Rond rouge avc une croix dedans
Depui 3 jour est arrivé ds la barre en bas (excusez moi je n'y connais rien, maman et enfants en vacances) un rond rouge avec une crois blche dedans et une fenetre qui s'ouvre tout le temps me disant que l'ordi est ifecté et qu'il est recommandé d'installer anti spyware tool etc... et si ça demarre c'est XP antispireware2009 install qui demarre , j'installe ou pas ?
Configuration: Windows XP Internet Explorer 6.0
67 réponses
La discussion porte sur une infection sous Windows XP affichant un rond rouge avec une croix et des fenêtres d’alerte anti-spyware, avec un démarrage automatique d’un logiciel supposément malveillant. Plusieurs approches sont proposées, notamment Malwarebytes' Anti-Malware et SmitfraudFix en mode sans échec pour nettoyer les fichiers infectés et générer des rapports, puis vérifier le registre et les paramètres. Des réponses insistent aussi sur des outils comme HijackThis pour identifier les objets suspects et sur l’importance de redémarrer en mode sans échec et d’utiliser des rapports pour orienter l’action. En cas de doute, certaines contributions mettent en garde contre des faux positifs et recommandent de lire les tutoriels et de ne pas exécuter directement des outils sans avis compétent.
-
Re,
Pour supprimer toutes les traces des logiciels qui ont servi à traiter les infections spécifiques
Télécharge toolscleaner sur ton Bureau :
toolscleaner
* Double-clique sur ToolsCleaner2.exe et laisse le travailler
* Clique sur Recherche et laisse le scan se terminer.
* Clique sur Suppression pour finaliser.
* Tu peux, si tu le souhaites, te servir des Options facultatives.
* Clique sur Quitter, pour que le rapport puisse se créer.
* Le rapport (TCleaner.txt) se trouve à la racine de votre disque dur (C:\)...colle le dans ta réponse
Désactive et réactive la Restauration du système :
1 Dans la barre des tâches de Windows, clique sur Démarrer.
2 Clique avec le bouton droit de la souris sur Poste de travail puis clique sur Propriétés.
3 Dans l'onglet Restauration du système, coche "Désactiver la Restauration du système"
4 Clique sur Appliquer.
5 Ensuite décoche "Désactiver la restauration du systeme"
6 clique sur appliquer puis ok
7 vas créer un point de restauration dans accessoires----outils systeme----restauration du systeme.
Aussi met a jour:
Windows XP SP3
JAVA
Garde Malwarebyte et fait des analyse toutes les semaines et installe sa :
---> Télécharge CCleaner (N'installe pas la Yahoo Toolbar) :
https://www.ccleaner.com/ccleaner/download
---> Lance-le. Va dans "Options" puis "Avancé", tu décoches la case "Effacer uniquement les fichiers etc...". Tu vas dans "Nettoyeur", tu fais "Analyse". Une fois terminé, tu lances le nettoyage. Puis tu vas dans "Registre", tu fais "Chercher des erreurs". Une fois terminé, tu répares toutes les erreurs sans sauvegarder la base de registre.
@+ -
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:05:05, on 04/11/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\System32\FTRTSVC.exe
C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Orange HSS\Launcher\Launcher.exe
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
C:\Program Files\Orange HSS\connectivity\connectivitymanager.exe
C:\Program Files\Orange HSS\systray\systrayapp.exe
C:\Program Files\Orange HSS\Deskboard\deskboard.exe
C:\Program Files\Orange HSS\connectivity\CoreCom\CoreCom.exe
C:\Program Files\Orange HSS\connectivity\CoreCom\OraConfigRecover.exe
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTCOMModule\0\FTCOMModule.exe
C:\Program Files\Orange HSS\browser\browser.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\Orange HSS\SearchURLHook\SearchPageURL.dll
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: https://www.orange.fr/portail
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O16 - DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} (GoPetsWeb Control) - https://secure.gopetslive.com/dev/GoPetsWeb.cab
O20 - AppInit_DLLs: xdcppd.dll
O21 - SSODL: pkMXrrFog - {5C0434E1-F6AE-9E4B-A8B3-229277981D42} - C:\WINDOWS\System32\mmuod.dll
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InstallShield Licensing Service - Macrovision - C:\Program Files\Fichiers communs\InstallShield Shared\Service\InstallShield Licensing Service.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: OneStepSearch Service - Unknown owner - C:\Program Files\OneStep\onestep.exe (file missing)
-
Re,
Fait moi un nouveau hijackthis.
merci -
pas encore, c'est + de 3 heures et j'en ai fait un ce matin ou alors un pas en complet ou pâs en mode echec que je puisse me servir de l'ordi, car la ca va faire du 18h30 et a part navilog il ne sait rien passé depuis, dis moi alors ce que tu en penses,merci
-
Re,
Fait de nouveau un malwarebyte.
merci -
Ci dessous le rapport, par contre je suis toujours branché sur messenger skinner (c'est dailleurs la seule fenêtre qui s'ouvre au demarrage maintenant).
Search Navipromo version 3.6.7 commencé le 04/11/2008 à 14:02:24,48
!!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
!!! Postez ce rapport sur le forum pour le faire analyser !!!
!!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!
Outil exécuté depuis C:\Program Files\navilog1
Session actuelle : "Nathalie"
Mise à jour le 22.10.2008 à 20h00 par IL-MAFIOSO
Microsoft Windows XP [version 5.1.2600]
Internet Explorer : 6.0.2900.2180
Système de fichiers : NTFS
Recherche executé en mode normal
*** Recherche Programmes installés ***
Favorit
Favorit
Favorit
Favorit
Favorit
Favorit
Favorit
*** Recherche dossiers dans "C:\WINDOWS" ***
*** Recherche dossiers dans "C:\Program Files" ***
*** Recherche dossiers dans "C:\Documents and Settings\All Users\menudm~1\progra~1" ***
*** Recherche dossiers dans "C:\Documents and Settings\All Users\menudm~1" ***
*** Recherche dossiers dans "c:\docume~1\alluse~1\applic~1" ***
*** Recherche dossiers dans "C:\Documents and Settings\Nathalie\applic~1" ***
*** Recherche dossiers dans "C:\DOCUME~1\ADMINI~1\applic~1" ***
*** Recherche dossiers dans "C:\DOCUME~1\INVIT~1\applic~1" ***
*** Recherche dossiers dans "C:\DOCUME~1\mario\applic~1" ***
*** Recherche dossiers dans "C:\DOCUME~1\MARIO~1.HUR\applic~1" ***
*** Recherche dossiers dans "C:\Documents and Settings\Nathalie\locals~1\applic~1" ***
*** Recherche dossiers dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" ***
*** Recherche dossiers dans "C:\DOCUME~1\INVIT~1\locals~1\applic~1" ***
*** Recherche dossiers dans "C:\DOCUME~1\mario\locals~1\applic~1" ***
*** Recherche dossiers dans "C:\DOCUME~1\MARIO~1.HUR\locals~1\applic~1" ***
*** Recherche dossiers dans "C:\Documents and Settings\Nathalie\menudm~1\progra~1" ***
*** Recherche dossiers dans "C:\DOCUME~1\ADMINI~1\menudm~1\progra~1" ***
*** Recherche dossiers dans "C:\DOCUME~1\INVIT~1\menudm~1\progra~1" ***
*** Recherche dossiers dans "C:\DOCUME~1\mario\menudm~1\progra~1" ***
*** Recherche dossiers dans "C:\DOCUME~1\MARIO~1.HUR\menudm~1\progra~1" ***
*** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
pour + d'infos : http://www.gmer.net
*** Recherche avec GenericNaviSearch ***
!!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
!!! A vérifier impérativement avant toute suppression manuelle !!!
* Recherche dans "C:\WINDOWS\system32" *
* Recherche dans "C:\Documents and Settings\Nathalie\locals~1\applic~1" *
* Recherche dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" *
* Recherche dans "C:\DOCUME~1\INVIT~1\locals~1\applic~1" *
* Recherche dans "C:\DOCUME~1\mario\locals~1\applic~1" *
* Recherche dans "C:\DOCUME~1\MARIO~1.HUR\locals~1\applic~1" *
*** Recherche fichiers ***
*** Recherche clés spécifiques dans le Registre ***
*** Module de Recherche complémentaire ***
(Recherche fichiers spécifiques)
1)Recherche nouveaux fichiers Instant Access :
2)Recherche Heuristique :
* Dans "C:\WINDOWS\system32" :
* Dans "C:\Documents and Settings\Nathalie\locals~1\applic~1" :
* Dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" :
* Dans "C:\DOCUME~1\INVIT~1\locals~1\applic~1" :
* Dans "C:\DOCUME~1\mario\locals~1\applic~1" :
* Dans "C:\DOCUME~1\MARIO~1.HUR\locals~1\applic~1" :
3)Recherche Certificats :
Certificat Egroup absent !
Certificat Electronic-Group absent !
Certificat Montorgueil absent !
Certificat OOO-Favorit absent !
Certificat Sunny-Day-Design-Ltd absent !
4)Recherche fichiers connus :
*** Analyse terminée le 04/11/2008 à 14:33:40,20 *** -
Re,
Je trouve bizarre que tu es encore un rogue messsenger-skinner?
installe NAVILOG1
Remarque concernant la détection de Navilog1 par certains programmes de sécurités :
Certains fichiers de Navilog1.exe peuvent être considérés comme dangereux et donc supprimés ou neutralisés par certains programmes de sécurités. Ce sont des faux positifs et dans certains cas, vous serez amener à désactiver votre protection le temps du téléchargement/utilisation de Navilog1.
/ !\ Déconnecte toi du net et désactive ton antivirus et antispyware résident pour que Navilog1 puisse s'exécuter normalement. / !\
Utilisateurs de Windows Vista :
* Afin que Navilog1 puisse fonctionner correctement, il est recommandé de désactiver l'UAC pendant l'utilisation de Navilog1 (Installation, Utilisation). N'oubliez pas dès l'utilisation de Navilog1 terminé à réactiver l'UAC sur votre Ordinateur.
comment faire pour désactiver l'UAC
* A chaque fois que vous êtes amené à exécuter Navilog1.bat ou Navilog1.exe pour l'installation, ne double-cliquez pas sur le fichier ou raccourci mais faites un clic droit dessus et dans le menu contextuel choisssez "Exécuter en tant qu'administrateur".
Le lancement de l'installation de Navilog1 se fait en exécutant Navilog1.exe
(Si vous avez téléchargé navilog1.zip, Veuillez auparavant décompresser ce fichier)
Une fois l'installation terminé, pour lancer le fix :
- en utilisant le raccourci crée sur le bureau : Navilog1
- Via le poste de travail, en exécutant le fichier Navilog1.bat se trouvant dans %program files%Navilog1
Après le choix de la langue et les messages d'avertissement, le menu s'affiche.
Faite le choix 1
Effectue la vérification du système à la recherche de l'adware. Un scan avec catchme de GMER est également éffectué pour Windows XP. Cette analyse peut durer une dizaine de minutes. Patientez alors jusqu'au message «Analyse terminée le ....». Appuyez sur une touche comme demandé et le bloc note va souvrir , Enregistrez-le sur votre disque. Puis Ouvrez-le et Copiez-Collez l'intégralité de ce rapport sur le forum qui vous l'auras demandé.
(si le bloc-note ne s'ouvre pas : Rendez-vous dans votre poste de travail, à la racine du disque C vous trouverez le rapport sous le nom de fixnavi.txt)
Attention : Ne lancez-pas la partie désinfection (choix 2, 3 ou 4) sans l'avis/accord express de l'Helper qui vous as pris en charge sur le forum d'aide ou vous aurez exposer votre problème.
==>>Tutoriel Navilog1 -
donc voila,
rien de special là
- Rapport MSNCleaner 1.3.7
- Rapport créé: 04/11/2008 on 13:44:32
- Système d'exploitation: Windows XP
- Mode de démarrage: Mode sans échec
_________________________________________
Fichiers détectés: 0
Fichiers supprimés: 0
Fichiers non supprimés: 0
<<<<<<< Pas de fichiers trouvés >>>>>>> -
Re,
Supprime la quarantaine et redemare le pc et ensuite refait
Télécharges MsnCleaner.zip de ElPiedra :
http://www.clubic.com/lancer-le-telechargement-53800-0-msncleaner.html
Décompresses le sur ton bureau. (Cliques droit sur le fichier .zip puis "Extraire tout").
Démarrer en mode sans echec .
/!\ Ne jamais démarrer en mode sans échec via MSCONFIG /!\
Comment aller en Mode sans échec :
1) Redémarres ton ordi .
2) Tapotes la touche F8 immédiatement, (F5 sur certains PC) juste après le "Bip" .
3) Tu tapotes jusqu' à l'apparition de l'écran avec les options de démarrage .
4) Choisis la première option : Sans Échec , et valides en tapant sur [Entrée] .
5) Choisis ton compte habituel ( et pas Administrateur ).
attention : pas de connexion possible en mode sans échec , donc copies ou imprimes bien la manipe pour éviter les erreurs ...
· Cliques sur MsnCleaner.exe pour le lancer.
· Sous Language, cliques sur la petite flèche et choisis French.
· Cliques sur le bouton Analyse.
->Si l'outil trouve une infection, cliques sur le bouton Supprimer .
· A la fin du scan un rapport va être créé.
-> Redémarres ton PC ( mode normal ).
Postes le rapport C:\MsnCleaner\MsnCleaner.txt dans ta prochaine réponse ... -
Bonjour,
Voila, j'ai lancé malwarebyte's ce matin , 4 infections (Trjan Fake Codec, 2 fois Rogue messenger
et Rootkit Agent), voici le rapport (mais plus de 3 heures c'est trop long en examen complet), je ne le referais pas .
Malwarebytes' Anti-Malware 1.30
Version de la base de données: 1354
Windows 5.1.2600 Service Pack 2
04/11/2008 11:07:11
mbam-log-2008-11-04 (11-07-11).txt
Type de recherche: Examen complet (C:\|)
Eléments examinés: 231674
Temps écoulé: 3 hour(s), 13 minute(s), 26 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 4
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
(Aucun élément nuisible détecté)
Fichier(s) infecté(s):
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP73\A0124758.exe (Trojan.FakeCodec) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP73\A0124759.dll (Rogue.MessengerSkinner) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP73\A0124760.dll (Rogue.MessengerSkinner) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP73\A0124767.sys (Rootkit.Agent) -> Quarantined and deleted successfully. -
Re,
OK.
antivir
et le pare feu qui vas bien avec:
comodo
et le tuto qui t'explique tout tutorial COMODO
A demain. -
Non pas ce soir, tout a l'heure ça m'a pris plus de 3 heures et je me leve à 6 damain, donc voila j'aimerai bien que tu me donnes un lien pour un antivirus et je reviendrais sur le site demain apres midi et surtout merci encore.
Nathalie -
Re,
Peut tu refaire une analyse avec malwarebyte.
STP.
Merci. -
voila,
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:29:04, on 03/11/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\System32\FTRTSVC.exe
C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Orange HSS\Launcher\Launcher.exe
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
C:\Program Files\Orange HSS\connectivity\connectivitymanager.exe
C:\Program Files\Orange HSS\systray\systrayapp.exe
C:\Program Files\Orange HSS\Deskboard\deskboard.exe
C:\Program Files\Orange HSS\connectivity\CoreCom\CoreCom.exe
C:\Program Files\Orange HSS\connectivity\CoreCom\OraConfigRecover.exe
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTCOMModule\0\FTCOMModule.exe
C:\Program Files\Orange HSS\browser\browser.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\Orange HSS\SearchURLHook\SearchPageURL.dll
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: https://www.orange.fr/portail
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O16 - DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} (GoPetsWeb Control) - https://secure.gopetslive.com/dev/GoPetsWeb.cab
O20 - AppInit_DLLs: xdcppd.dll
O21 - SSODL: pkMXrrFog - {5C0434E1-F6AE-9E4B-A8B3-229277981D42} - C:\WINDOWS\system32\mmuod.dll
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InstallShield Licensing Service - Macrovision - C:\Program Files\Fichiers communs\InstallShield Shared\Service\InstallShield Licensing Service.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: OneStepSearch Service - Unknown owner - C:\Program Files\OneStep\onestep.exe (file missing)
-
Relance hijack et clique sur "Do a system scan only"
Ensuite recherche ces lignes et coches les cases
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\yos hurtado\Menu Démarrer\Programmes\IMVU\Run IMVU.lnk (file missing)
Ensuite clique sur "Fix checked"
=>>Ensuite refait un rapport hijackthis.
Merci. -
Bon c'est fait, dis moi goldorak (c'est pour ta generation?) et 59 (c'est ton département?, je ne pense pas que ce soit ton année de naissance.)
Bon, j'en suis où ? tu me fais faire plein de choses aux quelles je ne comprend rien. Ce matin, je pensais que tout était fini. Il est encore 23h, je cale. Par contre , j'ai toujours les 2 écus, le jaune et le rouge, mais bon, voici le rapport,
-------------- UsbFix V2.395 ---------------
* User : Nathalie - HURTADO-E725D7B
* Outils mis a jours le 03/11/2008 par Chiquitine29 et Chimay8
* Recherche effectuée à 23:01:01 le 03/11/2008
* Windows Xp - Internet Explorer 6.0.2900.2180
--------------- [ Processus actifs ] ----------------
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\System32\FTRTSVC.exe
C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\userinit.exe
C:\DOCUME~1\Nathalie\LOCALS~1\Temp\1.tmp\b2e.exe
--------------- [ Informations lecteurs ] ----------------
C: - Lecteur fixe
--------------- [ Registre / Startup ] ----------------
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
QuickTime Task REG_SZ "C:\Program Files\QuickTime\QTTask.exe" -atboottime
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents
! REG.EXE VERSION 3.0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
QuickTime Task REG_SZ "C:\Program Files\QuickTime\QTTask.exe" -atboottime
msnmsgr REG_SZ "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
--------------- [ Registre / Mountpoint2 ] ----------------
-> Recherche négative.
--------------- [ Nettoyage des disques ] ----------------
--------------- [ Listing des fichiers présents ] ----------------
-> /!\ Le resultat doit etre interprété par un spécialiste /!\
[24/09/2007 12:15][--a------] C:\AUTOEXEC.BAT
[02/03/2006 13:00][-rahs----] C:\NTDETECT.COM
[03/11/2008 17:08][-rahs----] C:\boot.ini
--------------- ! Fin du rapport ! ---------------- -
Re,
Alors maintenant fait ceci:
--> Télécharge UsbFix (de Chiquitine29) sur ton Bureau :
http://sd-1.archive-host.com/membres/up/116615172019703188/UsbFix.exe
--> Lance l'installation avec les paramètres par défaut.
--> Branche tes sources de données externes à ton PC (clé USB, disque dur externe, etc...) sans les ouvrir.
--> Double-clique sur le raccourci UsbFix sur ton Bureau.
--> Le PC va redémarrer.
--> Après redémarrage, poste le rapport UsbFix.txt
Note : le rapport UsbFix.txt est sauvegardé à la racine du disque.
(Si le Bureau ne réapparait pas, presse Ctrl+Alt+Suppr, Onglet "Fichier", "Nouvelle tâche", tape explorer.exe et valide) -
voila,
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:30:05, on 03/11/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\System32\FTRTSVC.exe
C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Orange HSS\Launcher\Launcher.exe
C:\WINDOWS\system32\wscntfy.exe
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
C:\Program Files\Orange HSS\connectivity\connectivitymanager.exe
C:\Program Files\Orange HSS\systray\systrayapp.exe
C:\Program Files\Orange HSS\Deskboard\deskboard.exe
C:\Program Files\Orange HSS\connectivity\CoreCom\CoreCom.exe
C:\Program Files\Orange HSS\connectivity\CoreCom\OraConfigRecover.exe
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTCOMModule\0\FTCOMModule.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Orange HSS\browser\browser.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.lo.st
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\Orange HSS\SearchURLHook\SearchPageURL.dll
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\yos hurtado\Menu Démarrer\Programmes\IMVU\Run IMVU.lnk (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: https://www.orange.fr/portail
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O16 - DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} (GoPetsWeb Control) - https://secure.gopetslive.com/dev/GoPetsWeb.cab
O20 - AppInit_DLLs: xdcppd.dll
O21 - SSODL: pkMXrrFog - {5C0434E1-F6AE-9E4B-A8B3-229277981D42} - C:\WINDOWS\system32\mmuod.dll
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InstallShield Licensing Service - Macrovision - C:\Program Files\Fichiers communs\InstallShield Shared\Service\InstallShield Licensing Service.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: OneStepSearch Service - Unknown owner - C:\Program Files\OneStep\onestep.exe (file missing)
-
Re,
Ok.
Tu peut me refaire un hijackthis .
Merci. -
Bonsoir,
J'ai passé + de 3 heures a effectuer Malwarebytes (ce matin, vu que mon probleme de crois blanche dans le rond rouge), était résolu, j'étais trop contente, alors pour te dire que ça fait bientot + de 72 heures que je suis sur le site , j'ai du mal car demain je me leve tot. Voila, pendant les 3 heures , avant dix minutes j'avais 5 fichiers infectés et puis ça a recommencé jusqu'a 105 après deux heures et après voila. Quand j'ai redemarré en mode sans echec tout était en couleur contrairement à hier et en plus, effectivement maintenant je tape f8, alors que je tapais f10, tu me diras ton record de correspondance en heures(je blague), bon je ne sais pas pôurquoi j'ai 2 rapports, donc les voici :
Malwarebytes' Anti-Malware 1.30
Version de la base de données: 1354
Windows 5.1.2600 Service Pack 2
03/11/2008 21:53:39
mbam-log-2008-11-03 (21-53-26).txt
Type de recherche: Examen complet (C:\|)
Eléments examinés: 230782
Temps écoulé: 3 hour(s), 15 minute(s), 43 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 3
Valeur(s) du Registre infectée(s): 1
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 1
Fichier(s) infecté(s): 109
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{c5428486-50a0-4a02-9d20-520b59a9f9b3} (Adware.Shopping.Report) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\onestep (Adware.OneStepSearch) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\dslcnnct (Trojan.Vundo) -> No action taken.
Valeur(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\ShellBrowser\{07aa283a-43d7-4cbe-a064-32a21112d94d} (Adware.Zango) -> No action taken.
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
C:\Program Files\OneStep (Adware.OneStepSearch) -> No action taken.
Fichier(s) infecté(s):
C:\Documents and Settings\mario.HURTADO-E725D7B\Bureau\Codec.exe (Trojan.FakeCodec) -> No action taken.
C:\Documents and Settings\Nathalie\Bureau\MessengerSkinner\MessengerSkinnerDll.dll (Rogue.MessengerSkinner) -> No action taken.
C:\Documents and Settings\Nathalie\Bureau\MessengerSkinner\MessengerSkinnerDll_new.dll (Rogue.MessengerSkinner) -> No action taken.
C:\Qoobox\Quarantine\C\Program Files\APPATC~1\dvdplay.exe.vir (Adware.ClickSpring) -> No action taken.
C:\Qoobox\Quarantine\C\Program Files\SEMBLY~1\dexplore.exe.vir (Adware.ClickSpring) -> No action taken.
C:\Qoobox\Quarantine\C\WINDOWS\system32\almfoaof.dll.vir (Trojan.Vundo) -> No action taken.
C:\Qoobox\Quarantine\C\WINDOWS\system32\bcozmy.dll.vir (Trojan.Vundo) -> No action taken.
C:\Qoobox\Quarantine\C\WINDOWS\system32\czrxsw.dll.vir (Trojan.Vundo) -> No action taken.
C:\Qoobox\Quarantine\C\WINDOWS\system32\dgodppng.dll.vir (Trojan.Vundo) -> No action taken.
C:\Qoobox\Quarantine\C\WINDOWS\system32\dhcifooo.dll.vir (Trojan.Vundo) -> No action taken.
C:\Qoobox\Quarantine\C\WINDOWS\system32\dqgzxj.dll.vir (Trojan.Vundo) -> No action taken.
C:\Qoobox\Quarantine\C\WINDOWS\system32\dxq.dll.vir (Adware.ClickSpring) -> No action taken.
C:\Qoobox\Quarantine\C\WINDOWS\system32\fuxfgwcp.exe.vir (Trojan.LowZones) -> No action taken.
C:\Qoobox\Quarantine\C\WINDOWS\system32\goqdamqr.dll.vir (Trojan.Vundo) -> No action taken.
C:\Qoobox\Quarantine\C\WINDOWS\system32\jnsofq.dll.vir (Trojan.Vundo) -> No action taken.
C:\Qoobox\Quarantine\C\WINDOWS\system32\jrfkhh.dll.vir (Trojan.Vundo) -> No action taken.
C:\Qoobox\Quarantine\C\WINDOWS\system32\kcuciysw.dll.vir (Trojan.Vundo) -> No action taken.
C:\Qoobox\Quarantine\C\WINDOWS\system32\kwivbl.dll.vir (Trojan.Vundo) -> No action taken.
C:\Qoobox\Quarantine\C\WINDOWS\system32\mlJBSmJc.dll.vir (Trojan.Vundo) -> No action taken.
C:\Qoobox\Quarantine\C\WINDOWS\system32\niazwb.dll.vir (Trojan.Vundo) -> No action taken.
C:\Qoobox\Quarantine\C\WINDOWS\system32\nqcgfoqb.dll.vir (Trojan.Vundo) -> No action taken.
C:\Qoobox\Quarantine\C\WINDOWS\system32\oenwiarc.exe.vir (Trojan.LowZones) -> No action taken.
C:\Qoobox\Quarantine\C\WINDOWS\system32\qltsuecu.exe.vir (Trojan.LowZones) -> No action taken.
C:\Qoobox\Quarantine\C\WINDOWS\system32\qoiscemb.exe.vir (Trojan.LowZones) -> No action taken.
C:\Qoobox\Quarantine\C\WINDOWS\system32\tiftarpi.exe.vir (Trojan.LowZones) -> No action taken.
C:\Qoobox\Quarantine\C\WINDOWS\system32\tkhdcbaj.dll.vir (Trojan.Vundo) -> No action taken.
C:\Qoobox\Quarantine\C\WINDOWS\system32\tuvTjJbY.dll.vir (Trojan.Vundo) -> No action taken.
C:\Qoobox\Quarantine\C\WINDOWS\system32\tuvWmNHy.dll.vir (Trojan.Vundo) -> No action taken.
C:\Qoobox\Quarantine\C\WINDOWS\system32\tyeupl.dll.vir (Trojan.Vundo) -> No action taken.
C:\Qoobox\Quarantine\C\WINDOWS\system32\wlevqpgh.exe.vir (Trojan.LowZones) -> No action taken.
C:\Qoobox\Quarantine\C\WINDOWS\system32\xxkcwj.dll.vir (Trojan.Vundo) -> No action taken.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP30\A0038766.sys (Rootkit.Agent) -> No action taken.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP30\A0039800.exe (Adware.ClickSpring) -> No action taken.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP30\A0039805.exe (Adware.ClickSpring) -> No action taken.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP32\A0043193.dll (Adware.ClickSpring) -> No action taken.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP32\A0043206.exe (Adware.ClickSpring) -> No action taken.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP32\A0043208.exe (Adware.ClickSpring) -> No action taken.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP32\A0044178.dll (Adware.ClickSpring) -> No action taken.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP33\A0048253.sys (Rootkit.Agent) -> No action taken.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP33\A0049266.exe (Adware.ClickSpring) -> No action taken.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP33\A0049273.sys (Rootkit.Agent) -> No action taken.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP34\A0052331.exe (Adware.ClickSpring) -> No action taken.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP40\A0054530.dll (Adware.ClickSpring) -> No action taken.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP40\A0054531.exe (Adware.ClickSpring) -> No action taken.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP40\A0054535.dll (Adware.ClickSpring) -> No action taken.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP42\A0057575.exe (Adware.ClickSpring) -> No action taken.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP42\A0058566.dll (Adware.ClickSpring) -> No action taken.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP42\A0058567.dll (Adware.ClickSpring) -> No action taken.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP50\A0061782.exe (Adware.ClickSpring) -> No action taken.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP50\A0062774.dll (Adware.ClickSpring) -> No action taken.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP50\A0062826.sys (Rootkit.Agent) -> No action taken.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP50\A0064852.exe (Adware.ClickSpring) -> No action taken.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP55\A0068047.exe (Adware.ClickSpring) -> No action taken.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP55\A0068054.dll (Adware.ClickSpring) -> No action taken.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP56\A0070099.sys (Rootkit.Agent) -> No action taken.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP56\A0072117.exe (Adware.ClickSpring) -> No action taken.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP57\A0075154.dll (Adware.ClickSpring) -> No action taken.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP57\A0075155.exe (Adware.ClickSpring) -> No action taken.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP58\A0076170.sys (Rootkit.Agent) -> No action taken.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP58\A0079179.exe (Adware.ClickSpring) -> No action taken.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP63\A0096375.dll (Adware.ClickSpring) -> No action taken.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP63\A0096376.exe (Adware.ClickSpring) -> No action taken.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP64\A0096415.sys (Rootkit.Agent) -> No action taken.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP65\A0097487.exe (Adware.ClickSpring) -> No action taken.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP65\A0098520.dll (Trojan.Vundo) -> No action taken.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP65\A0100520.dll (Trojan.Vundo) -> No action taken.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP68\A0102685.sys (Rootkit.Agent) -> No action taken.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP69\A0114937.dll (Trojan.Vundo) -> No action taken.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP69\A0121262.dll (Adware.ClickSpring) -> No action taken.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP69\A0121263.exe (Adware.ClickSpring) -> No action taken.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP70\A0122281.EXE (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP70\A0122283.DLL (Adware.MyWebSearch) -> No action taken.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP70\A0122284.DLL (Adware.AskSBAR) -> No action taken.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP70\A0122285.DLL (Trojan.Agent) -> No action taken.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP71\A0122338.exe (Adware.ClickSpring) -> No action taken.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP71\A0122346.exe (Adware.ClickSpring) -> No action taken.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP71\A0122349.exe (Adware.ClickSpring) -> No action taken.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP71\A0122352.dll (Adware.ClickSpring) -> No action taken.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP71\A0122355.dll (Trojan.Vundo) -> No action taken.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP71\A0122359.dll (Trojan.Vundo) -> No action taken.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP71\A0122363.dll (Trojan.Vundo) -> No action taken.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP71\A0122365.dll (Trojan.Vundo) -> No action taken.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP71\A0122366.dll (Trojan.Vundo) -> No action taken.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP71\A0122368.dll (Trojan.Vundo) -> No action taken.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP71\A0122375.exe (Trojan.LowZones) -> No action taken.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP71\A0122378.dll (Trojan.Vundo) -> No action taken.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP71\A0122394.dll (Trojan.Vundo) -> No action taken.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP71\A0122397.dll (Trojan.Vundo) -> No action taken.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP71\A0122402.dll (Trojan.Vundo) -> No action taken.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP71\A0122404.dll (Trojan.Vundo) -> No action taken.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP71\A0122410.dll (Trojan.Vundo) -> No action taken.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP71\A0122412.dll (Trojan.Vundo) -> No action taken.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP71\A0122413.dll (Trojan.Vundo) -> No action taken.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP71\A0122415.exe (Trojan.LowZones) -> No action taken.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP71\A0122423.exe (Trojan.LowZones) -> No action taken.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP71\A0122425.exe (Trojan.LowZones) -> No action taken.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP71\A0122435.exe (Trojan.LowZones) -> No action taken.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP71\A0122437.dll (Trojan.Vundo) -> No action taken.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP71\A0122440.dll (Trojan.Vundo) -> No action taken.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP71\A0122441.dll (Trojan.Vundo) -> No action taken.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP71\A0122443.dll (Trojan.Vundo) -> No action taken.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP71\A0122453.exe (Trojan.LowZones) -> No action taken.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP71\A0122460.dll (Trojan.Vundo) -> No action taken.
C:\Program Files\OneStep\home.js (Adware.OneStepSearch) -> No action taken.
C:\Program Files\OneStep\onestep.dll (Adware.OneStepSearch) -> No action taken.
C:\Program Files\OneStep\onestep.exe (Adware.OneStepSearch) -> No action taken.
C:\Program Files\OneStep\osopt.exe (Adware.OneStepSearch) -> No action taken.
C:\Program Files\OneStep\readme.html (Adware.OneStepSearch) -> No action taken.
C:\Program Files\OneStep\uninstall.exe (Adware.OneStepSearch) -> No action taken.
Malwarebytes' Anti-Malware 1.30
Version de la base de données: 1354
Windows 5.1.2600 Service Pack 2
03/11/2008 21:54:35
mbam-log-2008-11-03 (21-54-35).txt
Type de recherche: Examen complet (C:\|)
Eléments examinés: 230782
Temps écoulé: 3 hour(s), 15 minute(s), 43 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 3
Valeur(s) du Registre infectée(s): 1
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 1
Fichier(s) infecté(s): 109
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{c5428486-50a0-4a02-9d20-520b59a9f9b3} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\onestep (Adware.OneStepSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\dslcnnct (Trojan.Vundo) -> Quarantined and deleted successfully.
Valeur(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\ShellBrowser\{07aa283a-43d7-4cbe-a064-32a21112d94d} (Adware.Zango) -> Quarantined and deleted successfully.
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
C:\Program Files\OneStep (Adware.OneStepSearch) -> Quarantined and deleted successfully.
Fichier(s) infecté(s):
C:\Documents and Settings\mario.HURTADO-E725D7B\Bureau\Codec.exe (Trojan.FakeCodec) -> Quarantined and deleted successfully.
C:\Documents and Settings\Nathalie\Bureau\MessengerSkinner\MessengerSkinnerDll.dll (Rogue.MessengerSkinner) -> Quarantined and deleted successfully.
C:\Documents and Settings\Nathalie\Bureau\MessengerSkinner\MessengerSkinnerDll_new.dll (Rogue.MessengerSkinner) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\Program Files\APPATC~1\dvdplay.exe.vir (Adware.ClickSpring) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\Program Files\SEMBLY~1\dexplore.exe.vir (Adware.ClickSpring) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\almfoaof.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\bcozmy.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\czrxsw.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\dgodppng.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\dhcifooo.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\dqgzxj.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\dxq.dll.vir (Adware.ClickSpring) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\fuxfgwcp.exe.vir (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\goqdamqr.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\jnsofq.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\jrfkhh.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\kcuciysw.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\kwivbl.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\mlJBSmJc.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\niazwb.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\nqcgfoqb.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\oenwiarc.exe.vir (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\qltsuecu.exe.vir (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\qoiscemb.exe.vir (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\tiftarpi.exe.vir (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\tkhdcbaj.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\tuvTjJbY.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\tuvWmNHy.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\tyeupl.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\wlevqpgh.exe.vir (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\xxkcwj.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP30\A0038766.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP30\A0039800.exe (Adware.ClickSpring) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP30\A0039805.exe (Adware.ClickSpring) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP32\A0043193.dll (Adware.ClickSpring) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP32\A0043206.exe (Adware.ClickSpring) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP32\A0043208.exe (Adware.ClickSpring) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP32\A0044178.dll (Adware.ClickSpring) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP33\A0048253.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP33\A0049266.exe (Adware.ClickSpring) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP33\A0049273.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP34\A0052331.exe (Adware.ClickSpring) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP40\A0054530.dll (Adware.ClickSpring) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP40\A0054531.exe (Adware.ClickSpring) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP40\A0054535.dll (Adware.ClickSpring) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP42\A0057575.exe (Adware.ClickSpring) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP42\A0058566.dll (Adware.ClickSpring) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP42\A0058567.dll (Adware.ClickSpring) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP50\A0061782.exe (Adware.ClickSpring) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP50\A0062774.dll (Adware.ClickSpring) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP50\A0062826.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP50\A0064852.exe (Adware.ClickSpring) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP55\A0068047.exe (Adware.ClickSpring) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP55\A0068054.dll (Adware.ClickSpring) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP56\A0070099.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP56\A0072117.exe (Adware.ClickSpring) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP57\A0075154.dll (Adware.ClickSpring) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP57\A0075155.exe (Adware.ClickSpring) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP58\A0076170.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP58\A0079179.exe (Adware.ClickSpring) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP63\A0096375.dll (Adware.ClickSpring) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP63\A0096376.exe (Adware.ClickSpring) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP64\A0096415.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP65\A0097487.exe (Adware.ClickSpring) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP65\A0098520.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP65\A0100520.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP68\A0102685.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP69\A0114937.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP69\A0121262.dll (Adware.ClickSpring) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP69\A0121263.exe (Adware.ClickSpring) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP70\A0122281.EXE (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP70\A0122283.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP70\A0122284.DLL (Adware.AskSBAR) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP70\A0122285.DLL (Trojan.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP71\A0122338.exe (Adware.ClickSpring) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP71\A0122346.exe (Adware.ClickSpring) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP71\A0122349.exe (Adware.ClickSpring) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP71\A0122352.dll (Adware.ClickSpring) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP71\A0122355.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP71\A0122359.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP71\A0122363.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP71\A0122365.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP71\A0122366.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP71\A0122368.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP71\A0122375.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP71\A0122378.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP71\A0122394.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP71\A0122397.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP71\A0122402.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP71\A0122404.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP71\A0122410.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP71\A0122412.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP71\A0122413.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP71\A0122415.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP71\A0122423.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP71\A0122425.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP71\A0122435.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP71\A0122437.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP71\A0122440.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP71\A0122441.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP71\A0122443.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP71\A0122453.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{BAB077D8-141B-43AC-869A-7BB85C14B803}\RP71\A0122460.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Program Files\OneStep\home.js (Adware.OneStepSearch) -> Quarantined and deleted successfully.
C:\Program Files\OneStep\onestep.dll (Adware.OneStepSearch) -> Quarantined and deleted successfully.
C:\Program Files\OneStep\onestep.exe (Adware.OneStepSearch) -> Quarantined and deleted successfully.
C:\Program Files\OneStep\osopt.exe (Adware.OneStepSearch) -> Quarantined and deleted successfully.
C:\Program Files\OneStep\readme.html (Adware.OneStepSearch) -> Quarantined and deleted successfully.
C:\Program Files\OneStep\uninstall.exe (Adware.OneStepSearch) -> Quarantined and deleted successfully.
A chaque fois maintenant que je fais copier, coller on me demande si je l'autorise par rapport au presse papier,
bon ben voila
- 1
- 2
- 3
- 4