system32\WindowsCodecs.dll
0x75f70000 0x6a000 6.00.6000.16386 C:\Windows\system32\NETAPI32.dll
0x75b90000 0x39000 6.00.6000.16509 C:\Windows\system32\slc.dll
0x75cd0000 0x14000 6.00.6000.16386 C:\Windows\system32\MPR.dll
0x760e0000 0x16000 6.00.6000.16386 C:\Windows\system32\AUTHZ.dll
Le volume dans le lecteur C s'appelle Vista
Le numéro de série du volume est 3E37-91A8
Répertoire de C:\Windows\system32
02/11/2006 11:45 7 680 csrss.exe
1 fichier(s) 7 680 octets
0 Rép(s) 56 625 868 800 octets libres
Contenu de Downloaded Program Files
Le volume dans le lecteur C s'appelle Vista
Le numéro de série du volume est 3E37-91A8
Répertoire de C:\Windows\Downloaded Program Files
15/06/2008 00:47 <REP> .
15/06/2008 00:47 <REP> ..
09/01/2008 15:01 32 bdcore.dll
09/01/2008 15:01 118 784 bdupd.dll
18/09/2006 23:26 65 desktop.ini
24/03/2008 19:33 1 527 056 FP_AX_CAB_INSTALLER.exe
09/01/2008 15:01 53 248 ipsupd.dll
26/02/2008 15:42 7 724 lang.ini
09/01/2008 15:01 32 libfn.dll
21/01/2008 17:43 130 live.ini
07/02/2008 14:06 1 248 oscan8.inf
26/02/2008 15:59 487 424 oscan82.ocx
09/01/2008 15:01 6 828 scanoptions.tsi
10/04/2008 10:21 185 SETUP.INF
24/03/2008 19:18 247 swflash.inf
13 fichier(s) 2 203 003 octets
Total des fichiers listés :
13 fichier(s) 2 203 003 octets
2 Rép(s) 56 625 864 704 octets libres
Recherche de rootkit! (Merci S!Ri)
Recherche d'infections connues
Export des clefs sensibles..
Liste des fichiers en exception sur le pare-feu XP SP2
Export de la clef SharedTaskScheduler
[SharedTaskScheduler]
exports des policies
REGEDIT4
[System]
"ConsentPromptBehaviorAdmin"=dword:00000002
"ConsentPromptBehaviorUser"=dword:00000001
"EnableInstallerDetection"=dword:00000001
"EnableLUA"=dword:00000000
"EnableSecureUIAPaths"=dword:00000001
"EnableVirtualization"=dword:00000001
"PromptOnSecureDesktop"=dword:00000001
"ValidateAdminCodeSignatures"=dword:00000000
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"scforceoption"=dword:00000000
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
"FilterAdministratorToken"=dword:00000000
[System\UIPI]
[System\UIPI\Clipboard]
[System\UIPI\Clipboard\ExceptionFormats]
"CF_TEXT"=dword:00000001
"CF_BITMAP"=dword:00000002
"CF_OEMTEXT"=dword:00000007
"CF_DIB"=dword:00000008
"CF_PALETTE"=dword:00000009
"CF_UNICODETEXT"=dword:0000000d
"CF_DIBV5"=dword:00000011
Export des clefs sensibles..
Rechercher adresses sensibles dans le fichier HOSTS...
catchme 0.3.1351 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-17 22:41:50
Windows 6.0.6000 NTFS
scanning hidden services & system hive ...
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden services: 0
hidden files: 0
KProcCheck Version 0.2-beta1 Proof-of-Concept by SIG^2 (www.security.org.sg)
Sorry, this version supports only Win2K/XP
KProcCheck Version 0.2-beta1 Proof-of-Concept by SIG^2 (www.security.org.sg)
Sorry, this version supports only Win2K/XP
Le volume dans le lecteur C s'appelle Vista
Le numéro de série du volume est 3E37-91A8
Répertoire de C:\Program Files
17/06/2008 11:35 <REP> .
17/06/2008 11:35 <REP> ..
20/12/2006 14:26 <REP> Adobe
16/05/2008 19:09 <REP> Avira
12/06/2008 15:14 <REP> CCleaner
30/05/2008 12:59 <REP> Circle Developement
17/06/2008 11:35 <REP> Common Files
20/12/2006 10:13 <REP> CONEXANT
14/06/2008 20:37 <REP> Google
15/06/2008 00:44 <REP> happynote
04/06/2008 20:27 <REP> HP
12/06/2008 09:19 <REP> Internet Explorer
20/12/2006 13:18 <REP> InterVideo
29/05/2008 21:16 <REP> Java
13/05/2008 16:59 <REP> LimeWire
17/06/2008 11:35 <REP> Logitech
14/06/2008 23:56 <REP> Malwarebytes' Anti-Malware
13/06/2008 10:19 <REP> Messenger Plus! Live
14/05/2008 09:27 <REP> Microsoft CAPICOM 2.1.0.2
12/05/2008 20:42 <REP> Microsoft Games
02/11/2006 14:42 <REP> Movie Maker
02/11/2006 14:37 <REP> MSBuild
02/11/2006 14:37 <REP> MSN
14/05/2008 08:50 <REP> MSXML 4.0
20/12/2006 09:54 <REP> My Company Name
14/06/2008 21:50 <REP> Navilog1
15/06/2008 20:18 <REP> Neuf
26/05/2008 20:22 <REP> OneStopSoft.com
14/06/2008 22:32 <REP> OpenOffice.org 2.4
15/06/2008 00:23 <REP> PhotoScape
02/11/2006 14:37 <REP> Reference Assemblies
16/05/2008 22:40 <REP> Satsuki Decoder Pack
14/05/2008 16:02 <REP> Sibelius Software
20/12/2006 10:08 <REP> Synaptics
20/12/2006 16:01 <REP> TOSHIBA
14/06/2008 20:50 <REP> Trend Micro
08/06/2008 20:54 <REP> Trymedia
20/12/2006 13:15 <REP> Ulead Systems
14/05/2008 09:58 <REP> Windows Calendar
02/11/2006 14:42 <REP> Windows Collaboration
14/05/2008 09:58 <REP> Windows Defender
02/11/2006 14:42 <REP> Windows Journal
13/05/2008 17:02 <REP> Windows Live
12/06/2008 09:19 <REP> Windows Mail
20/12/2006 13:18 <REP> Windows Media Components
14/05/2008 09:58 <REP> Windows Media Player
12/05/2008 20:36 <REP> Windows NT
02/11/2006 14:42 <REP> Windows Photo Gallery
14/05/2008 09:58 <REP> Windows Sidebar
31/05/2008 22:04 <REP> WinRAR
0 fichier(s) 0 octets
50 Rép(s) 56 611 074 048 octets libres
Le volume dans le lecteur C s'appelle Vista
Le numéro de série du volume est 3E37-91A8
Répertoire de C:\Program Files\fichiers communs
Le volume dans le lecteur C s'appelle Vista
Le numéro de série du volume est 3E37-91A8
Répertoire de C:\Program Files\common files
17/06/2008 11:35 <REP> .
17/06/2008 11:35 <REP> ..
20/12/2006 14:27 <REP> Adobe
15/06/2008 00:49 <REP> BitDefender
04/06/2008 20:27 <REP> HP
20/12/2006 13:18 <REP> InstallShield
20/12/2006 09:52 <REP> Java
17/06/2008 11:43 <REP> LogiShrd
17/06/2008 11:38 <REP> Logitech
12/05/2008 20:51 <REP> Microsoft Games
13/05/2008 17:05 <REP> microsoft shared
02/11/2006 13:18 <REP> Services
02/11/2006 13:18 <REP> SpeechEngines
13/06/2008 22:15 <REP> Symantec Shared
14/05/2008 09:58 <REP> System
20/12/2006 13:18 <REP> Ulead Systems
0 fichier(s) 0 octets
16 Rép(s) 56 611 074 048 octets libres
****** Fin du rapport DiagHelp
Veuillez svp envoyer le fichier C:\upload_moi_PC-de-Sophie.tar.gz a l'adresse http://upload.malekal.com -
ah si c'est bon XD
-
ContributeurQuand tu clique droit sur le dossier tu as un e possibilité de décompresser le dossier ?
regarde bien ;-) -
Quand je clik droit sur le lien je n'est pas extraire tout...=(
-
Contributeurramage ??? pour maitre corbeau surement :-))
ok
pour le reste
on vérifie une dernière chose avec un nouveau scan
Télécharge DiagHelp.zip sur ton bureau http://www.malekal.com/download/DiagHelp.zip
==> Ne double-clic pas dessus !! Fais un clic droit sur le fichier et extraire tout
==> Un nouveau dossier chercher va être créé DiagHelp
==> Ouvre le et double-clic sur go.cmd (le .cmd peut ne pas apparaître)
==> Une fenêtre va s'ouvrir, choisis l'option 1
==> L'analyse va commencer, ceci peut durer quelques minutes, laisse faire et appuie sur une touche quand on te le demande
==> Copie/colle le contenu du bloc-note qui s'ouvre, pour cela :
==> Dans le bloc-note, cliquez sur le menu Edition / Selectionner tout
==> A nouveau menu Edition / copier
==> Dans un nouveau message ici, faire un clic droit / coller
@+
-
bah la c'est vrai que je n'est pratiquement plus de pub, ni de ramage (j'sais pas si sa se dit lol )
donc voila ^^ -
ContributeurOui c'est vrai excuse
as tu passer aft cleaner
et as tu encore des soucis ?
@+ -
Sa fait au moins 3 fois que je fais le scan en ligne de Bitdefender il me donne plus le rapport =/
-
Contributeurok pour la suite
Télécharge ATF Cleaner par Atribune.
http://www.atribune.org/ccount/click.php?id=1
Double-clique ATF-Cleaner.exe afin de lancer le programme.
Sous l'onglet Main, choisis : Select All
Clique sur le bouton Empty Selected
Si tu utilises le navigateur Firefox :
Clique Firefox au haut et choisis : Select All
Clique le bouton Empty Selected
NOTE : Si tu veux conserver tes mots de passe sauvegardés, clique No à l'invite.
Si tu utilises le navigateur Opera :
Clique Opera au haut et choisis : Select All
Clique le bouton Empty Selected
NOTE : Si tu veux conserver tes mots de passe sauvegardés, clique No à l'invite.
Clique Exit, du menu prinicipal, afin de fermer le programme.
ensuite
fait un scan en ligne
avec bitdefender et colle le rapport
https://www.bitdefender.com/toolbox/
Scan à faire sous Internet Explorer
un tuto
http://pageperso.aol.fr/rginformatique/mapage/defender.htm
ensuite un nouveau rapport hijack stp
@+
-
C:\ProgramData\idle enc enc.oyyffvr moved successfully.
C:\ProgramData\Eggs Platform Seek.qoyin moved successfully.
< EmptyTemp >
File delete failed. C:\Users\Sophie\AppData\Local\Temp\~DFB25E.tmp scheduled to be deleted on reboot.
File delete failed. C:\Users\Sophie\AppData\Local\Temp\~DFB27A.tmp scheduled to be deleted on reboot.
File delete failed. C:\Users\Sophie\AppData\Local\Temp\~DFD331.tmp scheduled to be deleted on reboot.
File delete failed. C:\Users\Sophie\AppData\Local\Temp\~DFD350.tmp scheduled to be deleted on reboot.
File delete failed. C:\Users\Sophie\AppData\Local\Temp\~DFE301.tmp scheduled to be deleted on reboot.
File delete failed. C:\Users\Sophie\AppData\Local\Temp\~DFE312.tmp scheduled to be deleted on reboot.
File delete failed. C:\Users\Sophie\AppData\Local\Temp\~DFE41E.tmp scheduled to be deleted on reboot.
File delete failed. C:\Users\Sophie\AppData\Local\Temp\~DFE425.tmp scheduled to be deleted on reboot.
File delete failed. C:\Users\Sophie\AppData\Local\Temp\~DFEEA9.tmp scheduled to be deleted on reboot.
File delete failed. C:\Users\Sophie\AppData\Local\Temp\~DFEEB2.tmp scheduled to be deleted on reboot.
Temp folders emptied.
IE temp folders emptied.
OTMoveIt2 by OldTimer - Version 1.0.4.2 log created on 06162008_231357
Voilaaa -
ContributeurBonsoir
Connais tu ces fichiers
C:\ProgramData\idle enc enc.oyyffvr
C:\ProgramData\Eggs Platform Seek.qoyin
si non
Relance hijack et clique sur "Do a system scan only"
Ensuite recherche ces lignes et coches les cases
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKCU\..\Run: [WindowReadme] "C:\ProgramData\idle enc enc.oyyffvr"
O4 - HKCU\..\Run: [ROAD ITCH AMOK PING] "C:\ProgramData\Eggs Platform Seek.qoyin"
O9 - Extra button: eBay - {C08CAF1D-C0A3-40D5-9970-06D067EAC017} - http://www.webtip.ch/cgi-bin/toshiba/tracker_url.pl?FR (file missing)
Ensuite clique sur "Fix checked"
Ensuite
Télécharge OTMoveIt (de OldTimer) sur ton Bureau.
http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe
clic double sur OTMoveIt.exe pour le lancer.
copie la liste qui se trouve en citation ci-dessous,
et colle-la dans le cadre de gauche de OTMoveIt :
Paste List of Files/Folders to be moved.
C:\ProgramData\idle enc enc.oyyffvr
C:\ProgramData\Eggs Platform Seek.qoyin
EmptyTemp
clique sur MoveIt! pour lancer la suppression.
le résultat apparaîtra dans le cadre Results.
clique sur Exit pour fermer.
poste le rapport situé dans C:\_OTMoveIt\MovedFiles.
il te sera peut-être demandé de faire redémarrer le PC pour achever la suppression.
@+
-
voici le rapport de Bitdefender (désolée d'avoir été aussi longue mais j'ai eu un problemme d'internet --")
BitDefender Online Scanner - Real Time Virus Report
Generated at: Mon, Jun 16, 2008 - 14:28:38
--------------------------------------------------------------------------------
Scan Info
Scanned Files
256745
Infected Files
0
Virus Detected
No virus found.
--------------------------------------------------------------------------------
This summary of the scan process will be used by the BitDefender Antivirus Lab to create agregate statistics about virus activity around the world.
Et le raport Hijack :
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:30:14, on 16/06/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16681)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\TOSHIBA\Utilities\VolControl.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\TOSHIBA\Toshiba Online Product Information\TOPI.exe
C:\Program Files\TOSHIBA\Registration\ToshibaRegistration.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe
C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Synaptics\SynTP\SynToshiba.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Windows\system32\conime.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\System32\Adobe\SHOCKW~1\SWHELP~1.EXE
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://actus.sfr.fr
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://actus.sfr.fr
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://actus.sfr.fr
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = https://actus.sfr.fr
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
O4 - HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [TOSHIBA Volume Indicator] "C:\Program Files\Toshiba\Utilities\VolControl.exe"
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [topi] C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe -startup
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Toshiba Registration] C:\Program Files\Toshiba\Registration\ToshibaRegistration.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" /hide
O4 - HKLM\..\Run: [LVCOMSX] "C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [WindowReadme] "C:\ProgramData\idle enc enc.oyyffvr"
O4 - HKCU\..\Run: [ROAD ITCH AMOK PING] "C:\ProgramData\Eggs Platform Seek.qoyin"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
O9 - Extra button: eBay - {C08CAF1D-C0A3-40D5-9970-06D067EAC017} - http://www.webtip.ch/cgi-bin/toshiba/tracker_url.pl?FR (file missing)
O13 - Gopher Prefix:
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/win/ActiveXPlugin.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\Logitech\SrvLnch\SrvLnch.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
-
Contributeurok attendons le rapport de bitdefender
@+ -
Le Scan avec Bitdefender n'a pas l'air pressé de se terminé donc desolée si je metrais d temps a t'envoyée le rapport
Mon ordi rame beaucoup moins deja mais j'ai toujours des pubs ...
J'te remercie de m'aidée je suis une nulle en informatique . -
ContributeurBon et bien tout ça et nickel
pour vérif
fait un scan en ligne
avec bitdefender et colle le rapport
https://www.bitdefender.com/toolbox/
Scan à faire sous Internet Explorer
un tuto
http://pageperso.aol.fr/rginformatique/mapage/defender.htm
ensuite un nouveau rapport hijack stp
@+
- 1
- 2