Wcs.exe
RésoluJai lu un truc dans le forum sur hijackthis et Malwarebytes mais je connais rien en informatique et sa parait quand méme compliqué donc si quelqu'un a une solution a me faire part je suis preneur .
un grand merci d'avance
Configuration: Windows Vista Firefox 3.0.3
47 réponses
Le problème porte sur une infection supposée qui déclenche des blocages système et des pages web affichant des invites de téléchargement antivirus, avec wcs.exe et d'autres processus suspects bloquant Windows. Pour éliminer l’infection, redémarrer en mode sans échec et relancer SmitFraudFix en choisissant l’option de nettoyage, puis sauvegarder le rapport et redémarrer en mode normal. Ensuite, analyser un nouveau rapport HijackThis pour repérer les entrées indésirables et, si nécessaire, compléter le nettoyage avec Malwarebytes et des antivirus, puis envisager l’installation d’un pare-feu pour prévenir les réinfections. Dernier élément utile: certains composants peuvent persister après le nettoyage, nécessitant une vérification manuelle des chemins d’exécution et des tâches planifiées.
-
ok ces plus clair au moins :) ben merci je crois que sans ton aide j'aurais formaté est perdre toute mes données par la méme occasions , encore merci pour ton aide et ta patience :) je classe le topic résolu et je te souhaite une bonne continuation :)
cordialement adkuate :) -
Contributeur sécuritéPourquoi ne pas garder ces outils ?
Certains mal utilisés peuvent au contraire endommager ta machine.
garde malwarebytes que tu pourras lancer régulièrement pour vérifier que ton PC n'est pas infecté.
Avec les protections que tu as sur ton PC, maintenant, tu devrais être plus tranquille.
Si tu as le moindre problème, reposte un message dans la discussion.
Peux-tu mettre le sujet comme résolu ? Merci.
Bon surf et bonne continuation.
Salut. -
moi ossi g pareil g kaspersky mais impossible de le suprimer c'est un petite iconne attenntion il veut pas partire et il ouvre plein d page et g ossi un otre truc bizzard c'est virus response 2009 jarrive pas a le suprimer g toute essayer aider moi!!!!!!!!!!!!!!!! deplus g pas de cd windows xp o cas ou il marrivera un trucc
-
Voila le rapport toolscleaner , mais pourquoi ne pas gardé ces logiciels au cas ou ? cela m'intrigue :)
Enfin en tout cas merci , je sens ma Machine revivre lol
[ Rapport ToolsCleaner version 2.2.3 (par A.Rothstein & dj QUIOU) ]
-->- Recherche:
C:\TB.txt: trouvé !
C:\Toolbar SD: trouvé !
C:\Program Files\_OtMoveIt: trouvé !
C:\Program Files\Trend Micro\HijackThis: trouvé !
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: trouvé !
C:\Program Files\Trend Micro\HijackThis\hijackthis.log: trouvé !
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis: trouvé !
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis\HijackThis.lnk: trouvé !
C:\Users\user\Documents\AntiSpyware et securités\HijackThis.lnk: trouvé !
C:\Users\user\Documents\AntiSpyware et securités\LopSD.exe: trouvé !
C:\Users\user\Documents\AntiSpyware et securités\OtMoveIt2.exe: trouvé !
C:\Users\user\Documents\AntiSpyware et securités\SmitFraudFix.exe: trouvé !
C:\Users\user\Documents\AntiSpyware et securités\ToolBarSD.exe: trouvé !
C:\Users\user\Documents\AntiSpyware et securités\SmitFraudfix: trouvé !
C:\Users\user\Documents\Installers\HJTInstall.exe: trouvé !
---------------------------------
-->- Suppression:
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: supprimé !
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis\HijackThis.lnk: supprimé !
C:\Users\user\Documents\AntiSpyware et securités\HijackThis.lnk: supprimé !
C:\Users\user\Documents\AntiSpyware et securités\LopSD.exe: supprimé !
C:\Users\user\Documents\AntiSpyware et securités\OtMoveIt2.exe: supprimé !
C:\Users\user\Documents\AntiSpyware et securités\SmitFraudFix.exe: supprimé !
C:\Users\user\Documents\AntiSpyware et securités\ToolBarSD.exe: supprimé !
C:\Users\user\Documents\Installers\HJTInstall.exe: supprimé !
C:\TB.txt: supprimé !
C:\Program Files\Trend Micro\HijackThis\hijackthis.log: supprimé !
C:\Toolbar SD: ERREUR DE SUPPRESSION !!
C:\Program Files\_OtMoveIt: supprimé !
C:\Program Files\Trend Micro\HijackThis: supprimé !
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis: supprimé !
C:\Users\user\Documents\AntiSpyware et securités\SmitFraudfix: supprimé !
Fichiers temporaires nettoyés ! -
Contributeur sécuritéCa y est.On l'a eu.
Bizarre que la première fois, l'outil ne l'ai pas supprimé.
1) On va enlever les logiciels qui ont été utilisés..
Télécharge ToolsCleaner .sur le bureau
http://pc-system.fr/
Double-clique sur ToolsCleaner2.exe --> Recherche --> Suppression.
Il est possible que ton bureau disparaisse.
Fais un copier/coller du rapport qui se trouve dans C:\TCleaner.txt
2) Tu vas utiliser CCleaner.
http://www.commentcamarche.net/telecharger/telecharger 168 ccleaner
utilise les fonctions nettoyeur et registre.
3) Les points de restauration :
- Désactivation de la restauration système :
Dans le Panneau de configuration choisis l’affichage classique :
Système --> dans la liste des taches, à gauche, choisis propriétés du système
Décoche les disques durs sélectionnés.
Ceci va t'avertir que la restauration système va être désactivée. Accepte.
Ceci va supprimer les points de restauration existants.
- Dans la même fenêtre, resélectionner le disque c: puis choisis appliquer.
Clique ensuite sur créer pour la création d’un point de restauration.
Suis les invites.
A+ -
-----------\\ ToolBar S&D 1.2.1 XP/Vista
Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6000 )
X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 Duo CPU T5550 @ 1.83GHz )
BIOS : Default System BIOS
USER : user ( Administrator )
BOOT : Normal boot
Antivirus : Avira AntiVir PersonalEdition 8.0.1.27 (Activated)
Firewall : Sunbelt Personal Firewall 4.6.1845 T (Activated)
C:\ (Local Disk) - NTFS - Total : 149 Go Free : 110 Go
D:\ (Local Disk) - NTFS - Total : 141 Go Free : 23 Go
E:\ (CD or DVD)
"C:\ToolBar SD" ( MAJ : 24-09-2008|21:50 )
Option : [2] ( 04/10/2008|17:50 )
[ UAC => 0 ]
-----------\\ SUPPRESSION
Supprime! - C:\Program Files\AskSBar\bar
Supprime! - C:\Program Files\AskSBar
-----------\\ Recherche de Fichiers / Dossiers ...
-----------\\ [..\Internet Explorer\Main]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Local Page"="C:\\Windows\\system32\\blank.htm"
"Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Start Page"="about:blank"
"Url"="https://www.msn.com/fr-fr/actualite/"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Start Page"="https://www.msn.com/fr-fr/"
"Default_Page_URL"="https://www.asus.com/fr/"
"Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Local Page"="%SystemRoot%\\system32\\blank.htm"
--------------------\\ Recherche d'autres infections
--------------------\\ Cracks & Keygens ..
C:\Users\user\Documents\Azureus Downloads\Tracktor DJ Studio 3 + Key\TRAKTOR_DJ_STUDIO_3_KEYGEN.EXE
[ UAC => 1 ]
1 - "C:\ToolBar SD\TB_1.txt" - 03/10/2008| 0:47 - Option : [1]
2 - "C:\ToolBar SD\TB_2.txt" - 03/10/2008|10:47 - Option : [1]
3 - "C:\ToolBar SD\TB_3.txt" - 03/10/2008|11:04 - Option : [2]
4 - "C:\ToolBar SD\TB_4.txt" - 03/10/2008|11:09 - Option : [2]
5 - "C:\ToolBar SD\TB_5.txt" - 04/10/2008|16:36 - Option : [1]
6 - "C:\ToolBar SD\TB_6.txt" - 04/10/2008|17:54 - Option : [2]
-----------\\ Fin du rapport a 17:54:05,01 -
Contributeur sécuritéPour la suite, il faut absolument que tu désactives l4UAC.
Sinon, l'outil ne nettoiera pas l'infection.
relance ensuite TollBarS&d ( click droit -> ... )
Choisis l'option 2 et poste le rapport.
A+ -
hé hop ci joint le rapport toolbar
-----------\\ ToolBar S&D 1.2.1 XP/Vista
Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6000 )
X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 Duo CPU T5550 @ 1.83GHz )
BIOS : Default System BIOS
USER : user ( Administrator )
BOOT : Normal boot
Antivirus : Avira AntiVir PersonalEdition 8.0.1.27 (Activated)
Firewall : Sunbelt Personal Firewall 4.6.1845 T (Activated)
C:\ (Local Disk) - NTFS - Total : 149 Go Free : 111 Go
D:\ (Local Disk) - NTFS - Total : 141 Go Free : 23 Go
E:\ (CD or DVD)
"C:\ToolBar SD" ( MAJ : 24-09-2008|21:50 )
Option : [1] ( 04/10/2008|16:33 )
[ UAC => 1 ]
-----------\\ Recherche de Fichiers / Dossiers ...
C:\Program Files\AskSBar
C:\Program Files\AskSBar\bar
-----------\\ [..\Internet Explorer\Main]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Local Page"="C:\\Windows\\system32\\blank.htm"
"Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Start Page"="about:blank"
"Url"="https://www.msn.com/fr-fr/actualite/"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Start Page"="https://www.msn.com/fr-fr/"
"Default_Page_URL"="https://www.asus.com/fr/"
"Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Local Page"="%SystemRoot%\\system32\\blank.htm"
--------------------\\ Recherche d'autres infections
--------------------\\ Cracks & Keygens ..
C:\Users\user\Documents\Azureus Downloads\Tracktor DJ Studio 3 + Key\TRAKTOR_DJ_STUDIO_3_KEYGEN.EXE
[ UAC => 1 ]
1 - "C:\ToolBar SD\TB_1.txt" - 03/10/2008| 0:47 - Option : [1]
2 - "C:\ToolBar SD\TB_2.txt" - 03/10/2008|10:47 - Option : [1]
3 - "C:\ToolBar SD\TB_3.txt" - 03/10/2008|11:04 - Option : [2]
4 - "C:\ToolBar SD\TB_4.txt" - 03/10/2008|11:09 - Option : [2]
5 - "C:\ToolBar SD\TB_5.txt" - 04/10/2008|16:36 - Option : [1] -
Contributeur sécuritéOups, je me suis trompé d'outil, c'est ToolbarS&D et non LpoS&D.
Désinstalle LopS&D : panneau de configuration --> choisir affichage classique ( en haut à gauche ) --> programmes et fonctionnalités.
LopS&D devrait apparaitre dans la liste.
1) Vérifie que l'UAC est bien désactivée.
2) Télécharge Toolbar-S&D sur ton Bureau ( si tu l'as supprimé )
https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/ToolBarSD.exe?attachauth=ANoY7cqJWPphpudyTqv7TRo5RQ3nm_Sx8JluVMO59X5E9cyE3j3LqKlmStIqiDqJdIgMJLi7MXn2nKVajQfoWuVvZZ2wIx_vkqO4k4P0K9jh-ra9jaKPXdZcoaVF2UqJZNH8ubL_42uIwh6f35xJ2GJMuzddVj2Qth1DgZ839lxEIFGkgWz3TdfvNMy-YtxfA3gqBUrj4U4LFeAPiWr3ClmjIP0t_Xs5PQ%3D%3D&attredirects=2
* Lance l'installation du programme en exécutant le fichier téléchargé.
* click droit --> exécuter en tant qu'administrateur sur le raccourci de Toolbar-S&D.
* Sélectionne la langue puis valide.
* Choisis maintenant l'option 1 (Recherche). Patiente jusqu'à la fin de la recherche.
* Copie/colle le contenu du rapport situé dans C:\TB.txt .
A+ -
voila le rapport lopsd
--------------------\\ Lop S&D 4.2.4-5 XP/Vista
Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6000 )
X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 Duo CPU T5550 @ 1.83GHz )
BIOS : Default System BIOS
USER : user ( Administrator )
BOOT : Normal boot
Antivirus : Avira AntiVir PersonalEdition 8.0.1.27 (Activated)
Firewall : Sunbelt Personal Firewall 4.6.1845 T (Activated)
C:\ (Local Disk) - NTFS - Total : 149 Go Free : 111 Go
D:\ (Local Disk) - NTFS - Total : 141 Go Free : 23 Go
E:\ (CD or DVD)
"C:\Lop SD" ( MAJ : 02-10-2008|23:42 )
Option : [1] ( 04/10/2008|16:24 )
[ UAC => 0 ]
--------------------\\ Listing des dossiers dans Local
[25/09/2008|12:13] C:\Users\user\AppData\Local\Adobe
[25/09/2008|12:02] C:\Users\user\AppData\Local\Ahead
[25/09/2008|11:59] C:\Users\user\AppData\Local\Application Data
[04/10/2008|00:20] C:\Users\user\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[01/10/2008|23:37] C:\Users\user\AppData\Local\GDIPFONTCACHEV1.DAT
[25/09/2008|11:59] C:\Users\user\AppData\Local\Historique
[04/10/2008|14:13] C:\Users\user\AppData\Local\IconCache.db
[03/10/2008|20:59] C:\Users\user\AppData\Local\Microsoft
[01/10/2008|23:34] C:\Users\user\AppData\Local\Mozilla
[01/10/2008|22:30] C:\Users\user\AppData\Local\Seven Zip
[04/10/2008|16:23] C:\Users\user\AppData\Local\Temp
[25/09/2008|11:59] C:\Users\user\AppData\Local\Temporary Internet Files
[03/10/2008|21:03] C:\Users\user\AppData\Local\VirtualStore
--------------------\\ Tâches planifiées dans C:\Windows\tasks
[04/10/2008 16:17][--a------] C:\Windows\tasks\Uniblue SpyEraser Nag.job
[04/10/2008 13:55][--a------] C:\Windows\tasks\Uniblue SpyEraser.job
[04/10/2008 16:21][--a------] C:\Windows\tasks\Maintenance en 1 clic.job
[04/10/2008 16:17][--ah-----] C:\Windows\tasks\SA.DAT
[04/10/2008 14:13][--a------] C:\Windows\tasks\SCHEDLGU.TXT
--------------------\\ Listing des dossiers dans C:\ProgramData
[25/09/2008|12:13] C:\ProgramData\Adobe
[25/09/2008|12:02] C:\ProgramData\Ahead
[02/11/2006|15:02] C:\ProgramData\Application Data
[29/09/2008|09:01] C:\ProgramData\ASUS
[03/10/2008|14:38] C:\ProgramData\Avira
[02/10/2008|14:51] C:\ProgramData\Azureus
[02/11/2006|15:02] C:\ProgramData\Desktop
[02/11/2006|15:02] C:\ProgramData\Documents
[02/11/2006|15:02] C:\ProgramData\Favorites
[22/03/2008|03:55] C:\ProgramData\Intel
[02/10/2008|22:16] C:\ProgramData\Malwarebytes
[01/10/2008|23:34] C:\ProgramData\Microsoft
[01/10/2008|23:34] C:\ProgramData\Microsoft Help
[25/09/2008|12:01] C:\ProgramData\Nero
[22/03/2008|04:16] C:\ProgramData\NVIDIA
[22/03/2008|04:01] C:\ProgramData\P4G
[02/10/2008|00:05] C:\ProgramData\Soulseek
[03/10/2008|14:49] C:\ProgramData\Spybot - Search & Destroy
[02/11/2006|15:02] C:\ProgramData\Start Menu
[02/10/2008|00:29] C:\ProgramData\Symantec
[02/11/2006|15:02] C:\ProgramData\Templates
[02/10/2008|00:15] C:\ProgramData\TuneUp Software
[04/10/2008|13:54] C:\ProgramData\Uniblue
[03/10/2008|20:48] C:\ProgramData\WLInstaller
--------------------\\ Listing des dossiers dans C:\Program Files
[25/09/2008|12:12] C:\Program Files\Adobe
[01/10/2008|23:17] C:\Program Files\Alwil Software
[03/10/2008|15:01] C:\Program Files\AskSBar
[01/10/2008|23:44] C:\Program Files\ASUS
[22/03/2008|03:43] C:\Program Files\ATK Hotkey
[22/03/2008|03:43] C:\Program Files\ATKGFNEX
[22/03/2008|03:44] C:\Program Files\ATKOSD2
[22/03/2008|03:52] C:\Program Files\Attansic
[03/10/2008|14:38] C:\Program Files\Avira
[01/10/2008|23:28] C:\Program Files\CCleaner
[03/10/2008|20:49] C:\Program Files\Common Files
[22/03/2008|04:03] C:\Program Files\DIFX
[01/10/2008|23:52] C:\Program Files\Free Audio Pack
[01/10/2008|23:54] C:\Program Files\InstallShield Installation Information
[22/03/2008|03:54] C:\Program Files\Intel
[03/10/2008|10:35] C:\Program Files\Internet Explorer
[02/10/2008|00:22] C:\Program Files\Java
[25/09/2008|12:56] C:\Program Files\K-Lite Codec Pack
[02/10/2008|23:55] C:\Program Files\Malwarebytes' Anti-Malware
[04/10/2008|02:19] C:\Program Files\Microsoft CAPICOM 2.1.0.2
[02/11/2006|14:37] C:\Program Files\Microsoft Games
[18/04/2007|11:24] C:\Program Files\Movie Maker
[04/10/2008|16:21] C:\Program Files\Mozilla Firefox
[02/11/2006|14:37] C:\Program Files\MSBuild
[02/11/2006|14:37] C:\Program Files\MSN
[18/04/2007|10:43] C:\Program Files\MSXML 4.0
[25/09/2008|12:01] C:\Program Files\Nero
[22/03/2008|04:01] C:\Program Files\P4G
[22/03/2008|04:01] C:\Program Files\Power4Gear eXtreme
[22/03/2008|03:50] C:\Program Files\Realtek
[02/11/2006|14:37] C:\Program Files\Reference Assemblies
[02/10/2008|00:04] C:\Program Files\SoulseekNS
[02/10/2008|17:51] C:\Program Files\Spybot - Search & Destroy
[03/10/2008|17:49] C:\Program Files\Sunbelt Software
[22/03/2008|04:07] C:\Program Files\Synaptics
[02/10/2008|22:29] C:\Program Files\Trend Micro
[02/10/2008|00:16] C:\Program Files\TuneUp Utilities 2008
[02/11/2006|15:01] C:\Program Files\Uninstall Information
[01/10/2008|23:25] C:\Program Files\VideoLAN
[03/10/2008|15:01] C:\Program Files\Vuze
[22/03/2008|03:28] C:\Program Files\Windows Calendar
[18/04/2007|11:24] C:\Program Files\Windows Collaboration
[22/03/2008|03:28] C:\Program Files\Windows Defender
[18/04/2007|11:24] C:\Program Files\Windows Journal
[03/10/2008|20:59] C:\Program Files\Windows Live
[03/10/2008|10:35] C:\Program Files\Windows Mail
[22/03/2008|03:28] C:\Program Files\Windows Media Player
[02/11/2006|14:37] C:\Program Files\Windows NT
[18/04/2007|11:24] C:\Program Files\Windows Photo Gallery
[03/10/2008|10:35] C:\Program Files\Windows Sidebar
[02/10/2008|14:48] C:\Program Files\WinRAR
[22/03/2008|03:56] C:\Program Files\Wireless Console 2
--------------------\\ Listing des dossiers dans C:\Program Files\Common Files
[25/09/2008|12:12] C:\Program Files\Common Files\Adobe
[25/09/2008|12:02] C:\Program Files\Common Files\Ahead
[22/03/2008|04:08] C:\Program Files\Common Files\InstallShield
[02/10/2008|00:20] C:\Program Files\Common Files\Java
[25/09/2008|12:03] C:\Program Files\Common Files\LightScribe
[03/10/2008|20:49] C:\Program Files\Common Files\microsoft shared
[02/11/2006|13:18] C:\Program Files\Common Files\Services
[02/11/2006|13:18] C:\Program Files\Common Files\SpeechEngines
[01/10/2008|23:51] C:\Program Files\Common Files\Symantec Shared
[01/10/2008|23:31] C:\Program Files\Common Files\System
[03/10/2008|20:58] C:\Program Files\Common Files\WindowsLiveInstaller
[02/10/2008|00:15] C:\Program Files\Common Files\Wise Installation Wizard
--------------------\\ Process
( 72 Processes )
... OK !
--------------------\\ Recherche avec S_Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Recherche de Fichiers / Dossiers Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Verification du Registre
..... OK !
--------------------\\ Verification du fichier Hosts
Fichier Hosts PROPRE
--------------------\\ Recherche de fichiers avec Catchme
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-04 16:25:18
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 0
--------------------\\ Recherche d'autres infections
--------------------\\ Cracks & Keygens ..
C:\Users\user\Documents\Azureus Downloads\Tracktor DJ Studio 3 + Key\TRAKTOR_DJ_STUDIO_3_KEYGEN.EXE
[F:63][D:10]-> C:\Users\user\AppData\Local\Temp
[F:4][D:0]-> C:\Users\user\AppData\Roaming\MICROS~1\Windows\Cookies
[F:401][D:4]-> C:\Users\user\AppData\Local\MICROS~1\Windows\TEMPOR~1\content.IE5
[F:1][D:1]-> C:\$Recycle.Bin
1 - "C:\Lop SD\LopR_1.txt" - 04/10/2008|16:28 - Option : [1]
--------------------\\ Fin du rapport a 16:28:39
[ UAC => 1 ] -
Contributeur sécuritéOn va réessayer ToolBarS&D. Il doit sorcément la supprimer.
1) Vérifie que l'UAC est bien désactivée.
Je te remets la manip.
Dans le panneau de configuration, choisir l’affichage classique.
Dans Comptes d’Utilisateurs --> activer ou désactiver le contrôle des comptes d’utilisateurs
Puis décoche la ligne "Utiliser le controle .. "
Il te sera demandé de redémarrer l’ordinateur. Accepte.
2) Télécharge LopS&D si tu l'as supprimé.
https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/LopSD.exe?attachauth=ANoY7co3ntqUavpZ3q1BG-h4pc13vqDZmhcNeEPChtsyrgAykRbhE8bZzhk979EfQD4AgwtQUHCaQ7ZQwNYMo3_0kA8htAspckDJtu2K5t6J9z6dLW4fpZyH4FpFL1tVMBZ8H-KnN7afZ5vt-WxZRpnynk-a0XmV_Y0C0q6DxGEDKie1TnPT7gFoZnoCnspzBmbW6ZzxA4fNr3oEDlbelNZON-LjF8nOmQ%3D%3D&attredirects=2
Installe le logiciel. Une icône va apparaitre sur le bureau.
Lance le logiciel en tant qu’administrateur. ( click droit --> Exécuter en tant qu’administrateur )
Tu choisis la langue et valide puis l'option 1 pour effectuer la recherche.
A la fin de la recherche, un rapport LopR.txt apparait. Il se trouve en C:\LopR.txt.
Si il y a plusieurs rapports, choisis celui avec le chiffre le plus élevé.
Tu posteras ce rapport dans le prochain message.
A+ -
ok merci !
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:44:57, on 04/10/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16711)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskeng.exe
C:\Program Files\ASUS\ASUS Live Update\ALU.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\rundll32.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ASUS\ATK Media\DMedia.exe
C:\Windows\ASScrPro.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Sunbelt Software\Personal Firewall\SbPFCl.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.asus.com/fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
O1 - Hosts: ::1 localhost
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Ask Toolbar BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\2.bin\ASKSBAR.DLL
O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\2.bin\ASKSBAR.DLL
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files\ASUS\ATK Media\DMEDIA.EXE
O4 - HKLM\..\Run: [ASUS Camera ScreenSaver] C:\Windows\ASScrProlog.exe
O4 - HKLM\..\Run: [ASUS Screen Saver Protector] C:\Windows\ASScrPro.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O20 - AppInit_DLLs:
O23 - Service: ADSM Service (ADSMService) - Unknown owner - C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files\ATK Hotkey\ASLDRSrv.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - Unknown owner - C:\Program Files\ATKGFNEX\GFNEXSrv.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: SbPF.Launcher - Sunbelt Software, Inc. - C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe
O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software, Inc. - C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe
O23 - Service: spmgr - Unknown owner - C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
O23 - Service: Syntek AVStream USB2.0 WebCam Service (StkSSrv) - Syntek America Inc. - C:\Windows\System32\StkCSrv.exe
O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software GmbH - C:\Windows\System32\TuneUpDefragService.exe
-
Contributeur sécuritéPoste moi un rapport Hijackthis.
A+ -
Salut verni ! voila le rapport otmoveit e que j'ai effectué hier soir
Folder move failed. C:\Program Files\AskSBar\bar\2.bin scheduled to be moved on reboot.
Folder move failed. C:\Program Files\AskSBar\bar scheduled to be moved on reboot.
Folder move failed. C:\Program Files\AskSBar scheduled to be moved on reboot.
OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 10042008_005942
Les askbars son toujours la , ils ont dans C:/Otmoveit/Askbar , il ya 2 dossiers askbar maintenant + 1 dans mes programs files.... -
Contributeur sécuritéTon PC est propre. Il n'y aucune trace de virus.
poste moi le rapport OTMoveIT et après je te donne les dernières consignes.
A+ -
voila jai eu le temps de faire le rapport antivir , joint ci dessous.
J'attend ta réponse avec impatience !!
cordialement adkuate
eport file date: samedi 4 octobre 2008 01:54
Scanning for 1657543 virus strains and unwanted programs.
Licensed to: Avira AntiVir PersonalEdition Classic
Serial number: 0000149996-ADJIE-0001
Platform: Windows Vista
Windows version: (plain) [6.0.6000]
Boot mode: Normally booted
Username: SYSTEM
Computer name: PC-DE-USER
Version information:
BUILD.DAT : 8.1.0.331 16934 Bytes 12/08/2008 11:46:00
AVSCAN.EXE : 8.1.4.7 315649 Bytes 26/06/2008 08:57:53
AVSCAN.DLL : 8.1.4.0 40705 Bytes 26/05/2008 07:56:40
LUKE.DLL : 8.1.4.5 164097 Bytes 12/06/2008 12:44:19
LUKERES.DLL : 8.1.4.0 12033 Bytes 26/05/2008 07:58:52
ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 10:33:34
ANTIVIR1.VDF : 7.0.5.1 8182784 Bytes 24/06/2008 13:54:15
ANTIVIR2.VDF : 7.0.6.217 3773440 Bytes 26/09/2008 12:40:11
ANTIVIR3.VDF : 7.0.6.241 167936 Bytes 02/10/2008 12:40:14
Engineversion : 8.1.1.35
AEVDF.DLL : 8.1.0.5 102772 Bytes 25/02/2008 09:58:21
AESCRIPT.DLL : 8.1.0.76 319867 Bytes 03/10/2008 12:40:33
AESCN.DLL : 8.1.0.23 119156 Bytes 10/07/2008 12:44:49
AERDL.DLL : 8.1.1.2 438644 Bytes 03/10/2008 12:40:31
AEPACK.DLL : 8.1.2.3 364918 Bytes 03/10/2008 12:40:29
AEOFFICE.DLL : 8.1.0.25 196986 Bytes 03/10/2008 12:40:25
AEHEUR.DLL : 8.1.0.59 1438071 Bytes 03/10/2008 12:40:24
AEHELP.DLL : 8.1.0.15 115063 Bytes 10/07/2008 12:44:48
AEGEN.DLL : 8.1.0.36 315764 Bytes 03/10/2008 12:40:18
AEEMU.DLL : 8.1.0.7 430452 Bytes 31/07/2008 08:33:21
AECORE.DLL : 8.1.1.11 172406 Bytes 03/10/2008 12:40:15
AEBB.DLL : 8.1.0.1 53617 Bytes 10/07/2008 12:44:48
AVWINLL.DLL : 1.0.0.12 15105 Bytes 09/07/2008 08:40:05
AVPREF.DLL : 8.0.2.0 38657 Bytes 16/05/2008 09:28:01
AVREP.DLL : 8.0.0.2 98344 Bytes 03/10/2008 12:40:14
AVREG.DLL : 8.0.0.1 33537 Bytes 09/05/2008 11:26:40
AVARKT.DLL : 1.0.0.23 307457 Bytes 12/02/2008 08:29:23
AVEVTLOG.DLL : 8.0.0.16 119041 Bytes 12/06/2008 12:27:49
SQLITE3.DLL : 3.3.17.1 339968 Bytes 22/01/2008 17:28:02
SMTPLIB.DLL : 1.2.0.23 28929 Bytes 12/06/2008 12:49:40
NETNT.DLL : 8.0.0.1 7937 Bytes 25/01/2008 12:05:10
RCIMAGE.DLL : 8.0.0.51 2371841 Bytes 12/06/2008 13:48:07
RCTEXT.DLL : 8.0.52.0 86273 Bytes 27/06/2008 13:34:37
Configuration settings for the scan:
Jobname..........................: Complete system scan
Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
Logging..........................: low
Primary action...................: interactive
Secondary action.................: ignore
Scan master boot sector..........: on
Scan boot sector.................: on
Boot sectors.....................: C:, D:,
Process scan.....................: on
Scan registry....................: on
Search for rootkits..............: off
Scan all files...................: All files
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Macro heuristic..................: on
File heuristic...................: medium
Start of the scan: samedi 4 octobre 2008 01:54
The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'firefox.exe' - '1' Module(s) have been scanned
Scan process 'conime.exe' - '1' Module(s) have been scanned
Scan process 'wuauclt.exe' - '1' Module(s) have been scanned
Scan process 'SynTPHelper.exe' - '1' Module(s) have been scanned
Scan process 'KBFiltr.exe' - '1' Module(s) have been scanned
Scan process 'ATKOSD.exe' - '1' Module(s) have been scanned
Scan process 'LightScribeControlPanel.exe' - '1' Module(s) have been scanned
Scan process 'avgnt.exe' - '1' Module(s) have been scanned
Scan process 'ACEngSvr.exe' - '1' Module(s) have been scanned
Scan process 'jusched.exe' - '1' Module(s) have been scanned
Scan process 'ASScrPro.exe' - '1' Module(s) have been scanned
Scan process 'DMedia.exe' - '1' Module(s) have been scanned
Scan process 'SynTPEnh.exe' - '1' Module(s) have been scanned
Scan process 'SbPFCl.exe' - '1' Module(s) have been scanned
Scan process 'ACMON.exe' - '1' Module(s) have been scanned
Scan process 'BatteryLife.exe' - '1' Module(s) have been scanned
Scan process 'wcourier.exe' - '1' Module(s) have been scanned
Scan process 'ATKOSD2.exe' - '1' Module(s) have been scanned
Scan process 'HControl.exe' - '1' Module(s) have been scanned
Scan process 'RtHDVCpl.exe' - '1' Module(s) have been scanned
Scan process 'rundll32.exe' - '1' Module(s) have been scanned
Scan process 'rundll32.exe' - '1' Module(s) have been scanned
Scan process 'MSASCui.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'ALU.exe' - '1' Module(s) have been scanned
Scan process 'dwm.exe' - '1' Module(s) have been scanned
Scan process 'taskeng.exe' - '1' Module(s) have been scanned
Scan process 'WmiPrvSE.exe' - '1' Module(s) have been scanned
Scan process 'taskeng.exe' - '1' Module(s) have been scanned
Scan process 'SearchIndexer.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'StkCSrv.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'spmgr.exe' - '1' Module(s) have been scanned
Scan process 'SbPFSvc.exe' - '1' Module(s) have been scanned
Scan process 'SbPFLnch.exe' - '1' Module(s) have been scanned
Scan process 'RegSrvc.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'LSSrvc.exe' - '1' Module(s) have been scanned
Scan process 'EvtEng.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'avguard.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'sched.exe' - '1' Module(s) have been scanned
Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
Scan process 'GFNEXSrv.exe' - '1' Module(s) have been scanned
Scan process 'wlanext.exe' - '1' Module(s) have been scanned
Scan process 'ASLDRSrv.exe' - '1' Module(s) have been scanned
Scan process 'ADSMSrv.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'SLsvc.exe' - '1' Module(s) have been scanned
Scan process 'audiodg.exe' - '0' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'lsm.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'wininit.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
68 processes with 68 modules were scanned
Starting master boot sector scan:
Master boot sector HD0
[INFO] No virus was found!
Start scanning boot sectors:
Boot sector 'C:\'
[INFO] No virus was found!
Boot sector 'D:\'
[INFO] No virus was found!
Starting to scan the registry.
The registry was scanned ( '42' files ).
Starting the file scan:
Begin scan in 'C:\' <VistaOS>
C:\pagefile.sys
[WARNING] The file could not be opened!
Begin scan in 'D:\' <DATA>
End of the scan: samedi 4 octobre 2008 02:07
Used time: 13:25 Minute(s)
The scan has been done completely.
10521 Scanning directories
143504 Files were scanned
0 viruses and/or unwanted programs were found
0 Files were classified as suspicious:
0 files were deleted
0 files were repaired
0 files were moved to quarantine
0 files were renamed
1 Files cannot be scanned
143503 Files not concerned
1112 Archives were scanned
1 Warnings
0 Notes -
effectivement ASKbar ce trouve dans programs file , jai refait la manipe 18 comme tu me la dit , je te met quand même le rapport bitdefender ci dessus (Au cas ou ) .
Pour antivir je post tout sa demain ou ce soir si j'ai le temps , merci ^^
cordialement adkuate -
voila ci joint le rapport bitdefender
General]
App = "BitDefender Online Scanner v8"
Date = 04:10:2008
Time = 01:28:51
Scan Path = C:\;D:\;E:\;
[Engines Info]
Virus Definitions = 1833437
Engine build = "AVCORE v1.7 (build 8314.19) (i386) (Sep 10 2008 19:37:42)"
Scan plugins = 16
Archive plugins = 43
Unpack plugins = 7
E-mail plugins = 6
System plugins = 4
[Scan Statistics]
Folders = 10476
Files = 51562
Archives = 758
Packed files = 5287
Identified viruses = 0
Infected files = 0
Warnings = 0
Suspect files = 0
Disinfected files = 0
Deleted files = 0
Copied files = 0
Moved files = 0
Renamed files = 0
I/O Errors = 7
[Scan Settings]
SecondAction = Delete
FirstAction = Disinfect
Heuristics = 1
Enable Warnings = 1
Exclude Ext =
Extensions = exe;com;dll;ocx;scr;bin;dat;386;vxd;sys;wdm;cla;class;ovl;ole;hlp;doc;dot;xls;ppt;wbk;wiz;pot;ppa;xla;xlt;vbs;vbe;mdb;rtf;htm;hta;html;xml;xtp;php;asp;js;shs;chm;lnk;pif;prc;url;smm;pfd;msi;ini;csc;cmd;bas;
Scan Emails = 1
Scan Archives = 1
Scan Packed = 1
Scan Files = 1
Scan Boot = 1
Verify Memory = 0
[Scan Results]
Line00000000 = "No problems found." -
Contributeur sécuritéTout va pour le mieux ?
Pour les protections sur ton PC, Oui !!
- Antivir se met à jour très régulièrement. C'est le plus réactif et le meilleur antivirus gratuit.
- Windows defender est très bien. Je l'ai sur ma machine.
Lance Spybot de temps en temps pour vérifier la présence de spywares ou de mouchards. Il ne te trouvera à priori que des cookies, qui ne sont pas dangereux.
- Kerio est un bon parefeu. Tout dépend du niveau de protection que tu as choisi, mais tu auras sans doute au départ des alertes sur des programmes qui veulent accéder au net. Ce sont des règles à créer au debut de l'utilisation d'un parefeu.
Peut-être que je ne t'apprends rien sur ce sujet.
1) J'aimerais que tu me postes le rapport d'antivir.
lance un scan.
Lorsque le scan est terminé, tu as la possibilité de générer un rapport en cliquant sur le bouton report
2) La barre infectieuse AskBar est revenue. Mystère.
refais la manip du message 18
http://www.commentcamarche.net/forum/affich 8705666 wcs exe#18
A+ -
voila mon dernier rapport hijack
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:16:58, on 03/10/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16711)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\ASUS\ASUS Live Update\ALU.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\System32\rundll32.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ASUS\ATK Media\DMedia.exe
C:\Windows\ASScrPro.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\Sunbelt Software\Personal Firewall\SbPFCl.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.asus.com/fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
O1 - Hosts: ::1 localhost
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Ask Toolbar BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\2.bin\ASKSBAR.DLL
O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\2.bin\ASKSBAR.DLL
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files\ASUS\ATK Media\DMEDIA.EXE
O4 - HKLM\..\Run: [ASUS Camera ScreenSaver] C:\Windows\ASScrProlog.exe
O4 - HKLM\..\Run: [ASUS Screen Saver Protector] C:\Windows\ASScrPro.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O20 - AppInit_DLLs:
O23 - Service: ADSM Service (ADSMService) - Unknown owner - C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files\ATK Hotkey\ASLDRSrv.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - Unknown owner - C:\Program Files\ATKGFNEX\GFNEXSrv.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: SbPF.Launcher - Sunbelt Software, Inc. - C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe
O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software, Inc. - C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe
O23 - Service: spmgr - Unknown owner - C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
O23 - Service: Syntek AVStream USB2.0 WebCam Service (StkSSrv) - Syntek America Inc. - C:\Windows\System32\StkCSrv.exe
O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software GmbH - C:\Windows\System32\TuneUpDefragService.exe
- 1
- 2
- 3