

Superludi
Membres-
Compteur de contenus
19 -
Inscription
-
Dernière visite
Autres informations
-
Mes langues
Français
Superludi's Achievements

Junior Member (3/12)
0
Réputation sur la communauté
-
Un peu d'aide pour évaluer mon rapport hijackyhis svp...
Superludi a répondu à un(e) sujet de Superludi dans Sécurisation, prévention
Merci pour ton aide. En voyant le rapport, peux tu me dire si mon pc est infecté ou non? Bonne année 2009 -
Un peu d'aide pour évaluer mon rapport hijackyhis svp...
Superludi a posté un sujet dans Sécurisation, prévention
Bonjour la communauté, je souhaiterais un peu d'aide pour évaluer mon rapport hijackthis et éventuellement m'aider à supprimer ce qu'il faut pour optimiser mon pc. Merci. Voici le rapport: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 12:12:52, on 31/12/2008 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16762) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\WINDOWS\System32\Ati2evxx.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Eset\nod32krn.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\htpatch.exe C:\WINDOWS\system32\RunDll32.exe C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Program Files\ATI Technologies\ATI HydraVision\HydraDM.exe C:\Program Files\ATI Technologies\ATI HydraVision\HydraMD.exe C:\WINDOWS\System32\G-VGA.exe C:\Program Files\Prolific\USB Flash Disk Utility\PLBkMon.exe C:\WINDOWS\System32\HotfixQ0306270.exe C:\Program Files\Eset\nod32kui.exe C:\Program Files\ASUS\WLAN Card Utilities\Center.exe C:\Program Files\Belgacom\bin\sprtcmd.exe C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe C:\WINDOWS\System32\HPZipm12.exe C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe C:\Documents and Settings\Mélanie\Bureau\JavaRa\JavaRa.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Téléchargements\HiJackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.actu24.be/page/homepage/Dis/1.aspx R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll O4 - HKLM\..\Run: [HTpatch] C:\WINDOWS\htpatch.exe O4 - HKLM\..\Run: [siSUSBRG] C:\WINDOWS\SiSUSBrg.exe O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [HydraVisionDesktopManager] C:\Program Files\ATI Technologies\ATI HydraVision\HydraDM.exe O4 - HKLM\..\Run: [HydraVisionViewport] C:\Program Files\ATI Technologies\ATI HydraVision\HydraMD.exe O4 - HKLM\..\Run: [VGAUtil] C:\WINDOWS\System32\G-VGA.exe O4 - HKLM\..\Run: [Prolific_PLUtil] C:\Program Files\Prolific\USB Flash Disk Utility\PLBkMon.exe O4 - HKLM\..\Run: [PLFFAP] C:\WINDOWS\System32\HotfixQ0306270.exe O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [Control Center] C:\Program Files\ASUS\WLAN Card Utilities\Center.exe O4 - HKLM\..\Run: [belgacom] "C:\Program Files\Belgacom\bin\sprtcmd.exe" /P Belgacom O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe" O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" O4 - HKLM\..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user') O4 - Global Startup: hp psc 1000 series.lnk = ? O4 - Global Startup: hpoddt01.exe.lnk = ? O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://express.foto.com/ImageUploader5.cab O16 - DPF: {A73BAEFA-EE65-494D-BEDB-DD3E5A34FA98} (Image Uploader) - http://belgacom.extrafilm.be/ImageUploader4.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.adobe.com/pub/shockwave/...ash/swflash.cab O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: ASWLSVC - Unknown owner - C:\WINDOWS\System32\ASWLSVC.exe O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe -- End of file - 8593 bytes -
Neutralisation du système d'émulation?? (Résolu)
Superludi a répondu à un(e) sujet de Superludi dans Software
Bonne et mauvaise nouvelle. La bonne, le problème est résolu. La mauvaise c'est que mon lecteur dvd est out. D'ou le problème rencontré. J'ai essayé de lancer CoD par l'autre lecteur présent sur mon pc et ça fonctionne. Merci pour votre aide. -
Je suis de retour. J'ai tenté la manip en mode sans écec, mais ça n'a rien changé.
-
Bon j'ai désinstaller et redémarrer, mais le problème persiste. Concernant une éventuelle config qwerty, je confirme que les "lettres" correspondent tout à fait au clavier azerty. Dans les réglages de la barre de langues, j'étais réglé sur français (France). J'ai bien tenté français (Belgique).... et oui nul n'est parfait ...... mais ça ne change rien. please help me.
-
Bonjour, toutes les touches de mon pc ne correspondent pas exactement. Exemples: pour obtenir @ (Alt Gr + @) j'obtiens ~ la touche - juste à gauche du backspace me donne = pour obtenir ! je dois pousser sur le + juste à droite du shift droit Je sais qu'il n'y a pas grand chose à faire, mais je ne sais plus quoi exactement. MERCI POUR VOS CONSEILS
-
Neutralisation du système d'émulation?? (Résolu)
Superludi a répondu à un(e) sujet de Superludi dans Software
OS? BdR? Je suis un peu comme qui dirait novice.... -
Neutralisation du système d'émulation?? (Résolu)
Superludi a répondu à un(e) sujet de Superludi dans Software
J'avais bien Deamon tools avant. C'est maintenant qu'il est désinstaller, que le problème apparaît. C'est pourtant une version originale de CoD. -
Neutralisation du système d'émulation?? (Résolu)
Superludi a répondu à un(e) sujet de Superludi dans Software
Salut. Aucune idée? Je vois même pas pourquoi devrais-je avoir un système d'émulation pour CoD.... Du temps ou il fonctionnait, j'avais Deamon tools installé sur mon pc. Voilà tout ce quq je sais dire. -
Bonjour, je rencontre ce message au lancement de call of duty. http://www.hiboox.fr/go/images/informatiqu...102316.jpg.html Ce jeu fonctionnait très bien il y a quelques mois. Maintenant il ne veut plus se lancer. Quelqu'un peut-il m'aider? Merci
-
[resolu]Encore un rapport Hijackthis...
Superludi a répondu à un(e) sujet de Superludi dans Analyses et éradication malwares
Voilà, le scan MBAM est effectué. il m'a encore touvé une infection. Je te remercie mille fois pour le temps consacré à mon problème. Je tiens zébulon à l'oeil.... c'est extrêmement pratique. J'ai également une autre machine, qui fonctionne presque bien. Si j'ai un peu de temps, je vous sonderai une nouvelle fois. Euh au fait, comment indique t on résolu? Ludo -
[resolu]Encore un rapport Hijackthis...
Superludi a répondu à un(e) sujet de Superludi dans Analyses et éradication malwares
Mon pc est déjà nettement plus fonctionnel. Il démarre au qurt de tour. Dois=je encore effectuer l'une ou l'autre manip (suite au rapport antivir et java) ou puis je mettre résolu dans le titre? Merci, Ludo -
[resolu]Encore un rapport Hijackthis...
Superludi a répondu à un(e) sujet de Superludi dans Analyses et éradication malwares
Et voilà le rapport après scan par antivir: Avira AntiVir Personal Report file date: mercredi 10 septembre 2008 13:57 Scanning for 1607897 virus strains and unwanted programs. Licensed to: Avira AntiVir PersonalEdition Classic Serial number: 0000149996-ADJIE-0001 Platform: Windows XP Windows version: (Service Pack 2) [5.1.2600] Boot mode: Normally booted Username: SYSTEM Computer name: GRAND-CRU Version information: BUILD.DAT : 8.1.0.331 16934 Bytes 12/08/2008 11:46:00 AVSCAN.EXE : 8.1.4.7 315649 Bytes 26/06/2008 08:57:53 AVSCAN.DLL : 8.1.4.0 40705 Bytes 26/05/2008 07:56:40 LUKE.DLL : 8.1.4.5 164097 Bytes 12/06/2008 12:44:19 LUKERES.DLL : 8.1.4.0 12033 Bytes 26/05/2008 07:58:52 ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 10:33:34 ANTIVIR1.VDF : 7.0.5.1 8182784 Bytes 24/06/2008 13:54:15 ANTIVIR2.VDF : 7.0.6.94 2998784 Bytes 31/08/2008 10:02:01 ANTIVIR3.VDF : 7.0.6.140 308736 Bytes 10/09/2008 11:57:09 Engineversion : 8.1.1.28 AEVDF.DLL : 8.1.0.5 102772 Bytes 25/02/2008 09:58:21 AESCRIPT.DLL : 8.1.0.70 319866 Bytes 10/09/2008 10:02:07 AESCN.DLL : 8.1.0.23 119156 Bytes 10/07/2008 12:44:49 AERDL.DLL : 8.1.1.1 397683 Bytes 10/09/2008 10:02:06 AEPACK.DLL : 8.1.2.1 364917 Bytes 15/07/2008 12:58:35 AEOFFICE.DLL : 8.1.0.23 196987 Bytes 10/09/2008 10:02:05 AEHEUR.DLL : 8.1.0.51 1397111 Bytes 10/09/2008 10:02:05 AEHELP.DLL : 8.1.0.15 115063 Bytes 10/07/2008 12:44:48 AEGEN.DLL : 8.1.0.36 315764 Bytes 10/09/2008 10:02:03 AEEMU.DLL : 8.1.0.7 430452 Bytes 31/07/2008 08:33:21 AECORE.DLL : 8.1.1.11 172406 Bytes 10/09/2008 10:02:03 AEBB.DLL : 8.1.0.1 53617 Bytes 10/07/2008 12:44:48 AVWINLL.DLL : 1.0.0.12 15105 Bytes 09/07/2008 08:40:05 AVPREF.DLL : 8.0.2.0 38657 Bytes 16/05/2008 09:28:01 AVREP.DLL : 8.0.0.2 98344 Bytes 10/09/2008 10:02:02 AVREG.DLL : 8.0.0.1 33537 Bytes 09/05/2008 11:26:40 AVARKT.DLL : 1.0.0.23 307457 Bytes 12/02/2008 08:29:23 AVEVTLOG.DLL : 8.0.0.16 119041 Bytes 12/06/2008 12:27:49 SQLITE3.DLL : 3.3.17.1 339968 Bytes 22/01/2008 17:28:02 SMTPLIB.DLL : 1.2.0.23 28929 Bytes 12/06/2008 12:49:40 NETNT.DLL : 8.0.0.1 7937 Bytes 25/01/2008 12:05:10 RCIMAGE.DLL : 8.0.0.51 2371841 Bytes 12/06/2008 13:48:07 RCTEXT.DLL : 8.0.52.0 86273 Bytes 27/06/2008 13:34:37 Configuration settings for the scan: Jobname..........................: Complete system scan Configuration file...............: C:\Program Files\Avira\AntiVir PersonalEdition Classic\sysscan.avp Logging..........................: low Primary action...................: interactive Secondary action.................: ignore Scan master boot sector..........: on Scan boot sector.................: on Boot sectors.....................: C:, Process scan.....................: on Scan registry....................: on Search for rootkits..............: off Scan all files...................: Intelligent file selection Scan archives....................: on Recursion depth..................: 20 Smart extensions.................: on Macro heuristic..................: on File heuristic...................: medium Start of the scan: mercredi 10 septembre 2008 13:57 The scan of running processes will be started Scan process 'avscan.exe' - '1' Module(s) have been scanned Scan process 'avcenter.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'avgnt.exe' - '1' Module(s) have been scanned Scan process 'avguard.exe' - '1' Module(s) have been scanned Scan process 'sched.exe' - '1' Module(s) have been scanned Scan process 'IEXPLORE.EXE' - '1' Module(s) have been scanned Scan process 'explorer.exe' - '1' Module(s) have been scanned Scan process 'wuauclt.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'ctfmon.exe' - '1' Module(s) have been scanned Scan process 'sprtcmd.exe' - '1' Module(s) have been scanned Scan process 'Center.exe' - '1' Module(s) have been scanned Scan process 'ipoint.exe' - '1' Module(s) have been scanned Scan process 'type32.exe' - '1' Module(s) have been scanned Scan process 'hpotdd01.exe' - '1' Module(s) have been scanned Scan process 'hpztsb09.exe' - '1' Module(s) have been scanned Scan process 'hpcmpmgr.exe' - '1' Module(s) have been scanned Scan process 'hpwuSchd.exe' - '1' Module(s) have been scanned Scan process 'G-vga.exe' - '1' Module(s) have been scanned Scan process 'PDVDServ.exe' - '1' Module(s) have been scanned Scan process 'ALCWZRD.EXE' - '1' Module(s) have been scanned Scan process 'SOUNDMAN.EXE' - '1' Module(s) have been scanned Scan process 'ati2evxx.exe' - '1' Module(s) have been scanned Scan process 'alg.exe' - '1' Module(s) have been scanned Scan process 'GoogleUpdaterService.exe' - '1' Module(s) have been scanned Scan process 'guard.exe' - '1' Module(s) have been scanned Scan process 'spoolsv.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'MsMpEng.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'ati2evxx.exe' - '1' Module(s) have been scanned Scan process 'lsass.exe' - '1' Module(s) have been scanned Scan process 'services.exe' - '1' Module(s) have been scanned Scan process 'winlogon.exe' - '1' Module(s) have been scanned Scan process 'csrss.exe' - '1' Module(s) have been scanned Scan process 'smss.exe' - '1' Module(s) have been scanned 40 processes with 40 modules were scanned Starting master boot sector scan: Master boot sector HD0 [iNFO] No virus was found! Start scanning boot sectors: Boot sector 'C:\' [iNFO] No virus was found! Starting to scan the registry. The registry was scanned ( '54' files ). Starting the file scan: Begin scan in 'C:\' C:\pagefile.sys [WARNING] The file could not be opened! C:\Program Files\eMule\Temp\001.part [0] Archive type: RAR --> lc5setup.exe [1] Archive type: CAB SFX (self extracting) --> \Disk1\CVS\Repository [WARNING] No further files can be extracted from this archive. The archive will be closed C:\System Volume Information\_restore{D828316C-1C6B-4A4C-BF12-2841A558EEB4}\RP221\A0091117.exe [0] Archive type: HIDDEN --> FIL\\\?\C:\System Volume Information\_restore{D828316C-1C6B-4A4C-BF12-2841A558EEB4}\RP221\A0091117.exe [DETECTION] Is the TR/Crypt.ULPM.Gen Trojan [NOTE] The file was deleted! C:\System Volume Information\_restore{D828316C-1C6B-4A4C-BF12-2841A558EEB4}\RP221\A0091118.exe [0] Archive type: HIDDEN --> FIL\\\?\C:\System Volume Information\_restore{D828316C-1C6B-4A4C-BF12-2841A558EEB4}\RP221\A0091118.exe [DETECTION] Is the TR/Crypt.ULPM.Gen Trojan [NOTE] The file was deleted! C:\System Volume Information\_restore{D828316C-1C6B-4A4C-BF12-2841A558EEB4}\RP221\A0091119.exe [0] Archive type: HIDDEN --> FIL\\\?\C:\System Volume Information\_restore{D828316C-1C6B-4A4C-BF12-2841A558EEB4}\RP221\A0091119.exe [DETECTION] Is the TR/Crypt.ULPM.Gen Trojan [NOTE] The file was deleted! C:\System Volume Information\_restore{D828316C-1C6B-4A4C-BF12-2841A558EEB4}\RP221\A0091120.exe [0] Archive type: HIDDEN --> FIL\\\?\C:\System Volume Information\_restore{D828316C-1C6B-4A4C-BF12-2841A558EEB4}\RP221\A0091120.exe [DETECTION] Is the TR/Obfuscated.EN.383 Trojan [NOTE] The file was deleted! C:\System Volume Information\_restore{D828316C-1C6B-4A4C-BF12-2841A558EEB4}\RP221\A0091121.exe [0] Archive type: HIDDEN --> FIL\\\?\C:\System Volume Information\_restore{D828316C-1C6B-4A4C-BF12-2841A558EEB4}\RP221\A0091121.exe [DETECTION] Is the TR/Obfuscated.EN.209 Trojan [NOTE] The file was deleted! C:\System Volume Information\_restore{D828316C-1C6B-4A4C-BF12-2841A558EEB4}\RP221\A0091123.exe [0] Archive type: HIDDEN --> FIL\\\?\C:\System Volume Information\_restore{D828316C-1C6B-4A4C-BF12-2841A558EEB4}\RP221\A0091123.exe [DETECTION] Is the TR/Obfuscated.EN.383 Trojan [NOTE] The file was deleted! C:\System Volume Information\_restore{D828316C-1C6B-4A4C-BF12-2841A558EEB4}\RP221\A0091124.exe [0] Archive type: HIDDEN --> FIL\\\?\C:\System Volume Information\_restore{D828316C-1C6B-4A4C-BF12-2841A558EEB4}\RP221\A0091124.exe [DETECTION] Is the TR/Obfuscated.EN.146 Trojan [NOTE] The file was deleted! C:\System Volume Information\_restore{D828316C-1C6B-4A4C-BF12-2841A558EEB4}\RP221\A0091126.exe [0] Archive type: HIDDEN --> FIL\\\?\C:\System Volume Information\_restore{D828316C-1C6B-4A4C-BF12-2841A558EEB4}\RP221\A0091126.exe [DETECTION] Is the TR/Dldr.IstBar.32000 Trojan [NOTE] The file was deleted! C:\System Volume Information\_restore{D828316C-1C6B-4A4C-BF12-2841A558EEB4}\RP229\A0093861.cpl [DETECTION] Contains recognition pattern of the PHISH/FraudTool.MSAntivirus.X phishing file/email [NOTE] The file was deleted! C:\System Volume Information\_restore{D828316C-1C6B-4A4C-BF12-2841A558EEB4}\RP229\A0093862.exe [DETECTION] Is the TR/Fake.UltimaAV.bh Trojan [NOTE] The file was deleted! C:\System Volume Information\_restore{D828316C-1C6B-4A4C-BF12-2841A558EEB4}\RP230\A0093978.exe [0] Archive type: RAR SFX (self extracting) --> MSA.cpl [DETECTION] Contains recognition pattern of the PHISH/FraudTool.MSAntivirus.X phishing file/email --> MSA.exe [DETECTION] Is the TR/Fake.UltimaAV.bh Trojan [NOTE] The file was deleted! C:\System Volume Information\_restore{D828316C-1C6B-4A4C-BF12-2841A558EEB4}\RP230\A0093982.exe [DETECTION] Is the TR/Spy.Frauder.dk Trojan [NOTE] The file was deleted! C:\System Volume Information\_restore{D828316C-1C6B-4A4C-BF12-2841A558EEB4}\RP230\A0093983.dll [DETECTION] Is the TR/Vundo.Gen Trojan [NOTE] The file was deleted! C:\System Volume Information\_restore{D828316C-1C6B-4A4C-BF12-2841A558EEB4}\RP230\A0093984.dll [DETECTION] Is the TR/Vundo.Gen Trojan [NOTE] The file was deleted! C:\System Volume Information\_restore{D828316C-1C6B-4A4C-BF12-2841A558EEB4}\RP230\A0093985.dll [DETECTION] Is the TR/Vundo.Gen Trojan [NOTE] The file was deleted! C:\System Volume Information\_restore{D828316C-1C6B-4A4C-BF12-2841A558EEB4}\RP230\A0093986.dll [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan [NOTE] The file was deleted! C:\System Volume Information\_restore{D828316C-1C6B-4A4C-BF12-2841A558EEB4}\RP230\A0093987.dll [DETECTION] Is the TR/Vundo.Gen Trojan [NOTE] The file was deleted! C:\System Volume Information\_restore{D828316C-1C6B-4A4C-BF12-2841A558EEB4}\RP230\A0093988.dll [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan [NOTE] The file was deleted! C:\System Volume Information\_restore{D828316C-1C6B-4A4C-BF12-2841A558EEB4}\RP230\A0093989.dll [DETECTION] Is the TR/Vundo.Gen Trojan [NOTE] The file was deleted! C:\System Volume Information\_restore{D828316C-1C6B-4A4C-BF12-2841A558EEB4}\RP230\A0093990.dll [DETECTION] Is the TR/Vundo.Gen Trojan [NOTE] The file was deleted! C:\System Volume Information\_restore{D828316C-1C6B-4A4C-BF12-2841A558EEB4}\RP230\A0093991.dll [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan [NOTE] The file was deleted! C:\System Volume Information\_restore{D828316C-1C6B-4A4C-BF12-2841A558EEB4}\RP230\A0093992.dll [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan [NOTE] The file was deleted! C:\System Volume Information\_restore{D828316C-1C6B-4A4C-BF12-2841A558EEB4}\RP233\A0094448.cpl [DETECTION] Contains recognition pattern of the PHISH/FraudTool.MSAntivirus.X phishing file/email [NOTE] The file was deleted! End of the scan: mercredi 10 septembre 2008 14:46 Used time: 48:48 Minute(s) The scan has been done completely. 4521 Scanning directories 143321 Files were scanned 24 viruses and/or unwanted programs were found 0 Files were classified as suspicious: 23 files were deleted 0 files were repaired 0 files were moved to quarantine 0 files were renamed 1 Files cannot be scanned 143296 Files not concerned 781 Archives were scanned 2 Warnings 23 Notes -
[resolu]Encore un rapport Hijackthis...
Superludi a répondu à un(e) sujet de Superludi dans Analyses et éradication malwares
Merci. J'ai voulu vérifier si les anciennes versions java était bien désinstaller dans ajout/sup dans le panneau de config. Je n'y suis pas arriver car antivir a détecté une menace: http://www.hiboox.fr/go/images/informatiqu...4999bb.jpg.html Quelle option dois-je cocher? sup? quarantaine? Sinon voici le rapport java: JavaRa 1.11 Removal Log. Report follows after line. ------------------------------------ The JavaRa removal process was started on Wed Sep 10 12:44:57 2008 Could not delete: C:\Program Files\Java\jre1.5.0_11 Found and removed: Software\JavaSoft\Java2D\1.5.0_03 Found and removed: Software\JavaSoft\Java2D\1.5.0_11 Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} Found and removed: SOFTWARE\Classes\Installer\Features\8A0F842331866D117AB7000B0D511001 Found and removed: SOFTWARE\Classes\Installer\Products\8A0F842331866D117AB7000B0D511001 Found and removed: SOFTWARE\Classes\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D511001 Found and removed: SOFTWARE\Classes\JavaPlugin.150_11 Found and removed: SOFTWARE\Classes\JavaWebStart.isInstalled.1.5.0.0 Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.5.0_11 Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.5 Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.5.0_11 Found and removed: SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACBB9B2318A96D117A58000B0D511001 Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F842331866D117AB7000B0D511001 Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3248F0A8-6813-11D6-A77B-00B0D0150110} Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.5.0_11 Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA} Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.5.0_11\ Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1 Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_02 Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_03 Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_04 Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2 Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2.0_01 Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBB} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBA} Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBB} ------------------------------------ Finished reporting. -
[resolu]Encore un rapport Hijackthis...
Superludi a répondu à un(e) sujet de Superludi dans Analyses et éradication malwares
J'ai un petit problème. Lorsque j'arrive à cette étape: * Décompresse le fichier sur ton bureau (clic droit > Extraire tout) * Double-clique sur le répertoire JavaRa obtenu * Puis double-clique sur le fichier JavaRa.exe (le exe peut ne pas s'afficher) * Clique sur Search For Updates * Sélectionne Update Using jucheck.exe puis clique sur Search Le processus se bloque. Voir ci contre: http://www.hiboox.fr/go/images/informatiqu...7853f7.jpg.html Merci pour ton aide