

maykiki
Membres-
Compteur de contenus
139 -
Inscription
-
Dernière visite
-
Jours gagnés
1
Type de contenu
Profils
Forums
Blogs
Tout ce qui a été posté par maykiki
-
[Résolu] Pub incessante, infecte???
maykiki a répondu à un(e) sujet de maykiki dans Analyses et éradication malwares
Salut, Desole mais pas eu le temps de m en occuper avant! Impossible d executer Kaspersky car non compatible avec Vista. Que faire alors? Merci a toi @+ -
[Résolu] Pub incessante, infecte???
maykiki a répondu à un(e) sujet de maykiki dans Analyses et éradication malwares
Hello, Voila donc le rapport demande! Pourrais tu m expliquer brievement ce que tu fais a chaque fois a l avenir, ca m interesse d essayer de comprendre pour pouvoir me debrouiller seul les prochaines fois peut etre !!! Merci Malwarebytes' Anti-Malware 1.31 Version de la base de données: 1475 Windows 6.0.6001 Service Pack 1 08/12/2008 18:58:11 mbam-log-2008-12-08 (18-58-11).txt Type de recherche: Examen complet (C:\|) Eléments examinés: 132229 Temps écoulé: 1 hour(s), 2 minute(s), 12 second(s) Processus mémoire infecté(s): 0 Module(s) mémoire infecté(s): 0 Clé(s) du Registre infectée(s): 4 Valeur(s) du Registre infectée(s): 0 Elément(s) de données du Registre infecté(s): 0 Dossier(s) infecté(s): 2 Fichier(s) infecté(s): 3 Processus mémoire infecté(s): (Aucun élément nuisible détecté) Module(s) mémoire infecté(s): (Aucun élément nuisible détecté) Clé(s) du Registre infectée(s): HKEY_CLASSES_ROOT\CLSID\{147a976f-eee1-4377-8ea7-4716e4cdd239} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{8e3fbde2-7dbd-4040-85d9-29bbc559c129} (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\AntispywareD (Rogue.SpywareDestructor) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\MS Juan (Trojan.Vundo) -> Quarantined and deleted successfully. Valeur(s) du Registre infectée(s): (Aucun élément nuisible détecté) Elément(s) de données du Registre infecté(s): (Aucun élément nuisible détecté) Dossier(s) infecté(s): C:\Program Files\Spyware-Secure (Rogue.Spyware-Secure) -> Quarantined and deleted successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spyware-Secure (Rogue.Spyware-Secure) -> Quarantined and deleted successfully. Fichier(s) infecté(s): C:\Program Files\Spyware-Secure\uninst.exe (Rogue.Spyware-Secure) -> Quarantined and deleted successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spyware-Secure\Spyware-Secure trial.lnk (Rogue.Spyware-Secure) -> Quarantined and deleted successfully. C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spyware-Secure\Website.lnk (Rogue.Spyware-Secure) -> Quarantined and deleted successfully. -
[Résolu] Pub incessante, infecte???
maykiki a répondu à un(e) sujet de maykiki dans Analyses et éradication malwares
Re! Impossible hier d ouvrir en mode sans echec!!! Je pense que le probleme va persister non? et tu n aimes pas Msconfig donc...??? -
[Résolu] Pub incessante, infecte???
maykiki a répondu à un(e) sujet de maykiki dans Analyses et éradication malwares
========== PROCESSES ========== Process explorer.exe killed successfully. ========== FILES ========== File/Folder C:\Program Files\Search Settings\kb126\SearchSettings.dll not found. File/Folder C:\Program Files\Search Settings\SearchSettings.exe not found. File/Folder C:\Program Files\Search Settings\kb126 not found. File/Folder C:\Program Files\Search Settings not found. File/Folder C:\Program Files\Dealio\DealioAU.exe not found. File/Folder C:\Program Files\Dealio not found. File move failed. C:\cleannavi.txt scheduled to be moved on reboot. File move failed. C:\TB.txt scheduled to be moved on reboot. C:\ToolBar SD moved successfully. File move failed. C:\fixnavi.txt scheduled to be moved on reboot. Folder move failed. C:\Program Files\Spyware-Secure scheduled to be moved on reboot. c:\users\dean\appdata\local\nnudcjjq.bat moved successfully. ========== REGISTRY ========== Unable to delete registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6A87B991-A31F-4130-AE72-6D0C294BF082}\\ . Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}\\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F}\\ not found. Unable to delete registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cmds\\ . Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\SearchSettings not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\au not found. ========== COMMANDS ========== File delete failed. C:\Users\DEAN\AppData\Local\Temp\~DF1E55.tmp scheduled to be deleted on reboot. File delete failed. C:\Users\DEAN\AppData\Local\Temp\~DF1E83.tmp scheduled to be deleted on reboot. File delete failed. C:\Users\DEAN\AppData\Local\Temp\~DFA098.tmp scheduled to be deleted on reboot. File delete failed. C:\Users\DEAN\AppData\Local\Temp\~DFA0C9.tmp scheduled to be deleted on reboot. File delete failed. C:\Users\DEAN\AppData\Local\Temp\~DFF9AD.tmp scheduled to be deleted on reboot. User's Temp folder emptied. User's Temporary Internet Files folder emptied. User's Internet Explorer cache folder emptied. Local Service Temp folder emptied. Local Service Temporary Internet Files folder emptied. Windows Temp folder emptied. FireFox cache emptied. Temp folders emptied. OTMoveIt3 by OldTimer - Version 1.0.7.2 log created on 12072008_175813 -
[Résolu] Pub incessante, infecte???
maykiki a répondu à un(e) sujet de maykiki dans Analyses et éradication malwares
Logfile of random's system information tool 1.04 (written by random/random) Run by DEAN at 2008-12-07 14:19:03 Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 1 System drive C: has 123 GB (53%) free of 230 GB Total RAM: 2047 MB (66% free) Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 14:19:37, on 07/12/2008 Platform: Windows Vista SP1 (WinNT 6.00.1905) MSIE: Internet Explorer v7.00 (7.00.6001.18000) Boot mode: Normal Running processes: C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\system32\taskeng.exe C:\Program Files\USB Disk Win98 Driver\Res.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe C:\Program Files\Search Settings\SearchSettings.exe C:\Windows\RtHDVCpl.exe C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe C:\Windows\System32\rundll32.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe C:\Program Files\Goto Software\Vade Retro\Vaderetro_mgr.exe C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe C:\Windows\ehome\ehtray.exe C:\Windows\System32\rundll32.exe C:\Windows\ehome\ehmsas.exe C:\Windows\system32\wbem\unsecapp.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe C:\Program Files\Internet Explorer\IEUser.exe C:\Windows\system32\SearchFilterHost.exe C:\Users\DEAN\Desktop\RSIT.exe C:\Program Files\trend micro\DEAN.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://format.packardbell.com/cgi-bin/redi...amp;key=IESTART R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.crawler.com/search/dispatcher.a...&tbid=60327 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://msn.fr/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://recherche.neuf.fr/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://recherche.neuf.fr/ie/default.html R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = R3 - URLSearchHook: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb126\SearchSettings.dll O1 - Hosts: ::1 localhost O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: DealioBHO Class - {6A87B991-A31F-4130-AE72-6D0C294BF082} - C:\Program Files\Dealio\kb126\Dealio.dll (file missing) O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Google\Google_BAE\BAE.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O2 - BHO: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb126\SearchSettings.dll O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O3 - Toolbar: Dealio - {E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F} - C:\Program Files\Dealio\kb126\Dealio.dll (file missing) O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide O4 - HKLM\..\Run: [uSB Storage Toolbox] C:\Program Files\USB Disk Win98 Driver\Res.EXE O4 - HKLM\..\Run: [toolbar_eula_launcher] C:\Program Files\Packard Bell\GOOGLE_EULA\EULALauncher.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" O4 - HKLM\..\Run: [sMSTray] C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe O4 - HKLM\..\Run: [skytel] Skytel.exe O4 - HKLM\..\Run: [searchSettings] C:\Program Files\Search Settings\SearchSettings.exe O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [au] C:\Program Files\Dealio\DealioAU.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min O4 - HKLM\..\Run: [VadeRetro Outlook] C:\Program Files\Goto Software\Vade Retro\VrMoRegister.exe -s O4 - HKLM\..\Run: [VadeRetro Desktop] C:\Program Files\Goto Software\Vade Retro\Vaderetro_Mgr.exe O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe O4 - HKCU\..\Run: [smpcSys] C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [iSUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL') O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL') O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU') O4 - HKUS\S-1-5-18\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'Default user') O4 - Startup: OneNote 2007 - Capture d'écran et lancement.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL O9 - Extra button: Dealio - {E908B145-C847-4e85-B315-07E2E70DECF8} - C:\Program Files\Dealio\kb126\Dealio.dll (file missing) O9 - Extra 'Tools' menuitem: Dealio - {E908B145-C847-4e85-B315-07E2E70DECF8} - C:\Program Files\Dealio\kb126\Dealio.dll (file missing) O13 - Gopher Prefix: O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/...lscbase6662.cab O20 - AppInit_DLLs: C:\PROGRA~1\Google\GO333C~1\GOEC62~1.DLL O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing) O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Windows\System32\ZoneLabs\vsmon.exe -- End of file - 11221 bytes ======Scheduled tasks folder====== C:\Windows\tasks\Extension de garantie.job C:\Windows\tasks\Maintenance en 1 clic.job C:\Windows\tasks\Vérifier les mises à jour de Windows Live Toolbar.job ======Registry dump====== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}] Yahoo! Toolbar Helper - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll [2006-11-29 436288] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}] Aide pour le lien d'Adobe PDF Reader - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6A87B991-A31F-4130-AE72-6D0C294BF082}] DealioBHO Class - C:\Program Files\Dealio\kb126\Dealio.dll [] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}] Java Plug-In SSV Helper - C:\Program Files\Java\jre6\bin\ssv.dll [2008-12-06 320920] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}] Programme d'aide de l'Assistant de connexion Windows Live - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2007-09-20 328752] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}] Google Toolbar Helper - c:\program files\google\googletoolbar2.dll [2008-03-06 2436160] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}] Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll [2008-10-10 652784] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}] Windows Live Toolbar Helper - C:\Program Files\Windows Live Toolbar\msntb.dll [2007-10-19 546320] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CA6319C0-31B7-401E-A518-A07C3DB8F777}] CBrowserHelperObject Object - C:\Program Files\Google\Google_BAE\BAE.dll [2006-11-09 98304] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}] Java Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2008-12-06 34816] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}] SearchSettings Class - C:\Program Files\Search Settings\kb126\SearchSettings.dll [2008-02-06 1160544] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - Windows Live Toolbar - C:\Program Files\Windows Live Toolbar\msntb.dll [2007-10-19 546320] {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Yahoo! Toolbar avec bloqueur de fenêtres pop-up - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll [2006-11-29 436288] {E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F} - Dealio - C:\Program Files\Dealio\kb126\Dealio.dll [] {2318C2B1-4965-11d4-9B18-009027A5CD4F} - &Google - c:\program files\google\googletoolbar2.dll [2008-03-06 2436160] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] ""= [] "Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-19 1008184] "USB Storage Toolbox"=C:\Program Files\USB Disk Win98 Driver\Res.EXE [2005-09-14 65536] "toolbar_eula_launcher"=C:\Program Files\Packard Bell\GOOGLE_EULA\EULALauncher.exe [2007-02-20 28672] "SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2008-12-06 136600] "SMSTray"=C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe [2007-09-20 132624] "Skytel"=C:\Windows\Skytel.exe [2007-05-07 1826816] "SearchSettings"=C:\Program Files\Search Settings\SearchSettings.exe [2008-02-06 1036640] "RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2007-05-10 4468736] "RoxWatchTray"=C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe [2007-01-11 232184] "NvSvc"=C:\Windows\system32\nvsvc.dll [2007-07-06 86016] "NvMediaCenter"=C:\Windows\system32\NvMcTray.dll [2007-07-06 81920] "NvCplDaemon"=C:\Windows\system32\NvCpl.dll [2007-07-06 8466432] "iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2008-03-30 267048] "au"=C:\Program Files\Dealio\DealioAU.exe [] "QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2008-05-27 413696] "avgnt"=C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe [2008-06-12 266497] "VadeRetro Outlook"=C:\Program Files\Goto Software\Vade Retro\VrMoRegister.exe [2008-02-20 87552] "VadeRetro Desktop"=C:\Program Files\Goto Software\Vade Retro\Vaderetro_Mgr.exe [2008-04-10 1054208] "Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-10-15 39792] "ZoneAlarm Client"=C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe [2008-03-03 959976] "Google Desktop Search"=C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2007-12-04 1836544] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2008-01-19 202240] "SmpcSys"=C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe [2007-07-19 1120568] "MsnMsgr"=C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe [2007-10-18 5724184] "ISUSPM"=C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe [2006-09-11 218032] "ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-19 125952] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cmds] C:\Users\DEAN\AppData\Local\Temp\geeeb.dll [] C:\Users\DEAN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup OneNote 2007 - Capture d'écran et lancement.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLS"="C:\PROGRA~1\Google\GO333C~1\GOEC62~1.DLL" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] "{88485281-8b4b-4f8d-9ede-82e29a064277}"=C:\PROGRA~1\MarkAny\CONTEN~1\MACSMA~1.DLL [2004-11-23 192512] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\aawservice] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System] "dontdisplaylastusername"=0 "legalnoticecaption"= "legalnoticetext"= "shutdownwithoutlogon"=1 "undockwithoutlogon"=1 "FilterAdministratorToken"=1 "EnableUIADesktopToggle"=0 [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] ======List of files/folders created in the last 1 months====== 2008-12-07 14:19:12 ----D---- C:\Program Files\trend micro 2008-12-07 14:19:03 ----D---- C:\rsit 2008-12-07 12:57:49 ----D---- C:\_OTMoveIt 2008-12-06 11:15:29 ----A---- C:\cleannavi.txt 2008-12-06 09:49:07 ----A---- C:\Windows\system32\javaws.exe 2008-12-06 09:49:07 ----A---- C:\Windows\system32\javaw.exe 2008-12-06 09:49:07 ----A---- C:\Windows\system32\java.exe 2008-12-06 09:49:07 ----A---- C:\Windows\system32\deploytk.dll 2008-12-05 13:57:55 ----A---- C:\Windows\system32\vsutil_loc040c.dll 2008-12-05 13:57:49 ----A---- C:\Windows\system32\vsregexp.dll 2008-12-05 13:57:47 ----A---- C:\Windows\system32\zlcommdb.dll 2008-12-05 13:57:47 ----A---- C:\Windows\system32\zlcomm.dll 2008-12-05 13:57:41 ----A---- C:\Windows\system32\vswmi.dll 2008-12-05 13:57:39 ----A---- C:\Windows\system32\zpeng24.dll 2008-12-05 13:57:38 ----A---- C:\Windows\system32\vsxml.dll 2008-12-05 13:57:37 ----D---- C:\Program Files\Zone Labs 2008-12-05 13:57:37 ----A---- C:\Windows\system32\vspubapi.dll 2008-12-05 13:57:36 ----A---- C:\Windows\system32\vsmonapi.dll 2008-12-05 13:57:35 ----A---- C:\Windows\system32\vsdata.dll 2008-12-05 13:56:40 ----D---- C:\Windows\system32\ZoneLabs 2008-12-05 13:54:43 ----A---- C:\Windows\system32\vsutil.dll 2008-12-05 13:54:43 ----A---- C:\Windows\system32\vsinit.dll 2008-12-05 13:06:54 ----A---- C:\TB.txt 2008-12-05 13:06:00 ----D---- C:\ToolBar SD 2008-12-05 12:45:10 ----A---- C:\fixnavi.txt 2008-12-03 11:37:46 ----D---- C:\Users\DEAN\AppData\Roaming\ArcSoft 2008-12-02 19:26:36 ----D---- C:\Program Files\Common Files\ArcSoft 2008-12-02 19:26:16 ----A---- C:\Windows\system32\gdiplus.dll 2008-12-02 19:26:14 ----A---- C:\Windows\PCDLIB32.DLL 2008-12-02 19:26:13 ----D---- C:\Program Files\ArcSoft 2008-12-02 19:23:21 ----D---- C:\Program Files\STK017_V2.03 2008-11-29 09:21:48 ----D---- C:\Program Files\Adobe 2008-11-26 01:52:12 ----A---- C:\Windows\system32\PortableDeviceApi.dll 2008-11-26 01:52:10 ----A---- C:\Windows\system32\WindowsCodecsExt.dll 2008-11-26 01:52:10 ----A---- C:\Windows\system32\WindowsCodecs.dll 2008-11-26 01:52:10 ----A---- C:\Windows\system32\PhotoMetadataHandler.dll 2008-11-26 01:52:08 ----A---- C:\Windows\system32\connect.dll 2008-11-21 05:49:17 ----A---- C:\Windows\system32\wups2.dll 2008-11-21 05:49:17 ----A---- C:\Windows\system32\wucltux.dll 2008-11-21 05:49:17 ----A---- C:\Windows\system32\wuaueng.dll 2008-11-21 05:49:17 ----A---- C:\Windows\system32\wuauclt.exe 2008-11-21 05:48:55 ----A---- C:\Windows\system32\wups.dll 2008-11-21 05:48:55 ----A---- C:\Windows\system32\wudriver.dll 2008-11-21 05:48:55 ----A---- C:\Windows\system32\wuapi.dll 2008-11-21 05:48:44 ----A---- C:\Windows\system32\wuwebv.dll 2008-11-21 05:48:44 ----A---- C:\Windows\system32\wuapp.exe 2008-11-18 15:36:19 ----D---- C:\Users\DEAN\AppData\Roaming\VadeRetro 2008-11-18 15:36:14 ----D---- C:\ProgramData\VadeRetro 2008-11-18 15:36:13 ----D---- C:\Program Files\Goto Software 2008-11-16 12:29:51 ----D---- C:\Program Files\Spyware-Secure 2008-11-12 07:32:28 ----A---- C:\Windows\system32\msxml3.dll 2008-11-12 07:32:26 ----A---- C:\Windows\system32\msxml6.dll 2008-11-09 17:39:33 ----D---- C:\Program Files\Windows Live Safety Center 2008-11-09 14:18:21 ----D---- C:\Program Files\JCA2000 2008-11-09 14:10:10 ----D---- C:\Program Files\Antipub 2008-11-08 15:48:00 ----D---- C:\ProgramData\CheckPoint 2008-11-08 15:42:35 ----D---- C:\Windows\Internet Logs ======List of files/folders modified in the last 1 months====== 2008-12-07 14:19:24 ----D---- C:\Windows\Prefetch 2008-12-07 14:19:15 ----D---- C:\Windows\Temp 2008-12-07 14:19:12 ----RD---- C:\Program Files 2008-12-07 13:07:17 ----D---- C:\Windows\inf 2008-12-07 13:07:17 ----AD---- C:\Windows\System32 2008-12-07 13:07:17 ----A---- C:\Windows\system32\PerfStringBackup.INI 2008-12-07 12:59:50 ----D---- C:\Windows\tracing 2008-12-07 12:59:12 ----D---- C:\Windows 2008-12-07 11:41:43 ----SHD---- C:\System Volume Information 2008-12-06 21:31:05 ----D---- C:\ProgramData\Google Updater 2008-12-06 14:59:41 ----D---- C:\Windows\pss 2008-12-06 14:08:41 ----D---- C:\Program Files\WebPopupKiller 2008-12-06 09:49:12 ----SHD---- C:\Windows\Installer 2008-12-06 09:48:50 ----D---- C:\Program Files\Java 2008-12-06 09:48:39 ----D---- C:\Windows\system32\catroot2 2008-12-05 13:57:34 ----D---- C:\Windows\system32\drivers 2008-12-05 13:57:28 ----D---- C:\Windows\system32\catroot 2008-12-03 20:32:20 ----D---- C:\Users\DEAN\AppData\Roaming\dvdcss 2008-12-03 11:37:07 ----HD---- C:\Program Files\InstallShield Installation Information 2008-12-03 11:37:07 ----D---- C:\Windows\twain_32 2008-12-02 19:26:36 ----D---- C:\Program Files\Common Files 2008-12-01 15:29:34 ----D---- C:\Program Files\Fighters 2008-11-29 09:22:05 ----D---- C:\Program Files\Common Files\Adobe 2008-11-29 09:22:01 ----D---- C:\ProgramData\Adobe 2008-11-26 03:01:08 ----D---- C:\Windows\winsxs 2008-11-22 05:38:38 ----D---- C:\Windows\rescache 2008-11-22 05:20:21 ----D---- C:\Windows\system32\fr-FR 2008-11-19 03:00:58 ----D---- C:\ProgramData\Microsoft Help 2008-11-18 15:36:14 ----HD---- C:\ProgramData 2008-11-18 09:43:11 ----A---- C:\Users\DEAN\AppData\Roaming\QuickZip45.ini 2008-11-16 19:11:05 ----D---- C:\Windows\Debug 2008-11-16 17:39:05 ----D---- C:\Users\DEAN\AppData\Roaming\LimeWire 2008-11-15 17:08:25 ----D---- C:\ProgramData\Roxio 2008-11-13 12:13:04 ----D---- C:\Program Files\Mozilla Firefox 2008-11-09 17:39:34 ----SD---- C:\Windows\Downloaded Program Files 2008-11-09 16:16:31 ----D---- C:\Program Files\DivX 2008-11-09 15:38:11 ----D---- C:\Users\DEAN\AppData\Roaming\Skype 2008-11-09 14:18:41 ----D---- C:\Windows\system32\Tasks 2008-11-08 16:36:39 ----D---- C:\Program Files\Common Files\Wise Installation Wizard 2008-11-08 15:46:27 ----D---- C:\Windows\SoftwareDistribution ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R1 avgio;avgio; \??\C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgio.sys [2007-02-27 11840] R1 avipbb;avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [2008-11-25 75072] R1 ssmdrv;ssmdrv; C:\Windows\system32\DRIVERS\ssmdrv.sys [2007-03-01 28352] R1 Vsdatant;Zone Alarm Firewall Driver; C:\Windows\system32\DRIVERS\vsdatant.sys [2008-03-03 279440] R3 Afc;PPdus ASPI Shell; C:\Windows\system32\drivers\Afc.sys [2005-02-23 11776] R3 avgntflt;avgntflt; \??\C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgntflt.sys [2008-05-20 52032] R3 GEARAspiWDM;GEARAspiWDM; C:\Windows\System32\Drivers\GEARAspiWDM.sys [2008-01-29 16168] R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2007-05-10 1775712] R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2007-07-06 7568832] R3 RT2500USB;Hercules Wireless USB Dongle Driver; C:\Windows\system32\DRIVERS\rt73.sys [2006-01-12 252928] R3 RTL8023xp;Realtek 10/100 NIC Family NDIS x86 Driver; C:\Windows\system32\DRIVERS\Rtnicxp.sys [2007-01-23 50176] R3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-19 83328] S3 catchme;catchme; \??\C:\Users\DEAN\AppData\Local\Temp\catchme.sys [] S3 drmkaud;Filtre de décodeur DRM (Noyau Microsoft); C:\Windows\system32\drivers\drmkaud.sys [2008-01-19 5632] S3 MSKSSRV;Proxy de service de répartition Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-19 8192] S3 MSPCLOCK;Proxy d'horloge de répartition Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-19 5888] S3 MSPQM;Proxy de gestion de qualité de répartition Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-01-19 5504] S3 MSTEE;Convertisseur en T/site-à-site de répartition Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-01-19 6016] S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2008-01-19 39936] S4 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\drivers\wmiacpi.sys [2006-11-02 11264] ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R2 aawservice;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe [2008-11-02 611664] R2 AntiVirScheduler;Avira AntiVir Personal - Free Antivirus Scheduler; C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe [2008-10-15 68865] R2 AntiVirService;Avira AntiVir Personal - Free Antivirus Guard; C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe [2008-10-15 151297] R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2007-09-06 110592] R2 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-10-10 168432] R2 NMSAccessU;NMSAccessU; C:\Program Files\CDBurnerXP\NMSAccessU.exe [2008-03-09 71096] R2 RoxWatch9;Roxio Hard Drive Watcher 9; C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe [2007-01-11 166648] R2 vsmon;TrueVector Internet Monitor; C:\Windows\System32\ZoneLabs\vsmon.exe [2008-03-03 79400] R3 iPod Service;Service de l'iPod; C:\Program Files\iPod\bin\iPodService.exe [2008-03-30 504104] R3 usnjsvc;Service Messenger Sharing Folders USN Journal Reader; C:\Program Files\Windows Live\Messenger\usnsvc.exe [2007-10-18 98328] S2 CLTNetCnService;Symantec Lic NetConnect service; C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe /h ccCommon [] S3 GoogleDesktopManager;GoogleDesktopManager; C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2007-12-04 1836544] S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728] S3 LiveUpdate;LiveUpdate; C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE [2007-09-26 2999664] S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2007-08-24 443776] S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184] S3 RoxMediaDB9;RoxMediaDB9; C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe [2007-01-11 887544] S3 stllssvr;stllssvr; C:\Program Files\Common Files\SureThing Shared\stllssvr.exe [2006-09-14 73728] S3 WLSetupSvc;Windows Live Setup Service; C:\Program Files\Windows Live\installer\WLSetupSvc.exe [2007-10-25 266240] -----------------EOF----------------- info.txt logfile of random's system information tool 1.04 2008-12-07 14:19:40 ======Uninstall list====== -->MsiExec.exe /I{0394CDC8-FABD-4ed8-B104-03393876DFDF} -->MsiExec.exe /I{0D330013-4A99-46D6-83C6-2C959C68DBFF} -->MsiExec.exe /I{0D397393-9B50-4c52-84D5-77E344289F87} -->MsiExec.exe /I{35E1EC43-D4FC-4E4A-AAB3-20DDA27E8BB0} -->MsiExec.exe /I{619CDD8A-14B6-43a1-AB6C-0F4EE48CE048} -->MsiExec.exe /I{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA} -->MsiExec.exe /I{83FFCFC7-88C6-41c6-8752-958A45325C82} -->MsiExec.exe /I{C8B0680B-CDAE-4809-9F91-387B6DE00F7C} 2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7} 2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-0018-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7} 2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001B-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7} 2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0401-0000-0000000FF1CE} /uninstall {5A2F65A4-808F-4A1E-973E-92E17824982D} 2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0407-0000-0000000FF1CE} /uninstall {2AB528A5-BB1B-4EBE-8E51-AD0C4CD33CA9} 2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {3EC77D26-799B-4CD8-914F-C1565E796173} 2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {430971B1-C31E-45DA-81E0-72C095BAB72C} 2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0413-0000-0000000FF1CE} /uninstall {B3F4DC34-7F60-4B7C-A79F-1C13012D99D4} 2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {F7A31780-33C4-4E39-951A-5EC9B91D7BF1} 2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {90120000-00A1-040C-0000-0000000FF1CE} /uninstall {A0353900-21A2-42CF-B973-883500A027F7} 2007 Microsoft Office Suite Service Pack 1 (SP1)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {BEE75E01-DD3F-4D5F-B96C-609E6538D419} Activation Assistant for the 2007 Microsoft Office suites-->"C:\ProgramData\{174892B1-CBE7-44F5-86FF-AB555EFD73A3}\Microsoft Office Activation Assistant.exe" REMOVE=TRUE MODIFY=FALSE Ad-Aware-->MsiExec.exe /I{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF} Adobe Flash Player 10 Plugin-->C:\Windows\system32\Macromed\Flash\uninstall_plugin.exe Adobe Flash Player ActiveX-->C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe Adobe Reader 8.1.3 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A81300000003} Adobe Reader 8-->"C:\Program Files\Packard Bell\Smart Restore\SmartRestore.exe" /MSADDREM *AdobeReader* Adobe Shockwave Player-->MsiExec.exe /X{A7DB362E-16DC-4E29-8A34-E74381E00B5B} ADSL Neuf-->"C:\Program Files\Packard Bell\Smart Restore\SmartRestore.exe" /MSADDREM *NEUF_FR* Apple Mobile Device Support-->MsiExec.exe /I{44734179-8A79-4DEE-BB08-73037F065543} Apple Software Update-->MsiExec.exe /I{02DFF6B1-1654-411C-8D7B-FD6052EF016F} ArcSoft Software Suite-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{4A712D29-DBE3-4381-A331-AF4AE5BEB244}\setup.exe" -l0x40c Assistant de connexion Windows Live-->MsiExec.exe /I{AFA4E5FD-ED70-4D92-99D0-162FD56DC986} Avira AntiVir Personal - Free Antivirus-->C:\Program Files\Avira\AntiVir PersonalEdition Classic\SETUP.EXE /REMOVE Browser Address Error Redirector-->regsvr32 /u /s "C:\Program Files\Google\Google_BAE\BAE.dll" CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe" CDBurnerXP-->"C:\Program Files\CDBurnerXP\unins000.exe" Creator 9-->"C:\Program Files\Packard Bell\Smart Restore\SmartRestore.exe" /MSADDREM *CREATOR9* Dealio Toolbar 3.3-->MsiExec.exe /X{8476C5A3-6DF0-467F-91D0-ABA22DC37373} DivX Content Uploader-->C:\Program Files\DivX\DivXContentUploaderUninstall.exe /CUPLOADER DivX Web Player-->C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN EmoDio-->"C:\Program Files\InstallShield Installation Information\{C20CE592-B0F8-4D20-BF31-0151CA6331A6}\setup.exe" -runfromtemp -l0x040c -removeonly eMule-->"C:\Program Files\eMule\Uninstall.exe" Extension de Windows Live Toolbar (Windows Live Toolbar)-->MsiExec.exe /X{0CA6047C-D28B-4295-834A-07C52BA20C2D} Favorit-->c:\users\dean\appdata\local\nnudcjjq.bat Firefox-->"C:\Program Files\Packard Bell\Smart Restore\SmartRestore.exe" /MSADDREM *FirefoxFR* Flash Player 9 Internet Explorer-->"C:\Program Files\Packard Bell\Smart Restore\SmartRestore.exe" /MSADDREM *Flashplayer* Galerie de photos Windows Live-->MsiExec.exe /X{A70FA218-6598-4AC9-813D-63597C5DD068} GearDrvs-->MsiExec.exe /I{206FD69B-F9FE-4164-81BD-D52552BC9C23} Google BAE-->"C:\Program Files\Packard Bell\Smart Restore\SmartRestore.exe" /MSADDREM *GoogleBAE* Google Desktop-->C:\Program Files\Google\Google Desktop Search\GoogleDesktopSetup.exe -uninstall Google Earth-->"C:\Program Files\Packard Bell\Smart Restore\SmartRestore.exe" /MSADDREM *GOOGLE_EARTH* Google Earth-->MsiExec.exe /I{1D14373E-7970-4F2F-A467-ACA4F0EA21E3} Google Toolbar for Internet Explorer-->MsiExec.exe /I{DBEA1034-5882-4A88-8033-81C4EF0CFA29} Google Toolbar for Internet Explorer-->regsvr32 /u /s "c:\program files\google\googletoolbar2.dll" GoogleToolbar-->"C:\Program Files\Packard Bell\Smart Restore\SmartRestore.exe" /MSADDREM *GoogleToolbar* HDReg France-->MsiExec.exe /I{0ED40D2A-7131-4FE7-941E-5C329336F712} HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall Infocentre Rev. 2.0-->"C:\Program Files\Packard Bell\Smart Restore\SmartRestore.exe" /MSADDREM *Infocentre* iTunes-->MsiExec.exe /I{585776BC-4BD6-4BD2-A19A-1D6CB44A403B} Java 6 Update 11-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216011FF} Java 6 Update 2-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160020} Java 6 Update 3-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030} Java 6 Update 5-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050} Java 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070} K-Lite Mega Codec Pack 3.8.0-->"C:\Program Files\K-Lite Codec Pack\unins000.exe" LiveUpdate 3.2 (Symantec Corporation)-->"C:\Program Files\Symantec\LiveUpdate\LSETUP.EXE" /U Menus intelligents (Windows Live Toolbar)-->MsiExec.exe /X{0CC70FEF-5068-4CD5-B4DE-86FFD98EC929} Microsoft .NET Framework 1.1 Hotfix (KB929729)-->"C:\Windows\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\Windows\Microsoft.NET\Framework\v1.1.4322\Updates\M929729\M929729Uninstall.msp" Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} Microsoft Office Excel MUI (French) 2007-->MsiExec.exe /X{90120000-0016-040C-0000-0000000FF1CE} Microsoft Office Home and Student 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall HOMESTUDENTR /dll OSETUP.DLL Microsoft Office Home and Student 2007-->MsiExec.exe /X{91120000-002F-0000-0000-0000000FF1CE} Microsoft Office Language Pack 2007 Service Pack 1 (SP1)-->msiexec /package {90120000-006E-040C-0000-0000000FF1CE} /uninstall {EC50B538-CBE1-42E6-B7FE-87AA540AADFB} Microsoft Office OneNote MUI (French) 2007-->MsiExec.exe /X{90120000-00A1-040C-0000-0000000FF1CE} Microsoft Office PowerPoint MUI (French) 2007-->MsiExec.exe /X{90120000-0018-040C-0000-0000000FF1CE} Microsoft Office PowerPoint Viewer 2007 (French)-->MsiExec.exe /X{95120000-00AF-040C-0000-0000000FF1CE} Microsoft Office Proof (Arabic) 2007-->MsiExec.exe /X{90120000-001F-0401-0000-0000000FF1CE} Microsoft Office Proof (Dutch) 2007-->MsiExec.exe /X{90120000-001F-0413-0000-0000000FF1CE} Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE} Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE} Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE} Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE} Microsoft Office Proofing (French) 2007-->MsiExec.exe /X{90120000-002C-040C-0000-0000000FF1CE} Microsoft Office Shared MUI (French) 2007-->MsiExec.exe /X{90120000-006E-040C-0000-0000000FF1CE} Microsoft Office Word MUI (French) 2007-->MsiExec.exe /X{90120000-001B-040C-0000-0000000FF1CE} Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8} Microsoft Works 9 SE-->"C:\Program Files\Packard Bell\Smart Restore\SmartRestore.exe" /MSADDREM *works9se* Microsoft Works-->MsiExec.exe /I{0214A441-A4AB-43A8-8DEF-2F73C5364673} Microsoft® Office Trial 2007-->"C:\Program Files\Packard Bell\Smart Restore\SmartRestore.exe" /MSADDREM *OFF2k7_FR* Module de compatibilité pour Microsoft Office System 2007-->MsiExec.exe /X{90120000-0020-040C-0000-0000000FF1CE} Mozilla Firefox (3.0.4)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF} MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71} neroxml-->MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B} Neuf - Kit de connexion-->C:\Program Files\Neuf\Kit\uninstall.exe Norton 360-->"C:\Program Files\Packard Bell\Smart Restore\SmartRestore.exe" /MSADDREM *N360_2007_FR* Norton 360-->MsiExec.exe /I{63A6E9A9-A190-46D4-9430-2DB28654AFD8} Norton Security Scan-->MsiExec.exe /I{230C4A45-2586-4161-84EF-5C0D75D5B270} NVIDIA Drivers-->C:\Windows\system32\NVUNINST.EXE UninstallGUI Outil de mise à jour Google-->"C:\Program Files\Google\Google Updater\GoogleUpdater.exe" -uninstall Packard Bell Demo-->"C:\Program Files\Packard Bell\Smart Restore\SmartRestore.exe" /MSADDREM *PB_DEMO* Packard Bell ImageWriter-->"C:\Program Files\Packard Bell\Smart Restore\SmartRestore.exe" /MSADDREM *ImageWriter* Packard Bell LCD Test-->"C:\Program Files\Packard Bell\Smart Restore\SmartRestore.exe" /MSADDREM *LCDTest* Packard Bell Updator-->"C:\Program Files\Packard Bell\Smart Restore\SmartRestore.exe" /MSADDREM *Updator* Picasa 2-->"C:\Program Files\Picasa2\Uninstall.exe" Picasa2-->"C:\Program Files\Packard Bell\Smart Restore\SmartRestore.exe" /MSADDREM *Picasa_2* Quick Zip 4.60.019-->"C:\Program Files\QuickZip4\unins000.exe" QuickTime-->MsiExec.exe /I{08CA9554-B5FE-4313-938F-D4A417B81175} Realtek HD Audio V6.0.1.5413-->"C:\Program Files\Packard Bell\Smart Restore\SmartRestore.exe" /MSADDREM *AUDIO_REALTEK* Realtek High Definition Audio Driver-->RtlUpd.exe -r -m Roxio Creator 9 LE-->MsiExec.exe /I{B7FB0C86-41A4-4402-9A33-912C462042A0} Samsung Media Studio-->C:\Program Files\InstallShield Installation Information\{C20CE592-B0F8-4D20-BF31-0151CA6331A6}\Setup.exe -runfromtemp -l0x040c -removeonly Search Settings 1.1-->MsiExec.exe /X{32AD1A7A-25F1-44B9-A396-EA8A4A6605B0} Security Update for 2007 Microsoft Office System (KB951550)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {B243E9A5-ED77-4F1B-B338-2486FD82DC85} Security Update for 2007 Microsoft Office System (KB951944)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {797AE457-BA17-4BBC-B501-25FB3A0103C7} Security Update for 2007 Microsoft Office System (KB955936)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {1D94099C-2BBA-440E-BD5E-093BBDF8F028} Security Update for CAPICOM (KB931906)-->MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A} Security Update for CAPICOM (KB931906)-->MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A} Security Update for Microsoft Office Excel 2007 (KB955470)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {6E8637D8-10D6-4568-AA06-E2706F31685E} Security Update for Microsoft Office OneNote 2007 (KB950130)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {F1B2401C-B610-4BF2-AA1C-52C55827A8F4} Security Update for Microsoft Office PowerPoint 2007 (KB951338)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {558B709B-821B-4FC5-90FC-9A8890641E77} Security Update for Microsoft Office system 2007 (KB951808)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {8F375E11-4FD6-4B89-9E2B-A76D48B51E00} Security Update for Microsoft Office system 2007 (KB954326)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {5F7F6FFF-395D-480E-8450-64F385D82C5F} Security Update for Microsoft Office Word 2007 (KB950113)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {AD72BABE-C733-4FCF-9674-4314466191B9} Security Update for Visio 2007 (KB947590)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {6BAD036C-261F-4BEF-96CF-C20678D07A41} SetUp My PC-->"C:\Program Files\Packard Bell\Smart Restore\SmartRestore.exe" /MSADDREM *SETUPMYPC_FR* SFR - Widget neufbox-->C:\Program Files\Neuf\Widget Neuf\uninstall.exe Shareaza 2.4.0.0-->"C:\Program Files\Shareaza\Uninstall\unins000.exe" Shockwave player 10-->"C:\Program Files\Packard Bell\Smart Restore\SmartRestore.exe" /MSADDREM *Shockwave* Skype 2.5.2.151-->"C:\Program Files\Packard Bell\Smart Restore\SmartRestore.exe" /MSADDREM *SKYPE* Skype™ 3.6-->MsiExec.exe /X{5C82DAE5-6EB0-4374-9254-BE3319BA4E82} Spelling Dictionaries Support For Adobe Reader 8-->MsiExec.exe /I{AC76BA86-7AD7-5464-3428-800000000003} Surligneur (Windows Live Toolbar)-->MsiExec.exe /X{81B5F83F-2291-48B0-8375-36B63A9BF5B0} Update for Microsoft Office Excel 2007 Help (KB957242)-->msiexec /package {90120000-0016-040C-0000-0000000FF1CE} /uninstall {49E314EE-81FA-4007-8F1A-8D39BDBB4498} Update for Office 2007 (KB946691)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {A420F522-7395-4872-9882-C591B4B92278} USB Disk Win98 Driver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{4E79A62F-7A2D-4058-BCE0-94E6B9E2F162}\Setup.exe" Vade Retro Outlook, Outlook Express, Windows Mail (Vista)-->C:\Program Files\Goto Software\Vade Retro\uninst.exe VCRedistSetup-->MsiExec.exe /I{3921A67A-5AB1-4E48-9444-C71814CF3027} Video NVIDIA v162.22-->"C:\Program Files\Packard Bell\Smart Restore\SmartRestore.exe" /MSADDREM *VIDEO_NVIDIA* VideoLAN VLC media player 0.8.6b-->C:\Program Files\VideoLAN\VLC\uninstall.exe Vista Codec Package-->MsiExec.exe /I{F9FD80CE-0448-4D4F-8BCD-77FC514C3F99} WebPopupKiller 1.0-->"C:\Program Files\WebPopupKiller\unins000.exe" WiFi Station-->C:\Program Files\InstallShield Installation Information\{DECE22F4-EEDD-4615-BC56-2F4827FAD64B}\Setup.exe -runfromtemp -l0x040c -removeonly Windows Live Favorites pour Windows Live Toolbar-->MsiExec.exe /X{786C4AD1-DCBA-49A6-B0EF-B317A344BD66} Windows Live installer-->MsiExec.exe /X{FD44E544-E7D0-4DBA-9FA0-8AE1A1300390} Windows Live Mail-->MsiExec.exe /I{C514C594-23AA-4F13-A070-DB8BDB27594F} Windows Live Messenger-->MsiExec.exe /X{BADF6744-3787-48F6-B8C9-4C4995401D65} Windows Live Toolbar-->"C:\Program Files\Windows Live Toolbar\UnInstall.exe" {0A8C97AD-DEED-4894-B446-3ABA95A77D0D} Windows Live Toolbar-->MsiExec.exe /X{0A8C97AD-DEED-4894-B446-3ABA95A77D0D} Windows Live Writer-->MsiExec.exe /X{3DFF4274-EBB0-4356-9692-972965018954} Windows Media Player Firefox Plugin-->MsiExec.exe /I{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4} XviD MPEG-4 Video Codec-->"C:\Program Files\XviD\unins000.exe" Yahoo! Toolbar avec bloqueur de fenêtres pop-up-->C:\PROGRA~1\Yahoo!\Common\unyt.exe ZoneAlarm-->C:\Program Files\Zone Labs\ZoneAlarm\zauninst.exe ======Security center information====== FW: ZoneAlarm Firewall AS: Spybot - Search and Destroy (outdated) AS: Windows Defender ======Environment variables====== "ComSpec"=%SystemRoot%\system32\cmd.exe "FP_NO_HOST_CHECK"=NO "OS"=Windows_NT "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\Common Files\Roxio Shared\DLLShared\;C:\Program Files\Common Files\Roxio Shared\9.0\DLLShared\;C:\Windows\Microsoft.NET\Framework\v2.0.50727;C:\Program Files\QuickTime\QTSystem\ "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC "PROCESSOR_ARCHITECTURE"=x86 "TEMP"=%SystemRoot%\TEMP "TMP"=%SystemRoot%\TEMP "USERNAME"=SYSTEM "windir"=%SystemRoot% "PROCESSOR_LEVEL"=15 "PROCESSOR_IDENTIFIER"=x86 Family 15 Model 6 Stepping 5, GenuineIntel "PROCESSOR_REVISION"=0605 "NUMBER_OF_PROCESSORS"=2 "RoxioCentral"=C:\Program Files\Common Files\Roxio Shared\9.0\Roxio Central33\ "CLASSPATH"=.;C:\Program Files\Java\jre1.6.0_05\lib\ext\QTJava.zip "QTJAVA"=C:\Program Files\Java\jre1.6.0_05\lib\ext\QTJava.zip "tvdumpflags"=8 -----------------EOF----------------- -
[Résolu] Pub incessante, infecte???
maykiki a répondu à un(e) sujet de maykiki dans Analyses et éradication malwares
hello! Voila alors le rapport: @+ ========== FILES ========== C:\Program Files\AskTBar\bar\Settings moved successfully. C:\Program Files\AskTBar\bar\History moved successfully. C:\Program Files\AskTBar\bar\Cache moved successfully. Folder move failed. C:\Program Files\AskTBar\bar\2.bin scheduled to be moved on reboot. Folder move failed. C:\Program Files\AskTBar\bar scheduled to be moved on reboot. Folder move failed. C:\Program Files\AskTBar scheduled to be moved on reboot. Folder move failed. C:\Program Files\AskTBar\bar\2.bin scheduled to be moved on reboot. Folder move failed. C:\Program Files\AskTBar\bar scheduled to be moved on reboot. Folder move failed. C:\Program Files\AskTBar\bar\2.bin scheduled to be moved on reboot. Folder move failed. C:\PROGRA~2\MICROS~1\Windows\STARTM~1\Programs\Dealio scheduled to be moved on reboot. C:\Program Files\Dealio\kb126\temp moved successfully. C:\Program Files\Dealio\kb126\rules moved successfully. C:\Program Files\Dealio\kb126\res moved successfully. C:\Program Files\Dealio\kb126 moved successfully. C:\Program Files\Dealio moved successfully. File/Folder C:\Program Files\Dealio\DealioAU.exe not found. File/Folder C:\Program Files\Dealio\kb126 not found. File/Folder C:\Program Files\Dealio\SearchSettingsKit.exe not found. File/Folder C:\Program Files\Dealio\kb126\Dealio Deskbar.exe not found. File/Folder C:\Program Files\Dealio\kb126\Dealio.dll not found. File/Folder C:\Program Files\Dealio\kb126\res not found. File/Folder C:\Program Files\Dealio\kb126\rules not found. File/Folder C:\Program Files\Dealio\kb126\temp not found. File/Folder C:\Program Files\Dealio\kb126\res\chevron-small.gif not found. File/Folder C:\Program Files\Dealio\kb126\res\DealioSearch.html not found. File/Folder C:\Program Files\Dealio\kb126\res\deals-leftcap.gif not found. File/Folder C:\Program Files\Dealio\kb126\res\deal_report.jpg not found. File/Folder C:\Program Files\Dealio\kb126\res\ebay_login.jpg not found. File/Folder C:\Program Files\Dealio\kb126\res\err_mainwindow.html not found. File/Folder C:\Program Files\Dealio\kb126\res\err_toolbar.html not found. File/Folder C:\Program Files\Dealio\kb126\res\global_scripts.js not found. File/Folder C:\Program Files\Dealio\kb126\res\headerbgthin.jpg not found. File/Folder C:\Program Files\Dealio\kb126\res\highlight-bg.png not found. File/Folder C:\Program Files\Dealio\kb126\res\logo.gif not found. File/Folder C:\Program Files\Dealio\kb126\res\logo_over.gif not found. File/Folder C:\Program Files\Dealio\kb126\res\man_toolbar.html not found. File/Folder C:\Program Files\Dealio\kb126\res\man_toolbar.js not found. File/Folder C:\Program Files\Dealio\kb126\res\post-this-deal.gif not found. File/Folder C:\Program Files\Dealio\kb126\res\post-this-deal_over.gif not found. File/Folder C:\Program Files\Dealio\kb126\res\scripts.js not found. File/Folder C:\Program Files\Dealio\kb126\res\scroller.js not found. File/Folder C:\Program Files\Dealio\kb126\res\search-chevron.gif not found. File/Folder C:\Program Files\Dealio\kb126\res\search-chevron_over.gif not found. File/Folder C:\Program Files\Dealio\kb126\res\search_bg_blink.gif not found. File/Folder C:\Program Files\Dealio\kb126\res\separator.gif not found. File/Folder C:\Program Files\Dealio\kb126\res\settings.gif not found. File/Folder C:\Program Files\Dealio\kb126\res\settings_over.gif not found. File/Folder C:\Program Files\Dealio\kb126\res\yahoo-search.png not found. File/Folder C:\Program Files\Dealio\kb126\rules\index.76.35 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.10.76 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.109.43 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.110.43 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.12.52 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.13.58 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.130.58 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.135.50 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.153.44 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.155.43 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.156.49 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.16.60 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.161.52 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.178.66 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.184.55 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.188.52 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.189.45 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.196.43 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.198.56 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.199.43 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.200.53 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.201.43 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.202.43 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.203.71 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.205.62 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.213.71 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.214.49 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.215.43 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.216.67 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.217.67 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.218.52 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.219.43 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.220.43 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.221.57 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.222.43 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.223.68 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.226.68 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.227.43 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.228.62 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.229.76 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.23.63 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.239.43 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.24.43 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.240.43 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.241.43 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.242.43 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.243.43 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.244.63 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.245.43 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.247.43 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.248.43 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.249.43 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.250.43 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.251.43 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.252.43 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.253.43 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.254.43 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.255.43 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.256.43 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.257.43 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.279.43 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.28.58 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.282.75 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.283.43 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.284.43 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.289.67 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.290.62 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.291.61 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.296.43 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.297.43 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.304.43 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.307.43 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.308.75 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.31.47 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.310.46 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.311.43 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.315.43 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.316.43 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.317.43 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.318.43 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.319.49 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.32.48 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.334.44 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.335.60 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.336.44 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.337.44 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.338.75 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.339.47 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.34.43 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.340.47 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.341.47 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.349.50 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.35.48 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.350.50 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.351.51 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.352.54 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.353.51 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.354.51 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.357.62 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.358.52 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.359.52 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.360.53 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.361.54 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.362.68 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.363.58 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.364.54 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.365.53 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.367.56 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.368.58 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.369.55 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.370.56 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.371.56 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.372.57 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.373.55 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.375.56 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.376.57 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.377.55 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.378.65 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.384.58 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.386.71 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.387.59 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.388.59 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.389.59 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.390.60 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.391.60 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.392.60 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.393.60 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.394.60 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.396.61 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.397.61 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.398.60 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.399.60 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.403.61 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.404.63 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.405.61 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.406.61 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.407.76 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.408.63 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.409.61 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.412.62 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.413.62 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.414.62 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.415.62 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.416.62 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.417.62 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.418.62 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.419.62 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.420.62 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.421.62 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.423.63 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.424.63 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.425.63 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.426.63 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.427.63 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.428.65 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.429.63 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.430.63 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.432.65 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.433.64 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.434.65 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.435.64 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.436.76 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.437.64 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.438.71 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.439.71 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.440.75 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.442.73 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.443.73 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.444.73 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.445.68 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.446.69 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.450.67 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.451.67 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.452.68 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.453.68 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.454.69 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.456.69 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.457.75 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.458.70 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.459.70 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.460.69 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.462.74 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.463.69 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.464.70 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.465.68 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.468.70 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.469.70 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.470.70 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.471.73 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.472.70 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.478.74 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.479.73 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.480.68 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.481.71 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.482.74 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.49.67 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.50.43 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.500.71 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.501.74 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.502.71 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.51.69 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.52.72 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.520.76 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.521.76 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.522.76 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.53.51 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.531.76 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.532.75 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.534.75 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.54.47 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.55.45 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.56.69 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.57.43 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.58.47 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.593.76 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.595.76 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.63.57 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.66.47 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.70.75 not found. File/Folder C:\Program Files\Dealio\kb126\rules\rules.1.71.43 not found. Folder move failed. C:\Program Files\Search Settings\kb126\temp scheduled to be moved on reboot. Folder move failed. C:\Program Files\Search Settings\kb126\res scheduled to be moved on reboot. Folder move failed. C:\Program Files\Search Settings\kb126 scheduled to be moved on reboot. Folder move failed. C:\Program Files\Search Settings scheduled to be moved on reboot. Folder move failed. C:\Program Files\Search Settings\kb126\temp scheduled to be moved on reboot. Folder move failed. C:\Program Files\Search Settings\kb126\res scheduled to be moved on reboot. Folder move failed. C:\Program Files\Search Settings\kb126 scheduled to be moved on reboot. File move failed. C:\Program Files\Search Settings\SearchSettings.exe scheduled to be moved on reboot. Folder move failed. C:\Program Files\Search Settings\kb126\res scheduled to be moved on reboot. C:\Program Files\Search Settings\kb126\SearchSettings.dll unregistered successfully. File move failed. C:\Program Files\Search Settings\kb126\SearchSettings.dll scheduled to be moved on reboot. Folder move failed. C:\Program Files\Search Settings\kb126\temp scheduled to be moved on reboot. File/Folder C:\Program Files\WebMediaPlayer not found. File/Folder C:\Program Files\WebMediaPlayer\resources not found. File/Folder C:\Program Files\WebMediaPlayer\skins not found. File/Folder C:\Program Files\WebMediaPlayer\sqlite3.dll not found. File/Folder C:\Program Files\WebMediaPlayer\updates not found. File/Folder C:\Program Files\WebMediaPlayer\WebMediaPlayer.exe not found. File/Folder C:\PROGRA~2\MICROS~1\Windows\STARTM~1\Programs\WebMediaPlayer not found. File/Folder C:\PROGRA~2\MICROS~1\Windows\STARTM~1\Programs\WebMediaPlayer\Conditions g‚n‚rales.url not found. File/Folder C:\PROGRA~2\MICROS~1\Windows\STARTM~1\Programs\WebMediaPlayer\Confidentialit‚.url not found. File/Folder C:\PROGRA~2\MICROS~1\Windows\STARTM~1\Programs\WebMediaPlayer\D‚sinstaller.lnk not found. File/Folder C:\PROGRA~2\MICROS~1\Windows\STARTM~1\Programs\WebMediaPlayer\WebMediaPlayer.lnk not found. File/Folder C:\PROGRA~2\MICROS~1\Windows\STARTM~1\Programs\WebMediaPlayer\Website.url not found. ========== COMMANDS ========== File delete failed. C:\Users\DEAN\AppData\Local\Temp\~DF96AA.tmp scheduled to be deleted on reboot. File delete failed. C:\Users\DEAN\AppData\Local\Temp\~DF96D3.tmp scheduled to be deleted on reboot. File delete failed. C:\Users\DEAN\AppData\Local\Temp\~DFD24F.tmp scheduled to be deleted on reboot. User's Temp folder emptied. User's Temporary Internet Files folder emptied. User's Internet Explorer cache folder emptied. Local Service Temp folder emptied. Local Service Temporary Internet Files folder emptied. Windows Temp folder emptied. FireFox cache emptied. Temp folders emptied. OTMoveIt3 by OldTimer - Version 1.0.7.2 log created on 12072008_125749 -
[Résolu] Pub incessante, infecte???
maykiki a répondu à un(e) sujet de maykiki dans Analyses et éradication malwares
ok, je vois ca demain! Pour info j avais fait un test via msconfig et tout remis normalement et ce redemarre normal ss pb!!! @+ -
[Résolu] Pub incessante, infecte???
maykiki a répondu à un(e) sujet de maykiki dans Analyses et éradication malwares
ca ne fonctionne pas non plus par contre j arrive a lui faire demarrer en mode sans echec en passant par msconfig je lui fais faire le scan toolbar demain. Merci! -
[Résolu] Pub incessante, infecte???
maykiki a répondu à un(e) sujet de maykiki dans Analyses et éradication malwares
Hello! Quelques petits soucis rencontres! Deja j ai fait faire le nettoyage navilog a mon oncle en oubmiant de desactiver l UAC, est ce genant ou non? Ensuite, impossible de demarrer le pc en mode sans echec. En appuyant sur F8 rien, en appuyant sur F5 et F8 simultanement comme hier il n ouvre plus la meme fenetre mais un ecran windows bleu me proposant Select Boot Menu (Cd, disque dur, internet). Meme en indiquant disque dur et en reessayant c pareil! Donc impossible de realiser le nettoyage Toolbar - S&D Etrange non? Sinon voila quand meme le raport Navilog fait avec UAC activé!!! Clean Navipromo version 3.6.9 commencé le 06/12/2008 à 11:15:29,38 Outil exécuté depuis C:\Program Files\navilog1 Session actuelle : "DEAN" Mise à jour le 05.11.2008 à 21h00 par IL-MAFIOSO Microsoft Windows Vista 6.0.6001 Internet Explorer : 7.0.6001.18000 Système de fichiers : NTFS Mode suppression automatique avec prise en charge résultats Catchme et GNS Nettoyage exécuté au redémarrage de l'ordinateur *** fsbl1.txt non trouvé *** (Assurez-vous que Catchme n'avait rien trouvé lors de la recherche) *** Suppression avec sauvegardes résultats GenericNaviSearch *** * Suppression dans "C:\Windows\System32" * * Suppression dans "C:\Users\DEAN\AppData\Local\Microsoft" * * Suppression dans "C:\Users\DEAN\AppData\Local\virtualstore\windows\system32" * * Suppression dans "C:\Users\DEAN\AppData\Local" * *** Suppression dossiers dans "C:\Windows" *** *** Suppression dossiers dans "C:\Program Files" *** ...\WebMediaPlayer ...suppression... ...\WebMediaPlayer supprimé ! *** Suppression dossiers dans "c:\progra~2\micros~1\windows\startm~1\programs" *** ...\WebMediaPlayer ...suppression... ...\WebMediaPlayer supprimé ! *** Suppression dossiers dans "c:\progra~2\micros~1\windows\startm~1" *** *** Suppression dossiers dans "C:\ProgramData" *** *** Suppression dossiers dans c:\users\dean\appdata\roaming\micros~1\windows\startm~1\programs *** *** Suppression dossiers dans "C:\Users\DEAN\AppData\Local\virtualstore\Program Files" *** *** Suppression dossiers dans "C:\Users\DEAN\AppData\Roaming" *** *** Suppression fichiers *** c:\users\public\desktop\WebMediaPlayer.lnk supprimé ! *** Suppression fichiers temporaires *** Nettoyage contenu C:\Windows\Temp effectué ! Nettoyage contenu C:\Users\DEAN\AppData\Local\Temp effectué ! *** Traitement Recherche complémentaire *** (Recherche fichiers spécifiques) 1)Suppression avec sauvegardes nouveaux fichiers Instant Access : 2)Recherche, création sauvegardes et suppression Heuristique : * Dans "C:\Windows\system32" * * Dans "C:\Users\DEAN\AppData\Local\Microsoft" * * Dans "C:\Users\DEAN\AppData\Local\virtualstore\windows\system32" * * Dans "C:\Users\DEAN\AppData\Local" * eascw.dat trouvé ! Copie eascw.dat réalisée avec succès ! eascw.dat supprimé ! eascw_nav.dat trouvé ! Copie eascw_nav.dat réalisée avec succès ! eascw_nav.dat supprimé ! eascw_navps.dat trouvé ! Copie eascw_navps.dat réalisée avec succès ! eascw_navps.dat supprimé ! hvvartd.dat trouvé ! Copie hvvartd.dat réalisée avec succès ! hvvartd.dat supprimé ! hvvartd_nav.dat trouvé ! Copie hvvartd_nav.dat réalisée avec succès ! hvvartd_nav.dat supprimé ! hvvartd_navps.dat trouvé ! Copie hvvartd_navps.dat réalisée avec succès ! hvvartd_navps.dat supprimé ! siusu.exe trouvé ! Copie siusu.exe réalisée avec succès ! siusu.exe supprimé ! siusu.dat trouvé ! Copie siusu.dat réalisée avec succès ! siusu.dat supprimé ! siusu_nav.dat trouvé ! Copie siusu_nav.dat réalisée avec succès ! siusu_nav.dat supprimé ! siusu_navps.dat trouvé ! Copie siusu_navps.dat réalisée avec succès ! siusu_navps.dat supprimé ! *** Sauvegarde du Registre vers dossier Safebackup *** sauvegarde du Registre réalisée avec succès ! *** Nettoyage Registre *** Nettoyage Registre Ok *** Certificats *** Certificat Egroup supprimé ! Certificat Electronic-Group supprimé ! Certificat Montorgueil absent ! Certificat OOO-Favorit supprimé ! Certificat Sunny-Day-Design-Ltdt absent ! *** Nettoyage terminé le 06/12/2008 à 11:19:03,83 *** -
[Résolu] Pub incessante, infecte???
maykiki a répondu à un(e) sujet de maykiki dans Analyses et éradication malwares
Hello! Merci de m avoir repondu! Voila les rapports: Search Navipromo version 3.6.9 commencé le 05/12/2008 à 12:45:10,62 !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!! !!! Postez ce rapport sur le forum pour le faire analyser !!! !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!! Outil exécuté depuis C:\Program Files\navilog1 Session actuelle : "DEAN" Mise à jour le 05.11.2008 à 21h00 par IL-MAFIOSO Microsoft Windows Vista 6.0.6001 Internet Explorer : 7.0.6001.18000 Système de fichiers : NTFS Recherche executé en mode normal *** Recherche Programmes installés *** *** Recherche dossiers dans "C:\Windows" *** *** Recherche dossiers dans "C:\Program Files" *** ...\WebMediaPlayer trouvé ! *** Recherche dossiers dans "c:\progra~2\micros~1\windows\startm~1\programs" *** ...\WebMediaPlayer trouvé ! *** Recherche dossiers dans "c:\progra~2\micros~1\windows\startm~1" *** *** Recherche dossiers dans "C:\ProgramData" *** *** Recherche dossiers dans "c:\users\dean\appdata\roaming\micros~1\windows\startm~1\programs" *** *** Recherche dossiers dans "C:\Users\DEAN\AppData\Local\virtualstore\Program Files" *** *** Recherche dossiers dans "C:\Users\DEAN\AppData\Roaming" *** *** Recherche avec Catchme-rootkit/stealth malware detector par gmer *** pour + d'infos : http://www.gmer.net *** Recherche avec GenericNaviSearch *** !!! Tous ces résultats peuvent révéler des fichiers légitimes !!! !!! A vérifier impérativement avant toute suppression manuelle !!! * Recherche dans "C:\Windows\system32" * * Recherche dans "C:\Users\DEAN\AppData\Local\Microsoft" * * Recherche dans "C:\Users\DEAN\AppData\Local\virtualstore\windows\system32" * * Recherche dans "C:\Users\DEAN\AppData\Local" * *** Recherche fichiers *** c:\users\public\desktop\WebMediaPlayer.lnk trouvé ! *** Recherche clés spécifiques dans le Registre *** HKEY_CURRENT_USER\Software\Lanconfig trouvé ! *** Module de Recherche complémentaire *** (Recherche fichiers spécifiques) 1)Recherche nouveaux fichiers Instant Access : 2)Recherche Heuristique : * Dans "C:\Windows\system32" : * Dans "C:\Users\DEAN\AppData\Local\Microsoft" : * Dans "C:\Users\DEAN\AppData\Local\virtualstore\windows\system32" : * Dans "C:\Users\DEAN\AppData\Local" : eascw.dat trouvé ! eascw_nav.dat trouvé ! eascw_navps.dat trouvé ! hvvartd.dat trouvé ! hvvartd_nav.dat trouvé ! hvvartd_navps.dat trouvé ! siusu.exe trouvé ! siusu.dat trouvé ! siusu_nav.dat trouvé ! siusu_navps.dat trouvé ! 3)Recherche Certificats : Certificat Egroup trouvé ! Certificat Electronic-Group trouvé ! Certificat Montorgueil absent ! Certificat OOO-Favorit trouvé ! Certificat Sunny-Day-Design-Ltd absent ! 4)Recherche fichiers connus : *** Analyse terminée le 05/12/2008 à 13:02:55,98 *** -----------\\ ToolBar S&D 1.2.6 XP/Vista Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6001 ) Service Pack 1 X86-based PC ( Multiprocessor Free : Intel® Pentium® D CPU 3.00GHz ) BIOS : Phoenix - AwardBIOS v6.00PG USER : DEAN ( Administrator ) BOOT : Normal boot C:\ (Local Disk) - NTFS - Total:224 Go (Free:120 Go) D:\ (CD or DVD) E:\ (USB) F:\ (USB) G:\ (USB) H:\ (USB) "C:\ToolBar SD" ( MAJ : 04-12-2008|20:40 ) Option : [1] ( 05/12/2008|13:09 ) [ UAC => 0 ] -----------\\ Recherche de Fichiers / Dossiers ... C:\Program Files\AskTBar C:\Program Files\AskTBar\bar C:\Program Files\AskTBar\bar\2.bin C:\PROGRA~2\MICROS~1\Windows\STARTM~1\Programs\Dealio C:\Program Files\Dealio C:\Program Files\Dealio\DealioAU.exe C:\Program Files\Dealio\kb126 C:\Program Files\Dealio\SearchSettingsKit.exe C:\Program Files\Dealio\kb126\Dealio Deskbar.exe C:\Program Files\Dealio\kb126\Dealio.dll C:\Program Files\Dealio\kb126\res C:\Program Files\Dealio\kb126\rules C:\Program Files\Dealio\kb126\temp C:\Program Files\Dealio\kb126\res\chevron-small.gif C:\Program Files\Dealio\kb126\res\DealioSearch.html C:\Program Files\Dealio\kb126\res\deals-leftcap.gif C:\Program Files\Dealio\kb126\res\deal_report.jpg C:\Program Files\Dealio\kb126\res\ebay_login.jpg C:\Program Files\Dealio\kb126\res\err_mainwindow.html C:\Program Files\Dealio\kb126\res\err_toolbar.html C:\Program Files\Dealio\kb126\res\global_scripts.js C:\Program Files\Dealio\kb126\res\headerbgthin.jpg C:\Program Files\Dealio\kb126\res\highlight-bg.png C:\Program Files\Dealio\kb126\res\logo.gif C:\Program Files\Dealio\kb126\res\logo_over.gif C:\Program Files\Dealio\kb126\res\man_toolbar.html C:\Program Files\Dealio\kb126\res\man_toolbar.js C:\Program Files\Dealio\kb126\res\post-this-deal.gif C:\Program Files\Dealio\kb126\res\post-this-deal_over.gif C:\Program Files\Dealio\kb126\res\scripts.js C:\Program Files\Dealio\kb126\res\scroller.js C:\Program Files\Dealio\kb126\res\search-chevron.gif C:\Program Files\Dealio\kb126\res\search-chevron_over.gif C:\Program Files\Dealio\kb126\res\search_bg_blink.gif C:\Program Files\Dealio\kb126\res\separator.gif C:\Program Files\Dealio\kb126\res\settings.gif C:\Program Files\Dealio\kb126\res\settings_over.gif C:\Program Files\Dealio\kb126\res\yahoo-search.png C:\Program Files\Dealio\kb126\rules\index.76.35 C:\Program Files\Dealio\kb126\rules\rules.1.10.76 C:\Program Files\Dealio\kb126\rules\rules.1.109.43 C:\Program Files\Dealio\kb126\rules\rules.1.110.43 C:\Program Files\Dealio\kb126\rules\rules.1.12.52 C:\Program Files\Dealio\kb126\rules\rules.1.13.58 C:\Program Files\Dealio\kb126\rules\rules.1.130.58 C:\Program Files\Dealio\kb126\rules\rules.1.135.50 C:\Program Files\Dealio\kb126\rules\rules.1.153.44 C:\Program Files\Dealio\kb126\rules\rules.1.155.43 C:\Program Files\Dealio\kb126\rules\rules.1.156.49 C:\Program Files\Dealio\kb126\rules\rules.1.16.60 C:\Program Files\Dealio\kb126\rules\rules.1.161.52 C:\Program Files\Dealio\kb126\rules\rules.1.178.66 C:\Program Files\Dealio\kb126\rules\rules.1.184.55 C:\Program Files\Dealio\kb126\rules\rules.1.188.52 C:\Program Files\Dealio\kb126\rules\rules.1.189.45 C:\Program Files\Dealio\kb126\rules\rules.1.196.43 C:\Program Files\Dealio\kb126\rules\rules.1.198.56 C:\Program Files\Dealio\kb126\rules\rules.1.199.43 C:\Program Files\Dealio\kb126\rules\rules.1.200.53 C:\Program Files\Dealio\kb126\rules\rules.1.201.43 C:\Program Files\Dealio\kb126\rules\rules.1.202.43 C:\Program Files\Dealio\kb126\rules\rules.1.203.71 C:\Program Files\Dealio\kb126\rules\rules.1.205.62 C:\Program Files\Dealio\kb126\rules\rules.1.213.71 C:\Program Files\Dealio\kb126\rules\rules.1.214.49 C:\Program Files\Dealio\kb126\rules\rules.1.215.43 C:\Program Files\Dealio\kb126\rules\rules.1.216.67 C:\Program Files\Dealio\kb126\rules\rules.1.217.67 C:\Program Files\Dealio\kb126\rules\rules.1.218.52 C:\Program Files\Dealio\kb126\rules\rules.1.219.43 C:\Program Files\Dealio\kb126\rules\rules.1.220.43 C:\Program Files\Dealio\kb126\rules\rules.1.221.57 C:\Program Files\Dealio\kb126\rules\rules.1.222.43 C:\Program Files\Dealio\kb126\rules\rules.1.223.68 C:\Program Files\Dealio\kb126\rules\rules.1.226.68 C:\Program Files\Dealio\kb126\rules\rules.1.227.43 C:\Program Files\Dealio\kb126\rules\rules.1.228.62 C:\Program Files\Dealio\kb126\rules\rules.1.229.76 C:\Program Files\Dealio\kb126\rules\rules.1.23.63 C:\Program Files\Dealio\kb126\rules\rules.1.239.43 C:\Program Files\Dealio\kb126\rules\rules.1.24.43 C:\Program Files\Dealio\kb126\rules\rules.1.240.43 C:\Program Files\Dealio\kb126\rules\rules.1.241.43 C:\Program Files\Dealio\kb126\rules\rules.1.242.43 C:\Program Files\Dealio\kb126\rules\rules.1.243.43 C:\Program Files\Dealio\kb126\rules\rules.1.244.63 C:\Program Files\Dealio\kb126\rules\rules.1.245.43 C:\Program Files\Dealio\kb126\rules\rules.1.247.43 C:\Program Files\Dealio\kb126\rules\rules.1.248.43 C:\Program Files\Dealio\kb126\rules\rules.1.249.43 C:\Program Files\Dealio\kb126\rules\rules.1.250.43 C:\Program Files\Dealio\kb126\rules\rules.1.251.43 C:\Program Files\Dealio\kb126\rules\rules.1.252.43 C:\Program Files\Dealio\kb126\rules\rules.1.253.43 C:\Program Files\Dealio\kb126\rules\rules.1.254.43 C:\Program Files\Dealio\kb126\rules\rules.1.255.43 C:\Program Files\Dealio\kb126\rules\rules.1.256.43 C:\Program Files\Dealio\kb126\rules\rules.1.257.43 C:\Program Files\Dealio\kb126\rules\rules.1.279.43 C:\Program Files\Dealio\kb126\rules\rules.1.28.58 C:\Program Files\Dealio\kb126\rules\rules.1.282.75 C:\Program Files\Dealio\kb126\rules\rules.1.283.43 C:\Program Files\Dealio\kb126\rules\rules.1.284.43 C:\Program Files\Dealio\kb126\rules\rules.1.289.67 C:\Program Files\Dealio\kb126\rules\rules.1.290.62 C:\Program Files\Dealio\kb126\rules\rules.1.291.61 C:\Program Files\Dealio\kb126\rules\rules.1.296.43 C:\Program Files\Dealio\kb126\rules\rules.1.297.43 C:\Program Files\Dealio\kb126\rules\rules.1.304.43 C:\Program Files\Dealio\kb126\rules\rules.1.307.43 C:\Program Files\Dealio\kb126\rules\rules.1.308.75 C:\Program Files\Dealio\kb126\rules\rules.1.31.47 C:\Program Files\Dealio\kb126\rules\rules.1.310.46 C:\Program Files\Dealio\kb126\rules\rules.1.311.43 C:\Program Files\Dealio\kb126\rules\rules.1.315.43 C:\Program Files\Dealio\kb126\rules\rules.1.316.43 C:\Program Files\Dealio\kb126\rules\rules.1.317.43 C:\Program Files\Dealio\kb126\rules\rules.1.318.43 C:\Program Files\Dealio\kb126\rules\rules.1.319.49 C:\Program Files\Dealio\kb126\rules\rules.1.32.48 C:\Program Files\Dealio\kb126\rules\rules.1.334.44 C:\Program Files\Dealio\kb126\rules\rules.1.335.60 C:\Program Files\Dealio\kb126\rules\rules.1.336.44 C:\Program Files\Dealio\kb126\rules\rules.1.337.44 C:\Program Files\Dealio\kb126\rules\rules.1.338.75 C:\Program Files\Dealio\kb126\rules\rules.1.339.47 C:\Program Files\Dealio\kb126\rules\rules.1.34.43 C:\Program Files\Dealio\kb126\rules\rules.1.340.47 C:\Program Files\Dealio\kb126\rules\rules.1.341.47 C:\Program Files\Dealio\kb126\rules\rules.1.349.50 C:\Program Files\Dealio\kb126\rules\rules.1.35.48 C:\Program Files\Dealio\kb126\rules\rules.1.350.50 C:\Program Files\Dealio\kb126\rules\rules.1.351.51 C:\Program Files\Dealio\kb126\rules\rules.1.352.54 C:\Program Files\Dealio\kb126\rules\rules.1.353.51 C:\Program Files\Dealio\kb126\rules\rules.1.354.51 C:\Program Files\Dealio\kb126\rules\rules.1.357.62 C:\Program Files\Dealio\kb126\rules\rules.1.358.52 C:\Program Files\Dealio\kb126\rules\rules.1.359.52 C:\Program Files\Dealio\kb126\rules\rules.1.360.53 C:\Program Files\Dealio\kb126\rules\rules.1.361.54 C:\Program Files\Dealio\kb126\rules\rules.1.362.68 C:\Program Files\Dealio\kb126\rules\rules.1.363.58 C:\Program Files\Dealio\kb126\rules\rules.1.364.54 C:\Program Files\Dealio\kb126\rules\rules.1.365.53 C:\Program Files\Dealio\kb126\rules\rules.1.367.56 C:\Program Files\Dealio\kb126\rules\rules.1.368.58 C:\Program Files\Dealio\kb126\rules\rules.1.369.55 C:\Program Files\Dealio\kb126\rules\rules.1.370.56 C:\Program Files\Dealio\kb126\rules\rules.1.371.56 C:\Program Files\Dealio\kb126\rules\rules.1.372.57 C:\Program Files\Dealio\kb126\rules\rules.1.373.55 C:\Program Files\Dealio\kb126\rules\rules.1.375.56 C:\Program Files\Dealio\kb126\rules\rules.1.376.57 C:\Program Files\Dealio\kb126\rules\rules.1.377.55 C:\Program Files\Dealio\kb126\rules\rules.1.378.65 C:\Program Files\Dealio\kb126\rules\rules.1.384.58 C:\Program Files\Dealio\kb126\rules\rules.1.386.71 C:\Program Files\Dealio\kb126\rules\rules.1.387.59 C:\Program Files\Dealio\kb126\rules\rules.1.388.59 C:\Program Files\Dealio\kb126\rules\rules.1.389.59 C:\Program Files\Dealio\kb126\rules\rules.1.390.60 C:\Program Files\Dealio\kb126\rules\rules.1.391.60 C:\Program Files\Dealio\kb126\rules\rules.1.392.60 C:\Program Files\Dealio\kb126\rules\rules.1.393.60 C:\Program Files\Dealio\kb126\rules\rules.1.394.60 C:\Program Files\Dealio\kb126\rules\rules.1.396.61 C:\Program Files\Dealio\kb126\rules\rules.1.397.61 C:\Program Files\Dealio\kb126\rules\rules.1.398.60 C:\Program Files\Dealio\kb126\rules\rules.1.399.60 C:\Program Files\Dealio\kb126\rules\rules.1.403.61 C:\Program Files\Dealio\kb126\rules\rules.1.404.63 C:\Program Files\Dealio\kb126\rules\rules.1.405.61 C:\Program Files\Dealio\kb126\rules\rules.1.406.61 C:\Program Files\Dealio\kb126\rules\rules.1.407.76 C:\Program Files\Dealio\kb126\rules\rules.1.408.63 C:\Program Files\Dealio\kb126\rules\rules.1.409.61 C:\Program Files\Dealio\kb126\rules\rules.1.412.62 C:\Program Files\Dealio\kb126\rules\rules.1.413.62 C:\Program Files\Dealio\kb126\rules\rules.1.414.62 C:\Program Files\Dealio\kb126\rules\rules.1.415.62 C:\Program Files\Dealio\kb126\rules\rules.1.416.62 C:\Program Files\Dealio\kb126\rules\rules.1.417.62 C:\Program Files\Dealio\kb126\rules\rules.1.418.62 C:\Program Files\Dealio\kb126\rules\rules.1.419.62 C:\Program Files\Dealio\kb126\rules\rules.1.420.62 C:\Program Files\Dealio\kb126\rules\rules.1.421.62 C:\Program Files\Dealio\kb126\rules\rules.1.423.63 C:\Program Files\Dealio\kb126\rules\rules.1.424.63 C:\Program Files\Dealio\kb126\rules\rules.1.425.63 C:\Program Files\Dealio\kb126\rules\rules.1.426.63 C:\Program Files\Dealio\kb126\rules\rules.1.427.63 C:\Program Files\Dealio\kb126\rules\rules.1.428.65 C:\Program Files\Dealio\kb126\rules\rules.1.429.63 C:\Program Files\Dealio\kb126\rules\rules.1.430.63 C:\Program Files\Dealio\kb126\rules\rules.1.432.65 C:\Program Files\Dealio\kb126\rules\rules.1.433.64 C:\Program Files\Dealio\kb126\rules\rules.1.434.65 C:\Program Files\Dealio\kb126\rules\rules.1.435.64 C:\Program Files\Dealio\kb126\rules\rules.1.436.76 C:\Program Files\Dealio\kb126\rules\rules.1.437.64 C:\Program Files\Dealio\kb126\rules\rules.1.438.71 C:\Program Files\Dealio\kb126\rules\rules.1.439.71 C:\Program Files\Dealio\kb126\rules\rules.1.440.75 C:\Program Files\Dealio\kb126\rules\rules.1.442.73 C:\Program Files\Dealio\kb126\rules\rules.1.443.73 C:\Program Files\Dealio\kb126\rules\rules.1.444.73 C:\Program Files\Dealio\kb126\rules\rules.1.445.68 C:\Program Files\Dealio\kb126\rules\rules.1.446.69 C:\Program Files\Dealio\kb126\rules\rules.1.450.67 C:\Program Files\Dealio\kb126\rules\rules.1.451.67 C:\Program Files\Dealio\kb126\rules\rules.1.452.68 C:\Program Files\Dealio\kb126\rules\rules.1.453.68 C:\Program Files\Dealio\kb126\rules\rules.1.454.69 C:\Program Files\Dealio\kb126\rules\rules.1.456.69 C:\Program Files\Dealio\kb126\rules\rules.1.457.75 C:\Program Files\Dealio\kb126\rules\rules.1.458.70 C:\Program Files\Dealio\kb126\rules\rules.1.459.70 C:\Program Files\Dealio\kb126\rules\rules.1.460.69 C:\Program Files\Dealio\kb126\rules\rules.1.462.74 C:\Program Files\Dealio\kb126\rules\rules.1.463.69 C:\Program Files\Dealio\kb126\rules\rules.1.464.70 C:\Program Files\Dealio\kb126\rules\rules.1.465.68 C:\Program Files\Dealio\kb126\rules\rules.1.468.70 C:\Program Files\Dealio\kb126\rules\rules.1.469.70 C:\Program Files\Dealio\kb126\rules\rules.1.470.70 C:\Program Files\Dealio\kb126\rules\rules.1.471.73 C:\Program Files\Dealio\kb126\rules\rules.1.472.70 C:\Program Files\Dealio\kb126\rules\rules.1.478.74 C:\Program Files\Dealio\kb126\rules\rules.1.479.73 C:\Program Files\Dealio\kb126\rules\rules.1.480.68 C:\Program Files\Dealio\kb126\rules\rules.1.481.71 C:\Program Files\Dealio\kb126\rules\rules.1.482.74 C:\Program Files\Dealio\kb126\rules\rules.1.49.67 C:\Program Files\Dealio\kb126\rules\rules.1.50.43 C:\Program Files\Dealio\kb126\rules\rules.1.500.71 C:\Program Files\Dealio\kb126\rules\rules.1.501.74 C:\Program Files\Dealio\kb126\rules\rules.1.502.71 C:\Program Files\Dealio\kb126\rules\rules.1.51.69 C:\Program Files\Dealio\kb126\rules\rules.1.52.72 C:\Program Files\Dealio\kb126\rules\rules.1.520.76 C:\Program Files\Dealio\kb126\rules\rules.1.521.76 C:\Program Files\Dealio\kb126\rules\rules.1.522.76 C:\Program Files\Dealio\kb126\rules\rules.1.53.51 C:\Program Files\Dealio\kb126\rules\rules.1.531.76 C:\Program Files\Dealio\kb126\rules\rules.1.532.75 C:\Program Files\Dealio\kb126\rules\rules.1.534.75 C:\Program Files\Dealio\kb126\rules\rules.1.54.47 C:\Program Files\Dealio\kb126\rules\rules.1.55.45 C:\Program Files\Dealio\kb126\rules\rules.1.56.69 C:\Program Files\Dealio\kb126\rules\rules.1.57.43 C:\Program Files\Dealio\kb126\rules\rules.1.58.47 C:\Program Files\Dealio\kb126\rules\rules.1.593.76 C:\Program Files\Dealio\kb126\rules\rules.1.595.76 C:\Program Files\Dealio\kb126\rules\rules.1.63.57 C:\Program Files\Dealio\kb126\rules\rules.1.66.47 C:\Program Files\Dealio\kb126\rules\rules.1.70.75 C:\Program Files\Dealio\kb126\rules\rules.1.71.43 C:\Program Files\Search Settings C:\Program Files\Search Settings\kb126 C:\Program Files\Search Settings\SearchSettings.exe C:\Program Files\Search Settings\kb126\res C:\Program Files\Search Settings\kb126\SearchSettings.dll C:\Program Files\Search Settings\kb126\temp -----------\\ [..\Internet Explorer\Main] [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Local Page"="C:\\Windows\\system32\\blank.htm" "Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"'>http://go.microsoft.com/fwlink/?LinkId=54896" "SearchMigratedDefaultURL"="http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}" "Start Page"="http://msn.fr/" "Default_Page_URL"="http://format.packardbell.com/cgi-bin/redirect/?country=FR&range=AD&phase=8&key=IESTART" "Search Bar"="http://www.crawler.com/search/dispatcher.aspx?tp=aus&qkw=%s&tbid=60327" "Url"="http://go.microsoft.com/fwlink/?LinkID=68928" "Url"="http://go.microsoft.com/fwlink/?LinkID=44406" "Url"="http://go.microsoft.com/fwlink/?LinkID=68929" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"'>http://go.microsoft.com/fwlink/?LinkId=69157" "Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157" "Default_Search_URL"="http://recherche.neuf.fr/" "Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896" --------------------\\ Recherche d'autres infections C:\Program Files\WebMediaPlayer C:\Program Files\WebMediaPlayer\resources C:\Program Files\WebMediaPlayer\skins C:\Program Files\WebMediaPlayer\sqlite3.dll C:\Program Files\WebMediaPlayer\updates C:\Program Files\WebMediaPlayer\WebMediaPlayer.exe C:\PROGRA~2\MICROS~1\Windows\STARTM~1\Programs\WebMediaPlayer C:\PROGRA~2\MICROS~1\Windows\STARTM~1\Programs\WebMediaPlayer\Conditions g‚n‚rales.url C:\PROGRA~2\MICROS~1\Windows\STARTM~1\Programs\WebMediaPlayer\Confidentialit‚.url C:\PROGRA~2\MICROS~1\Windows\STARTM~1\Programs\WebMediaPlayer\D‚sinstaller.lnk C:\PROGRA~2\MICROS~1\Windows\STARTM~1\Programs\WebMediaPlayer\WebMediaPlayer.lnk C:\PROGRA~2\MICROS~1\Windows\STARTM~1\Programs\WebMediaPlayer\Website.url C:\Users\DEAN\AppData\Local\eascw.dat C:\Users\DEAN\AppData\Local\eascw_nav.dat C:\Users\DEAN\AppData\Local\eascw_navps.dat C:\Users\DEAN\AppData\Local\hvvartd.dat C:\Users\DEAN\AppData\Local\hvvartd_nav.dat C:\Users\DEAN\AppData\Local\hvvartd_navps.dat C:\Users\DEAN\AppData\Local\siusu.dat C:\Users\DEAN\AppData\Local\siusu.exe C:\Users\DEAN\AppData\Local\siusu_nav.dat C:\Users\DEAN\AppData\Local\siusu_navps.dat ==> EGDACCESS <== --------------------\\ ROGUES .. C:\Users\DEAN\AppData\Roaming\WinButler C:\PROGRA~2\MICROS~1\Windows\STARTM~1\Programs\Spyware-Secure C:\PROGRA~1\Spyware-Secure [ UAC => 1 ] 1 - "C:\ToolBar SD\TB_1.txt" - 05/12/2008|13:10 - Option : [1] -----------\\ Fin du rapport a 13:10:13,36 @+ -
Salut tout le monde! J essaie d aider mon oncle avec son pc. Y a plein de fenetres de pubs qui s ouvrent des qu il va sur internet. Il est sous Vistaz et utilise firefox. Je vous laisse les rapports antivir et hijackthis si quelqu un peut me dire quoi! Merci d avance Avira AntiVir Personal Report file date: jeudi 4 décembre 2008 18:28 Scanning for 1071567 virus strains and unwanted programs. Licensed to: Avira AntiVir PersonalEdition Classic Serial number: 0000149996-ADJIE-0001 Platform: Windows Vista Windows version: (Service Pack 1) [6.0.6001] Boot mode: Save mode Username: DEAN Computer name: PC-DE-DEAN Version information: BUILD.DAT : 8.2.0.337 16934 Bytes 18/11/2008 13:05:00 AVSCAN.EXE : 8.1.4.10 315649 Bytes 25/11/2008 18:04:21 AVSCAN.DLL : 8.1.4.0 40705 Bytes 26/05/2008 08:56:40 LUKE.DLL : 8.1.4.5 164097 Bytes 12/06/2008 13:44:19 LUKERES.DLL : 8.1.4.0 12033 Bytes 26/05/2008 08:58:52 ANTIVIR0.VDF : 7.1.0.0 15603712 Bytes 27/10/2008 18:04:03 ANTIVIR1.VDF : 7.1.0.56 411136 Bytes 09/11/2008 18:03:07 ANTIVIR2.VDF : 7.1.0.160 571392 Bytes 30/11/2008 18:03:19 ANTIVIR3.VDF : 7.1.0.183 162304 Bytes 03/12/2008 18:02:51 Engineversion : 8.2.0.36 AEVDF.DLL : 8.1.0.6 102772 Bytes 14/10/2008 11:05:56 AESCRIPT.DLL : 8.1.1.15 332156 Bytes 12/11/2008 18:02:39 AESCN.DLL : 8.1.1.5 123251 Bytes 07/11/2008 18:04:15 AERDL.DLL : 8.1.1.3 438645 Bytes 07/11/2008 18:04:14 AEPACK.DLL : 8.1.3.4 393591 Bytes 12/11/2008 18:02:38 AEOFFICE.DLL : 8.1.0.30 196986 Bytes 07/11/2008 18:04:12 AEHEUR.DLL : 8.1.0.71 1487222 Bytes 07/11/2008 18:04:11 AEHELP.DLL : 8.1.2.0 119159 Bytes 19/11/2008 18:03:01 AEGEN.DLL : 8.1.1.6 323955 Bytes 28/11/2008 18:04:01 AEEMU.DLL : 8.1.0.9 393588 Bytes 14/10/2008 11:05:56 AECORE.DLL : 8.1.5.2 172405 Bytes 28/11/2008 18:03:59 AEBB.DLL : 8.1.0.3 53618 Bytes 14/10/2008 11:05:56 AVWINLL.DLL : 1.0.0.12 15105 Bytes 09/07/2008 09:40:05 AVPREF.DLL : 8.0.2.0 38657 Bytes 16/05/2008 10:28:01 AVREP.DLL : 8.0.0.2 98344 Bytes 07/11/2008 18:04:06 AVREG.DLL : 8.0.0.1 33537 Bytes 09/05/2008 12:26:40 AVARKT.DLL : 1.0.0.23 307457 Bytes 12/02/2008 09:29:23 AVEVTLOG.DLL : 8.0.0.16 119041 Bytes 12/06/2008 13:27:49 SQLITE3.DLL : 3.3.17.1 339968 Bytes 22/01/2008 18:28:02 SMTPLIB.DLL : 1.2.0.23 28929 Bytes 12/06/2008 13:49:40 NETNT.DLL : 8.0.0.1 7937 Bytes 25/01/2008 13:05:10 RCIMAGE.DLL : 8.0.0.51 2371841 Bytes 12/06/2008 14:48:07 RCTEXT.DLL : 8.0.52.0 86273 Bytes 27/06/2008 14:34:37 Configuration settings for the scan: Jobname..........................: Complete system scan Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp Logging..........................: low Primary action...................: interactive Secondary action.................: ignore Scan master boot sector..........: on Scan boot sector.................: on Boot sectors.....................: C:, Process scan.....................: on Scan registry....................: on Search for rootkits..............: off Scan all files...................: Intelligent file selection Scan archives....................: on Recursion depth..................: 20 Smart extensions.................: on Macro heuristic..................: on File heuristic...................: medium Start of the scan: jeudi 4 décembre 2008 18:28 The scan of running processes will be started Scan process 'avscan.exe' - '1' Module(s) have been scanned Scan process 'avcenter.exe' - '1' Module(s) have been scanned Scan process 'WmiPrvSE.exe' - '1' Module(s) have been scanned Scan process 'unsecapp.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'explorer.exe' - '1' Module(s) have been scanned Scan process 'aawservice.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'lsm.exe' - '1' Module(s) have been scanned Scan process 'lsass.exe' - '1' Module(s) have been scanned Scan process 'services.exe' - '1' Module(s) have been scanned Scan process 'winlogon.exe' - '1' Module(s) have been scanned Scan process 'wininit.exe' - '1' Module(s) have been scanned Scan process 'csrss.exe' - '1' Module(s) have been scanned Scan process 'csrss.exe' - '1' Module(s) have been scanned Scan process 'smss.exe' - '1' Module(s) have been scanned 20 processes with 20 modules were scanned Starting master boot sector scan: Master boot sector HD0 [iNFO] No virus was found! Master boot sector HD1 [iNFO] No virus was found! [WARNING] System error [21]: Le périphérique n'est pas prêt. [iNFO] Please restart the search with Administrator rights Master boot sector HD2 [iNFO] No virus was found! [WARNING] System error [21]: Le périphérique n'est pas prêt. [iNFO] Please restart the search with Administrator rights Master boot sector HD3 [iNFO] No virus was found! [WARNING] System error [21]: Le périphérique n'est pas prêt. [iNFO] Please restart the search with Administrator rights Master boot sector HD4 [iNFO] No virus was found! [WARNING] System error [21]: Le périphérique n'est pas prêt. [iNFO] Please restart the search with Administrator rights Start scanning boot sectors: Boot sector 'C:\' [iNFO] No virus was found! Starting to scan the registry. The registry was scanned ( '58' files ). Starting the file scan: Begin scan in 'C:\' <HDD> C:\pagefile.sys [WARNING] The file could not be opened! C:\Windows\System32\drivers\sptd.sys [WARNING] The file could not be opened! End of the scan: jeudi 4 décembre 2008 18:57 Used time: 29:06 Minute(s) The scan has been done completely. 17454 Scanning directories 278772 Files were scanned 0 viruses and/or unwanted programs were found 0 Files were classified as suspicious: 0 files were deleted 0 files were repaired 0 files were moved to quarantine 0 files were renamed 2 Files cannot be scanned 278770 Files not concerned 2132 Archives were scanned 6 Warnings 0 Notes Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 19:09:45, on 04/12/2008 Platform: Windows Vista SP1 (WinNT 6.00.1905) MSIE: Internet Explorer v7.00 (7.00.6001.18000) Boot mode: Normal Running processes: C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\USB Disk Win98 Driver\Res.exe C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe C:\Program Files\Search Settings\SearchSettings.exe C:\Windows\RtHDVCpl.exe C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe C:\Windows\System32\rundll32.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Goto Software\Vade Retro\Vaderetro_mgr.exe C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe C:\Windows\system32\taskeng.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe C:\Windows\ehome\ehtray.exe C:\Users\DEAN\AppData\Local\siusu.exe C:\Windows\ehome\ehmsas.exe C:\Windows\System32\rundll32.exe C:\Windows\system32\wbem\unsecapp.exe C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe C:\Windows\System32\mobsync.exe c:\Users\DEAN\Downloads\HiJackThis.exe C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://format.packardbell.com/cgi-bin/redi...amp;key=IESTART R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.crawler.com/search/dispatcher.a...&tbid=60327 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://msn.fr/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://format.packardbell.com/cgi-bin/redi...amp;key=IESTART R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://recherche.neuf.fr/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://recherche.neuf.fr/ie/default.html R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = R3 - URLSearchHook: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb126\SearchSettings.dll O1 - Hosts: ::1 localhost O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: DealioBHO Class - {6A87B991-A31F-4130-AE72-6D0C294BF082} - C:\Program Files\Dealio\kb126\Dealio.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Google\Google_BAE\BAE.dll O2 - BHO: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb126\SearchSettings.dll O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O3 - Toolbar: Dealio - {E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F} - C:\Program Files\Dealio\kb126\Dealio.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide O4 - HKLM\..\Run: [uSB Storage Toolbox] C:\Program Files\USB Disk Win98 Driver\Res.EXE O4 - HKLM\..\Run: [toolbar_eula_launcher] C:\Program Files\Packard Bell\GOOGLE_EULA\EULALauncher.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" O4 - HKLM\..\Run: [sMSTray] C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe O4 - HKLM\..\Run: [skytel] Skytel.exe O4 - HKLM\..\Run: [searchSettings] C:\Program Files\Search Settings\SearchSettings.exe O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [au] C:\Program Files\Dealio\DealioAU.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min O4 - HKLM\..\Run: [VadeRetro Outlook] C:\Program Files\Goto Software\Vade Retro\VrMoRegister.exe -s O4 - HKLM\..\Run: [VadeRetro Desktop] C:\Program Files\Goto Software\Vade Retro\Vaderetro_Mgr.exe O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe O4 - HKCU\..\Run: [smpcSys] C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [iSUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe O4 - HKCU\..\Run: [siusu] "c:\users\dean\appdata\local\siusu.exe" siusu O4 - HKUS\S-1-5-18\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'SYSTEM') O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'Default user') O4 - Startup: OneNote 2007 - Capture d'écran et lancement.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~4.0_0\bin\ssv.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~4.0_0\bin\ssv.dll O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL O9 - Extra button: Dealio - {E908B145-C847-4e85-B315-07E2E70DECF8} - C:\Program Files\Dealio\kb126\Dealio.dll O9 - Extra 'Tools' menuitem: Dealio - {E908B145-C847-4e85-B315-07E2E70DECF8} - C:\Program Files\Dealio\kb126\Dealio.dll O13 - Gopher Prefix: O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/...lscbase6662.cab O20 - AppInit_DLLs: C:\PROGRA~1\Google\GO333C~1\GOEC62~1.DLL O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing) O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe -- End of file - 10664 bytes
-
Désinfecté, besoin de petits conseils!
maykiki a répondu à un(e) sujet de maykiki dans Sécurisation, prévention
RE! Depuis que j ai enleve les entrees de hijackthis indiquees ci dessus, j ai l impression que mes vntilos tournent plus vite que d habitude et donc le bruit plus embetant!! Est ce normal, possible? Si oui quelle entree dois je remettre? Merci a vos de me repondre!!!!! @+ -
Désinfecté, besoin de petits conseils!
maykiki a répondu à un(e) sujet de maykiki dans Sécurisation, prévention
Apres avoir jete un coup d oeil ici, http://www.forumkeroinsite.com/tuto-info/t...ultats-t83.html j ai fixe les lignes suivantes: (ceux en gras reviennent malgre effacement. Asquared par exemple je n arrive pas a le supprimer de mon pc, il me reste toujours un fichier recalcitrant!) R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE O4 - HKLM\..\Run: [LXCRCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86 O4 - HKLM\..\Run: [sclauncher] C:\Program Files\SimpleCenter\bin\win\sclauncher.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU') O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user') O4 - .DEFAULT User Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe (User 'Default user') O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe O23 - Service: Apache2.2 - Apache Software Foundation - c:\xampp\apache\bin\apache.exe O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe Je vous joint le rapport definitif pour voir: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 01:16:31, on 29/11/2008 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16735) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\ZoneLabs\vsmon.exe C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe C:\WINDOWS\Explorer.EXE C:\Program Files\a-squared Free\a2service.exe C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe C:\WINDOWS\ehome\ehtray.exe C:\WINDOWS\system32\lxcrcoms.exe C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe C:\Program Files\CDBurnerXP\NMSAccessU.exe C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe C:\WINDOWS\RTHDCPL.EXE C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\Lexmark 2400 Series\lxcrmon.exe C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\NETGEAR\WG111v3\WG111v3.exe C:\WINDOWS\system32\wbem\wmiapsrv.exe C:\PROGRA~1\FICHIE~1\Nokia\MPLATF~1\NOKIAM~1.EXE C:\HP\KBD\KBD.EXE C:\Program Files\Mozilla Firefox\firefox.exe c:\windows\system\hpsysdrv.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/ O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe O4 - HKLM\..\Run: [iAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" O4 - HKLM\..\Run: [lxcrmon.exe] "C:\Program Files\Lexmark 2400 Series\lxcrmon.exe" O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" O4 - HKLM\..\Run: [Nokia FastStart] "C:\Program Files\Nokia\Nokia Music\NokiaMusic.exe" /command:faststart O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user') O4 - .DEFAULT User Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe (User 'Default user') O4 - Global Startup: NETGEAR WG111v3 Smart Wizard.lnk = C:\Program Files\NETGEAR\WG111v3\WG111v3.exe O17 - HKLM\System\CCS\Services\Tcpip\..\{A5022F0C-6EA2-42DB-B3A4-E3DB3BFEB653}: NameServer = 212.27.53.252,212.27.54.252 O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: Intel® Quick Resume technology (ELService) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology Drivers\Elservice.exe O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe O23 - Service: lxcr_device - - C:\WINDOWS\system32\lxcrcoms.exe O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe -- End of file - 6890 bytes Merci a vous! -
Salut a tous. J avais chope quelques petits trojans et autres. C est maintenant fini. Ici, http://forum.zebulon.fr/resolu-je-parais-i...93#entry1314993 on m a conseille ceci: Pour tes protections, il y en a trop: ZoneLabs®ZoneAlarm Lavasoft AB®Ad-Aware 2007 Safer Net Working®Spybot S&D Avira®AntiVir PersonalEdition Emsi Software®A-Squared Free Anti-malware Si tu installes ou as déjà MBAM (MalwareBytes AntiMalware) des solutions comme Ad-Aware, Spybot S&D et ASquared sont parfaitement inutiles et obsolètes. J ai donc supprime les 3 inutiles, ai installe MBAM (pas de protection en temps reelle?) et ai laisse antivir et Zone alarm. J ai egalement Zebprotect, AdBlock et NoScript (ou j ai autorise globalement java car ca m enerve de toujours devoir indiquer si j accepte ou non des que je change de page firefox!) Ai je bien fait? Sinon je me sers regulierement de ces logiciels, est ce utile et n y a t il pas certaines applications que je peux supprimer? Voila la liste: - ATF Cleaner - BeClean - EasyCleaner - jv16 Power tools - spyware blaster - CCleaner - RegSeeker - RegCleaner(qui me pose souvent des problemes pour se lancer!!!) Je vous joint aussi un rapport hijackthis si vous pouvez me donner des conseils! Merci a vous @+ Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 23:33:30, on 28/11/2008 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16735) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\ZoneLabs\vsmon.exe C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe C:\Program Files\a-squared Free\a2service.exe C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe c:\xampp\apache\bin\apache.exe C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe C:\WINDOWS\system32\lxcrcoms.exe C:\Program Files\CDBurnerXP\NMSAccessU.exe C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe C:\WINDOWS\system32\svchost.exe C:\xampp\apache\bin\apache.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\ehome\ehtray.exe C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe C:\WINDOWS\RTHDCPL.EXE C:\WINDOWS\system32\rundll32.exe C:\Program Files\Lexmark 2400 Series\lxcrmon.exe C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe C:\Program Files\SimpleCenter\bin\win\sclauncher.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\NETGEAR\WG111v3\WG111v3.exe C:\HP\KBD\KBD.EXE C:\PROGRA~1\FICHIE~1\Nokia\MPLATF~1\NOKIAM~1.EXE c:\windows\system\hpsysdrv.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\Program Files\Windows Live\Messenger\usnsvc.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\WINDOWS\system32\wbem\wmiapsrv.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Documents and Settings\HP_Administrateur\Bureau\ \RegCleanr.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe O4 - HKLM\..\Run: [iAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" O4 - HKLM\..\Run: [lxcrmon.exe] "C:\Program Files\Lexmark 2400 Series\lxcrmon.exe" O4 - HKLM\..\Run: [LXCRCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCRtime.dll,_RunDLLEntry@16 O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" O4 - HKLM\..\Run: [sclauncher] C:\Program Files\SimpleCenter\bin\win\sclauncher.exe O4 - HKLM\..\Run: [Nokia FastStart] "C:\Program Files\Nokia\Nokia Music\NokiaMusic.exe" /command:faststart O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU') O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user') O4 - .DEFAULT User Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe (User 'Default user') O4 - Global Startup: NETGEAR WG111v3 Smart Wizard.lnk = C:\Program Files\NETGEAR\WG111v3\WG111v3.exe O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/dow...llerControl.cab O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - http://gfx1.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} - http://messenger.zone.msn.com/binary/Bankshot.cab57213.cab O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} - http://messenger.zone.msn.com/binary/MineS...er.cab56986.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{A5022F0C-6EA2-42DB-B3A4-E3DB3BFEB653}: NameServer = 212.27.53.252,212.27.54.252 O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe O23 - Service: Apache2.2 - Apache Software Foundation - c:\xampp\apache\bin\apache.exe O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: Intel® Quick Resume technology (ELService) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology Drivers\Elservice.exe O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe O23 - Service: lxcr_device - - C:\WINDOWS\system32\lxcrcoms.exe O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe -- End of file - 11262 bytes
-
[resolu] Je parais infecté!!!
maykiki a répondu à un(e) sujet de maykiki dans Analyses et éradication malwares
Merci dpour ces conseils @+ -
[resolu] Je parais infecté!!!
maykiki a répondu à un(e) sujet de maykiki dans Analyses et éradication malwares
Oki merci a toi. Pour avoir des conseils par rapport aux logiciels que j utilise pour nettoyer mon pc par moment, je peux voir avec toi ou je dois aller sur le forum http://forum.zebulon.fr/optimisation-secur...ention-f52.html ?? -
[resolu] Je parais infecté!!!
maykiki a répondu à un(e) sujet de maykiki dans Analyses et éradication malwares
Hello! L installation Java n etatit pas possible car routeur eteint. Aucun probleme maintenant! Voila le rapport JavaRa que tu avais demande auparavant. Cela te sert il a qqch encore? Sinon, merci pour tout et @+ JavaRa 1.11 Removal Log. Report follows after line. ------------------------------------ The JavaRa removal process was started on Thu Nov 27 01:27:45 2008 There was an error removing C:\Program Files\Java\j2re1.4.2_03. The error returned was 32. Found and removed: C:\Program Files\Java\jre1.5.0_06 Found and removed: C:\Program Files\Java\jre1.5.0_11 There was an error removing C:\Program Files\Java\jre1.6.0_01. The error returned was 32. Found and removed: C:\Program Files\Java\jre1.6.0_02 Found and removed: C:\Program Files\Java\jre1.6.0_03 Found and removed: C:\Program Files\Java\jre1.6.0_04 Found and removed: C:\Program Files\Java\jre1.6.0_05 Found and removed: C:\Windows\Installer\{7148F0A8-6813-11D6-A77B-00B0D0142030} Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.4 Found and removed: Software\JavaSoft\Java2D\1.5.0_06 Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} Found and removed: SOFTWARE\Classes\Installer\Features\8A0F842331866D117AB7000B0D510006 Found and removed: SOFTWARE\Classes\Installer\Products\8A0F842331866D117AB7000B0D510006 Found and removed: SOFTWARE\Classes\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D510006 Found and removed: SOFTWARE\Classes\JavaPlugin.150_06 Found and removed: SOFTWARE\Classes\JavaWebStart.isInstalled.1.5.0.0 Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.5.0_06 Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.5 Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.5.0_06 Found and removed: SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACBB9B2318A96D117A58000B0D510006 Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F842331866D117AB7000B0D510006 Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3248F0A8-6813-11D6-A77B-00B0D0150060} Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBB} Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBB} Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBB} Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBC} Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBC} Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBC} Found and removed: SOFTWARE\Classes\Installer\Features\8A0F842331866D117AB7000B0D610003 Found and removed: SOFTWARE\Classes\Installer\Features\8A0F842331866D117AB7000B0D610004 Found and removed: SOFTWARE\Classes\Installer\Features\8A0F842331866D117AB7000B0D610005 Found and removed: SOFTWARE\Classes\Installer\Products\8A0F842331866D117AB7000B0D610003 Found and removed: SOFTWARE\Classes\Installer\Products\8A0F842331866D117AB7000B0D610004 Found and removed: SOFTWARE\Classes\Installer\Products\8A0F842331866D117AB7000B0D610005 Found and removed: SOFTWARE\Classes\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D610003 Found and removed: SOFTWARE\Classes\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D610004 Found and removed: SOFTWARE\Classes\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D610005 Found and removed: SOFTWARE\Classes\JavaPlugin.160_03 Found and removed: SOFTWARE\Classes\JavaPlugin.160_04 Found and removed: SOFTWARE\Classes\JavaPlugin.160_05 Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.6.0_03 Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.6.0_04 Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.6.0_05 Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.6.0_03 Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.6.0_04 Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.6.0_05 Found and removed: SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} Found and removed: SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} Found and removed: SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D610003 Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D610004 Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D610005 Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACBB9B2318A96D117A58000B0D610003 Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACBB9B2318A96D117A58000B0D610004 Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACBB9B2318A96D117A58000B0D610005 Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F842331866D117AB7000B0D610003 Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F842331866D117AB7000B0D610004 Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F842331866D117AB7000B0D610005 Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3248F0A8-6813-11D6-A77B-00B0D0160030} Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3248F0A8-6813-11D6-A77B-00B0D0160040} Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3248F0A8-6813-11D6-A77B-00B0D0160050} Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7148F0A8-6813-11D6-A77B-00B0D0142030} Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBB} Found and removed: SOFTWARE\Classes\Installer\Products\8A0F841731866D117AB7000B0D410203 Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F841731866D117AB7000B0D410203 Found and removed: SOFTWARE\Classes\JavaPlugin.142_03 Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.4.2_03 Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.4.2_03 Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.4.2_03 Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.5.0_06 Found and removed: SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} Found and removed: Software\Classes\JavaPlugin.142_03 Found and removed: Software\Classes\JavaPlugin.160_03 Found and removed: Software\Classes\JavaPlugin.160_04 Found and removed: Software\Classes\JavaPlugin.160_05 Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA} Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.5.0_06\ Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_03\ Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_04\ Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_05\ Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_03\bin\ Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_04\bin\ Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_05\bin\ Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1 Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_02 Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_03 Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_04 Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2 Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2.0_01 Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.6.0_03 Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.6.0_04 Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.6.0_05 Found and removed: Software\JavaSoft\Java2D\1.6.0 Found and removed: Software\JavaSoft\Java2D\1.6.0_03 Found and removed: Software\JavaSoft\Java2D\1.6.0_04 Found and removed: Software\JavaSoft\Java2D\1.6.0_05 Found and removed: Software\JavaSoft\Java Runtime Environment\1.6.0_03 Found and removed: Software\JavaSoft\Java Runtime Environment\1.6.0_05 Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBB} JavaRa 1.11 Removal Log. Report follows after line. ------------------------------------ The JavaRa removal process was started on Thu Nov 27 01:32:03 2008 There was an error removing C:\Program Files\Java\j2re1.4.2_03. The error returned was 32. Found and removed: C:\Program Files\Java\jre1.6.0_01 ------------------------------------ Finished reporting. JavaRa 1.11 Removal Log. Report follows after line. ------------------------------------ The JavaRa removal process was started on Fri Nov 28 22:41:37 2008 Found and removed: C:\Program Files\Java\j2re1.4.2_03 There was an error removing C:\Program Files\Java\jre1.6.0_07. The error returned was 32. Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA} Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1 Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_02 Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_03 Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_04 Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2 Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2.0_01 Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBB} ------------------------------------ Finished reporting. -
[resolu] Je parais infecté!!!
maykiki a répondu à un(e) sujet de maykiki dans Analyses et éradication malwares
Eureka! En ce qui concerne mon probleme d adresse ip, j avais tout simplement oublie de reouvrir mon router depuis que je me suis achete il y a quelques jours une WII que j ai relie via wifi a ma freebox!!!! Tout simplement. Par contre si tu peux quand meme terminer de me conseiller suite au rapport hijackthis ci dessus au cas ou il me faudrait effacer de nouvelles choses ou autre ...!!! -
[resolu] Je parais infecté!!!
maykiki a répondu à un(e) sujet de maykiki dans Analyses et éradication malwares
Bon, j ai essaye de faire tout ce que tu m a dit mise a part la mise a jour java comme indique ci dessus. Voila le rapport hijackthis. Par contre toujours ce probleme de conflit d adresse ip et je n y connais rien. A priori rien a voir avec une infection ce probleme! Que faire. Merci a toit. Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 22:22:54, on 27/11/2008 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16735) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\ZoneLabs\vsmon.exe C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe C:\Program Files\a-squared Free\a2service.exe C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe c:\xampp\apache\bin\apache.exe C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe C:\WINDOWS\system32\lxcrcoms.exe C:\Program Files\CDBurnerXP\NMSAccessU.exe C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe C:\WINDOWS\system32\svchost.exe C:\xampp\apache\bin\apache.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\ehome\ehtray.exe C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe C:\WINDOWS\system32\rundll32.exe C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe C:\WINDOWS\RTHDCPL.EXE C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe C:\Program Files\Lexmark 2400 Series\lxcrmon.exe C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe C:\Program Files\SimpleCenter\bin\win\sclauncher.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\NETGEAR\WG111v3\WG111v3.exe C:\PROGRA~1\FICHIE~1\Nokia\MPLATF~1\NOKIAM~1.EXE C:\HP\KBD\KBD.EXE c:\windows\system\hpsysdrv.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\WINDOWS\system32\rundll32.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe O4 - HKLM\..\Run: [iAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" O4 - HKLM\..\Run: [lxcrmon.exe] "C:\Program Files\Lexmark 2400 Series\lxcrmon.exe" O4 - HKLM\..\Run: [LXCRCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCRtime.dll,_RunDLLEntry@16 O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" O4 - HKLM\..\Run: [sclauncher] C:\Program Files\SimpleCenter\bin\win\sclauncher.exe O4 - HKLM\..\Run: [Nokia FastStart] "C:\Program Files\Nokia\Nokia Music\NokiaMusic.exe" /command:faststart O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU') O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user') O4 - .DEFAULT User Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe (User 'Default user') O4 - Global Startup: NETGEAR WG111v3 Smart Wizard.lnk = C:\Program Files\NETGEAR\WG111v3\WG111v3.exe O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/dow...llerControl.cab O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - http://gfx1.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} - http://messenger.zone.msn.com/binary/Bankshot.cab57213.cab O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} - http://messenger.zone.msn.com/binary/MineS...er.cab56986.cab O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe O23 - Service: Apache2.2 - Apache Software Foundation - c:\xampp\apache\bin\apache.exe O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: Intel® Quick Resume technology (ELService) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology Drivers\Elservice.exe O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe O23 - Service: lxcr_device - - C:\WINDOWS\system32\lxcrcoms.exe O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe -- End of file - 10710 bytes @+ -
[resolu] Je parais infecté!!!
maykiki a répondu à un(e) sujet de maykiki dans Analyses et éradication malwares
Re! Impossible de mettre a jour Java. A chaque fois aprees installation, je clique sur accepter et il me dit le programme d installation a ete interrompu. Et Javara, erreur a chaque fois! ah!!! Javara a fonctionné! -
[resolu] Je parais infecté!!!
maykiki a répondu à un(e) sujet de maykiki dans Analyses et éradication malwares
Merci a toi de m avoir repondu aussi vite! J ai supprime les keygen et les crack, il n y a plus aucune detection au niveau d antivir, quelques warning. Probleme de conflit toujours present. Voila les rapports! Avira AntiVir Personal Report file date: mercredi 26 novembre 2008 23:29 Scanning for 1054678 virus strains and unwanted programs. Licensed to: Avira AntiVir PersonalEdition Classic Serial number: 0000149996-ADJIE-0001 Platform: Windows XP Windows version: (Service Pack 3) [5.1.2600] Boot mode: Normally booted Username: SYSTEM Computer name: NOM-FB9B15D2723 Version information: BUILD.DAT : 8.2.0.337 16934 Bytes 18/11/2008 13:05:00 AVSCAN.EXE : 8.1.4.10 315649 Bytes 26/11/2008 21:17:20 AVSCAN.DLL : 8.1.4.0 40705 Bytes 18/07/2008 20:36:40 LUKE.DLL : 8.1.4.5 164097 Bytes 18/07/2008 20:36:41 LUKERES.DLL : 8.1.4.0 12033 Bytes 18/07/2008 20:36:41 ANTIVIR0.VDF : 7.1.0.0 15603712 Bytes 27/10/2008 21:42:18 ANTIVIR1.VDF : 7.1.0.56 411136 Bytes 09/11/2008 20:33:08 ANTIVIR2.VDF : 7.1.0.124 376832 Bytes 23/11/2008 17:17:00 ANTIVIR3.VDF : 7.1.0.143 133120 Bytes 26/11/2008 21:17:21 Engineversion : 8.2.0.35 AEVDF.DLL : 8.1.0.6 102772 Bytes 15/10/2008 20:32:38 AESCRIPT.DLL : 8.1.1.15 332156 Bytes 12/11/2008 20:33:07 AESCN.DLL : 8.1.1.5 123251 Bytes 07/11/2008 20:33:41 AERDL.DLL : 8.1.1.3 438645 Bytes 05/11/2008 20:34:04 AEPACK.DLL : 8.1.3.4 393591 Bytes 12/11/2008 20:33:06 AEOFFICE.DLL : 8.1.0.30 196986 Bytes 07/11/2008 20:33:40 AEHEUR.DLL : 8.1.0.71 1487222 Bytes 07/11/2008 20:33:39 AEHELP.DLL : 8.1.2.0 119159 Bytes 19/11/2008 17:05:42 AEGEN.DLL : 8.1.1.5 323956 Bytes 21/11/2008 17:11:20 AEEMU.DLL : 8.1.0.9 393588 Bytes 15/10/2008 20:32:31 AECORE.DLL : 8.1.5.1 172406 Bytes 21/11/2008 17:11:19 AEBB.DLL : 8.1.0.3 53618 Bytes 15/10/2008 20:32:29 AVWINLL.DLL : 1.0.0.12 15105 Bytes 18/07/2008 20:36:40 AVPREF.DLL : 8.0.2.0 38657 Bytes 18/07/2008 20:36:40 AVREP.DLL : 8.0.0.2 98344 Bytes 31/07/2008 20:38:00 AVREG.DLL : 8.0.0.1 33537 Bytes 18/07/2008 20:36:40 AVARKT.DLL : 1.0.0.23 307457 Bytes 18/04/2008 10:07:35 AVEVTLOG.DLL : 8.0.0.16 119041 Bytes 18/07/2008 20:36:40 SQLITE3.DLL : 3.3.17.1 339968 Bytes 18/04/2008 10:07:36 SMTPLIB.DLL : 1.2.0.23 28929 Bytes 18/07/2008 20:36:41 NETNT.DLL : 8.0.0.1 7937 Bytes 18/04/2008 10:07:36 RCIMAGE.DLL : 8.0.0.51 2371841 Bytes 18/07/2008 20:36:38 RCTEXT.DLL : 8.0.52.0 86273 Bytes 18/07/2008 20:36:38 Configuration settings for the scan: Jobname..........................: Complete system scan Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp Logging..........................: low Primary action...................: quarantine Secondary action.................: delete Scan master boot sector..........: on Scan boot sector.................: on Boot sectors.....................: C:, D:, E:, Process scan.....................: on Scan registry....................: on Search for rootkits..............: on Scan all files...................: Intelligent file selection Scan archives....................: on Recursion depth..................: 20 Smart extensions.................: on Macro heuristic..................: on File heuristic...................: medium Start of the scan: mercredi 26 novembre 2008 23:29 Starting search for hidden objects. '70659' objects were checked, '0' hidden objects were found. The scan of running processes will be started Scan process 'avwsc.exe' - '0' Module(s) have been scanned Scan process 'avscan.exe' - '1' Module(s) have been scanned Scan process 'sched.exe' - '1' Module(s) have been scanned Scan process 'avgnt.exe' - '1' Module(s) have been scanned Scan process 'avguard.exe' - '1' Module(s) have been scanned Scan process 'WG111v3.exe' - '1' Module(s) have been scanned Scan process 'hpsysdrv.exe' - '1' Module(s) have been scanned Scan process 'alg.exe' - '1' Module(s) have been scanned Scan process 'NOKIAM~1.EXE' - '1' Module(s) have been scanned Scan process 'kbd.exe' - '1' Module(s) have been scanned Scan process 'apache.exe' - '1' Module(s) have been scanned Scan process 'TeaTimer.exe' - '1' Module(s) have been scanned Scan process 'rundll32.exe' - '1' Module(s) have been scanned Scan process 'ctfmon.exe' - '1' Module(s) have been scanned Scan process 'sclauncher.exe' - '1' Module(s) have been scanned Scan process 'zlclient.exe' - '0' Module(s) have been scanned Scan process 'ezprint.exe' - '1' Module(s) have been scanned Scan process 'lxcrmon.exe' - '1' Module(s) have been scanned Scan process 'jusched.exe' - '1' Module(s) have been scanned Scan process 'RTHDCPL.EXE' - '1' Module(s) have been scanned Scan process 'IAAnotif.exe' - '1' Module(s) have been scanned Scan process 'ehtray.exe' - '1' Module(s) have been scanned Scan process 'explorer.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'StarWindServiceAE.exe' - '1' Module(s) have been scanned Scan process 'nvsvc32.exe' - '1' Module(s) have been scanned Scan process 'NMSAccessU.exe' - '1' Module(s) have been scanned Scan process 'lxcrcoms.exe' - '1' Module(s) have been scanned Scan process 'LSSrvc.exe' - '1' Module(s) have been scanned Scan process 'IAANTmon.exe' - '1' Module(s) have been scanned Scan process 'AppleMobileDeviceService.exe' - '1' Module(s) have been scanned Scan process 'apache.exe' - '1' Module(s) have been scanned Scan process 'a2service.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'spoolsv.exe' - '1' Module(s) have been scanned Scan process 'aawservice.exe' - '1' Module(s) have been scanned Scan process 'vsmon.exe' - '0' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'lsass.exe' - '1' Module(s) have been scanned Scan process 'services.exe' - '1' Module(s) have been scanned Scan process 'winlogon.exe' - '1' Module(s) have been scanned Scan process 'csrss.exe' - '1' Module(s) have been scanned Scan process 'smss.exe' - '1' Module(s) have been scanned 43 processes with 43 modules were scanned Starting master boot sector scan: Master boot sector HD0 [iNFO] No virus was found! Master boot sector HD1 [iNFO] No virus was found! [WARNING] System error [21]: Le périphérique n'est pas prêt. Master boot sector HD2 [iNFO] No virus was found! [WARNING] System error [21]: Le périphérique n'est pas prêt. Master boot sector HD3 [iNFO] No virus was found! [WARNING] System error [21]: Le périphérique n'est pas prêt. Master boot sector HD4 [iNFO] No virus was found! [WARNING] System error [21]: Le périphérique n'est pas prêt. Start scanning boot sectors: Boot sector 'C:\' [iNFO] No virus was found! Boot sector 'D:\' [iNFO] No virus was found! Boot sector 'E:\' [iNFO] No virus was found! Starting to scan the registry. The registry was scanned ( '65' files ). Starting the file scan: Begin scan in 'C:\' <HP_PAVILION> C:\pagefile.sys [WARNING] The file could not be opened! C:\WINDOWS\system32\drivers\sptd.sys [WARNING] The file could not be opened! Begin scan in 'D:\' <Musique, Vidéo, Photos, Papiers> Begin scan in 'E:\' <HP_RECOVERY> End of the scan: jeudi 27 novembre 2008 00:32 Used time: 1:02:59 Hour(s) The scan has been done completely. 12631 Scanning directories 679395 Files were scanned 0 viruses and/or unwanted programs were found 0 Files were classified as suspicious: 0 files were deleted 0 files were repaired 0 files were moved to quarantine 0 files were renamed 2 Files cannot be scanned 679393 Files not concerned 18084 Archives were scanned 6 Warnings 0 Notes 70659 Objects were scanned with rootkit scan 0 Hidden objects were found Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 00:39:17, on 27/11/2008 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16735) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\ZoneLabs\vsmon.exe C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\a-squared Free\a2service.exe c:\xampp\apache\bin\apache.exe C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe C:\WINDOWS\system32\lxcrcoms.exe C:\Program Files\CDBurnerXP\NMSAccessU.exe C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\ehome\ehtray.exe C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe C:\WINDOWS\RTHDCPL.EXE C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe C:\Program Files\Lexmark 2400 Series\lxcrmon.exe C:\Program Files\Lexmark 2400 Series\ezprint.exe C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe C:\Program Files\SimpleCenter\bin\win\sclauncher.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\system32\rundll32.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\xampp\apache\bin\apache.exe C:\HP\KBD\KBD.EXE C:\PROGRA~1\FICHIE~1\Nokia\MPLATF~1\NOKIAM~1.EXE c:\windows\system\hpsysdrv.exe C:\Program Files\NETGEAR\WG111v3\WG111v3.exe C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe O4 - HKLM\..\Run: [iAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" O4 - HKLM\..\Run: [lxcrmon.exe] "C:\Program Files\Lexmark 2400 Series\lxcrmon.exe" O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 2400 Series\ezprint.exe" O4 - HKLM\..\Run: [LXCRCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCRtime.dll,_RunDLLEntry@16 O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" O4 - HKLM\..\Run: [sclauncher] C:\Program Files\SimpleCenter\bin\win\sclauncher.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [Nokia FastStart] "C:\Program Files\Nokia\Nokia Music\NokiaMusic.exe" /command:faststart O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe O4 - HKCU\..\Run: [uniblue RegistryBooster 2009] C:\Program Files\Uniblue\RegistryBooster\RegistryBooster.exe /S O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU') O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user') O4 - .DEFAULT User Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe (User 'Default user') O4 - Global Startup: NETGEAR WG111v3 Smart Wizard.lnk = C:\Program Files\NETGEAR\WG111v3\WG111v3.exe O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/dow...llerControl.cab O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - http://gfx1.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} - http://messenger.zone.msn.com/binary/Bankshot.cab57213.cab O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} - http://messenger.zone.msn.com/binary/MineS...er.cab56986.cab O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe O23 - Service: Apache2.2 - Apache Software Foundation - c:\xampp\apache\bin\apache.exe O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: Intel® Quick Resume technology (ELService) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology Drivers\Elservice.exe O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe O23 - Service: lxcr_device - - C:\WINDOWS\system32\lxcrcoms.exe O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe -- End of file - 11509 bytes -
Bonjour a tous! Alors avant tout je vous raconte les symptomes: Depuis peu j ai ma connexion internet (Free connecte par wifi) qui se plante et il apparait au niveau des icones en bas a droite j ai le triangle alerte qui m indique alerte systeme detectee! Il me faut alors eteindre ma connecion et la relancer et ca remarche. Au demarrage du pc bien souvent j ai le message conflit d adresse ip detectee. J ai essayer de reparer la connexion dont je me sers mais procedure impossible, impossible de lancer la procedure de nettoyage du cache DNS. J ai essaye en passant par cmd / ipconfig /flushdns, idem, impossible. Alors infecte ou non, je sais pas! J ai suivi votre procedure mais impossible de lancer antivir en mode sans echec, ca me marque "log database could not be initialized." J ai alors effectue le scan en mode normal. Voila les rapports, il apparait 9 infections mais je n y connais pas grand chose alors si quelqu un peut y jeter un coup d oeil et me debloquer cette connexion et le reste si besoin!!! Merci a vous! Avira AntiVir Personal Report file date: lundi 24 novembre 2008 22:20 Scanning for 1049308 virus strains and unwanted programs. Licensed to: Avira AntiVir PersonalEdition Classic Serial number: 0000149996-ADJIE-0001 Platform: Windows XP Windows version: (Service Pack 3) [5.1.2600] Boot mode: Normally booted Username: SYSTEM Computer name: NOM-FB9B15D2723 Version information: BUILD.DAT : 8.2.0.336 16933 Bytes 30/10/2008 11:40:00 AVSCAN.EXE : 8.1.4.7 315649 Bytes 18/07/2008 20:36:40 AVSCAN.DLL : 8.1.4.0 40705 Bytes 18/07/2008 20:36:40 LUKE.DLL : 8.1.4.5 164097 Bytes 18/07/2008 20:36:41 LUKERES.DLL : 8.1.4.0 12033 Bytes 18/07/2008 20:36:41 ANTIVIR0.VDF : 7.1.0.0 15603712 Bytes 27/10/2008 21:42:18 ANTIVIR1.VDF : 7.1.0.56 411136 Bytes 09/11/2008 20:33:08 ANTIVIR2.VDF : 7.1.0.124 376832 Bytes 23/11/2008 17:17:00 ANTIVIR3.VDF : 7.1.0.131 53248 Bytes 24/11/2008 17:17:01 Engineversion : 8.2.0.35 AEVDF.DLL : 8.1.0.6 102772 Bytes 15/10/2008 20:32:38 AESCRIPT.DLL : 8.1.1.15 332156 Bytes 12/11/2008 20:33:07 AESCN.DLL : 8.1.1.5 123251 Bytes 07/11/2008 20:33:41 AERDL.DLL : 8.1.1.3 438645 Bytes 05/11/2008 20:34:04 AEPACK.DLL : 8.1.3.4 393591 Bytes 12/11/2008 20:33:06 AEOFFICE.DLL : 8.1.0.30 196986 Bytes 07/11/2008 20:33:40 AEHEUR.DLL : 8.1.0.71 1487222 Bytes 07/11/2008 20:33:39 AEHELP.DLL : 8.1.2.0 119159 Bytes 19/11/2008 17:05:42 AEGEN.DLL : 8.1.1.5 323956 Bytes 21/11/2008 17:11:20 AEEMU.DLL : 8.1.0.9 393588 Bytes 15/10/2008 20:32:31 AECORE.DLL : 8.1.5.1 172406 Bytes 21/11/2008 17:11:19 AEBB.DLL : 8.1.0.3 53618 Bytes 15/10/2008 20:32:29 AVWINLL.DLL : 1.0.0.12 15105 Bytes 18/07/2008 20:36:40 AVPREF.DLL : 8.0.2.0 38657 Bytes 18/07/2008 20:36:40 AVREP.DLL : 8.0.0.2 98344 Bytes 31/07/2008 20:38:00 AVREG.DLL : 8.0.0.1 33537 Bytes 18/07/2008 20:36:40 AVARKT.DLL : 1.0.0.23 307457 Bytes 18/04/2008 10:07:35 AVEVTLOG.DLL : 8.0.0.16 119041 Bytes 18/07/2008 20:36:40 SQLITE3.DLL : 3.3.17.1 339968 Bytes 18/04/2008 10:07:36 SMTPLIB.DLL : 1.2.0.23 28929 Bytes 18/07/2008 20:36:41 NETNT.DLL : 8.0.0.1 7937 Bytes 18/04/2008 10:07:36 RCIMAGE.DLL : 8.0.0.51 2371841 Bytes 18/07/2008 20:36:38 RCTEXT.DLL : 8.0.52.0 86273 Bytes 18/07/2008 20:36:38 Configuration settings for the scan: Jobname..........................: Complete system scan Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp Logging..........................: low Primary action...................: interactive Secondary action.................: ignore Scan master boot sector..........: on Scan boot sector.................: on Boot sectors.....................: C:, D:, E:, Process scan.....................: on Scan registry....................: on Search for rootkits..............: on Scan all files...................: Intelligent file selection Scan archives....................: on Recursion depth..................: 20 Smart extensions.................: on Macro heuristic..................: on File heuristic...................: medium Start of the scan: lundi 24 novembre 2008 22:20 Starting search for hidden objects. '70709' objects were checked, '0' hidden objects were found. The scan of running processes will be started Scan process 'avscan.exe' - '1' Module(s) have been scanned Scan process 'avcenter.exe' - '1' Module(s) have been scanned Scan process 'hpsysdrv.exe' - '1' Module(s) have been scanned Scan process 'wuauclt.exe' - '1' Module(s) have been scanned Scan process 'kbd.exe' - '1' Module(s) have been scanned Scan process 'NOKIAM~1.EXE' - '1' Module(s) have been scanned Scan process 'alg.exe' - '1' Module(s) have been scanned Scan process 'apache.exe' - '1' Module(s) have been scanned Scan process 'wmiprvse.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'StarWindServiceAE.exe' - '1' Module(s) have been scanned Scan process 'nvsvc32.exe' - '1' Module(s) have been scanned Scan process 'NMSAccessU.exe' - '1' Module(s) have been scanned Scan process 'lxcrcoms.exe' - '1' Module(s) have been scanned Scan process 'LSSrvc.exe' - '1' Module(s) have been scanned Scan process 'IAANTmon.exe' - '1' Module(s) have been scanned Scan process 'AppleMobileDeviceService.exe' - '1' Module(s) have been scanned Scan process 'apache.exe' - '1' Module(s) have been scanned Scan process 'sched.exe' - '1' Module(s) have been scanned Scan process 'a2service.exe' - '1' Module(s) have been scanned Scan process 'WG111v3.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'RegistryBooster.exe' - '1' Module(s) have been scanned Scan process 'TeaTimer.exe' - '1' Module(s) have been scanned Scan process 'ctfmon.exe' - '1' Module(s) have been scanned Scan process 'sclauncher.exe' - '1' Module(s) have been scanned Scan process 'zlclient.exe' - '0' Module(s) have been scanned Scan process 'ezprint.exe' - '1' Module(s) have been scanned Scan process 'lxcrmon.exe' - '1' Module(s) have been scanned Scan process 'rundll32.exe' - '1' Module(s) have been scanned Scan process 'jusched.exe' - '1' Module(s) have been scanned Scan process 'RTHDCPL.EXE' - '1' Module(s) have been scanned Scan process 'avgnt.exe' - '1' Module(s) have been scanned Scan process 'IAAnotif.exe' - '1' Module(s) have been scanned Scan process 'avguard.exe' - '1' Module(s) have been scanned Scan process 'ehtray.exe' - '1' Module(s) have been scanned Scan process 'spoolsv.exe' - '1' Module(s) have been scanned Scan process 'explorer.exe' - '1' Module(s) have been scanned Scan process 'aawservice.exe' - '1' Module(s) have been scanned Scan process 'vsmon.exe' - '0' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'lsass.exe' - '1' Module(s) have been scanned Scan process 'services.exe' - '1' Module(s) have been scanned Scan process 'winlogon.exe' - '1' Module(s) have been scanned Scan process 'csrss.exe' - '1' Module(s) have been scanned Scan process 'smss.exe' - '1' Module(s) have been scanned 47 processes with 47 modules were scanned Starting master boot sector scan: Master boot sector HD0 [iNFO] No virus was found! Master boot sector HD1 [iNFO] No virus was found! [WARNING] System error [21]: Le périphérique n'est pas prêt. Master boot sector HD2 [iNFO] No virus was found! [WARNING] System error [21]: Le périphérique n'est pas prêt. Master boot sector HD3 [iNFO] No virus was found! [WARNING] System error [21]: Le périphérique n'est pas prêt. Master boot sector HD4 [iNFO] No virus was found! [WARNING] System error [21]: Le périphérique n'est pas prêt. Start scanning boot sectors: Boot sector 'C:\' [iNFO] No virus was found! Boot sector 'D:\' [iNFO] No virus was found! Boot sector 'E:\' [iNFO] No virus was found! Starting to scan the registry. The registry was scanned ( '65' files ). Starting the file scan: Begin scan in 'C:\' <HP_PAVILION> C:\hiberfil.sys [WARNING] The file could not be opened! C:\pagefile.sys [WARNING] The file could not be opened! C:\Program Files\eMule1\Incoming\Jeux Progs Nokia n95.rar [0] Archive type: RAR --> nokia N95 programmas & Games\Programma's\Best Full Screen Caller v2.00\Best Full Screen Caller 2.00 keygen.exe [DETECTION] Is the TR/Dldr.Agent.CQI Trojan --> nokia N95 programmas & Games\Programma's\Best TaskMan v1.00 s60v3\keygen.exe [DETECTION] Is the TR/Dropper.Gen Trojan --> nokia N95 programmas & Games\Programma's\Resco Photo Viewer For S60 3rd Edition v4.40\keygen.exe [DETECTION] Is the TR/Dropper.Gen Trojan --> nokia N95 programmas & Games\Programma's\Resco Photo Viewer v4.43 S60v3 Symbian OS9.1\keygen.exe [DETECTION] Is the TR/Dropper.Gen Trojan --> nokia N95 programmas & Games\Programma's\Smartphoneware AIO S60 9.1 3rd incl. Keygen\keygen.exe [DETECTION] Is the TR/Drop.VB.fhe Trojan --> nokia N95 programmas & Games\Programma's\Smartphoneware Best Full Screen Caller v2.0 S60 3rd\keygen.exe [DETECTION] Is the TR/Dldr.Agent.CQI Trojan --> nokia N95 programmas & Games\Programma's\Smartphoneware Best Message Storer v1.0\Smartphoneware Best Message Storer v1.0 keygen.exe [DETECTION] Is the TR/Dropper.Gen Trojan --> nokia N95 programmas & Games\Programma's\Smartphoneware Best Safe v1.0\keygen.exe [DETECTION] Is the TR/Dropper.Gen Trojan --> setup.exe [DETECTION] Contains recognition pattern of the WORM/P2P.Kapucen.Gen worm [NOTE] The file was moved to '49a021ff.qua'! C:\Program Files\eMule1\Temp\006.part [0] Archive type: ZIP --> OFFICE XP 2005 SP3 ( word excel access powerpoint frontpage ) FRENCH FRANCAIS no fake cracked by FRELON VERT/FILES/OSP/1036/IE5/FR/IELPKZHT.CAB [1] Archive type: CAB (Microsoft) --> ADVPACK.DLL [WARNING] No further files can be extracted from this archive. The archive will be closed --> OFFICE XP 2005 SP3 ( word excel access powerpoint frontpage ) FRENCH FRANCAIS no fake cracked by FRELON VERT/FILES/OSP/1036/IE5/FR/SCAIME.CAB [1] Archive type: CAB (Microsoft) --> dimm.dll [WARNING] No further files can be extracted from this archive. The archive will be closed C:\WINDOWS\system32\drivers\sptd.sys [WARNING] The file could not be opened! Begin scan in 'D:\' <Musique, Vidéo, Photos, Papiers> Begin scan in 'E:\' <HP_RECOVERY> End of the scan: lundi 24 novembre 2008 23:37 Used time: 1:16:45 Hour(s) The scan has been done completely. 12671 Scanning directories 733956 Files were scanned 9 viruses and/or unwanted programs were found 0 Files were classified as suspicious: 0 files were deleted 0 files were repaired 1 files were moved to quarantine 0 files were renamed 3 Files cannot be scanned 733944 Files not concerned 18751 Archives were scanned 9 Warnings 1 Notes 70709 Objects were scanned with rootkit scan 0 Hidden objects were found Logfile of HijackThis v1.99.1 Scan saved at 10:20:44, on 25/11/2008 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16735) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\ZoneLabs\vsmon.exe C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\ehome\ehtray.exe C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe C:\WINDOWS\RTHDCPL.EXE C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe C:\WINDOWS\system32\rundll32.exe C:\Program Files\Lexmark 2400 Series\lxcrmon.exe C:\Program Files\Lexmark 2400 Series\ezprint.exe C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe C:\Program Files\SimpleCenter\bin\win\sclauncher.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\Program Files\Uniblue\RegistryBooster\RegistryBooster.exe C:\Program Files\NETGEAR\WG111v3\WG111v3.exe C:\Program Files\a-squared Free\a2service.exe C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe c:\xampp\apache\bin\apache.exe C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe C:\WINDOWS\system32\lxcrcoms.exe C:\Program Files\CDBurnerXP\NMSAccessU.exe C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe C:\WINDOWS\system32\svchost.exe C:\xampp\apache\bin\apache.exe C:\PROGRA~1\FICHIE~1\Nokia\MPLATF~1\NOKIAM~1.EXE C:\HP\KBD\KBD.EXE c:\windows\system\hpsysdrv.exe C:\Program Files\hijackthis\Maykiki.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe O4 - HKLM\..\Run: [iAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" O4 - HKLM\..\Run: [lxcrmon.exe] "C:\Program Files\Lexmark 2400 Series\lxcrmon.exe" O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 2400 Series\ezprint.exe" O4 - HKLM\..\Run: [LXCRCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCRtime.dll,_RunDLLEntry@16 O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" O4 - HKLM\..\Run: [sclauncher] C:\Program Files\SimpleCenter\bin\win\sclauncher.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [Nokia FastStart] "C:\Program Files\Nokia\Nokia Music\NokiaMusic.exe" /command:faststart O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe O4 - HKCU\..\Run: [uniblue RegistryBooster 2009] C:\Program Files\Uniblue\RegistryBooster\RegistryBooster.exe /S O4 - Global Startup: NETGEAR WG111v3 Smart Wizard.lnk = C:\Program Files\NETGEAR\WG111v3\WG111v3.exe O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O11 - Options group: [iNTERNATIONAL] International* O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/dow...llerControl.cab O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - http://gfx1.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} - http://messenger.zone.msn.com/binary/Bankshot.cab57213.cab O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} - http://messenger.zone.msn.com/binary/MineS...er.cab56986.cab O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing) O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe O23 - Service: Apache2.2 - Unknown owner - c:\xampp\apache\bin\apache.exe" -k runservice (file missing) O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: Intel® Quick Resume technology (ELService) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology Drivers\Elservice.exe O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe O23 - Service: lxcr_device - - C:\WINDOWS\system32\lxcrcoms.exe O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
-
Hello a tous, J ai le pc d une amie pour y jeter un coup d oeil. elle trouve que celui ci rame enormement depuis quelques temps, plein de messages d alerte, des blocages d ecran... J ai tout nettoye avec differents logiciels et y a plus desormais de messages de spyware mais peu de changement pour le reste. De plus, comment retirer certaines traces dans les cles registres ineffacables comme celle de france telecom suite a un ancien abonnement internet? Il faut savoir que cette amie a internet haut debit depuis peu avec cet ancien pc et qu il n a que 256 de RAm ce qui peut peut etre etre responsable des ralentissements, non? Alors voila les rapports: AntiVir PersonalEdition Classic Report file date: mardi 21 août 2007 13:14 Scanning for 1026840 virus strains and unwanted programs. Licensed to: Avira AntiVir PersonalEdition Classic Serial number: 0000149996-ADJIE-0001 Platform: Windows XP Windows version: (Service Pack 2) [5.1.2600] Username: Parents Computer name: SZCRUPAK-PC Version information: BUILD.DAT : 247 14437 Bytes 10/05/2007 11:55:00 AVSCAN.EXE : 7.0.4.15 282664 Bytes 20/04/2007 11:37:14 AVSCAN.DLL : 7.0.4.4 33832 Bytes 27/03/2007 11:31:54 LUKE.DLL : 7.0.4.11 143400 Bytes 27/03/2007 11:26:04 LUKERES.DLL : 7.0.4.0 10280 Bytes 19/03/2007 11:18:59 ANTIVIR0.VDF : 6.35.0.1 7371264 Bytes 31/05/2006 13:08:58 ANTIVIR1.VDF : 6.39.0.129 7251968 Bytes 10/07/2007 19:44:51 ANTIVIR2.VDF : 6.39.1.15 1451008 Bytes 17/08/2007 18:48:18 ANTIVIR3.VDF : 6.39.1.17 2048 Bytes 18/08/2007 18:48:18 AVEWIN32.DLL : 7.4.1.62 2724352 Bytes 16/08/2007 18:46:17 AVWINLL.DLL : 1.0.0.7 14376 Bytes 26/02/2007 09:36:26 AVPREF.DLL : 7.0.2.1 24616 Bytes 27/03/2007 11:31:50 AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 12:16:24 AVPACK32.DLL : 7.3.0.15 360488 Bytes 05/08/2007 09:39:50 AVREG.DLL : 7.0.1.2 31784 Bytes 15/03/2007 08:05:08 AVEVTLOG.DLL : 7.0.0.18 86056 Bytes 27/03/2007 11:16:05 AVARKT.DLL : 1.0.0.17 278568 Bytes 02/05/2007 10:32:26 NETNT.DLL : 7.0.0.0 7720 Bytes 08/03/2007 10:09:42 RCIMAGE.DLL : 7.0.1.15 2228264 Bytes 13/03/2007 09:46:18 RCTEXT.DLL : 7.0.45.0 86056 Bytes 19/03/2007 11:42:42 Configuration settings for the scan: Jobname..........................: Local Drives Configuration file...............: C:\Program Files\AntiVir PersonalEdition Classic\alldrives.avp Logging..........................: low Primary action...................: interactive Secondary action.................: ignore Scan master boot sector..........: off Scan boot sector.................: on Boot sectors.....................: G:, Scan memory......................: on Process scan.....................: on Scan registry....................: on Search for rootkits..............: off Scan all files...................: Intelligent file selection Scan archives....................: on Recursion depth..................: 20 Smart extensions.................: on Macro heuristic..................: on File heuristic...................: medium Start of the scan: mardi 21 août 2007 13:14 The scan of running processes will be started Scan process 'avscan.exe' - '1' Module(s) have been scanned Scan process 'avcenter.exe' - '1' Module(s) have been scanned Scan process 'explorer.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'aawservice.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'lsass.exe' - '1' Module(s) have been scanned Scan process 'services.exe' - '1' Module(s) have been scanned Scan process 'winlogon.exe' - '1' Module(s) have been scanned Scan process 'csrss.exe' - '1' Module(s) have been scanned Scan process 'smss.exe' - '1' Module(s) have been scanned 12 processes with 12 modules were scanned Start scanning boot sectors: Boot sector 'C:\' [NOTE] No virus was found! Boot sector 'D:\' [NOTE] No virus was found! Boot sector 'E:\' [NOTE] No virus was found! Boot sector 'A:\' [NOTE] In the drive 'A:\' no data medium is inserted! Starting to scan the registry. The registry was scanned ( '9' files ). Starting the file scan: Begin scan in 'C:\' C:\pagefile.sys [WARNING] The file could not be opened! C:\WINDOWS\$NtUninstallKB824141_RTM$\user32.dll [WARNING] The file could not be opened! C:\WINDOWS\$NtUninstallKB824141_RTM$\win32k.sys [WARNING] The file could not be opened! C:\WINDOWS\$NtUninstallKB828035$\msgsvc.dll [WARNING] The file could not be opened! C:\WINDOWS\$NtUninstallKB828035$\wkssvc.dll [WARNING] The file could not be opened! C:\WINDOWS\$NtUninstallKB828035_RTM$\msgsvc.dll [WARNING] The file could not be opened! C:\WINDOWS\$NtUninstallKB828035_RTM$\wkssvc.dll [WARNING] The file could not be opened! C:\WINDOWS\$NtUninstallKB828741$\catsrv.dll [WARNING] The file could not be opened! C:\WINDOWS\$NtUninstallKB828741$\catsrvut.dll [WARNING] The file could not be opened! C:\WINDOWS\$NtUninstallKB828741$\clbcatex.dll [WARNING] The file could not be opened! C:\WINDOWS\$NtUninstallKB828741$\clbcatq.dll [WARNING] The file could not be opened! C:\WINDOWS\$NtUninstallKB828741$\colbact.dll [WARNING] The file could not be opened! C:\WINDOWS\$NtUninstallKB828741$\comadmin.dll [WARNING] The file could not be opened! C:\WINDOWS\$NtUninstallKB828741$\comsvcs.dll [WARNING] The file could not be opened! C:\WINDOWS\$NtUninstallKB828741$\comuid.dll [WARNING] The file could not be opened! C:\WINDOWS\$NtUninstallKB828741$\es.dll [WARNING] The file could not be opened! C:\WINDOWS\$NtUninstallKB828741$\msdtcprx.dll [WARNING] The file could not be opened! C:\WINDOWS\$NtUninstallKB828741$\msdtctm.dll [WARNING] The file could not be opened! C:\WINDOWS\$NtUninstallKB828741$\msdtcuiu.dll [WARNING] The file could not be opened! C:\WINDOWS\$NtUninstallKB828741$\mtxclu.dll [WARNING] The file could not be opened! C:\WINDOWS\$NtUninstallKB828741$\mtxoci.dll [WARNING] The file could not be opened! C:\WINDOWS\$NtUninstallKB828741$\ole32.dll [WARNING] The file could not be opened! C:\WINDOWS\$NtUninstallKB828741$\rpcrt4.dll [WARNING] The file could not be opened! C:\WINDOWS\$NtUninstallKB828741$\rpcss.dll [WARNING] The file could not be opened! C:\WINDOWS\$NtUninstallKB828741$\txflog.dll [WARNING] The file could not be opened! C:\WINDOWS\$NtUninstallKB828741_RTM$\catsrv.dll [WARNING] The file could not be opened! C:\WINDOWS\$NtUninstallKB828741_RTM$\catsrvut.dll [WARNING] The file could not be opened! C:\WINDOWS\$NtUninstallKB828741_RTM$\clbcatex.dll [WARNING] The file could not be opened! C:\WINDOWS\$NtUninstallKB828741_RTM$\clbcatq.dll [WARNING] The file could not be opened! C:\WINDOWS\$NtUninstallKB828741_RTM$\colbact.dll [WARNING] The file could not be opened! C:\WINDOWS\$NtUninstallKB828741_RTM$\comadmin.dll [WARNING] The file could not be opened! C:\WINDOWS\$NtUninstallKB828741_RTM$\comrepl.exe [WARNING] The file could not be opened! C:\WINDOWS\$NtUninstallKB828741_RTM$\comsvcs.dll [WARNING] The file could not be opened! C:\WINDOWS\$NtUninstallKB828741_RTM$\comuid.dll [WARNING] The file could not be opened! C:\WINDOWS\$NtUninstallKB828741_RTM$\es.dll [WARNING] The file could not be opened! C:\WINDOWS\$NtUninstallKB828741_RTM$\migregdb.exe [WARNING] The file could not be opened! C:\WINDOWS\$NtUninstallKB828741_RTM$\msdtcprx.dll [WARNING] The file could not be opened! C:\WINDOWS\$NtUninstallKB828741_RTM$\msdtctm.dll [WARNING] The file could not be opened! C:\WINDOWS\$NtUninstallKB828741_RTM$\msdtcuiu.dll [WARNING] The file could not be opened! C:\WINDOWS\$NtUninstallKB828741_RTM$\mtxclu.dll [WARNING] The file could not be opened! C:\WINDOWS\$NtUninstallKB828741_RTM$\mtxoci.dll [WARNING] The file could not be opened! C:\WINDOWS\$NtUninstallKB828741_RTM$\ole32.dll [WARNING] The file could not be opened! C:\WINDOWS\$NtUninstallKB828741_RTM$\rpcrt4.dll [WARNING] The file could not be opened! C:\WINDOWS\$NtUninstallKB828741_RTM$\rpcss.dll [WARNING] The file could not be opened! C:\WINDOWS\$NtUninstallKB828741_RTM$\txflog.dll [WARNING] The file could not be opened! C:\WINDOWS\$NtUninstallKB835732$\callcont.dll [WARNING] The file could not be opened! C:\WINDOWS\$NtUninstallKB835732$\evtgprov.dll [WARNING] The file could not be opened! C:\WINDOWS\$NtUninstallKB835732$\h323msp.dll [WARNING] The file could not be opened! C:\WINDOWS\$NtUninstallKB835732$\ipnathlp.dll [WARNING] The file could not be opened! C:\WINDOWS\$NtUninstallKB835732$\lsasrv.dll [WARNING] The file could not be opened! C:\WINDOWS\$NtUninstallKB835732$\msasn1.dll [WARNING] The file could not be opened! C:\WINDOWS\$NtUninstallKB835732$\msgina.dll [WARNING] The file could not be opened! C:\WINDOWS\$NtUninstallKB835732$\mst120.dll [WARNING] The file could not be opened! C:\WINDOWS\$NtUninstallKB835732$\nmcom.dll [WARNING] The file could not be opened! C:\WINDOWS\$NtUninstallKB835732$\rtcdll.dll [WARNING] The file could not be opened! C:\WINDOWS\$NtUninstallKB835732$\schannel.dll [WARNING] The file could not be opened! C:\WINDOWS\$NtUninstallKB835732_RTM$\browser.dll [WARNING] The file could not be opened! C:\WINDOWS\$NtUninstallKB835732_RTM$\callcont.dll [WARNING] The file could not be opened! C:\WINDOWS\$NtUninstallKB835732_RTM$\gdi32.dll [WARNING] The file could not be opened! C:\WINDOWS\$NtUninstallKB835732_RTM$\h323msp.dll [WARNING] The file could not be opened! C:\WINDOWS\$NtUninstallKB835732_RTM$\ipnathlp.dll [WARNING] The file could not be opened! C:\WINDOWS\$NtUninstallKB835732_RTM$\lsasrv.dll [WARNING] The file could not be opened! C:\WINDOWS\$NtUninstallKB835732_RTM$\mf3216.dll [WARNING] The file could not be opened! C:\WINDOWS\$NtUninstallKB835732_RTM$\msasn1.dll [WARNING] The file could not be opened! C:\WINDOWS\$NtUninstallKB835732_RTM$\msgina.dll [WARNING] The file could not be opened! C:\WINDOWS\$NtUninstallKB835732_RTM$\mst120.dll [WARNING] The file could not be opened! C:\WINDOWS\$NtUninstallKB835732_RTM$\netapi32.dll [WARNING] The file could not be opened! C:\WINDOWS\$NtUninstallKB835732_RTM$\nmcom.dll [WARNING] The file could not be opened! C:\WINDOWS\$NtUninstallKB835732_RTM$\rtcdll.dll [WARNING] The file could not be opened! C:\WINDOWS\$NtUninstallKB835732_RTM$\schannel.dll [WARNING] The file could not be opened! C:\WINDOWS\$NtUninstallKB839645_RTM$\shell32.dll [WARNING] The file could not be opened! C:\WINDOWS\$NtUninstallQ309521$\dxmasf.dll [WARNING] The file could not be opened! C:\WINDOWS\$NtUninstallQ309521$\lsasrv.dll [WARNING] The file could not be opened! C:\WINDOWS\$NtUninstallQ309521$\sfcfiles.dll [WARNING] The file could not be opened! C:\WINDOWS\$NtUninstallQ309521$\ssdpapi.dll [WARNING] The file could not be opened! C:\WINDOWS\$NtUninstallQ309521$\ssdpsrv.dll [WARNING] The file could not be opened! C:\WINDOWS\$NtUninstallQ309521$\url.dll [WARNING] The file could not be opened! C:\WINDOWS\$NtUninstallQ309521$\wininet.dll [WARNING] The file could not be opened! C:\WINDOWS\$NtUninstallQ309521$\spuninst\spuninst.exe [WARNING] The file could not be opened! C:\WINDOWS\$NtUninstallQ315000$\netsetup.exe [WARNING] The file could not be opened! C:\WINDOWS\$NtUninstallQ315000$\ssdpapi.dll [WARNING] The file could not be opened! C:\WINDOWS\$NtUninstallQ315000$\ssdpsrv.dll [WARNING] The file could not be opened! C:\WINDOWS\$NtUninstallQ315000$\upnp.dll [WARNING] The file could not be opened! C:\WINDOWS\$NtUninstallQ315000$\spuninst\spuninst.exe [WARNING] The file could not be opened! C:\WINDOWS\$NtUninstallQ828026$\wmpcore.dll [WARNING] The file could not be opened! C:\WINDOWS\system32\drivers\sptd.sys [WARNING] The file could not be opened! Begin scan in 'D:\' <BACKUP> Begin scan in 'E:\' <RECOVER> Begin scan in 'A:\' Search path A:\ could not be opened! Le périphérique n'est pas prêt. Begin scan in 'F:\' Search path F:\ could not be opened! Le périphérique n'est pas prêt. Begin scan in 'G:\' <1300 Series> End of the scan: mardi 21 août 2007 14:51 Used time: 1:36:51 min The scan has been done completely. 3796 Scanning directories 234020 Files were scanned 0 viruses and/or unwanted programs were found 0 classified as suspicious: 0 files were deleted 0 files were repaired 0 files were moved to quarantine 0 files were renamed 86 Files cannot be scanned 234020 Files not concerned 2175 Archives were scanned 86 Warnings 8 Notes 0 Hidden objects were found Logfile of Trend Micro HijackThis v2.0.0 (BETA) Scan saved at 15:01:20, on 21/08/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\ZoneLabs\vsmon.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe C:\Program Files\a-squared Free\a2service.exe C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe C:\Program Files\AntiVir PersonalEdition Classic\sched.exe C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe C:\WINDOWS\system32\lxdccoms.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe C:\Program Files\inKline Global\PC Booster\PCBooster.exe C:\Program Files\Lexmark 1300 Series\lxdcamon.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Messenger\msmsgs.exe C:\Documents and Settings\Parents\Bureau\Sécurité\HiJackThis_v2.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://french.ircfast.com/index.php?rvs=hompag R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min O4 - HKLM\..\Run: [PC Booster] C:\Program Files\inKline Global\PC Booster\PCBooster.exe O4 - HKLM\..\Run: [lxdcmon.exe] "C:\Program Files\Lexmark 1300 Series\lxdcmon.exe" O4 - HKLM\..\Run: [lxdcamon] "C:\Program Files\Lexmark 1300 Series\lxdcamon.exe" O4 - HKLM\..\Run: [LXDCCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXDCtime.dll,_RunDLLEntry@16 O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file) O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - Unknown owner - C:\WINDOWS\System32\dmadmin.exe O23 - Service: Journal des événements (Eventlog) - Unknown owner - C:\WINDOWS\system32\services.exe O23 - Service: Service COM de gravage de CD IMAPI (ImapiService) - Unknown owner - C:\WINDOWS\System32\imapi.exe O23 - Service: lxdc_device - - C:\WINDOWS\system32\lxdccoms.exe O23 - Service: Partage de Bureau à distance NetMeeting (mnmsrvc) - Unknown owner - C:\WINDOWS\System32\mnmsrvc.exe O23 - Service: Plug-and-Play (PlugPlay) - Unknown owner - C:\WINDOWS\system32\services.exe O23 - Service: Gestionnaire de session d'aide sur le Bureau à distance (RDSessMgr) - Unknown owner - C:\WINDOWS\system32\sessmgr.exe O23 - Service: Carte à puce (SCardSvr) - Unknown owner - C:\WINDOWS\System32\SCardSvr.exe O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - Unknown owner - C:\Program Files\Spyware Doctor\svcntaux.exe O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe O23 - Service: Journaux et alertes de performance (SysmonLog) - Unknown owner - C:\WINDOWS\system32\smlogsvc.exe O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe O23 - Service: Cliché instantané de volume (VSS) - Unknown owner - C:\WINDOWS\System32\vssvc.exe O23 - Service: Carte de performance WMI (WmiApSrv) - Unknown owner - C:\WINDOWS\System32\wbem\wmiapsrv.exe -- End of file - 4785 bytes Merci, @ +
-
en fait j ai acces a presque rien de l onglet outiels comme le filtre anti ameconnage par exemple! Et dans le panneau de config aucune icone d option internet! aidez moi SVP! @+
-
Slt a tous. Il m est impossible depuis qq temps d avoir acces aus options internet explorer. Je clique dessus je vois la fenetre s ouvrir mais celle ci se referme aussitot. J ai du mal parametrer quelque chose au niveau securite peut etre ou autre mais je ne vois pas que faire. Cela fonctionnait avant et je suis l administrateur de ce pc! (enfin je crois bien lol) Merci de vos conseils et @+