Terrible infection
Lenteur de l ordinateur
Moteur de recherche qui s ouvre tout seul
Redirection vers page go.google.com
Tout les cookies sont accépter(option internet) et si je remet par defaut sa ne reste pas
J ai telecharger malwarebytes mais impossible de le lancer meme en mode sans echecs,je suis vraiment desesperer
merci de votre aide
Configuration: Windows XP pro Internet Explorer 7.0 firefox
26 réponses
Une infection est signalée sur un PC Windows XP Pro avec Internet Explorer 7 et Firefox, provoquant lenteur, redirections vers go.google.com et blocages, Malwarebytes ne démarre pas et les cookies restent activés. Plusieurs méthodes ont été proposées, notamment SDFix en mode sans échec avec RunThis.bat, puis redémarrage et suppression des services et entrées de registre associées, afin d’obtenir un Bureau opérationnel et un rapport. D’autres réponses évoquent SmitfraudFix ou ComboFix (renommage recommandé), en précisant les étapes hors ligne, la déconnexion d'internet et la désactivation temporaire de protections, puis l’analyse et le rapport. Le fil signale aussi des traces du Trojan.Vundo.H et de DNSChanger dans le registre et les fichiers, et propose de déposer les rapports pour poursuivre le nettoyage.
-
Contributeurnon te tapes la tete contre le mur : :)
prends le ici :
http://sd-1.archive-host.com/membres/up/1366464061/ComboFix_7.rar -
tjrs pareil c est un .htm
ps:j ai envie de me tapper la tete contre le mur ;) -
Contributeuret la :
http://www.yourfilehost.com/media.php?cat=other&file=ComboFix.rar
je ne connais pas vraiment ce service de host mais le service que j´utilise est plein, je ne peu plus uploader de fichier... -
girly ton lien fonctionne par contre le nom du fichier est combofix.htm et si je le renomme en .exe sa ne fonctionne pas
-
je ne peut pas utiliser combofix puisque je ne le trouve pas et ne pouvant effectuer de recherche .....
pourriez vous me l envoyer sur mon mail ? -
Contributeuressaie de le telecharger ici :
http://www.yourfilehost.com/media.php?cat=other&file=ComboFix.rar
désolé pour le coté un peu olé olé de la page...
@+ -
mais je peut pas passr combofix vu que je ne peut pas effectuer de recherche sur le net
-
Contributeur sécuritéfait combofix ! ;)))
-
en fait quand je clic sur un lien sa m ouvre toujours une page qui na rien a voir sttyle go.google.com je na rrive plus a rechercher quoi que se soit
-
dsl me suis tromper de rapport voici le bon
Malwarebytes' Anti-Malware 1.30
Version de la base de données: 1306
Windows 5.1.2600 Service Pack 3
01/12/2008 19:48:10
mbam-log-2008-12-01 (19-48-10).txt
Type de recherche: Examen rapide
Eléments examinés: 46879
Temps écoulé: 15 minute(s), 2 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 2
Clé(s) du Registre infectée(s): 9
Valeur(s) du Registre infectée(s): 1
Elément(s) de données du Registre infecté(s): 8
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 18
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
C:\WINDOWS\system32\qoMeETKc.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\mmycey.dll (Trojan.Vundo.H) -> Delete on reboot.
Clé(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31d36c7c-bcb9-4643-ba67-fcf7253b4052} (Trojan.Vundo.H) -> Delete on reboot.
HKEY_CLASSES_ROOT\CLSID\{31d36c7c-bcb9-4643-ba67-fcf7253b4052} (Trojan.Vundo.H) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{32c7a845-a34f-4326-a3bc-959fe57b6cdb} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{32c7a845-a34f-4326-a3bc-959fe57b6cdb} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\tdss (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.
Valeur(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\7ccd97f1 (Trojan.Vundo.H) -> Quarantined and deleted successfully.
Elément(s) de données du Registre infecté(s):
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\qomeetkc -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\qomeetkc -> Delete on reboot.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\StartMenuLogOff (Hijack.StartMenu) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{e1f9f635-647c-4cb8-927c-856c814ea7b1}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.26;85.255.112.117 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{e1f9f635-647c-4cb8-927c-856c814ea7b1}\DhcpNameServer (Trojan.DNSChanger) -> Data: 85.255.112.26;85.255.112.117 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{e1f9f635-647c-4cb8-927c-856c814ea7b1}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.26;85.255.112.117 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Tcpip\Parameters\Interfaces\{e1f9f635-647c-4cb8-927c-856c814ea7b1}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.26;85.255.112.117 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{e1f9f635-647c-4cb8-927c-856c814ea7b1}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.26;85.255.112.117 -> Quarantined and deleted successfully.
Dossier(s) infecté(s):
(Aucun élément nuisible détecté)
Fichier(s) infecté(s):
C:\WINDOWS\system32\qoMeETKc.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\cKTEeMoq.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\cKTEeMoq.ini2 (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\mmycey.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\gqnatsms.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\smstanqg.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ddcYOeCu.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\dzgagn.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\fymxzr.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ilshdd.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\mtnjfagq.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\qtofbkku.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ukwafoky.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\upfvwoxx.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\mcrh.tmp (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\msiconf.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\Temp\tempo-0FF.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\Temp\tempo-D13.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
par contre me suis rejouit trop vite les soucis revienne (je ne peut a nouveau plus lancer malwarebytes) quand a combo les liens ne fonctionne pas et je ne peut pas effectuer de recherche -
Contributeur sécuritétu les as pas mis en quarantaine de malwarebyte's poste le rapport de combo stp :)
-
Contributeurtu as supprimé ce que malwarebytes a trouvé ?
-
voici le rapport malwarebytes
Malwarebytes' Anti-Malware 1.30
Version de la base de données: 1306
Windows 5.1.2600 Service Pack 3
01/12/2008 19:47:57
mbam-log-2008-12-01 (19-47-53).txt
Type de recherche: Examen rapide
Eléments examinés: 46879
Temps écoulé: 15 minute(s), 2 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 2
Clé(s) du Registre infectée(s): 9
Valeur(s) du Registre infectée(s): 1
Elément(s) de données du Registre infecté(s): 8
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 18
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
C:\WINDOWS\system32\qoMeETKc.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\mmycey.dll (Trojan.Vundo.H) -> No action taken.
Clé(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31d36c7c-bcb9-4643-ba67-fcf7253b4052} (Trojan.Vundo.H) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{31d36c7c-bcb9-4643-ba67-fcf7253b4052} (Trojan.Vundo.H) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{32c7a845-a34f-4326-a3bc-959fe57b6cdb} (Trojan.Vundo.H) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{32c7a845-a34f-4326-a3bc-959fe57b6cdb} (Trojan.Vundo.H) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\tdss (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> No action taken.
Valeur(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\7ccd97f1 (Trojan.Vundo.H) -> No action taken.
Elément(s) de données du Registre infecté(s):
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\qomeetkc -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\qomeetkc -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\StartMenuLogOff (Hijack.StartMenu) -> Bad: (1) Good: (0) -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{e1f9f635-647c-4cb8-927c-856c814ea7b1}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.26;85.255.112.117 -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{e1f9f635-647c-4cb8-927c-856c814ea7b1}\DhcpNameServer (Trojan.DNSChanger) -> Data: 85.255.112.26;85.255.112.117 -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{e1f9f635-647c-4cb8-927c-856c814ea7b1}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.26;85.255.112.117 -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Tcpip\Parameters\Interfaces\{e1f9f635-647c-4cb8-927c-856c814ea7b1}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.26;85.255.112.117 -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{e1f9f635-647c-4cb8-927c-856c814ea7b1}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.26;85.255.112.117 -> No action taken.
Dossier(s) infecté(s):
(Aucun élément nuisible détecté)
Fichier(s) infecté(s):
C:\WINDOWS\system32\qoMeETKc.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\cKTEeMoq.ini (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\cKTEeMoq.ini2 (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\mmycey.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\gqnatsms.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\smstanqg.ini (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\ddcYOeCu.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\dzgagn.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\fymxzr.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\ilshdd.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\mtnjfagq.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\qtofbkku.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\ukwafoky.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\upfvwoxx.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\mcrh.tmp (Malware.Trace) -> No action taken.
C:\WINDOWS\system32\msiconf.exe (Trojan.Downloader) -> No action taken.
C:\WINDOWS\Temp\tempo-0FF.tmp (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\Temp\tempo-D13.tmp (Trojan.FakeAlert) -> No action taken.
par contre quand j effectue une recherche sur le net j ai tjrs une redirection sur go.google.com je n arrive dc pas a faire une recherche et les liens donner plus pour combofix ne fonctionne pas -
Contributeurcool
post le rapport de malwarebytes pour voir avec le rapport de combofix stp :)
@+ -
re je pose dc le rapport sdfix
[b]SDFix: Version 1.240 [/b]
Run by Administrateur on 01/12/2008 at 19:01
Microsoft Windows XP [version 5.1.2600]
Running From: C:\DOCUME~1\ADMINI~1\Bureau\SDFix
[b]Checking Services [/b]:
Restoring Default Security Values
Restoring Default Hosts File
DNSChanger Trojan Found!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"="kdokb.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"C:\\WINDOWS\\system32\\kdokb.exe"
Restoring Default System value
Rebooting
[b]Checking Files [/b]:
Trojan Files Found:
C:\WINDOWS\system32\awtqoLdb.dll - Deleted
C:\WINDOWS\system32\kdokb.exe - Deleted
Folder C:\resycled - Removed
Removing Temp Files
[b]ADS Check [/b]:
[b]Final Check [/b]:
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-01 19:22:11
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
disk error: C:\WINDOWS\system32\config\system, 0
scanning hidden registry entries ...
disk error: C:\WINDOWS\system32\config\software, 0
disk error: C:\Documents and Settings\Administrateur\ntuser.dat, 0
scanning hidden files ...
disk error: C:\WINDOWS\
please note that you need administrator rights to perform deep scan
[b]Remaining Services [/b]:
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\ma-config.com\\maconfservice.exe"="C:\\Program Files\\ma-config.com\\maconfservice.exe:LocalSubNet:Enabled:maconfservice"
"E:\\teamscript\\mirc.exe"="E:\\teamscript\\mirc.exe:*:Enabled:mIRC"
"C:\\Program Files\\uTorrent\\uTorrent.exe"="C:\\Program Files\\uTorrent\\uTorrent.exe:*:Enabled:æTorrent"
"C:\\Program Files\\Messenger\\Msmsgs.exe"="C:\\Program Files\\Messenger\\Msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\\Program Files\\RealVNC\\VNC4\\winvnc4.exe"="C:\\Program Files\\RealVNC\\VNC4\\winvnc4.exe:*:Enabled:VNC Server Enterprise Edition for Win32"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
"E:\\eMule\\emule.exe"="E:\\eMule\\emule.exe:*:Enabled:eMule"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"C:\\Program Files\\Camfrog\\Camfrog Video Chat\\Camfrog Video Chat.exe"="C:\\Program Files\\Camfrog\\Camfrog Video Chat\\Camfrog Video Chat.exe:*:Enabled:Camfrog Client Module"
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"="C:\\Program Files\\Mozilla Firefox\\firefox.exe:*:Enabled:Firefox"
"C:\\Program Files\\Ventrilo\\Ventrilo.exe"="C:\\Program Files\\Ventrilo\\Ventrilo.exe:*:Enabled:Ventrilo"
"F:\\eMule\\emule.exe"="F:\\eMule\\emule.exe:*:Enabled:eMule"
"F:\\la mule 2\\eMule\\emule.exe"="F:\\la mule 2\\eMule\\emule.exe:*:Enabled:eMule"
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\\Program Files\\RealVNC\\VNC4\\vncviewer.exe"="C:\\Program Files\\RealVNC\\VNC4\\vncviewer.exe:*:Enabled:VNC Viewer Enterprise Edition for Win32"
"F:\\teamscript\\mirc.exe"="F:\\teamscript\\mirc.exe:*:Enabled:mIRC"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
[b]Remaining Files [/b]:
File Backups: - C:\DOCUME~1\ADMINI~1\Bureau\SDFix\backups\backups.zip
[b]Files with Hidden Attributes [/b]:
Thu 14 Aug 2008 1,429,840 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SDUpdate.exe"
Wed 30 Jul 2008 4,891,984 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe"
Mon 18 Aug 2008 1,832,272 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
Mon 18 Aug 2008 1,832,272 A.SHR --- "C:\Program Files\TeaTimer (Spybot - Search & Destroy)\TeaTimer.exe"
Tue 30 Sep 2008 560,640 A..H. --- "C:\Documents and Settings\Administrateur\Local Settings\Temp\~tmp001.tmp"
[b]Finished![/b]
suite au passage de sdfix j ai pus passer malwarebytes qui ma supprimer pas mal de malware,l ordi a deja l air plus rapide mais j ai encore de gros freeze dc je fait la 3eme methode et je reviens poster
En tout cas merci de votre aide -
Contributeurok je te laisse, je passerais voir quand même :)
@+ -
Contributeur sécuritési smitfraudfix de marche SDfix non plus a mon avis ...
A+ -
Contributeurbah laisse le essayer sdfix quand meme !
-
Contributeur sécuritéBien
Fait ceci :
Télécharge combofix (par sUBs)à partir d'un de ces liens :
En premier
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
http://www.geekstogo.com/forum/files/file/197-combofix-by-subs/
A lire
http://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix
impératif: renomme le : tuto pour le renommé: http://forum.pcastuces.com/combofix___renommer_au_telechargement-f31s22.htm
-> Double clique sur combofix.exe.
-> Tape sur la touche 1 (Yes) pour démarrer le scan.
-> Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.
NOTE : Le rapport se trouve également ici : C:\Combofix.txt
Avant d'utiliser ComboFix :
-> Déconnecte toi d'internet et referme les fenêtres de tous les programmes en cours.
-> Désactive provisoirement et seulement le temps de l'utilisation de ComboFix, la protection en temps réel de ton Antivirus et de tes Antispywares, qui peuvent géner fortement la procédure de recherche et de nettoyage de l'outil.
Une fois fait, sur ton bureau double-clic sur Combofix.exe.
- Répond oui au message d'avertissement, pour que le programme commence à procéder à l'analyse du pc.
/!\ Pendant la durée de cette étape, ne te sert pas du pc et n'ouvre aucun programmes.
- En fin de scan il est possible que ComboFix ait besoin de redemarrer le pc pour finaliser la désinfection\recherche, laisses-le faire.
- Un rapport s'ouvrira ensuite dans le bloc notes, ce fichier rapport Combofix.txt, est automatiquement sauvegardé et rangé à C:\Combofix.txt)
-> Réactive la protection en temps réel de ton Antivirus et de tes Antispywares, avant de te reconnecter à internet.
-> Reviens sur le forum, et copie et colle la totalité du contenu de C:\Combofix.txt dans ton prochain message. -
re bonjour donc pour la methode de SmitfraudFix je na rrive pas a le lancer tout comme malwarebytes j essaye la 2eme methode eteje reviens
- 1
- 2