

Zerocool81
Membres-
Compteur de contenus
32 -
Inscription
-
Dernière visite
Type de contenu
Profils
Forums
Blogs
Tout ce qui a été posté par Zerocool81
-
Impossible d'afficher les fichiers et dossiers cachés
Zerocool81 a répondu à un(e) sujet de Zerocool81 dans Software
J'ai essayé 1) ça n'a pas marché et pour 2) j'ai un disque de reinstallation vaio qui permet pas la réparation mais j'ai trouvé un tutorial pour en créer mais si quelqu'un à une solution qui m'éviterai tout ça je suis preneur. Merci. -
Impossible d'afficher les fichiers et dossiers cachés
Zerocool81 a répondu à un(e) sujet de Zerocool81 dans Software
J'ai comparé et chez moi le registre est comme "avant" même après avoir coché "afficher les fichiers et dossiers cachésé et décoché "masquer les fichiers système". Voila. Tout aide pourrait m'être précieuse. Merci. -
Impossible d'afficher les fichiers et dossiers cachés
Zerocool81 a répondu à un(e) sujet de Zerocool81 dans Software
Merci pour ton intervention. J'ai regardé et j'ai bien la clé "SHOWALL" avec les mêmes valeurs que celles que tu m'as marquées pour créer la clé. -
Impossible d'afficher les fichiers et dossiers cachés
Zerocool81 a répondu à un(e) sujet de Zerocool81 dans Software
Merci pour ta réponse rapide. Donc je suis allé sur cette clé Hidden (avec mon compte administrateur qui est le seul) j'ai mis controle total mais ça n'a rien changé quand je fais "afficher les fichiers et dossiers cachés" appliquer puis ok ça ne fait rien. je reviens dans le menu affichage des dossiers et c'est déselectionné. Si t'as un autre idée merci -
Bonsoir j'ai été infecté par un méchant virus, qui a été éradiqué à 99% grâce à Régis du forum "Sécurité" qui m'envoie sur cette partie pour résoudre les derniers problèmes qu'il me reste. En effet, il m'est toujours impossible "d'afficher les fichiers et dossiers cachés". J'ai beau faire "appliquer puis ok" cela ne prend pas effet. Merci en espérant que quelqu'un puisse m'aider.
-
Infection due à TvAnts
Zerocool81 a répondu à un(e) sujet de Zerocool81 dans Analyses et éradication malwares
Re Il a rien detecté, du côté des pubs intempestives plus rien par contre je peux toujours pas afficher les fichiers cachés et j'ai toujours sur le disque d:/ le problème de changement de priorité du clique-droit (en gras auto au lieu de ouvrir) qui fait qu'en faisant 2 cliques gauche ça n'ouvre pas. Voila merci pour m'avoir assaini l'ordinateur, si tu peux résoudre ces 2 problèmes tu seras mon dieu -
Infection due à TvAnts
Zerocool81 a répondu à un(e) sujet de Zerocool81 dans Analyses et éradication malwares
Re Logfile of HijackThis v1.99.1 Scan saved at 18:14:01, on 11/03/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Intel\Wireless\Bin\EvtEng.exe C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe C:\Program Files\Sygate\SPF\smc.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\PROGRA~1\Grisoft\AVG7\avgcc.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe C:\Program Files\MSN Messenger\MsnMsgr.Exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe C:\PROGRA~1\Grisoft\AVG7\avgemc.exe C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe C:\Program Files\Sony\VAIO Event Service\VESMgr.exe C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\Program Files\MSN Messenger\usnsvc.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Documents and Settings\Zerocool\Bureau\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://vcl.vaio.sony.co.jp/eu/PforVAIO.htm R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.club-vaio.com/fr/ R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O4 - HKLM\..\Run: [smcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O14 - IERESET.INF: START_PAGE_URL=http://www.club-vaio.com/fr/ O15 - Trusted Zone: *.sony-europe.com O15 - Trusted Zone: *.sonystyle-europe.com O15 - Trusted Zone: *.vaio-link.com O17 - HKLM\System\CCS\Services\Tcpip\..\{8536AA5E-2A9A-4901-82BC-C2784EC182B4}: NameServer = 212.27.39.134 O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll O20 - Winlogon Notify: VESWinlogon - C:\WINDOWS\SYSTEM32\VESWinlogon.dll O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing) O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing) O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe O23 - Service: VAIO Entertainment Aggregation and Control Service - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment\VzRs\VzRs.exe O23 - Service: VAIO Entertainment Task Scheduler - Sony Corporation - C:\Program Files\Sony\VAIO Entertainment\VzTaskScheduler.exe O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Unknown owner - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-IntegratedServer-HTTP /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="Applications\IntegratedServer\HTTP (file missing) O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Unknown owner - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe" /Service=VAIOMediaPlatform-Mobile-Gateway /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Addons\Packages\Mobile\Gateway" /DisplayName="VAIO Media Gateway Server (file missing) O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe Voila pour log Hijackthis, merci pour ta rapidité. Là je dois m'absenter 2h environ, dès que je reviens je te poste les résultats. -
Infection due à TvAnts
Zerocool81 a répondu à un(e) sujet de Zerocool81 dans Analyses et éradication malwares
J'ai suivi à la lettre ton explication mais ça n'a pas voulu marcher, que je fasse les 2 en même temps ou un par un j'ai ce message que qui apparait : alors qu'il vérifie le registre avant de rédémarrer.Et toujours impossible d'afficher les fichiers et dossiers cachés quand j'ai redémarré. Voila le log de killbox Pocket Killbox version 2.0.0.648 Running on Windows XP as Zerocool(Administrator) was started @ dimanche, mars 11, 2007, 5:48 PM Killbox Closed(Exit) @ 5:51:36 PM __________________________________________________ Pocket Killbox version 2.0.0.648 Running on Windows XP as Zerocool(Administrator) was started @ dimanche, mars 11, 2007, 5:51 PM # 1 [Delete on Reboot] Path = c:\WINDOWS\cSMVS.exe # 2 [Delete on Reboot] Path = C:\WINDOWS\system32\EBFA74E0.EXE PendingFileRenameOperations Registry Data has been Removed by External Process! @ 5:54:08 PM # 3 [Delete on Reboot] Path = C:\WINDOWS\system32\EBFA74E0.EXE PendingFileRenameOperations Registry Data has been Removed by External Process! @ 5:54:28 PM # 4 [Delete on Reboot] Path = C:\WINDOWS\system32\EBFA74E0.EXE PendingFileRenameOperations Registry Data has been Removed by External Process! @ 5:55:25 PM # 5 [Delete on Reboot] Path = C:\WINDOWS\system32\EBFA74E0.EXE PendingFileRenameOperations Registry Data has been Removed by External Process! @ 5:55:48 PM Killbox Closed(Exit) @ 5:55:53 PM __________________________________________________ Pocket Killbox version 2.0.0.648 Running on Windows XP as Zerocool(Administrator) was started @ dimanche, mars 11, 2007, 5:55 PM # 1 [Delete on Reboot] Path = c:\WINDOWS\cSMVS.exe PendingFileRenameOperations Registry Data has been Removed by External Process! @ 5:56:21 PM Killbox Closed(Exit) @ 5:56:43 PM __________________________________________________ -
Infection due à TvAnts
Zerocool81 a répondu à un(e) sujet de Zerocool81 dans Analyses et éradication malwares
Merci. Bon tous s'est déroulé correctement jusque là: Cette ligne n'y était pas. Et j'ai toujours pas accès aux fichiers et dossiers cachés, donc j'ai pas pu continuer -
Infection due à TvAnts
Zerocool81 a répondu à un(e) sujet de Zerocool81 dans Analyses et éradication malwares
Logfile of HijackThis v1.99.1 Scan saved at 15:59:56, on 11/03/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Intel\Wireless\Bin\EvtEng.exe C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe C:\Program Files\Sygate\SPF\smc.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\PROGRA~1\Grisoft\AVG7\avgcc.exe C:\Program Files\MSN Messenger\MsnMsgr.Exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe C:\PROGRA~1\Grisoft\AVG7\avgemc.exe C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe C:\Program Files\Sony\VAIO Event Service\VESMgr.exe C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\Documents and Settings\Zerocool\Bureau\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://vcl.vaio.sony.co.jp/eu/PforVAIO.htm R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.club-vaio.com/fr/ R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,c:\WINDOWS\cSMVS.exe O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: AdPopup - {11F09AFD-75AD-4E51-AB43-E09E9351CE16} - (no file) O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O4 - HKLM\..\Run: [smcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O14 - IERESET.INF: START_PAGE_URL=http://www.club-vaio.com/fr/ O15 - Trusted Zone: *.sony-europe.com O15 - Trusted Zone: *.sonystyle-europe.com O15 - Trusted Zone: *.vaio-link.com O17 - HKLM\System\CCS\Services\Tcpip\..\{8536AA5E-2A9A-4901-82BC-C2784EC182B4}: NameServer = 212.27.39.134 O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll O20 - Winlogon Notify: VESWinlogon - C:\WINDOWS\SYSTEM32\VESWinlogon.dll O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing) O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing) O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe O23 - Service: EBFA74E0 - Unknown owner - C:\WINDOWS\system32\EBFA74E0.EXE (file missing) O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe O23 - Service: VAIO Entertainment Aggregation and Control Service - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment\VzRs\VzRs.exe O23 - Service: VAIO Entertainment Task Scheduler - Sony Corporation - C:\Program Files\Sony\VAIO Entertainment\VzTaskScheduler.exe O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Unknown owner - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-IntegratedServer-HTTP /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="Applications\IntegratedServer\HTTP (file missing) O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Unknown owner - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe" /Service=VAIOMediaPlatform-Mobile-Gateway /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Addons\Packages\Mobile\Gateway" /DisplayName="VAIO Media Gateway Server (file missing) O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe Je t'ai noirci celui que je reconnais mais je pense qu'il doit y avoir autre chose qui m'empêche de voir les fichiers et dossiers cachés -
Infection due à TvAnts
Zerocool81 a répondu à un(e) sujet de Zerocool81 dans Analyses et éradication malwares
Salut à toi ! Voila j'ai formaté mon disque "sytème" mais je pense que certains trojans/malwares/virus s'étaient cachés sur l'autre partition du disque, et recommencent à polluer ma partie système depuis le reformatage (j'ai bien reinstallé parefeu et antivirus avant de remettre internet etc...). En bref, il y en a un que j'ai reconnu qui était sous la forme d'un autorun.inf sur le disque d:/ et qui m'empeche de l'ouvrir directement en faisant double clique, puis j'ai eu les quelques pages chinoises (bon la on dirait que je ne les ai plus depuis que j'ai fait un scan en mode sans echec avec AVG) et le plus embettant et qui m'empeche de supprime le premier que j'ai reconnu c'est qu'il m'est impossible de faire "afficher les fichiers et dossiers cachés", j'ai beau faire appliquer et ok ça ne change rien. Je m'empresse de faire un rapport hijack this. Encore merci de ton aide. -
Infection due à TvAnts
Zerocool81 a répondu à un(e) sujet de Zerocool81 dans Analyses et éradication malwares
Bon j'ai été donc contraint de formater ce week end, mon disque dur étant partitionné, j'ai l'impression que certaines "bestioles" trainaient sur le disque D:/ car les symptomes reviennent sans que je n'ai fait quoi que ce soit. Le principal problème est que "afficher les fichiers et dossiers cachés ne marche" plus ce qui m'empêche de supprimer les quelques trojans que je commence à connaitre (en particulier celui qui me change l'ordre de priorité du clique droit quand je veux ouvrir un disque dur). J'espère pouvoir avec votre aide enfin éliminer ces saletés de mon ordinateur. -
Infection due à TvAnts
Zerocool81 a répondu à un(e) sujet de Zerocool81 dans Analyses et éradication malwares
Oui même chose, j'ai l'écran bleu. edit: ton lien ne marche pas pour moi. -
Infection due à TvAnts
Zerocool81 a répondu à un(e) sujet de Zerocool81 dans Analyses et éradication malwares
Salut! J'ai essayé de reconstruire avec un cd de windows XP familiale que j'ai enfin pu me procurer mais cela n'a pas marché, l'installation terminée, au premier démarrage de windows j'ai un ecran bleu d'un 1/10e de s impossible a lire on voit juste du bleu et ça redémarre. En ce qui concerne la 2ème méthode j'ai peur qu'elle puisse s'appliquer à mon cas : Sachant que mon ordinateur est un portable Sony Vaio, je suppose que je suis dans le cas auquel s'adresse l'avertissement non ? Merci. -
Infection due à TvAnts
Zerocool81 a répondu à un(e) sujet de Zerocool81 dans Analyses et éradication malwares
Sachant que le Xp qui était installé sur ce portable d'origine était un xp familial il faut que je trouve un cd de xp familial également ? Merci. -
Infection due à TvAnts
Zerocool81 a répondu à un(e) sujet de Zerocool81 dans Analyses et éradication malwares
Voila le contenu du cd "recovery" que je possède : http://www.hiboox.com/image.php?img=dcb4268c.jpg Sachant que mon dossier I386 fait 95mo environ -
Infection due à TvAnts
Zerocool81 a répondu à un(e) sujet de Zerocool81 dans Analyses et éradication malwares
Je suis allé voir ton lien, pour créer ce fameux cd, je peux le faire d'un autre PC ? Les 2 méthodes que tu me proposes me permettent de seulement reinstaller windows en gardant les fichiers de "mes documents" et "bureau" ? Merci de ton aide. -
Infection due à TvAnts
Zerocool81 a répondu à un(e) sujet de Zerocool81 dans Analyses et éradication malwares
La je suis un peu dans la "mouise" vu que la seule chose qu'on me propose c'est la reinstalation avec restauration de l'ordinateur à son état original. Ayant des données assez importantes dans "mes documents" je suis ouvert à toute autre suggestion -
Infection due à TvAnts
Zerocool81 a répondu à un(e) sujet de Zerocool81 dans Analyses et éradication malwares
J'ai pas le choix de "administrateur" c'est juste mon compte qui s'affiche. Sinon pour la réparation, c'est un portable avec windows déjà installé mais je vais essayer de metre le cd Vaio qu'ils m'ont fait créer quand je l'ai eu. Je te tiens au courant. Edit : même chose en mode sans echec, que ce soit admin ou mon compte j'ai passage de chargement des paramètres personnels à enregistrement des paramètres... -
Infection due à TvAnts
Zerocool81 a répondu à un(e) sujet de Zerocool81 dans Analyses et éradication malwares
Depuis que j'ai voulu redémarer je n'arrive plus à accéder à windows en effet au redémarage maintenant j'accède à l'invite d'ouverture de session(que j'avais désactivée au auparavant) et lorsque que je clique sur "l'icone" de mon nom d'utilisateur windows fait comme s'il fermait la session (changement de vos paramètres personnels, deconexion). Voila j'espère que tu trouveras une explication logique et une solution à cela -
Infection due à TvAnts
Zerocool81 a répondu à un(e) sujet de Zerocool81 dans Analyses et éradication malwares
Je n'ai plus les pages chinoises qui s'affichent intempestivement, par contre j'ai un message d'erreur au démarrage (je vais redémarrer pour te dire exactement) et j'ai encore des processus inconnus quand je fais CTRL+ALT+SUPPR mais tu m'as débarassé du plus ennuyeux -
Infection due à TvAnts
Zerocool81 a répondu à un(e) sujet de Zerocool81 dans Analyses et éradication malwares
Voila le log Avenger Logfile of The Avenger version 1, by Swandog46 Running from registry key: \Registry\Machine\System\CurrentControlSet\Services\yqxpbnlx ******************* Script file located at: \??\C:\WINDOWS\system32\vsoeomdl.txt Script file opened successfully. Script file read successfully Backups directory opened successfully at C:\Avenger ******************* Beginning to process script file: Registry key \Registry\Machine\System\CurrentControlSet\Services\ast not found! Unload of driver ast failed! Could not process line: ast Status: 0xc0000034 Registry key \Registry\Machine\System\CurrentControlSet\Services\https not found! Unload of driver https failed! Could not process line: https Status: 0xc0000034 Registry key \Registry\Machine\System\CurrentControlSet\Services\hidproc not found! Unload of driver hidproc failed! Could not process line: hidproc Status: 0xc0000034 Registry key \Registry\Machine\System\CurrentControlSet\Services\bdwxbni not found! Unload of driver bdwxbni failed! Could not process line: bdwxbni Status: 0xc0000034 Registry key \Registry\Machine\System\CurrentControlSet\Services\ffpbek not found! Unload of driver ffpbek failed! Could not process line: ffpbek Status: 0xc0000034 Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Client IP-IPX not found! Deletion of registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Client IP-IPX failed! Could not process line: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Client IP-IPX Status: 0xc0000034 Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\System Local Kernel Service not found! Deletion of registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\System Local Kernel Service failed! Could not process line: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\System Local Kernel Service Status: 0xc0000034 Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Network Logon not found! Deletion of registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Network Logon failed! Could not process line: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Network Logon Status: 0xc0000034 Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Windows User Mode Driver not found! Deletion of registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Windows User Mode Driver failed! Could not process line: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Windows User Mode Driver Status: 0xc0000034 Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SysReplaceOldServers not found! Deletion of registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SysReplaceOldServers failed! Could not process line: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SysReplaceOldServers Status: 0xc0000034 File C:\WINDOWS\4y9s.dll not found! Deletion of file C:\WINDOWS\4y9s.dll failed! Could not process line: C:\WINDOWS\4y9s.dll Status: 0xc0000034 File C:\WINDOWS\sclgntfys.dll not found! Deletion of file C:\WINDOWS\sclgntfys.dll failed! Could not process line: C:\WINDOWS\sclgntfys.dll Status: 0xc0000034 File C:\WINDOWS9xro366yo.dll not found! Deletion of file C:\WINDOWS9xro366yo.dll failed! Could not process line: C:\WINDOWS9xro366yo.dll Status: 0xc0000034 File C:\WINDOWS\system32\winsys16_070221.dll not found! Deletion of file C:\WINDOWS\system32\winsys16_070221.dll failed! Could not process line: C:\WINDOWS\system32\winsys16_070221.dll Status: 0xc0000034 File C:\WINDOWS\system32\cryptimg.dll not found! Deletion of file C:\WINDOWS\system32\cryptimg.dll failed! Could not process line: C:\WINDOWS\system32\cryptimg.dll Status: 0xc0000034 File C:\WINDOWS\system32\4e64ntos.dll not found! Deletion of file C:\WINDOWS\system32\4e64ntos.dll failed! Could not process line: C:\WINDOWS\system32\4e64ntos.dll Status: 0xc0000034 File C:\WINDOWS\system32\cnwin.dll not found! Deletion of file C:\WINDOWS\system32\cnwin.dll failed! Could not process line: C:\WINDOWS\system32\cnwin.dll Status: 0xc0000034 File C:\WINDOWS\system32\drivers\__delete_on_reboot__r_e_s_t_o_r_e_._d_l_l_ not found! Deletion of file C:\WINDOWS\system32\drivers\__delete_on_reboot__r_e_s_t_o_r_e_._d_l_l_ failed! Could not process line: C:\WINDOWS\system32\drivers\__delete_on_reboot__r_e_s_t_o_r_e_._d_l_l_ Status: 0xc0000034 File C:\WINDOWS\system32\drivers\ast.sys not found! Deletion of file C:\WINDOWS\system32\drivers\ast.sys failed! Could not process line: C:\WINDOWS\system32\drivers\ast.sys Status: 0xc0000034 File C:\WINDOWS\System32\drivers\restore.ini not found! Deletion of file C:\WINDOWS\System32\drivers\restore.ini failed! Could not process line: C:\WINDOWS\System32\drivers\restore.ini Status: 0xc0000034 File C:\WINDOWS\System32\drivers\https.sys not found! Deletion of file C:\WINDOWS\System32\drivers\https.sys failed! Could not process line: C:\WINDOWS\System32\drivers\https.sys Status: 0xc0000034 File C:\WINDOWS\system32\drivers\hidproc.sys not found! Deletion of file C:\WINDOWS\system32\drivers\hidproc.sys failed! Could not process line: C:\WINDOWS\system32\drivers\hidproc.sys Status: 0xc0000034 File C:\WINDOWS\bar.exe not found! Deletion of file C:\WINDOWS\bar.exe failed! Could not process line: C:\WINDOWS\bar.exe Status: 0xc0000034 File C:\WINDOWS\rising128.exe not found! Deletion of file C:\WINDOWS\rising128.exe failed! Could not process line: C:\WINDOWS\rising128.exe Status: 0xc0000034 File C:\WINDOWS\system32\2100qqgm.exe not found! Deletion of file C:\WINDOWS\system32\2100qqgm.exe failed! Could not process line: C:\WINDOWS\system32\2100qqgm.exe Status: 0xc0000034 File C:\WINDOWS\system32\cacheur.exe not found! Deletion of file C:\WINDOWS\system32\cacheur.exe failed! Could not process line: C:\WINDOWS\system32\cacheur.exe Status: 0xc0000034 File C:\WINDOWS\system32\12.exe deleted successfully. File C:\WINDOWS\system32\1010s.exe deleted successfully. File C:\WINDOWS\system32\UniBar.exe not found! Deletion of file C:\WINDOWS\system32\UniBar.exe failed! Could not process line: C:\WINDOWS\system32\UniBar.exe Status: 0xc0000034 File C:\WINDOWS\system32\bind_50099.exe~ not found! Deletion of file C:\WINDOWS\system32\bind_50099.exe~ failed! Could not process line: C:\WINDOWS\system32\bind_50099.exe~ Status: 0xc0000034 File C:\WINDOWS\system32\unsvchosts.exe not found! Deletion of file C:\WINDOWS\system32\unsvchosts.exe failed! Could not process line: C:\WINDOWS\system32\unsvchosts.exe Status: 0xc0000034 File C:\WINDOWS\system32\aswBoot.exe deleted successfully. File C:\WINDOWS\system32\mctet.dll not found! Deletion of file C:\WINDOWS\system32\mctet.dll failed! Could not process line: C:\WINDOWS\system32\mctet.dll Status: 0xc0000034 File C:\WINDOWS\system32\umtcap.dll not found! Deletion of file C:\WINDOWS\system32\umtcap.dll failed! Could not process line: C:\WINDOWS\system32\umtcap.dll Status: 0xc0000034 File C:\WINDOWS\system32\cnwin.dll not found! Deletion of file C:\WINDOWS\system32\cnwin.dll failed! Could not process line: C:\WINDOWS\system32\cnwin.dll Status: 0xc0000034 File C:\WINDOWS\system32\4f7ecfsb.dll not found! Deletion of file C:\WINDOWS\system32\4f7ecfsb.dll failed! Could not process line: C:\WINDOWS\system32\4f7ecfsb.dll Status: 0xc0000034 File C:\WINDOWS\system32\4e64ntos.dll not found! Deletion of file C:\WINDOWS\system32\4e64ntos.dll failed! Could not process line: C:\WINDOWS\system32\4e64ntos.dll Status: 0xc0000034 File C:\WINDOWS\system32\ffudf.exe deleted successfully. File C:\WINDOWS\system32\dufs1.exe not found! Deletion of file C:\WINDOWS\system32\dufs1.exe failed! Could not process line: C:\WINDOWS\system32\dufs1.exe Status: 0xc0000034 File C:\WINDOWS\system32\dufs2.exe not found! Deletion of file C:\WINDOWS\system32\dufs2.exe failed! Could not process line: C:\WINDOWS\system32\dufs2.exe Status: 0xc0000034 File C:\WINDOWS\system32\jsefusf.exe deleted successfully. File C:\WINDOWS\system32\drivers\bdwxbni.sys not found! Deletion of file C:\WINDOWS\system32\drivers\bdwxbni.sys failed! Could not process line: C:\WINDOWS\system32\drivers\bdwxbni.sys Status: 0xc0000034 File C:\WINDOWS\system32\drivers\ffpbek.sys not found! Deletion of file C:\WINDOWS\system32\drivers\ffpbek.sys failed! Could not process line: C:\WINDOWS\system32\drivers\ffpbek.sys Status: 0xc0000034 File C:\WINDOWS\system32\advport.dll not found! Deletion of file C:\WINDOWS\system32\advport.dll failed! Could not process line: C:\WINDOWS\system32\advport.dll Status: 0xc0000034 File C:\WINDOWS\system32\wbem\ocmor.dll not found! Deletion of file C:\WINDOWS\system32\wbem\ocmor.dll failed! Could not process line: C:\WINDOWS\system32\wbem\ocmor.dll Status: 0xc0000034 File C:\WINDOWS\System32\tcpipmon.exe not found! Deletion of file C:\WINDOWS\System32\tcpipmon.exe failed! Could not process line: C:\WINDOWS\System32\tcpipmon.exe Status: 0xc0000034 Could not open file C:\Documents and Settings\All Users\Application Data\Microsoft\Office\USERDATA\n8JRjXqheJ_2002.dll for deletion Deletion of file C:\Documents and Settings\All Users\Application Data\Microsoft\Office\USERDATA\n8JRjXqheJ_2002.dll failed! Could not process line: C:\Documents and Settings\All Users\Application Data\Microsoft\Office\USERDATA\n8JRjXqheJ_2002.dll Status: 0xc000003a Could not open file C:\Documents and Settings\Zerocool\Application Data\Fichiers communs\CPUSH\cpush0.dll for deletion Deletion of file C:\Documents and Settings\Zerocool\Application Data\Fichiers communs\CPUSH\cpush0.dll failed! Could not process line: C:\Documents and Settings\Zerocool\Application Data\Fichiers communs\CPUSH\cpush0.dll Status: 0xc000003a File C:\WINDOWS\System32\drivers\ttp.exe not found! Deletion of file C:\WINDOWS\System32\drivers\ttp.exe failed! Could not process line: C:\WINDOWS\System32\drivers\ttp.exe Status: 0xc0000034 File C:\WINDOWS\temp\162.exe not found! Deletion of file C:\WINDOWS\temp\162.exe failed! Could not process line: C:\WINDOWS\temp\162.exe Status: 0xc0000034 Could not open file C:\Documents and Settings\Zerocool\Application Data\Fichiers communs\System\Updaterun.exe for deletion Deletion of file C:\Documents and Settings\Zerocool\Application Data\Fichiers communs\System\Updaterun.exe failed! Could not process line: C:\Documents and Settings\Zerocool\Application Data\Fichiers communs\System\Updaterun.exe Status: 0xc000003a Could not open file C:\Documents and Settings\All Users\Application Data\Microsoft\Office\SYSTEM\BkD1C4M4i3.exe for deletion Deletion of file C:\Documents and Settings\All Users\Application Data\Microsoft\Office\SYSTEM\BkD1C4M4i3.exe failed! Could not process line: C:\Documents and Settings\All Users\Application Data\Microsoft\Office\SYSTEM\BkD1C4M4i3.exe Status: 0xc000003a File C:\WINDOWS\System32\AlxRes070221.exe not found! Deletion of file C:\WINDOWS\System32\AlxRes070221.exe failed! Could not process line: C:\WINDOWS\System32\AlxRes070221.exe Status: 0xc0000034 File C:\WINDOWS\System32\scrsys070221.scr not found! Deletion of file C:\WINDOWS\System32\scrsys070221.scr failed! Could not process line: C:\WINDOWS\System32\scrsys070221.scr Status: 0xc0000034 File C:\WINDOWS\System32\scrsys16_070221.scr not found! Deletion of file C:\WINDOWS\System32\scrsys16_070221.scr failed! Could not process line: C:\WINDOWS\System32\scrsys16_070221.scr Status: 0xc0000034 File C:\WINDOWS\System32\winsys16_070221.dll not found! Deletion of file C:\WINDOWS\System32\winsys16_070221.dll failed! Could not process line: C:\WINDOWS\System32\winsys16_070221.dll Status: 0xc0000034 File C:\WINDOWS\System32\winsys32_070221.dll not found! Deletion of file C:\WINDOWS\System32\winsys32_070221.dll failed! Could not process line: C:\WINDOWS\System32\winsys32_070221.dll Status: 0xc0000034 File C:\WINDOWS\System32\winsys.ini not found! Deletion of file C:\WINDOWS\System32\winsys.ini failed! Could not process line: C:\WINDOWS\System32\winsys.ini Status: 0xc0000034 File C:\myplay.pif not found! Deletion of file C:\myplay.pif failed! Could not process line: C:\myplay.pif Status: 0xc0000034 File C:\WINDOWS\SYSTEM32\RUNDLLFROMWIN2000.EXE not found! Deletion of file C:\WINDOWS\SYSTEM32\RUNDLLFROMWIN2000.EXE failed! Could not process line: C:\WINDOWS\SYSTEM32\RUNDLLFROMWIN2000.EXE Status: 0xc0000034 File C:\WINDOWS\System32\regscan.exe not found! Deletion of file C:\WINDOWS\System32\regscan.exe failed! Could not process line: C:\WINDOWS\System32\regscan.exe Status: 0xc0000034 File C:\WINDOWS\4y9s.dll not found! Deletion of file C:\WINDOWS\4y9s.dll failed! Could not process line: C:\WINDOWS\4y9s.dll Status: 0xc0000034 File C:\unwise.exe deleted successfully. File C:\WINDOWS\System32\drivers\DJPXEKRXGMTBIP.DAT deleted successfully. File C:\WINDOWS\sysinit.obi deleted successfully. File C:\WINDOWS\bd9.exe deleted successfully. File C:\WINDOWS\bd7.exe deleted successfully. File C:\WINDOWS\bd5.exe deleted successfully. File C:\WINDOWS\bd4.exe deleted successfully. File C:\WINDOWS\bd3.exe deleted successfully. File C:\WINDOWS30.exe not found! Deletion of file C:\WINDOWS30.exe failed! Could not process line: C:\WINDOWS30.exe Status: 0xc0000034 File C:\WINDOWS\100.exe deleted successfully. File C:\WINDOWS\bd2.exe deleted successfully. File C:\WINDOWS\bd3.exe not found! Deletion of file C:\WINDOWS\bd3.exe failed! Could not process line: C:\WINDOWS\bd3.exe Status: 0xc0000034 File C:\WINDOWS\bd4.exe not found! Deletion of file C:\WINDOWS\bd4.exe failed! Could not process line: C:\WINDOWS\bd4.exe Status: 0xc0000034 File C:\WINDOWS\bd5.exe not found! Deletion of file C:\WINDOWS\bd5.exe failed! Could not process line: C:\WINDOWS\bd5.exe Status: 0xc0000034 File C:\WINDOWS\bd7.exe not found! Deletion of file C:\WINDOWS\bd7.exe failed! Could not process line: C:\WINDOWS\bd7.exe Status: 0xc0000034 File C:\WINDOWS\bd9.exe not found! Deletion of file C:\WINDOWS\bd9.exe failed! Could not process line: C:\WINDOWS\bd9.exe Status: 0xc0000034 File C:\WINDOWS\system32\1249.exe deleted successfully. File C:\WINDOWS\system32\57sex109.exe deleted successfully. File C:\WINDOWS\system32\ad2273.exe deleted successfully. File C:\WINDOWS\system32\bind_50259.exe deleted successfully. File C:\WINDOWS\system32\DIOVDJRYFMSAGN.EXE deleted successfully. File C:\WINDOWS\system32\dodolook207.exe deleted successfully. File C:\WINDOWS\system32\msmgrupdate.exe deleted successfully. File C:\WINDOWS\system32\poptang.exe deleted successfully. File C:\WINDOWS\system32\sofa020.exe deleted successfully. File C:\WINDOWS\system32\zy0002.exe deleted successfully. File C:\WINDOWS\system32\_msinst.exe deleted successfully. File C:\WINDOWS\system32\1F8g8gk0g.dll deleted successfully. File C:\WINDOWS\system32\GMTZG.DLL deleted successfully. File C:\WINDOWS\system32\mshtmll.dll deleted successfully. File C:\WINDOWS\system32\PVBJQXEL.DLL deleted successfully. File C:\WINDOWS\system32\safobj32.dll deleted successfully. File C:\WINDOWS\system32\VBHNTAHNUBI.DLL deleted successfully. File C:\WINDOWS\system32\YEMUCJPWDKPW.DLL deleted successfully. Error: C:\WINDOWS\system32\AdCache is a folder, not a file! Deletion of file C:\WINDOWS\system32\AdCache failed! Could not process line: C:\WINDOWS\system32\AdCache Status: 0xc00000ba File C:\WINDOWS\ndpQO.exe deleted successfully. Folder C:\Documents and Settings\Zerocool\Application Data\superutilbar not found! Deletion of folder C:\Documents and Settings\Zerocool\Application Data\superutilbar failed! Could not process line: C:\Documents and Settings\Zerocool\Application Data\superutilbar Status: 0xc0000034 Could not open folder C:\Documents and Settings\Zerocool\Application Data\fichiers communs\. for deletion Deletion of folder C:\Documents and Settings\Zerocool\Application Data\fichiers communs\. failed! Could not process line: C:\Documents and Settings\Zerocool\Application Data\fichiers communs\. Status: 0xc000003a Could not open folder C:\Documents and Settings\Zerocool\Application Data\fichiers communs\.. for deletion Deletion of folder C:\Documents and Settings\Zerocool\Application Data\fichiers communs\.. failed! Could not process line: C:\Documents and Settings\Zerocool\Application Data\fichiers communs\.. Status: 0xc000003a Could not open folder C:\Documents and Settings\Zerocool\Application Data\Fichiers communs\CPUSH for deletion Deletion of folder C:\Documents and Settings\Zerocool\Application Data\Fichiers communs\CPUSH failed! Could not process line: C:\Documents and Settings\Zerocool\Application Data\Fichiers communs\CPUSH Status: 0xc000003a Could not open folder C:\Documents and Settings\Zerocool\Application Data\fichiers communs\{589E5AE1-0640-1036-0820-040406110021} for deletion Deletion of folder C:\Documents and Settings\Zerocool\Application Data\fichiers communs\{589E5AE1-0640-1036-0820-040406110021} failed! Could not process line: C:\Documents and Settings\Zerocool\Application Data\fichiers communs\{589E5AE1-0640-1036-0820-040406110021} Status: 0xc000003a Could not open folder C:\Documents and Settings\Zerocool\Application Data\. for deletion Deletion of folder C:\Documents and Settings\Zerocool\Application Data\. failed! Could not process line: C:\Documents and Settings\Zerocool\Application Data\. Status: 0xc0000033 Could not open folder C:\Documents and Settings\Zerocool\Application Data\.. for deletion Deletion of folder C:\Documents and Settings\Zerocool\Application Data\.. failed! Could not process line: C:\Documents and Settings\Zerocool\Application Data\.. Status: 0xc0000033 Folder C:\Documents and Settings\Zerocool\Application Data\²Æ¸»Í¨ not found! Deletion of folder C:\Documents and Settings\Zerocool\Application Data\²Æ¸»Í¨ failed! Could not process line: C:\Documents and Settings\Zerocool\Application Data\²Æ¸»Í¨ Status: 0xc0000034 Folder C:\Documents and Settings\Zerocool\Application Data\SoftToolbar not found! Deletion of folder C:\Documents and Settings\Zerocool\Application Data\SoftToolbar failed! Could not process line: C:\Documents and Settings\Zerocool\Application Data\SoftToolbar Status: 0xc0000034 Folder C:\Documents and Settings\Zerocool\Application Data\TVAnts not found! Deletion of folder C:\Documents and Settings\Zerocool\Application Data\TVAnts failed! Could not process line: C:\Documents and Settings\Zerocool\Application Data\TVAnts Status: 0xc0000034 Could not delete registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main|http://hao123.union123.com/index.htm Deletion of registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main|http://hao123.union123.com/index.htm failed! Status: 0xc0000034 Could not delete registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\system.ini|UserInit Deletion of registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\system.ini|UserInit failed! Status: 0xc0000034 Could not delete registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar|03465FF5-00AE-411a-9C34-960ED566EC03 Deletion of registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar|03465FF5-00AE-411a-9C34-960ED566EC03 failed! Status: 0xc0000034 Could not delete registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar|DFCB34B6-902D-426E-AE2B-1B294AE19F4F Deletion of registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar|DFCB34B6-902D-426E-AE2B-1B294AE19F4F failed! Status: 0xc0000034 Could not delete registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|D:\Windows\System32\drivers\ttp.exe Deletion of registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|D:\Windows\System32\drivers\ttp.exe failed! Status: 0xc0000034 Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|sdafdsafds deleted successfully. Could not delete registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|tcpipmon Deletion of registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|tcpipmon failed! Status: 0xc0000034 Could not delete registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|System Deletion of registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|System failed! Status: 0xc0000034 Could not delete registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|qfv4c3g7xm Deletion of registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|qfv4c3g7xm failed! Status: 0xc0000034 Could not delete registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|9cu Deletion of registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|9cu failed! Status: 0xc0000034 Could not delete registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|Regscan Deletion of registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|Regscan failed! Status: 0xc0000034 Could not delete registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar|B7D3E479-CC68-42B5-A338-C6B1F168274C Deletion of registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar|B7D3E479-CC68-42B5-A338-C6B1F168274C failed! Status: 0xc0000034 Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|init deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11F09AFD-75AD-4E51-AB43-E09E9351CE16} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6CFD436C-7AAD-4e50-992F-C0C87A94CAD2} not found! Deletion of registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6CFD436C-7AAD-4e50-992F-C0C87A94CAD2} failed! Status: 0xc0000034 Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C86488AF-13D5-4FEF-9DDF-9FB88698CFC1} not found! Deletion of registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C86488AF-13D5-4FEF-9DDF-9FB88698CFC1} failed! Status: 0xc0000034 Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{dad6277f-c7eb-4f7e-8b0d-4e03f37a8dbf} not found! Deletion of registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{dad6277f-c7eb-4f7e-8b0d-4e03f37a8dbf} failed! Status: 0xc0000034 Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DE7C3CF0-4B15-11D1-ABED-709549C10000} not found! Deletion of registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DE7C3CF0-4B15-11D1-ABED-709549C10000} failed! Status: 0xc0000034 Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DFCB34B6-902D-426E-AE2B-1B294AE19F4F} not found! Deletion of registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DFCB34B6-902D-426E-AE2B-1B294AE19F4F} failed! Status: 0xc0000034 Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptimg not found! Deletion of registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptimg failed! Status: 0xc0000034 Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\rpcc not found! Deletion of registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\rpcc failed! Status: 0xc0000034 Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfys not found! Deletion of registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfys failed! Status: 0xc0000034 Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BBBE1C1A-89F7-4AF6-ABD1-2B2EF2D7A73B} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FA9295D9-42ED-4CE1-B2F5-AF6401111196} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{B7D3E479-CC68-42B5-A338-C6B1F168274C} deleted successfully. Program C:\restore.reg successfully set up to run once on reboot. Completed script processing. ******************* Finished! Terminate. Log Hijackthis Logfile of HijackThis v1.99.1 Scan saved at 19:19:08, on 02/03/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16414) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Intel\Wireless\Bin\EvtEng.exe C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\166.exe C:\Program Files\Sony\VAIO Event Service\VESMgr.exe C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\Program Files\Apoint\Apoint.exe C:\Program Files\Sony\VAIO Power Management\SPMgr.exe C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\Program Files\DAEMON Tools\daemon.exe C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe C:\Program Files\MSN Messenger\MsnMsgr.Exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe C:\Program Files\Apoint\Apntex.exe C:\WINDOWS\BricoPacks\Crystal Clear\RocketDock\RocketDock.exe C:\WINDOWS\system32\notepad.exe C:\WINDOWS\system32\wuauclt.exe C:\PROGRA~1\MOZILL~1\FIREFOX.EXE C:\Documents and Settings\Zerocool\Bureau\A ranger\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://wwww.cq223.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://wwww.cq223.com R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens F2 - REG:system.ini: UserInit=%WINDIR%\system32\userinit.exe, O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FlashGet\jccatch.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll O3 - Toolbar: sofa - {B7D3E479-CC68-42B5-A338-C6B1F168274C} - C:\Program Files\SoftToolbar\soft.dll O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [sonyPowerCfg] C:\Program Files\Sony\VAIO Power Management\SPMgr.exe O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033 O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe O4 - Startup: RocketDock.lnk = C:\WINDOWS\BricoPacks\Crystal Clear\RocketDock\RocketDock.exe O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000 O8 - Extra context menu item: Télécharger avec FlashGet - C:\Program Files\FlashGet\jc_link.htm O8 - Extra context menu item: Télécharger tout avec FlashGet - C:\Program Files\FlashGet\jc_all.htm O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra button: ²Æ¸»Í¨ - {C1F0024B-8278-4999-B7E6-2718426D9FE6} - C:\Program Files\²Æ¸»Í¨\caif.dll (HKCU) O11 - Options group: [iNTERNATIONAL] International* O14 - IERESET.INF: START_PAGE_URL=http://www.club-vaio.com/fr/ O15 - Trusted Zone: *.sony-europe.com O15 - Trusted Zone: *.sonystyle-europe.com O15 - Trusted Zone: *.vaio-link.com O16 - DPF: {2250C29C-C5E9-4F55-BE4E-01E45A40FCF1} (CMediaMix Object) - http://musicmix.messenger.msn.com/Medialogic.CAB O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{FC80CAE2-5754-4AE4-BF7D-91677E0C7955}: NameServer = 212.27.39.134 O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll O20 - Winlogon Notify: VESWinlogon - C:\WINDOWS\SYSTEM32\VESWinlogon.dll O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing) O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing) O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: jsefusf - Unknown owner - C:\WINDOWS\system32\jsefusf.exe (file missing) O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe O23 - Service: SysReplaceOldServers (ReplaceOldServers) - Unknown owner - C:\Windows\system32\DIOVDJRYFMSAGN.EXE (file missing) O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe O23 - Service: ·þÎñÃû (svcname) - Unknown owner - C:\WINDOWS\system32\166.exe O23 - Service: VAIO Entertainment Aggregation and Control Service - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment\VzRs\VzRs.exe O23 - Service: VAIO Entertainment Task Scheduler - Sony Corporation - C:\Program Files\Sony\VAIO Entertainment\VzTaskScheduler.exe O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Unknown owner - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-IntegratedServer-HTTP /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="Applications\IntegratedServer\HTTP (file missing) O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Unknown owner - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe" /Service=VAIOMediaPlatform-Mobile-Gateway /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Addons\Packages\Mobile\Gateway" /DisplayName="VAIO Media Gateway Server (file missing) O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe Voila encore merci -
Infection due à TvAnts
Zerocool81 a répondu à un(e) sujet de Zerocool81 dans Analyses et éradication malwares
Pas de Problème. Encore merci pour ton temps et tes services. -
Infection due à TvAnts
Zerocool81 a répondu à un(e) sujet de Zerocool81 dans Analyses et éradication malwares
D'accord. Bonne Nuit a toi aussi. -
Infection due à TvAnts
Zerocool81 a répondu à un(e) sujet de Zerocool81 dans Analyses et éradication malwares
Clean pour finir Rapport clean par Malekal_morte - http://www.malekal.com Option 1, executee le 02/03/2007 a 0:35:44,76 *** Recherche de fichiers sur C: C:\unwise.exe FOUND *** Recherche des fichiers dans C:\WINDOWS\ *** Recherche des fichiers dans C:\WINDOWS\system32 C:\WINDOWS\system32\1010s.exe FOUND C:\WINDOWS\system32\AdCache FOUND C:\WINDOWS\system32\AdCache FOUND C:\WINDOWS\system32\jsefusf.exe FOUND C:\WINDOWS\system32\AdCache\ FOUND C:\WINDOWS\system32\1010s.exe FOUND C:\WINDOWS\system32\57sex109.exe FOUND C:\WINDOWS\system32\ffudf.exe FOUND C:\WINDOWS\system32\jsefusf.exe FOUND C:\WINDOWS\system32\mshtmll.dll FOUND C:\WINDOWS\System32\jsefusf.dll FOUND C:\WINDOWS\system32\jsefusf.dll FOUND C:\WINDOWS\system32\mshtmll.dll FOUND "C:\Program Files\Fichiers communs\CPUSH\" FOUND *** Fin du rapport ! Voila encore merci